This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

adware popup and pc slowing down

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys. I have having some pop-up from  "Ads-mini blocker" and I have noticed a slowing down on my laptop,

Please help.

 

OS Name Microsoft Windows 7 Home Premium
Version 6.1.7601 Service Pack 1 Build 7601
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name BHP
System Manufacturer Acer
System Model Aspire E1-771
System Type x64-based PC
Processor Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2601 Mhz, 2 Core(s), 4 Logical Processor(s)
BIOS Version/Date Insyde Corp. V1.17, 12/17/2013
SMBIOS Version 2.7
Windows Directory C:\Windows
System Directory C:\Windows\system32
Boot Device \Device\HarddiskVolume2
Locale United States
Hardware Abstraction Layer Version = "6.1.7601.17514"
User Name BHP\chakotay
Time Zone Atlantic Standard Time
Installed Physical Memory (RAM) 6.00 GB
Total Physical Memory 5.84 GB
Available Physical Memory 3.79 GB
Total Virtual Memory 11.7 GB
Available Virtual Memory 9.40 GB
Page File Space 5.84 GB
Page File C:\pagefile.sys
 

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.

  • Perform everything in the correct order. Sometimes one step requires the previous one.

  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.

  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.

  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.

  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.

  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.

  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

 
 
 
 
 
HijackThis is not the preferred initial scanning tool in this forum. With today's malware, a more comprehensive set of logs is required to determine the presence of malware.
 
 
 
 
Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)
 
  • Run FRST.

  • Don´t change one of the checkboxes and hit Scan.

  • Logfiles are created on your desktop.

  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

 
 
 
 
 Scan with aswMBR

Please download aswMBR ( 4.5MB ) to your desktop.
  • Double click the aswMBR.exe icon, and click Run.

  • There will be a short delay before the next dialog box comes up. Please just wait a minute or two.

  • When asked if you'd like to "download the latest Avast! virus definitions", click Yes.

  • Typically this is about a 100MB download so depending on your connection speed it can take a short while to download and become ready.

  • Click the Scan button to start the scan once the update has finished downloading

  • On completion of the scan, click the save log button, save it to your desktop, then copy and paste it in your next reply.

Note: There will also be a file on your desktop named MBR.dat do not delete this for now. It is an actual backup of the MBR (master boot record).

I have posted the results of the three scans:


 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
Ran by [removed] (administrator) on BHP on 16-07-2015 13:50:05
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(Kingsoft Corporation) C:\Program Files (x86)\kingsoft\kingsoft antivirus\kxescore.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
() C:\ProgramData\DatacardService\DCService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(http://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Kingsoft Corporation) C:\Program Files (x86)\kingsoft\kingsoft antivirus\kxetray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDirector11\PDR11.exe
(CyberLink) C:\Program Files\CyberLink\PowerDirector11\PDHanumanSvr.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmprph.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-10] (ELAN Microelectronics Corp.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM\…\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters).
HKLM-x32\…\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297024 2012-09-26] (NTI Corporation)
HKLM-x32\…\Run: [LManager] => [X]
HKLM-x32\…\Run: [kxesc] => c:\program files (x86)\kingsoft\kingsoft antivirus\kxetray.exe [1595056 2014-11-28] (Kingsoft Corporation)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\…\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-11-29] (Qualcomm®Atheros®)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: F - F:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {377237db-0f84-11e5-b616-2025648ad16f} - E:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {cf758d48-0996-11e5-9c81-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {cf758dc4-0996-11e5-9c81-2025648ad16f} - F:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {cf758ddc-0996-11e5-9c81-2025648ad16f} - F:\AutoRun.exe
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = facebook.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\Software\Microsoft\Internet Explorer\Main,Start Page = facebook.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-10-15] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{2BF3A20D-9269-4620-A48C-CDAC8C9EEC48}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{FAE97252-6038-418F-804C-1DCC4B89A53E}: [NameServer] 10.235.35.162 10.235.35.163
 
FireFox:
========
FF ProfilePath: C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: delta-homes
FF SelectedSearchEngine: delta-homes
FF Homepage: hxxp://www.delta-homes.com/?type=hp&ts;=1430820023&from;=wpm05053&uid;=ST500LT012-1DG142_S3P2KN68XXXXS3P2KN68
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-04-22] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-04-22] (Microsoft Corporation)
FF Extension: ReadyCoupon - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] [2015-05-05]
FF Extension: DealSSpacie - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] [2015-05-05]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\extensions\[removed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\extensions\[removed]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]
 
Chrome: 
=======
CHR Profile: C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-13]
CHR Extension: (Google Docs) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-13]
CHR Extension: (Google Drive) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-28]
CHR Extension: (YouTube) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-28]
CHR Extension: (Google Search) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-28]
CHR Extension: (Google Sheets) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-13]
CHR Extension: (Ed2kHelper) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk [2015-05-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-17]
CHR Extension: (SaveFrom.net helper) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdpljndcmbeikfnlflcggaipgnhiedbl [2015-06-03]
CHR Extension: (Google Wallet) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-28]
CHR Extension: (Gmail) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-28]
CHR Profile: C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-25]
CHR Extension: (Google Docs) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-25]
CHR Extension: (Google Drive) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-25]
CHR Extension: (YouTube) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-25]
CHR Extension: (チャットワーク) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cdnfjpioepnoeojoighemmpnaogcfagj [2015-06-25]
CHR Extension: (Google Search) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-25]
CHR Extension: (HelloSign for Gmail) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dciflieigdmogpmamcgbigingaodhnil [2015-06-25]
CHR Extension: (Google+) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2015-06-25]
CHR Extension: (Google Sheets) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-25]
CHR Extension: (HelloSign: Online signatures made easy) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kajjckmbclbffbpecfbiecehkfgopppd [2015-06-25]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-13]
CHR Extension: (SaveFrom.net helper) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdpljndcmbeikfnlflcggaipgnhiedbl [2015-06-25]
CHR Extension: (Hangouts) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-06-25]
CHR Extension: (Google Wallet) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-25]
CHR Extension: (Gmail) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-25]
CHR HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [mdpljndcmbeikfnlflcggaipgnhiedbl] - http://sf-addon.com/helper/chrome/updates-3.xml
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [318592 2013-11-29] (Windows (R) Win 7 DDK provider) [File not signed]
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 kxescore; c:\program files (x86)\kingsoft\kingsoft antivirus\kxescore.exe [123992 2014-11-28] (Kingsoft Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256576 2012-09-26] (NTI Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-09-12] ()
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026944 2015-07-08] (Enigma Software Group USA, LLC.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 41218fb7; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\SystemPromote\SystemPromote.dll",serv
S2 81bd61f5; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\BocaFunc\BocaFunc.dll",serv
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-11-29] (Qualcomm Atheros)
S3 CXPLRCAP; C:\Windows\System32\drivers\CxPlrCap.sys [235904 2010-01-06] (Conexant Systems, Inc.) [File not signed]
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-07-08] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-07-08] ()
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [252928 2010-04-30] (Huawei Technologies Co., Ltd.)
R0 kavbootc; C:\Windows\System32\drivers\kavbootc64.sys [31848 2014-11-28] (Kingsoft Corporation)
R1 KDHacker; c:\program files (x86)\kingsoft\kingsoft antivirus\security\kxescan\kdhacker64.sys [164696 2014-11-28] (Kingsoft Corporation)
R2 kisknl; C:\Windows\system32\drivers\kisknl.sys [210296 2014-11-28] (Kingsoft Corporation)
R4 KUsbGuard; C:\Program Files (x86)\kingsoft\kingsoft antivirus\kusbquery64.sys [18296 2014-11-28] (Kingsoft Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [128200 2013-06-19] (Qualcomm Atheros Co., Ltd.)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2004-04-01] (Padus, Inc.) [File not signed]
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-16 13:50 - 2015-07-16 13:50 - 00025753 _____ C:\Users\chakotay\Desktop\FRST.txt
2015-07-16 13:49 - 2015-07-16 13:50 - 00000000 ____D C:\FRST
2015-07-16 13:48 - 2015-07-16 13:48 - 02133504 _____ (Farbar) C:\Users\chakotay\Desktop\FRST64.exe
2015-07-16 07:25 - 2015-07-16 07:25 - 09494290 _____ C:\Users\chakotay\Downloads\After Effects Template - Broadcast News Package - Intro.mp4
2015-07-16 06:57 - 2015-07-16 07:28 - 00000000 ____D C:\Users\chakotay\Desktop\Cropover
2015-07-15 19:56 - 2014-06-08 01:31 - 00000644 _____ C:\Users\chakotay\Downloads\addon.xml
2015-07-15 19:54 - 2015-07-15 19:54 - 01008766 _____ C:\Users\chakotay\Downloads\PluginCreator.zip
2015-07-15 19:54 - 2015-07-15 19:54 - 00000000 ____D C:\Users\chakotay\Downloads\PluginCreator
2015-07-15 06:47 - 2015-07-09 13:58 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-15 06:47 - 2015-07-09 13:58 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-15 06:47 - 2015-07-09 13:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-15 06:47 - 2015-07-09 13:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-15 06:47 - 2015-07-02 17:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-07-15 06:47 - 2015-07-02 17:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-07-15 06:47 - 2015-07-02 16:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-07-15 06:47 - 2015-07-02 16:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-07-15 06:47 - 2015-07-02 16:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-07-15 06:47 - 2015-07-02 15:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-07-15 06:47 - 2015-06-26 22:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-07-15 06:47 - 2015-06-26 22:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-07-15 06:47 - 2015-06-26 21:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-07-15 06:47 - 2015-06-26 21:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-07-15 06:47 - 2015-06-25 04:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-15 06:47 - 2015-06-17 13:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-15 06:47 - 2015-06-17 13:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-07-15 06:47 - 2015-06-09 14:03 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-07-15 06:47 - 2015-06-09 14:03 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-07-15 06:47 - 2015-06-01 20:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-15 06:47 - 2015-06-01 19:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll
2015-07-15 06:46 - 2015-07-02 16:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-07-15 06:46 - 2015-07-02 16:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-07-15 06:46 - 2015-07-02 16:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-07-15 06:46 - 2015-07-02 16:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-07-15 06:46 - 2015-07-02 15:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-07-15 06:46 - 2015-07-02 14:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-07-15 06:46 - 2015-06-25 14:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-07-15 06:46 - 2015-06-25 13:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-07-15 06:46 - 2015-06-20 16:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-07-15 06:46 - 2015-06-20 15:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-07-15 06:46 - 2015-06-20 15:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-07-15 06:46 - 2015-06-20 15:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-07-15 06:46 - 2015-06-20 15:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-07-15 06:46 - 2015-06-20 15:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-07-15 06:46 - 2015-06-20 15:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-07-15 06:46 - 2015-06-20 15:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-07-15 06:46 - 2015-06-20 15:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-07-15 06:46 - 2015-06-20 15:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-07-15 06:46 - 2015-06-20 15:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-07-15 06:46 - 2015-06-20 15:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-07-15 06:46 - 2015-06-20 15:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-07-15 06:46 - 2015-06-20 15:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-07-15 06:46 - 2015-06-20 15:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-07-15 06:46 - 2015-06-20 15:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-07-15 06:46 - 2015-06-20 15:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-07-15 06:46 - 2015-06-20 14:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-07-15 06:46 - 2015-06-20 14:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-07-15 06:46 - 2015-06-20 14:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-07-15 06:46 - 2015-06-20 14:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-07-15 06:46 - 2015-06-20 14:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-07-15 06:46 - 2015-06-20 14:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-07-15 06:46 - 2015-06-19 14:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-07-15 06:46 - 2015-06-19 14:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-07-15 06:46 - 2015-06-19 14:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-07-15 06:46 - 2015-06-19 14:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-07-15 06:46 - 2015-06-19 14:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-07-15 06:46 - 2015-06-19 14:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-07-15 06:46 - 2015-06-19 14:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-07-15 06:46 - 2015-06-19 14:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-07-15 06:46 - 2015-06-19 14:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-07-15 06:46 - 2015-06-19 14:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-07-15 06:46 - 2015-06-19 13:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-07-15 06:46 - 2015-06-19 13:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-07-15 06:46 - 2015-06-19 13:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-07-15 06:46 - 2015-06-19 13:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-07-15 06:46 - 2015-06-19 13:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-07-15 06:46 - 2015-06-19 13:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-07-15 06:46 - 2015-06-19 13:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-07-15 06:46 - 2015-06-19 13:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-07-15 06:46 - 2015-06-19 13:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-07-15 06:45 - 2015-06-11 13:57 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-07-15 06:45 - 2015-06-11 13:57 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-07-15 06:45 - 2015-06-11 13:57 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-07-15 06:45 - 2015-06-11 13:56 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-07-15 06:45 - 2015-06-11 13:56 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-07-15 06:45 - 2015-06-11 13:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-07-15 06:45 - 2015-06-11 09:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-07-15 06:44 - 2015-07-09 13:59 - 00017856 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-07-15 06:44 - 2015-07-09 13:58 - 01085440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-07-15 06:44 - 2015-07-09 13:50 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-07-15 06:44 - 2015-07-04 14:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-15 06:44 - 2015-07-04 13:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-07-15 06:44 - 2015-07-03 13:56 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-07-15 06:44 - 2015-07-03 13:56 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-15 06:44 - 2015-07-03 13:56 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-07-15 06:44 - 2015-07-03 13:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-07-15 06:44 - 2015-07-03 12:52 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-15 06:44 - 2015-07-03 12:42 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-15 06:44 - 2015-07-01 16:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-07-15 06:44 - 2015-07-01 16:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-15 06:44 - 2015-07-01 16:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-07-15 06:44 - 2015-07-01 16:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-07-15 06:44 - 2015-07-01 16:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-07-15 06:44 - 2015-07-01 16:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-07-15 06:44 - 2015-07-01 16:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-07-15 06:44 - 2015-07-01 16:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-07-15 06:44 - 2015-07-01 16:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-07-15 06:44 - 2015-07-01 16:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-07-15 06:44 - 2015-07-01 16:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-07-15 06:44 - 2015-07-01 16:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-07-15 06:44 - 2015-07-01 16:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-07-15 06:44 - 2015-07-01 16:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-07-15 06:44 - 2015-07-01 16:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-07-15 06:44 - 2015-07-01 16:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-07-15 06:44 - 2015-07-01 15:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-15 06:44 - 2015-07-01 15:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-15 06:44 - 2015-07-01 15:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-15 06:44 - 2015-06-15 17:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-07-15 06:44 - 2015-06-15 17:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-15 06:44 - 2015-06-15 17:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-07-15 06:44 - 2015-06-15 17:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-07-15 06:44 - 2015-06-15 17:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-07-15 06:44 - 2015-06-15 17:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-15 06:44 - 2015-06-15 17:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-07-15 06:44 - 2015-06-15 17:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-07-15 06:44 - 2015-06-15 17:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-07-15 06:44 - 2015-06-15 17:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-07-15 06:44 - 2015-06-15 17:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-07-15 06:44 - 2015-06-15 17:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-07-15 06:44 - 2015-04-27 15:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-07-15 06:44 - 2015-04-27 15:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-07-15 06:44 - 2015-04-27 15:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-07-15 06:44 - 2015-04-27 15:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-07-13 22:42 - 2015-07-13 22:42 - 00003472 _____ C:\Windows\system32\Wimbledon Champions Novak Djokovic of Serbia, right, and Serena Williams of the US, dance on stage at the Wimbledon Champion dinner, at the Guildhall, London, Sunday, July 12, 2015. (Thomas Lov.jpg.lnk
2015-07-12 07:37 - 2015-07-12 07:37 - 00036313 _____ C:\Users\chakotay\.recently-used.xbel
2015-07-11 21:46 - 2015-07-11 21:46 - 06483456 _____ (Tim Kosse) C:\Users\chakotay\Downloads\FileZilla_3.12.0.2_win64-setup.exe
2015-07-11 21:32 - 2015-07-11 21:32 - 101356557 _____ C:\Users\chakotay\Desktop\Poetic7-11.mp4
2015-07-11 21:16 - 2015-07-11 21:24 - 683879516 _____ C:\Users\chakotay\Desktop\Poetic.m2ts
2015-07-08 15:23 - 2015-07-11 23:06 - 00001135 _____ C:\Users\chakotay\Desktop\SpyHunter.lnk
2015-07-08 15:23 - 2015-07-08 15:23 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Enigma Software Group
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\sh4ldr
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 _____ C:\autoexec.bat
2015-07-08 15:22 - 2015-07-08 15:22 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\chakotay\Downloads\SpyHunter-Installer.exe
2015-07-07 07:21 - 2015-07-07 07:21 - 00000000 _____ C:\Users\chakotay\Desktop\Live.csv
2015-07-06 07:59 - 2015-07-06 07:59 - 00013073 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day3.Highlights.Sat.Feed.MotorsTV.720p.X264.English.French-BF.torrent
2015-07-06 07:57 - 2015-07-06 07:57 - 00012813 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day2.Highlights.Sat.Feed.MotorsTV.720p.X264.English.French-BF.torrent
2015-07-06 07:56 - 2015-07-06 07:56 - 00012232 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day1.Highlights.Sat.Feed.720p.X264.English.Natural.Sounds-BF.torrent
2015-07-06 07:56 - 2015-07-06 07:56 - 00012232 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day1.Highlights.Sat.Feed.720p.X264.English.Natural.Sounds-BF (1).torrent
2015-07-06 07:49 - 2015-07-06 07:49 - 00012898 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day3.Highlights.BTSportHD.1080i.H264.English-BF.torrent
2015-07-02 10:51 - 2015-07-02 10:51 - 00000000 _____ C:\Users\chakotay\Downloads\noname
2015-07-01 14:52 - 2015-07-01 14:54 - 114225037 _____ C:\Users\chakotay\Downloads\Two.mp4
2015-07-01 10:23 - 2015-07-01 10:40 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (8)
2015-06-30 03:24 - 2015-06-30 03:24 - 11595328 _____ (New IT Solutions) C:\Users\chakotay\Downloads\4shared_Desktop_4.0.14.27377.exe
2015-06-27 00:37 - 2015-06-27 00:38 - 10060670 _____ C:\Users\chakotay\Downloads\RacingPostAndroid.apk
2015-06-25 13:28 - 2015-07-09 11:32 - 00000000 ____D C:\Users\chakotay\Desktop\OPEN
2015-06-25 13:27 - 2015-06-25 13:27 - 00000000 ____D C:\Users\chakotay\Downloads\plugin.video.france24 (1)
2015-06-25 13:26 - 2015-06-25 13:26 - 00121971 _____ C:\Users\chakotay\Downloads\plugin.video.france24.zip
2015-06-25 13:26 - 2015-06-25 13:26 - 00121971 _____ C:\Users\chakotay\Downloads\plugin.video.france24 (1).zip
2015-06-25 00:48 - 2015-06-25 00:48 - 00002986 _____ C:\Windows\System32\Tasks\{0750E579-12D8-41F8-ABE7-245FA68EE652}
2015-06-21 11:19 - 2015-06-24 06:58 - 00000000 ____D C:\Users\chakotay\Desktop\clothes
2015-06-20 06:48 - 2015-06-20 06:50 - 00171642 _____ C:\Users\chakotay\Desktop\Untitled.xcf
2015-06-17 21:41 - 2015-06-18 06:52 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (6)
2015-06-17 20:29 - 2015-06-17 20:29 - 00251963 _____ C:\ProgramData\1434587004.bdinstall.bin
2015-06-17 20:13 - 2015-06-17 20:13 - 00284176 _____ C:\Windows\Minidump\061715-26130-01.dmp
2015-06-17 18:57 - 2015-06-17 18:57 - 00519016 _____ (Biztree Inc.) C:\Users\chakotay\Downloads\Business-in-a-Box_setup.exe
2015-06-17 16:55 - 2015-06-17 17:12 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (3)
2015-06-17 12:25 - 2015-06-17 12:25 - 00170534 _____ C:\Users\chakotay\Desktop\Rocket Lawyer Interview.html
2015-06-17 12:25 - 2015-06-17 12:25 - 00000000 ____D C:\Users\chakotay\Desktop\Rocket Lawyer Interview_files
2015-06-17 12:15 - 2015-06-17 12:15 - 00284176 _____ C:\Windows\Minidump\061715-27861-01.dmp
2015-06-17 12:08 - 2015-06-17 12:08 - 00284176 _____ C:\Windows\Minidump\061715-28657-01.dmp
2015-06-17 10:46 - 2015-06-17 10:46 - 00074000 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2015-06-17 10:16 - 2015-06-17 10:16 - 00000385 _____ C:\Windows\system32\user_gensett.xml
2015-06-17 10:16 - 2015-06-17 10:16 - 00000385 _____ C:\Users\chakotay\AppData\Roaminguser_gensett.xml
2015-06-17 10:16 - 2015-06-17 10:16 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2015-06-17 10:15 - 2015-06-17 10:15 - 00000000 ____D C:\ProgramData\BDLogging
2015-06-17 10:15 - 2015-01-09 11:44 - 00074000 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
2015-06-17 10:15 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2015-06-17 10:00 - 2015-06-17 20:30 - 00000000 ____D C:\Program Files\Bitdefender
2015-06-17 10:00 - 2015-01-09 11:44 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll
2015-06-17 10:00 - 2015-01-09 11:44 - 00033360 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll
2015-06-17 09:59 - 2015-06-17 20:29 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2015-06-17 09:59 - 2015-06-17 09:59 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\QuickScan
2015-06-17 09:36 - 2015-06-17 09:36 - 02868840 _____ C:\Users\chakotay\Downloads\bitdefender_antivirus.exe
2015-06-17 08:56 - 2015-07-15 10:36 - 00000024 _____ C:\Users\chakotay\AppData\Roaming\appdataFr25.bin
2015-06-17 08:48 - 2015-06-17 08:48 - 00005933 _____ C:\Users\chakotay\Desktop\JRT.txt
2015-06-17 08:42 - 2015-06-17 08:42 - 00000207 _____ C:\Windows\tweaking.com-regbackup-BHP-Windows-7-Home-Premium-(64-bit).dat
2015-06-17 08:42 - 2015-06-17 08:42 - 00000000 ____D C:\RegBackup
2015-06-17 08:39 - 2015-06-17 08:39 - 02949914 _____ (Thisisu) C:\Users\chakotay\Downloads\JRT.exe
2015-06-16 16:31 - 2015-06-16 16:31 - 01691816 _____ (Microsoft Corporation) C:\Windows\system32\FM20.DLL
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-16 13:34 - 2015-01-26 23:51 - 00000000 ____D C:\Users\chakotay\Desktop\WORKING
2015-07-16 13:08 - 2014-04-02 06:27 - 01439161 _____ C:\Windows\WindowsUpdate.log
2015-07-16 13:06 - 2015-04-22 22:50 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-16 13:03 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-16 13:03 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-16 12:58 - 2015-04-22 22:50 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-16 12:58 - 2015-01-18 09:22 - 00000000 ____D C:\Users\chakotay\AppData\Local\TSVNCache
2015-07-16 10:07 - 2015-05-30 05:16 - 00016046 _____ C:\Windows\setupact.log
2015-07-16 10:07 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-15 21:25 - 2009-07-14 00:45 - 05065680 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-15 21:21 - 2014-12-10 07:23 - 00000000 ____D C:\Windows\system32\appraiser
2015-07-15 21:21 - 2014-09-21 00:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-07-15 21:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-07-15 21:20 - 2015-06-13 19:23 - 00006212 _____ C:\Windows\PFRO.log
2015-07-15 20:41 - 2014-11-23 20:39 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-07-15 20:41 - 2014-11-23 20:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-15 20:34 - 2009-07-13 22:34 - 00000633 _____ C:\Windows\win.ini
2015-07-15 20:30 - 2014-09-21 22:17 - 00000000 ____D C:\Windows\system32\MRT
2015-07-15 18:29 - 2015-01-04 06:53 - 00000000 ____D C:\Users\chakotay\.gimp-2.6
2015-07-15 18:01 - 2015-04-22 22:50 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-15 18:01 - 2015-04-22 22:50 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-15 17:44 - 2015-05-28 21:33 - 00000000 ____D C:\Users\chakotay\Desktop\Ads
2015-07-15 17:43 - 2014-11-23 20:11 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\NCH Software
2015-07-15 17:43 - 2014-11-23 20:10 - 00000000 ____D C:\Program Files (x86)\NCH Software
2015-07-15 17:40 - 2014-12-15 21:17 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\uTorrent
2015-07-14 13:08 - 2015-04-22 22:50 - 00002147 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-12 09:26 - 2009-07-14 01:13 - 00723326 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-12 07:37 - 2015-01-04 07:01 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\gtk-2.0
2015-07-12 07:37 - 2014-09-17 15:34 - 00000000 ____D C:\Users\chakotay
2015-07-12 07:34 - 2015-01-04 07:00 - 00000000 ____D C:\Users\chakotay\.thumbnails
2015-07-12 07:29 - 2015-04-06 13:35 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-07-12 07:29 - 2015-04-06 13:35 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-12 00:31 - 2015-01-04 09:00 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\FileZilla
2015-07-11 21:46 - 2015-01-04 09:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-07-11 21:46 - 2015-01-04 09:00 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2015-07-11 16:18 - 2015-01-05 18:42 - 00000000 ____D C:\Users\chakotay\Documents\vMixStorage
2015-07-11 16:17 - 2013-12-10 09:45 - 00000000 ____D C:\ProgramData\Temp
2015-07-11 16:13 - 2014-10-29 16:34 - 00000000 ____D C:\Users\chakotay\AppData\Local\CrashDumps
2015-07-11 16:11 - 2015-01-05 18:42 - 00019969 _____ C:\Users\chakotay\AppData\Roaming\last.vmix
2015-07-11 11:28 - 2015-05-30 18:18 - 00000000 ____D C:\Users\chakotay\Desktop\RallyPics
2015-07-10 00:03 - 2014-09-21 00:20 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\vlc
2015-07-09 11:20 - 2015-05-13 15:31 - 00000000 ____D C:\Users\chakotay\Desktop\INVOICE
2015-07-09 06:22 - 2015-01-05 21:53 - 00000107 _____ C:\Users\chakotay\AppData\default.pls
2015-07-08 17:13 - 2015-05-19 05:56 - 00000000 ____D C:\Users\chakotay\Desktop\NANCY
2015-07-08 16:08 - 2015-04-10 07:55 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (7)
2015-07-08 16:04 - 2015-01-16 11:18 - 00000000 ____D C:\Program Files (x86)\BitLord
2015-07-06 11:05 - 2015-01-16 07:22 - 00000000 ____D C:\Users\chakotay\Documents\ConvertXtoDVD
2015-07-05 15:17 - 2015-05-31 14:15 - 00000000 ____D C:\Users\chakotay\Desktop\Sheena
2015-07-03 08:43 - 2014-09-21 22:17 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-07-03 08:10 - 2015-06-13 19:15 - 00290304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\subinacl.exe
2015-06-30 23:31 - 2014-09-17 22:56 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Skype
2015-06-27 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2015-06-27 06:26 - 2014-11-21 19:35 - 00000000 __SHD C:\Users\chakotay\AppData\Local\EmieBrowserModeList
2015-06-27 06:26 - 2014-09-21 00:25 - 00000000 __SHD C:\Users\chakotay\AppData\Local\EmieUserList
2015-06-27 06:26 - 2014-09-21 00:25 - 00000000 __SHD C:\Users\chakotay\AppData\Local\EmieSiteList
2015-06-26 09:31 - 2015-02-02 00:51 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Audacity
2015-06-25 08:30 - 2015-04-22 22:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-25 08:30 - 2014-11-23 20:40 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-06-25 08:30 - 2014-10-17 20:28 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\dvdcss
2015-06-25 08:30 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\registration
2015-06-25 08:07 - 2010-11-21 03:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-06-23 13:30 - 2010-11-20 23:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-06-19 19:55 - 2014-12-31 16:13 - 00000000 ____D C:\ProgramData\SmartSound Software Inc
2015-06-19 00:02 - 2013-12-10 09:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-06-18 23:51 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-17 20:13 - 2015-06-02 22:18 - 634715340 _____ C:\Windows\MEMORY.DMP
2015-06-17 20:13 - 2014-12-08 08:36 - 00000000 ____D C:\Windows\Minidump
2015-06-17 13:09 - 2015-03-23 06:31 - 00000000 ____D C:\Program Files (x86)\Pin Search Image Search on Pinterest
2015-06-16 05:18 - 2015-06-12 12:45 - 00000000 ____D C:\Users\chakotay\Desktop\IMAGE2
 
==================== Files in the root of some directories =======
 
2015-06-17 08:56 - 2015-07-15 10:36 - 0000024 _____ () C:\Users\chakotay\AppData\Roaming\appdataFr25.bin
2014-09-21 00:25 - 2014-09-21 00:25 - 0099384 _____ () C:\Users\chakotay\AppData\Roaming\inst.exe
2015-01-05 18:42 - 2015-07-11 16:11 - 0019969 _____ () C:\Users\chakotay\AppData\Roaming\last.vmix
2014-09-21 00:25 - 2014-09-21 00:25 - 0007859 _____ () C:\Users\chakotay\AppData\Roaming\pcouffin.cat
2014-09-21 00:25 - 2014-09-21 00:25 - 0001167 _____ () C:\Users\chakotay\AppData\Roaming\pcouffin.inf
2014-09-21 00:25 - 2014-09-21 00:25 - 0000055 _____ () C:\Users\chakotay\AppData\Roaming\pcouffin.log
2014-09-21 00:25 - 2014-09-21 00:25 - 0082816 _____ (VSO Software) C:\Users\chakotay\AppData\Roaming\pcouffin.sys
2015-05-21 14:01 - 2015-05-21 14:01 - 0033193 _____ () C:\Users\chakotay\AppData\Roaming\UserTile.png
2015-05-05 11:40 - 2015-05-05 11:40 - 0011838 _____ () C:\Users\chakotay\AppData\Local\Temp-log.txt
2015-06-17 20:29 - 2015-06-17 20:29 - 0251963 _____ () C:\ProgramData\1434587004.bdinstall.bin
2014-04-02 07:00 - 2014-04-02 07:02 - 0002439 _____ () C:\ProgramData\clear.fiSDK20.log
2014-04-02 06:48 - 2014-04-02 06:48 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-04-02 07:01 - 2014-04-02 07:01 - 0000032 _____ () C:\ProgramData\PS.log
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-13 12:44
 
==================== End of log ============================aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2015-07-16 18:14:19
—————————–
18:14:19.240    OS Version: Windows x64 6.1.7601 Service Pack 1
18:14:19.241    Number of processors: 4 586 0x3A09
18:14:19.242    ComputerName: BHP  UserName: 
18:14:23.898    Initialize success
18:14:23.998    VM: initialized successfully
18:14:24.000    VM: Intel CPU supported 
18:15:13.933    VM: supported disk I/O iaStor.sys
18:17:35.289    AVAST engine defs: 15071603
18:18:28.595    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:18:28.599    Disk 0 Vendor: ST500LT0 0001 Size: 476940MB BusType: 3
18:18:28.603    Disk 1  \Device\Harddisk1\DR1 -> \Device\00000083
18:18:28.609    Disk 1 Vendor: Realtek_ 1.00 Size: 476940MB BusType: 1
18:18:28.776    VM: Disk 0 MBR read successfully
18:18:28.781    Disk 0 MBR scan
18:18:28.791    Disk 0 Windows 7 default MBR code
18:18:28.806    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        19456 MB offset 2048
18:18:28.830    Disk 0 Partition 2 80 (A) 07      HPFS/NTFS NTFS          100 MB offset 39847936
18:18:28.842    Disk 0 default boot code
18:18:28.864    Disk 0 Partition 3 00     07      HPFS/NTFS NTFS       457383 MB offset 40052736
18:18:29.034    Disk 0 scanning C:\Windows\system32\drivers
18:18:44.607    Service scanning
18:19:14.743    Modules scanning
18:19:14.752    Disk 0 trace - called modules:
18:19:14.776    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
18:19:14.784    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008bea060]
18:19:14.791    3 CLASSPNP.SYS[fffff88001c9c43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062be050]
18:19:16.014    AVAST engine scan C:\
18:19:16.654    File: C:\$Recycle.Bin\S-1-5-21-3430744594-213253022-3560247601-1000\$R24RLUG.exe  **INFECTED** Win32:Dropper-gen [Drp]
18:43:30.300    File: C:\Program Files (x86)\IncrementEdit\IncrementEdit.dll  **INFECTED** Win32:Malware-gen
18:47:21.768    Disk 0 statistics 8232598/0/22 @ 3.46 MB/s
18:47:21.778    Scan stopped
18:47:32.238    Disk 0 MBR has been saved successfully to "C:\Users\chakotay\Desktop\MBR.dat"
18:47:32.244    The log file has been saved successfully to "C:\Users\chakotay\Desktop\aswMBR.txt"
18:51:16.629    Disk 0 MBR has been saved successfully to "C:\Users\chakotay\Desktop\MBR.dat"
18:51:16.645    The log file has been saved successfully to "C:\Users\chakotay\Desktop\FRST.txt"
 


Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by [removed] at 2015-07-16 13:51:14
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3430744594-213253022-3560247601-500 - Administrator - Disabled)
chakotay (S-1-5-21-3430744594-213253022-3560247601-1000 - Administrator - Enabled) => C:\Users\chakotay
Guest (S-1-5-21-3430744594-213253022-3560247601-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3430744594-213253022-3560247601-1002 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kingsoft Antivirus System Defense (Enabled - Up to date) {B6A51389-A795-5AC9-13BA-F569D73F3FE8}
AS: Kingsoft Antivirus System Defense (Enabled - Up to date) {0DC4F26D-81AF-5547-290A-CE1BACB87555}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.38 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0938-000001000000}) (Version: 9.38.00.0 - Igor Pavlov)
AC3Filter 2.6.0b (HKLM-x32\…\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky)
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.105 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2904.00 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.5.2904.00 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3508 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.04.3507 - Acer Incorporated)
Acer Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3502 - Acer Incorporated)
Acoustica Mixcraft 7 (64-bit) (HKLM-x32\…\Mixcraft 7-64) (Version: 7.0.0.251 - Acoustica)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Media Live Encoder 3.2 (HKLM-x32\…\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.0.6 (HKLM-x32\…\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Backup Manager V3 (x32 Version: 3.0.0.105 - NTI Corporation) Hidden
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.00 - Piriform)
clear.fi SDK - MVP 2 (x32 Version: 2.0.1702 - CyberLink Corp.) Hidden
clear.fi SDK- Movie 2 (x32 Version: 2.0.1707 - CyberLink Corp.) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.2727_43992 - CyberLink Corp.)
CyberLink PowerDirector 11 (HKLM-x32\…\InstallShield_{551F492A-01B0-4DC4-866F-875EC4EDC0A8}) (Version: 11.0.0.2418 - CyberLink Corp.)
CyberLink PowerDirector 11 (Version: 11.0.0.2418 - CyberLink Corp.) Hidden
DVD Shrink 3.2 (HKLM-x32\…\DVD Shrink_is1) (Version:  - DVD Shrink)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
ETDWare PS/2-X64 11.6.4.001_WHQL (HKLM\…\Elantech) (Version: 11.6.4.001 - ELAN Microelectronic Corp.)
Evernote v. 4.5.2 (HKLM-x32\…\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
EZ Grabber (HKLM-x32\…\{8543A572-5993-4101-BACC-C83884E183A4}) (Version: 2.00.0000 - EZ Grabber)
File Association Helper (HKLM\…\{C168639F-5810-4EC8-B1E8-0251AA8A771C}) (Version: 1.2.225.65451 - WinZip Computing International, LLC)
FileZilla Client 3.12.0.2 (HKLM-x32\…\FileZilla Client) (Version: 3.12.0.2 - Tim Kosse)
GIMP 2.6.10 (HKLM-x32\…\WinGimp-2.0_is1) (Version: 2.6.10 - The GIMP Team)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\…\HaaliMkx) (Version:  - )
HandBrake 0.10.0 (HKLM-x32\…\HandBrake) (Version: 0.10.0 - )
iCloud (HKLM\…\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3503 - Acer Incorporated)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2752 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Kingsoft Antivirus 2012 (HKLM-x32\…\Kingsoft Internet Security) (Version: 2012.5.7 - Kingsoft Internet Security)
LAME v3.99.3 (for Windows) (HKLM-x32\…\LAME_is1) (Version:  - )
Launch Manager (HKLM-x32\…\LManager) (Version: 7.0.12 - Acer Inc.)
Livestream Producer (HKLM-x32\…\{0017632B-E77C-43F2-9FE5-CAB59206FA6F}) (Version: 1.0.0 - Livestream)
MagicYUV Lossless Video Codec version 1.0 (HKLM-x32\…\{90410593-E0EB-4F9B-B984-65BEA8F07B91}_is1) (Version: 1.0 - INNOMAGIC, Ltd.)
Malwarebytes' Anti-Malware (HKLM-x32\…\Malwarebytes' Anti-Malware_is1) (Version:  - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Camera Codec Pack (HKLM\…\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\…\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MP3jam 1.1.1.10 (HKLM-x32\…\MP3jam_is1) (Version: 1.1.1.10 - MP3jam)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Nero 7 Ultra Edition (HKLM-x32\…\{CF097717-F174-4144-954A-FBC4BF301033}) (Version: 7.02.9753 - Nero AG)
Nero Backup Drivers (HKLM\…\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}) (Version: 1.0.11100.8.0 - Nero AG)
Newblue Art Effects for PowerDirector (HKLM\…\NewBlue Art Effects for PowerDirector) (Version: 2.0 - NewBlue)
newsXpresso (HKLM-x32\…\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.)
newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.6.9575 - Barnesandnoble.com)
Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.7.3 - Notepad++ Team)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9006 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9006 - NTI Corporation) Hidden
One Touch Video Capture (HKLM-x32\…\{C3A6202F-8F3E-424C-83B8-189F92A1AB43}) (Version:  - )
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PowerDirector (Version: 11.0 - CyberLink Corp.) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.312 - Qualcomm Atheros Communications)
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.19 - Qualcomm Atheros Inc.)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.21 - Qualcomm Atheros)
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RadioBOSS 5.0.0.9 (HKLM-x32\…\RadioBOSS) (Version: 5.0.0.9 - DJSoft.Net)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.28145 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\…\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Skype™ 7.2 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
SmartSound Quicktracks 5 (HKLM-x32\…\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.8 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (x32 Version: 5.1.8 - SmartSound Software Inc.) Hidden
SpyHunter 4 (HKLM-x32\…\SpyHunter) (Version: 4.20.9.4533 - Enigma Software Group, LLC)
TortoiseSVN 1.8.10.26129 (64 bit) (HKLM\…\{A9E679EC-8FD4-49D8-A5A5-ACE462515A9E}) (Version: 1.8.26129 - TortoiseSVN)
TuneUp Utilities Language Pack (en-US) (x32 Version: 12.0.3600.181 - TuneUp Software) Hidden
Turbonett móvil (HKLM-x32\…\Turbonett móvil) (Version: 11.302.09.09.519 - Huawei Technologies Co.,Ltd)
Unlocker 1.9.2 (HKLM\…\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\…\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{40930C8E-A677-414C-A72F-DFDEB10738FB}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3054791) 64-Bit Edition (HKLM\…\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{591150FB-47D4-495C-9E76-F8D354A2577D}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3054791) 64-Bit Edition (HKLM\…\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{591150FB-47D4-495C-9E76-F8D354A2577D}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3054791) 64-Bit Edition (HKLM\…\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{591150FB-47D4-495C-9E76-F8D354A2577D}) (Version:  - Microsoft)
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VidBlaster (HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\VidBlaster) (Version:  - )
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
vMix (HKLM-x32\…\{93D664E9-E81E-4277-9E90-6CDABAC7208F}_is1) (Version:  - StudioCoast)
vMix Social (HKLM-x32\…\{1A0C8557-EB4A-4DD1-B4F9-A974ADEFE05F}_is1) (Version:  - StudioCoast Pty Ltd)
VSO ConvertXToDVD (HKLM-x32\…\{CE1F93C0-4353-4C9D-84DA-AB4E7C63ED32}_is1) (Version: 5.1.0.12 - VSO Software)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
Winamp (HKLM-x32\…\Winamp) (Version: 5.666  - Nullsoft, Inc)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
10-07-2015 09:24:41 Windows Update
12-07-2015 07:28:04 Windows Update
15-07-2015 20:24:02 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {2D721CE7-DE86-483F-9AD0-A7B60287D6AE} - System32\Tasks\{CA6A25F2-B0ED-4BB5-8969-283D4FD9584E} => pcalua.exe -a C:\Users\chakotay\Downloads\QuickTimeInstaller.exe -d C:\Users\chakotay\Downloads
Task: {3738A5A8-2B99-4B8C-8E1A-8C44B1148DD6} - System32\Tasks\{0750E579-12D8-41F8-ABE7-245FA68EE652} => C:\Program Files (x86)\kingsoft\kingsoft antivirus\kismain.exe [2014-11-28] (Kingsoft Corporation)
Task: {3AF0A0F3-40DE-47B1-B7B4-0EF79D097CB3} - System32\Tasks\{A3C7E78D-B6B7-4135-A935-E03E31EFF19E} => pcalua.exe -a "C:\Program Files (x86)\CombiTech\VidBlaster\Uninstal.exe" -d "C:\Program Files (x86)\CombiTech\VidBlaster"
Task: {4B590BBB-19EF-454A-B4FF-29A5BE7F5520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-22] (Google Inc.)
Task: {69273BCF-C266-4606-B93F-A728C405322B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {6F44620D-B2FF-46F2-AA07-5522C34F8C39} - System32\Tasks\{B472276A-A9B2-42D6-BABF-6EFC38DA4A1F} => pcalua.exe -a "C:\Program Files (x86)\Picexa\uninstall.exe"
Task: {79262722-605C-49AA-BBBF-EA704250D666} - System32\Tasks\{121251DE-FBB3-419E-9EDB-24189CD589F5} => C:\Program Files (x86)\DVD Shrink\DVD Shrink 3.2.exe [2004-07-26] (DVD Shrink)
Task: {7AA29476-3887-44CF-AE0A-1A79DBABAC9F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-22] (Google Inc.)
Task: {8B48926E-86F5-40C9-9A14-DE742D711B04} - System32\Tasks\{CAA64F76-9505-49A7-9930-2ECBBDBAC512} => pcalua.exe -a C:\Users\chakotay\AppData\Local\TNT2\2.0.0.1918\TNT2User.exe -c /UNINSTALL PARTNER=11187
Task: {91F2CEA2-ADAD-4BB3-9CFB-3D6ABC02B51E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A82D1DC5-9944-403F-BE80-690340FC37DC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
Task: {A8D83114-AEFD-4CD3-935F-33A82845BBD9} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {AE6E3F71-83ED-4740-B39C-7DE59B160636} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {AE91A892-3F73-494E-A77B-3ED15EBAC8A1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {B634ADD5-D2FE-4E37-B9BD-EA1F453FBE34} - System32\Tasks\{6545B3D7-8D40-4C4C-A44E-A33EB8BFB88D} => pcalua.exe -a C:\Users\chakotay\Downloads\SetupVidBlaster.exe -d C:\Users\chakotay\Downloads
Task: {B656EF60-87CC-4D07-88B8-3DC5A2BE2B4F} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-03-28] (CyberLink)
Task: {CBF1F544-8AC3-4D7F-BB11-4AC5F3613D82} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {CD0B4B59-4C7A-4C14-A8C7-F289BE9C03CF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {EF5B9E02-56AD-4BB9-9ADD-08196330AB69} - System32\Tasks\{5AD7CDEE-B7D9-487F-8894-DD0D27086285} => pcalua.exe -a C:\Users\chakotay\AppData\Roaming\sweet-page\UninstallManager.exe -c  -ptid=cor
Task: {F27C63A4-8D91-497F-81BD-0749B2DFC46C} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-28] (Egis Technology Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2010-05-08 07:48 - 2010-05-08 07:48 - 00229376 _____ () C:\ProgramData\DatacardService\DCService.exe
2014-12-31 16:13 - 2012-09-12 03:14 - 00390672 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-12-31 16:13 - 2012-09-12 03:14 - 00024080 _____ () C:\Program Files\Cyberlink\Shared files\RichVideops64.dll
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-12-17 21:31 - 2014-12-17 21:31 - 00076032 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
2014-12-17 21:30 - 2014-12-17 21:30 - 00088832 _____ () C:\Program Files\TortoiseSVN\bin\libsasl.dll
2015-07-09 13:32 - 2015-07-09 13:32 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2010-07-15 00:44 - 2010-07-15 00:44 - 00020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2009-01-21 20:45 - 2009-01-21 20:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2014-05-12 05:49 - 2014-05-12 05:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2013-11-29 01:32 - 2013-11-29 01:32 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2013-12-10 08:29 - 2012-05-09 19:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-26 14:17 - 2012-12-26 14:17 - 01604312 _____ () C:\Program Files\CyberLink\PowerDirector11\Language\ENU\PDrt.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00303616 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\mediacache\libebml.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00672256 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\mediacache\libmatroska.dll
2012-09-12 03:13 - 2012-09-12 03:13 - 00160784 _____ () C:\Program Files\CyberLink\PowerDirector11\CLVistaAudioMixer.dll
2012-09-12 03:13 - 2012-09-12 03:13 - 00230928 _____ () C:\Program Files\CyberLink\PowerDirector11\HanumanCache.dll
2015-01-05 18:36 - 2014-10-27 14:10 - 00029696 _____ () C:\Program Files (x86)\vMix\VCMWrapper.dll
2015-01-05 18:36 - 2010-02-21 14:12 - 00303104 _____ () C:\Program Files (x86)\vMix\DirectShowLib-2005.dll
2015-01-05 18:36 - 2014-11-06 22:15 - 00037376 _____ () C:\Program Files (x86)\vMix\MJPEGDMO.dll
2015-01-05 18:36 - 2014-10-25 14:18 - 00108032 _____ () C:\Program Files (x86)\vMix\x64\vMixNative.dll
2012-07-26 13:33 - 2012-07-26 13:33 - 00061440 _____ () C:\Program Files\CyberLink\Shared files\PlugIn\NewBlue\NewBlue_PlugIn_ArtEffectsBundleForPDR.dll
2012-07-26 13:32 - 2012-07-26 13:32 - 00136704 _____ () C:\Program Files\CyberLink\Shared files\Plugin\NewBlue\NewBlueResources64.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 01485312 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\magicModule\cv110_64.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 01597440 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\magicModule\cxcore110_64.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00620544 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\magicModule\highgui110_64.dll
2014-12-31 16:10 - 2012-07-11 06:11 - 00096784 _____ () C:\Program Files\CyberLink\Shared files\PlugIn\9.0\AEJ_Converter.dll
2012-12-26 14:17 - 2012-12-26 14:17 - 02173984 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\authoring\AuroraU.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00018960 _____ () C:\Program Files\CyberLink\PowerDirector11\S3Dutility.dll
2015-03-29 00:26 - 2013-04-05 21:27 - 02231296 _____ () C:\Windows\system32\ac3filter64.acm
2012-09-26 19:41 - 2012-09-26 19:41 - 00465384 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2012-09-26 19:41 - 2012-09-26 19:41 - 01081408 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2012-09-26 19:41 - 2012-09-26 19:41 - 00125504 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2014-04-02 06:43 - 2012-06-24 22:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-12-17 20:53 - 2014-12-17 20:53 - 00065792 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub32.dll
2014-12-17 20:53 - 2014-12-17 20:53 - 00071936 _____ () C:\Program Files\TortoiseSVN\bin\libsasl32.dll
2014-07-31 12:16 - 2014-07-31 12:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-05 18:36 - 2014-08-06 18:54 - 00968192 _____ () C:\Program Files (x86)\vMix\filters\vMixVideo.ax
2013-04-26 05:39 - 2010-11-19 09:01 - 00093936 _____ () C:\Program Files (x86)\CombiTech\VidBlaster\DatasteadVirtualStream.ax
2015-07-09 13:32 - 2015-07-09 13:32 - 00039384 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2015-07-14 13:08 - 2015-07-13 17:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-14 13:08 - 2015-07-13 17:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll
2015-07-14 13:08 - 2015-07-13 17:55 - 16308040 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:8E236DBE
AlternateDataStreams: C:\ProgramData\Temp:A7D26093
AlternateDataStreams: C:\Users\chakotay\Downloads\Business-in-a-Box_setup.exe:BDU
AlternateDataStreams: C:\Users\chakotay\AppData\Local\Temporary Internet Files:e4HGVDlquN4U2E0PgNO1fHY1Twz
AlternateDataStreams: C:\Users\chakotay\AppData\Local\y3MRxgN3l:RKFHd2Pgq95QDNJ71iNHKHckksBM
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\chakotay\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^Users^chakotay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Audition CC 2014 7.0 Multilanguage (64-Bit) + Patch [ATOM].lnk => C:\Windows\pss\Adobe Audition CC 2014 7.0 Multilanguage (64-Bit) + Patch [ATOM].lnk.Startup
MSCONFIG\startupfolder: C:^Users^chakotay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Karaoke-4,499 songs.lnk => C:\Windows\pss\Karaoke-4,499 songs.lnk.Startup
MSCONFIG\startupfolder: C:^Users^chakotay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^peter tosh - Downpressor man.lnk => C:\Windows\pss\peter tosh - Downpressor man.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{A91A2C36-4235-47CA-9544-7C67A0FC47DD}] => (Allow) %SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
FirewallRules: [{F554F7A1-01E4-4196-8917-B3DB32125C22}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{696900F2-C519-451C-8FFC-B59D8F1F58FD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{2631D757-D086-4091-8658-23D29A0E69C7}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{2EDE97B0-8031-4C54-A000-803CB50C19D5}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{2BF4D63B-15C7-4208-9114-08104003B544}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{1230DA12-5580-429A-A002-B356ADED78A0}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{799F77FF-8752-43D1-8447-E514F9AF2A48}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{7F5417A2-A2F3-46D9-B84C-B0294BC33169}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{BDCA150D-A8B0-4174-8D6B-B31DDEF44CED}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{E89E51C4-E005-428B-8CFD-5427B985FE9A}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\Movie\PlayMovie.exe
FirewallRules: [{216BEFD4-94C1-4C3A-ABAC-E9EDBA388FF2}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\VideoPlayer.exe
FirewallRules: [{5B00ED62-A053-4F02-8009-F9AF44B8A2C2}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\MusicPlayer.exe
FirewallRules: [{E1DFA818-46BF-486F-A597-F82C2815C107}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{86107616-037E-42A8-86F1-CA89D9EBCA1C}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{FDE280EB-CDA0-4DAE-A523-90CAC900C1ED}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{C55A959B-219A-4D68-8CE3-AAC19B63D10D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{E03024F2-32FF-4490-84CB-EBEEB121D894}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{88D48036-EA14-4D22-8CE1-8366EF38186E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{41D7EE51-7C31-40A3-B0B9-B84766B391D7}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{12B85B91-A17C-47F1-AF49-C14CADEFCDE2}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{9A4FBAB3-84B4-4EEB-A1A3-75AC466EBB2B}] => (Allow) C:\Program Files\CyberLink\PowerDirector11\PDR10.EXE
FirewallRules: [{EE586337-D102-46BF-A853-79AA47636F21}] => (Allow) C:\Users\chakotay\AppData\Local\TNT2\2.0.0.1918\TNT2User.exe
FirewallRules: [TCP Query User{B7AD81D1-065A-4C70-9B05-97FFCDA38E56}C:\program files (x86)\combitech\vidblaster\vidblaster.exe] => (Block) C:\program files (x86)\combitech\vidblaster\vidblaster.exe
FirewallRules: [UDP Query User{25C0F8CA-8B4B-4906-A54E-7E0B97F6AE85}C:\program files (x86)\combitech\vidblaster\vidblaster.exe] => (Block) C:\program files (x86)\combitech\vidblaster\vidblaster.exe
FirewallRules: [TCP Query User{A09F173D-F041-4D93-8028-CB772ED4AD35}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [UDP Query User{4C2B69A1-E07D-4B70-B84B-EEB1BFCBEA66}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [TCP Query User{4D1180A2-36E5-4CB6-BE18-25341AE2744A}C:\program files (x86)\vmix\vmix.exe] => (Allow) C:\program files (x86)\vmix\vmix.exe
FirewallRules: [UDP Query User{75851E82-10CC-443A-B3D7-D956E949769C}C:\program files (x86)\vmix\vmix.exe] => (Allow) C:\program files (x86)\vmix\vmix.exe
FirewallRules: [TCP Query User{D3881386-B789-4CA4-BA8D-018C17657DED}C:\program files (x86)\vmix\vmixdesktopcapture.exe] => (Allow) C:\program files (x86)\vmix\vmixdesktopcapture.exe
FirewallRules: [UDP Query User{973CEB0F-3A2D-4663-9294-6179AFE2CA93}C:\program files (x86)\vmix\vmixdesktopcapture.exe] => (Allow) C:\program files (x86)\vmix\vmixdesktopcapture.exe
FirewallRules: [TCP Query User{AAC6DEF4-64EA-40C0-9CC1-D86E4BB45813}C:\program files (x86)\vmixsocial\vmixsocial.exe] => (Allow) C:\program files (x86)\vmixsocial\vmixsocial.exe
FirewallRules: [UDP Query User{76EA0F6E-EAB2-4972-8533-90041086A072}C:\program files (x86)\vmixsocial\vmixsocial.exe] => (Allow) C:\program files (x86)\vmixsocial\vmixsocial.exe
FirewallRules: [{BBD5F3D9-394E-4E1F-BB98-C2232D96BC20}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{383C7871-75E6-4831-BB4C-CA5D158CA99E}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{62A423FF-38B9-4D80-A1A6-06B6A43D23A0}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{067A6EC2-BBC3-4123-9CC8-7BB9C6E75067}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{94AEC4B2-F89C-4B56-91C8-6F2C2C77308B}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [UDP Query User{A6F85450-3BA9-4A3A-BA03-81774D48210A}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [TCP Query User{6146B76E-36BE-4E2F-9B46-F6756FDE7A90}C:\program files (x86)\radioboss\radioboss.exe] => (Allow) C:\program files (x86)\radioboss\radioboss.exe
FirewallRules: [UDP Query User{9EF9FFAC-883F-4A5D-889E-F884B4E4CDD3}C:\program files (x86)\radioboss\radioboss.exe] => (Allow) C:\program files (x86)\radioboss\radioboss.exe
FirewallRules: [TCP Query User{D850F216-C68E-4D8D-9C98-D0B3625291CD}C:\program files (x86)\miniget\miniget.exe] => (Allow) C:\program files (x86)\miniget\miniget.exe
FirewallRules: [UDP Query User{65344B1F-6731-425D-9EF6-BDD8B462D468}C:\program files (x86)\miniget\miniget.exe] => (Allow) C:\program files (x86)\miniget\miniget.exe
FirewallRules: [{99C5F9CF-FFFB-470D-A0ED-743EAF0AAF3C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{F668A504-BE5A-4B1E-B6AB-F00D071A5D6C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{96355800-5F68-4CE5-99EB-F92B62FF8F95}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{8F7B4D63-4AFF-4337-A5A5-EAEFDB0E1B87}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{7C03C433-FA7D-40C1-84DC-DF72F0A0576A}C:\program files (x86)\nero\nero 7\nero home\nerohome.exe] => (Block) C:\program files (x86)\nero\nero 7\nero home\nerohome.exe
FirewallRules: [UDP Query User{973A5C17-4611-42EE-BC26-1F1C397BD695}C:\program files (x86)\nero\nero 7\nero home\nerohome.exe] => (Block) C:\program files (x86)\nero\nero 7\nero home\nerohome.exe
FirewallRules: [TCP Query User{D3F31BAC-4B4E-4B8B-9A9D-F8A9DA3CBDFE}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [UDP Query User{B09943F6-9AF8-403D-AC89-89ACD633588F}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [{A567DB28-0987-4D7D-9603-208602ABBF8F}] => (Allow) C:\Users\chakotay\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{55A172A6-B82E-4929-BDA8-6EB3ACDD2466}] => (Allow) C:\Users\chakotay\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{4B87595F-A1A2-48BE-9383-0F07F382172F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
Name: HD WebCam
Description: USB Video Device
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/16/2015 10:08:37 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/16/2015 06:35:28 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (07/15/2015 09:28:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 09:25:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 05:40:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 11:28:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 10:51:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 06:01:30 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (07/14/2015 06:57:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/14/2015 12:59:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (07/16/2015 10:08:22 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the BocaFunc service to connect.
 
Error: (07/16/2015 10:07:52 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SystemPromote service to connect.
 
Error: (07/16/2015 10:07:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The sbapifs service failed to start due to the following error: 
%%2
 
Error: (07/16/2015 10:06:51 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
 
Error: (07/15/2015 09:28:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the BocaFunc service to connect.
 
Error: (07/15/2015 09:27:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SystemPromote service to connect.
 
Error: (07/15/2015 09:27:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The sbapifs service failed to start due to the following error: 
%%2
 
Error: (07/15/2015 09:25:52 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
 
Error: (07/15/2015 09:25:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the BocaFunc service to connect.
 
Error: (07/15/2015 09:24:31 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SystemPromote service to connect.
 
 
Microsoft Office:
=========================
Error: (07/16/2015 10:08:37 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/16/2015 06:35:28 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (07/15/2015 09:28:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 09:25:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 05:40:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 11:28:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 10:51:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/15/2015 06:01:30 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (07/14/2015 06:57:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/14/2015 12:59:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 56%
Total physical RAM: 5982.36 MB
Available physical RAM: 2618.37 MB
Total Virtual: 11962.92 MB
Available Virtual: 6945.7 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:446.66 GB) (Free:34.47 GB) NTFS
Drive f: (EOS_DIGITAL) (Removable) (Total:29.82 GB) (Free:17.76 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7C819AB2)
Partition 1: (Not Active) - (Size=19 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=446.7 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 29.8 GB) (Disk ID: 00000000)
 
Partition: GPT Partition Type.
 
==================== End of log ============================


aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2015-07-16 18:14:19
—————————–
18:14:19.240    OS Version: Windows x64 6.1.7601 Service Pack 1
18:14:19.241    Number of processors: 4 586 0x3A09
18:14:19.242    ComputerName: BHP  UserName: 
18:14:23.898    Initialize success
18:14:23.998    VM: initialized successfully
18:14:24.000    VM: Intel CPU supported 
18:15:13.933    VM: supported disk I/O iaStor.sys
18:17:35.289    AVAST engine defs: 15071603
18:18:28.595    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:18:28.599    Disk 0 Vendor: ST500LT0 0001 Size: 476940MB BusType: 3
18:18:28.603    Disk 1  \Device\Harddisk1\DR1 -> \Device\00000083
18:18:28.609    Disk 1 Vendor: Realtek_ 1.00 Size: 476940MB BusType: 1
18:18:28.776    VM: Disk 0 MBR read successfully
18:18:28.781    Disk 0 MBR scan
18:18:28.791    Disk 0 Windows 7 default MBR code
18:18:28.806    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        19456 MB offset 2048
18:18:28.830    Disk 0 Partition 2 80 (A) 07      HPFS/NTFS NTFS          100 MB offset 39847936
18:18:28.842    Disk 0 default boot code
18:18:28.864    Disk 0 Partition 3 00     07      HPFS/NTFS NTFS       457383 MB offset 40052736
18:18:29.034    Disk 0 scanning C:\Windows\system32\drivers
18:18:44.607    Service scanning
18:19:14.743    Modules scanning
18:19:14.752    Disk 0 trace - called modules:
18:19:14.776    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
18:19:14.784    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008bea060]
18:19:14.791    3 CLASSPNP.SYS[fffff88001c9c43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062be050]
18:19:16.014    AVAST engine scan C:\
18:19:16.654    File: C:\$Recycle.Bin\S-1-5-21-3430744594-213253022-3560247601-1000\$R24RLUG.exe  **INFECTED** Win32:Dropper-gen [Drp]
18:43:30.300    File: C:\Program Files (x86)\IncrementEdit\IncrementEdit.dll  **INFECTED** Win32:Malware-gen
18:47:21.768    Disk 0 statistics 8232598/0/22 @ 3.46 MB/s
18:47:21.778    Scan stopped
18:47:32.238    Disk 0 MBR has been saved successfully to "C:\Users\chakotay\Desktop\MBR.dat"
18:47:32.244    The log file has been saved successfully to "C:\Users\chakotay\Desktop\aswMBR.txt"
 
 

 

Fix with FRST (normal mode)

WARNING: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 

  • Download the attached fixlist.txt and save it to the location where FRST is saved to.
  • Run FRST.exe (on 64bit, run FRST64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

Full System Scan with Malwarebytes Antimalware



  • If not existing, please download Malwarebytes Anti-Malware to your desktop.
  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

Scan with ESET Online Scan

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

 

Attachments:

Hi, I found "FRST.txt" but I didn't find anything listed as  "fixlist.txt "

 

I even tried a search of the machine and nothing with that name was found.

The fixlist.txt is attached to my last reply, you need to download and save it to the same location where FRST.exe is.

Hi, I found the attachment. Here are the results of the scans.
Thanks.

 
Malwarebytes Anti-Malware
 
Scan Date: 7/21/2015
Scan Time: 2:20 AM
Logfile: 
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.07.21.01
Rootkit Database: v2015.07.17.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: chakotay
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 368365
Time Elapsed: 25 min, 7 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 93
PUP.Optional.WeCare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}, Quarantined, [f66fae363e4c280e1929348b6f93ab55], 
PUP.Optional.WeCare.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}, Quarantined, [f66fae363e4c280e1929348b6f93ab55], 
PUP.Optional.SweetIM.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{DEDAF650-12B8-48F5-A843-BBA100716106}, Quarantined, [df86fee64a40db5b08821e6f51b103fd], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [fe678b593951c175500fbad3e61eb848], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [ee770fd54d3d3ef8afb05d307d87f10f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [5411c71d3f4b8ea8fe61cdc0a75d0ef2], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [323303e1602a7abc144c6b22af550000], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [b2b3b1332a60d95d3e22a4e90bf95ca4], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [abba9b491674b87e3c240c81ee16a45c], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [fe6763812763f442045c46478a7a2ad6], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [184d984ceaa01c1ac19ff6971ee625db], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [ec7917cd1575db5b73ed503d4abaee12], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [0a5bf1f32169ec4a94cc4d40758f17e9], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [570e776d6c1ee94d312fbfce6f95a957], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [1055c123652553e384dc64299a6ad22e], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [f075c4202c5e2f07c898167711f3758b], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [fb6a6c788208c86ee47cc9c437cdee12], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [c89d92521c6e1125c9972568d430b54b], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [5411ca1a7b0f38fe9fc1bcd12fd56e92], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [4e1741a366242a0cbea2fb9258ac7888], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [d78e5c88cac02115223e414cab59f30d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [6cf9b331bbcf46f07ae6523bd62e8a76], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [174e63815139d85e8fd1afde31d36898], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [4b1a05df4f3b9f973b25335a8183c838], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [53128d57612953e3223ee2ab5ea6a060], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [81e49153f496b48272ee890433d12dd3], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [bfa602e2c2c8e353b0b0137ae81c56aa], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [e184766edcae7abc0a56830a43c17090], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [164f677d048676c0035d5d308b79cc34], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [78ed15cf1575a49279e70e7f44c0d12f], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, Quarantined, [9acb5193d6b489adca906ed8fd06f808], 
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32LDR  , Quarantined, [b6af9b4995f595a13f5d5540e91bec14], 
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, Quarantined, [b9ac0dd70585b77fcafaaad7d034c23e], 
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, Quarantined, [dd8831b33159d95dab18d8a9d52ff010], 
PUP.Optional.MyPCBackup.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\MyPC Backup, Quarantined, [c2a320c432584aecd36d9981b64dd22e], 
PUP.Optional.Cinema.A, HKLM\SOFTWARE\WOW6432NODE\CinemaP-1.9cV16.03, Quarantined, [b2b38a5a24665ed8f00142e9a85ba15f], 
PUP.Optional.Cinema.A, HKLM\SOFTWARE\WOW6432NODE\CinemaP-1.9cV16.03-nv, Quarantined, [df86677d167424122ec3cd5ea95af30d], 
PUP.Optional.Cinema.A, HKLM\SOFTWARE\WOW6432NODE\CinemaP-1.9cV16.03-nv-ie, Quarantined, [1d48c81cc6c4e74f5b965ecd7d861de3], 
PUP.Optional.FFPluginHp.A, HKLM\SOFTWARE\WOW6432NODE\FFPluginHp, Quarantined, [95d0994bdab045f1fa3ee22749ba59a7], 
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, Quarantined, [cb9a3ea6f09ad75fdde7fc1d56adea16], 
PUP.Optional.Picexa.A, HKLM\SOFTWARE\WOW6432NODE\PicexaSvc, Quarantined, [402580648cfe60d632bd068d719357a9], 
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, Quarantined, [461ff4f0c4c6b4825049f384b351d828], 
PUP.Optional.CrossRider.C, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [ec79bf252b5f86b0daffb5545fa445bb], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [8fd69d473a500432d58abcd1976def11], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine, Quarantined, [b4b1ffe54d3d2b0b045b8b0243c123dd], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickProcessLauncherMachine.1.0, Quarantined, [f66fb2327d0d40f6aeb1107d7e868779], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync, Quarantined, [e77ecd172b5f23130a56a7e61de703fd], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoCreateAsync.1.0, Quarantined, [03625d873e4c1b1bd48c2667ea1a39c7], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass, Quarantined, [4c193ba996f479bdb2aee2ab21e3a25e], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreClass.1, Quarantined, [0e576d77b6d4b383b9a75d30bf458080], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass, Quarantined, [fd680bd93b4f0135e67a7e0fc83cb947], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CoreMachineClass.1, Quarantined, [8cd9578dff8b59dd3828226bdb2929d7], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine, Quarantined, [273e52921278e25465fbaedf9d67e11f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.CredentialDialogMachine.1.0, Quarantined, [cb9a91530f7bea4c71ef0a83a4604ab6], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine, Quarantined, [de8725bf57334fe7b4ac3855f311d32d], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [590c9450fb8f73c391cf058844c0847c], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback, Quarantined, [dd882db7a4e61224c59bade09e669a66], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [b3b217cdc3c7033382de8eff49bb0000], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc, Quarantined, [0d5821c3dfabfe38baa6afde58ac8d73], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [8ed70bd9fe8cef476cf4bfce4fb5e11f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher, Quarantined, [bda844a00f7b1c1a72ee7a13df2535cb], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.ProcessLauncher.1.0, Quarantined, [5c09ce166a20b0866df397f6af550df3], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService, Quarantined, [f27381635b2f9d990f518a03e1235ba5], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3COMClassService.1.0, Quarantined, [baabedf70b7fe45275eb6f1e7193f10f], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine, Quarantined, [20455a8ad4b6989ea9b7a8e5798bc53b], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachine.1.0, Quarantined, [de87bb29d7b3b284055bdfae0004f50b], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback, Quarantined, [0b5af9ebbad0b48261ffb4d95ba96a96], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebMachineFallback.1.0, Quarantined, [95d041a36c1e4cea4c14226b15efac54], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc, Quarantined, [9bca7371a0ead5610f519bf2d430728e], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdateUpdate.Update3WebSvc.1.0, Quarantined, [9ec715cff397e353510f137a8d770000], 
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE\Clients, Quarantined, [41245f8553372c0a3b2a3c5717ed40c0], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Quarantined, [a2c3f7edc2c8fb3bc05fc2717c87d62a], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, Quarantined, [a7be00e4ec9eb3835a0065e118eb1fe1], 
PUP.Optional.MyPCBackup.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\MyPC Backup, Quarantined, [e184d80caae01f175ae6fc1ece359c64], 
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SPPDCOM, Quarantined, [293c7f65fb8f0f2748c88415dc288c74], 
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, Quarantined, [d1949e4674167fb7e0910a19d62dc63a], 
PUP.Optional.Cinema.A, HKU\S-1-5-18\SOFTWARE\CinemaP-1.9cV16.03-nv, Quarantined, [dc89f8ece0aa80b621d19497748fab55], 
PUP.Optional.Cinema.A, HKU\S-1-5-18\SOFTWARE\CinemaP-1.9cV16.03-nv-ie, Quarantined, [0461994b97f3d46249a984a7659e916f], 
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, Quarantined, [baab6084305a8da954ac761a758fc838], 
PUP.Optional.Cinema.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\CinemaP-1.9cV16.03, Quarantined, [422373715c2ed75f50a24fdc8d767987], 
PUP.Optional.Cinema.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\CinemaP-1.9cV16.03-nv, Quarantined, [4b1a9450aae0f244faf83eed72916c94], 
PUP.Optional.Cinema.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\CinemaP-1.9cV16.03-nv-ie, Quarantined, [ea7b0bd9d9b159dd8d65230851b28977], 
PUP.Optional.InstallCore.C, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\InstallCore, Quarantined, [2d38e8fcd4b6b5813200ebace91b29d7], 
PUP.Optional.TNT.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\TNT2, Quarantined, [ce97cf15454592a4bb983fd690730af6], 
PUP.Optional.WeCare, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\wecarereminder, Quarantined, [d0958a5a0585ce686acd4fe2cc3758a8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [2d38776d0d7d2b0b056c4532a55f8779], 
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, Quarantined, [e481e6febfcb49ed07f3729911f27987], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, Quarantined, [baab459f3555fd395b2847e2897a28d8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Cinema PlusV16.03, Quarantined, [a7be38ace0aadd59eb7d32ed26dd52ae], 
PUP.Optional.TidyNetwork.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\DRAGDROP\{70BC1CDB-0744-4172-BDA0-B5A487D00C3A}, Quarantined, [d4916282d2b8c27409289f79808306fa], 
PUP.Optional.TNT.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}, Quarantined, [9fc62db7b0da54e2f3d1838556adf30d], 
PUP.Optional.QuickSearch.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\MOZILLA\EXTENDS, Quarantined, [115413d11f6bc76ff05e9d6dcb383cc4], 
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\PRODUCTSETUP, Quarantined, [67fe4e96a9e1e6507478f2a4dc28738d], 
 
Registry Values: 14
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\chrome.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130644590718448026, Quarantined, [f075f7edb3d71f17bedd2f66f113ce32]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\explorer.xxx|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130644590718448026, Quarantined, [66ff657fe4a664d27e1de3b2df254fb1]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\firefox.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130644590718448026, Quarantined, [79ec21c3c5c57abca6f52e679074ef11]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\iexplore.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130644590718448026, Quarantined, [cd981bc9800a2313811a8b0a788cd828]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_removal_tool.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130644590718448026, Quarantined, [88dd16cec4c669cd7d1e1580e91b7f81]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\software_reporter_tool.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130644590718448026, Quarantined, [194c8064236742f4b4e75d38f60ea25e]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32Ldr  |{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130644590718448026, Quarantined, [b6af9b4995f595a13f5d5540e91bec14]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [a2c3f7edc2c8fb3bc05fc2717c87d62a]
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATEDEV|AuCheckPeriodMs, 21600000, Quarantined, [0d58588cabdfbb7bb9ae0605c93a12ee]
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SPPDCOM|TS, 2, Quarantined, [293c7f65fb8f0f2748c88415dc288c74]
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, Quarantined, [e481e6febfcb49ed07f3729911f27987]
PUP.Optional.TNT.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{72A6AB0F-2FA8-4C73-9FCB-1E62A608F001}|AppName, TNT2User.exe, Quarantined, [9fc62db7b0da54e2f3d1838556adf30d]
PUP.Optional.QuickSearch.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\MOZILLA\EXTENDS|appid, [removed], Quarantined, [115413d11f6bc76ff05e9d6dcb383cc4]
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\PRODUCTSETUP|tb, 0Z1B1L2Z1S, Quarantined, [67fe4e96a9e1e6507478f2a4dc28738d]
 
Registry Data: 1
 
Folders: 4
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{dd948b50-2cf1-9d2e-dd94-48b502cf2d40}, Quarantined, [2e37bf252268989e1ff46c9df211738d], 
PUP.Optional.MultiPlug.A, C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk\101, Quarantined, [8dd86d7722685cdafcc9800c32d2a45c], 
PUP.Optional.MultiPlug.A, C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk, Quarantined, [8dd86d7722685cdafcc9800c32d2a45c], 
PUP.Optional.MiniAdblocker.A, C:\ProgramData\Mini - Adblocker, Quarantined, [73f2d410b1d9c96d4f7fc52bda28e719], 
 
Files: 21
PUP.Optional.MultiPlug.Uns, C:\ProgramData\Mini - Adblocker\Mini - Adblocker.exe, Quarantined, [0164cf1512787db9c52e275117eb37c9], 
PUP.Optional.MultiPlug, C:\ProgramData\{5b90a11d-0982-22e6-5b90-0a11d0988474}\peter tosh - Downpressor man.exe, Quarantined, [0560cd17147661d526c4dbbb669b0ef2], 
PUP.Optional.MultiPlug, C:\ProgramData\{84db6fc2-fc2b-3154-84db-b6fc2fc2bf0b}\peter tosh - Downpressor man.exe, Quarantined, [6500b52fddad51e5fceef2a4af526d93], 
PUP.Optional.Bundler, C:\ProgramData\{f9735180-22eb-9b1c-f973-3518022e4600}\Karaoke-4,499 songs.exe, Quarantined, [fc6912d2216930068aba18fb27de1fe1], 
PUP.Optional.WeCare.A, C:\Users\chakotay\AppData\Roaming\RHEng\89A8C8D4A7E845F9A125CCC5CDDA0C48\SliderCWAv4.1.32.3_20141114.msi, Quarantined, [590cc4208efc1f1720b9120e837d04fc], 
PUP.Optional.Multiplug.A, C:\Program Files (x86)\HHApppy2Savve\HHApppy2Savve.exe, Quarantined, [65006e76b6d496a01700403b9e63b947], 
PUP.Optional.OpenCandy, C:\Users\chakotay\Downloads\ac3filter_2_6_0b.exe, Quarantined, [204518cc236747ef497be9eb2bd67090], 
PUP.Optional.Bundler, C:\Users\chakotay\Downloads\Karaoke-4,499 songs.exe, Quarantined, [76ef2fb54f3bb086fd47021165a0b54b], 
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, Quarantined, [f174657fa7e36ccafa6ce9455aa7857b], 
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{dd948b50-2cf1-9d2e-dd94-48b502cf2d40}\Adobe Audition CC 2014 7.0 Multilanguage (64-Bit) + Patch [ATOM].dat, Quarantined, [2e37bf252268989e1ff46c9df211738d], 
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{dd948b50-2cf1-9d2e-dd94-48b502cf2d40}\Adobe Audition CC 2014 7.0 Multilanguage (64-Bit) + Patch [ATOM].exe, Quarantined, [2e37bf252268989e1ff46c9df211738d], 
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{dd948b50-2cf1-9d2e-dd94-48b502cf2d40}\b31978a077b817c, Quarantined, [2e37bf252268989e1ff46c9df211738d], 
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{dd948b50-2cf1-9d2e-dd94-48b502cf2d40}\c6cc31df20af66a8, Quarantined, [2e37bf252268989e1ff46c9df211738d], 
PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\Msft_Kernel_webTinstMKTN_01009.Wdf, Quarantined, [95d0519384064de95e08080a9e658779], 
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, Quarantined, [bea7905411792a0c014b9781e122e41c], 
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, Quarantined, [2045b43054366ccad5f1bfc2f90b9967], 
PUP.Optional.MultiPlug.A, C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk\101\lsdb.js, Quarantined, [8dd86d7722685cdafcc9800c32d2a45c], 
PUP.Optional.MultiPlug.A, C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk\101\background.html, Quarantined, [8dd86d7722685cdafcc9800c32d2a45c], 
PUP.Optional.MultiPlug.A, C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk\101\content.js, Quarantined, [8dd86d7722685cdafcc9800c32d2a45c], 
PUP.Optional.MultiPlug.A, C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk\101\manifest.json, Quarantined, [8dd86d7722685cdafcc9800c32d2a45c], 
PUP.Optional.MultiPlug.A, C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk\101\YPFF4DTvIu.js, Quarantined, [8dd86d7722685cdafcc9800c32d2a45c], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
_______________________________________________
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by [removed] at 2015-07-21 02:10:46 Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
AlternateDataStreams: C:\ProgramData\Temp:8E236DBE
AlternateDataStreams: C:\ProgramData\Temp:A7D26093
AlternateDataStreams: C:\Users\chakotay\Downloads\Business-in-a-Box_setup.exe:BDU
AlternateDataStreams: C:\Users\chakotay\AppData\Local\Temporary Internet Files:e4HGVDlquN4U2E0PgNO1fHY1Twz
AlternateDataStreams: C:\Users\chkotay\AppData\Local\y3MRxgN3l:RKFHd2Pgq95QDNJ71iNHKHckksBM
Task: {EF5B9E02-56AD-4BB9-9ADD-08196330AB69} - System32\Tasks\{5AD7CDEE-B7D9-487F-8894-DD0D27086285} => pcalua.exe -a C:\Users\chakotay\AppData\Roaming\sweet-page\UninstallManager.exe -c  -ptid=cor
FF Extension: ReadyCoupon - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] [2015-05-05]
FF Extension: DealSSpacie - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] [2015-05-05]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\extensions\[removed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\extensions\[removed]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: delta-homes
FF SelectedSearchEngine: delta-homes
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
S2 41218fb7; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\SystemPromote\SystemPromote.dll",serv
S2 81bd61f5; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\BocaFunc\BocaFunc.dll",serv
 
2015-06-17 08:56 - 2015-07-15 10:36 - 0000024 _____ () C:\Users\chakotay\AppData\Roaming\appdataFr25.bin
2014-04-02 06:48 - 2014-04-02 06:48 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
C:\Program Files (x86)\IncrementEdit
C:\$Recycle.Bin\S-1-5-21-3430744594-213253022-3560247601-1000\$R24RLUG.exe
C:\Users\chakotay\AppData\Roaming\sweet-page
c:\Program Files (x86)\SystemPromote
c:\Program Files (x86)\BocaFunc
C:\Program Files (x86)\globalUpdate
 
EmptyTemp:
*****************
 
C:\ProgramData\Temp => ":8E236DBE" ADS removed successfully.
C:\ProgramData\Temp => ":A7D26093" ADS removed successfully.
C:\Users\chakotay\Downloads\Business-in-a-Box_setup.exe => ":BDU" ADS removed successfully.
"C:\Users\chakotay\AppData\Local\Temporary Internet Files" => ":e4HGVDlquN4U2E0PgNO1fHY1Twz" ADS not found.
"C:\Users\chkotay\AppData\Local\y3MRxgN3l" => ":RKFHd2Pgq95QDNJ71iNHKHckksBM" ADS not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EF5B9E02-56AD-4BB9-9ADD-08196330AB69}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EF5B9E02-56AD-4BB9-9ADD-08196330AB69}" => key removed successfully
C:\Windows\System32\Tasks\{5AD7CDEE-B7D9-487F-8894-DD0D27086285} => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5AD7CDEE-B7D9-487F-8894-DD0D27086285}" => key removed successfully
C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] => moved successfully.
C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] => moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\[removed] => value removed successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\[removed] => value removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4" => key removed successfully
Firefox newtab removed successfully
Firefox DefaultSearchEngine removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox homepage removed successfully
"HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully.
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
41218fb7 => Service removed successfully
81bd61f5 => Service removed successfully
C:\Users\chakotay\AppData\Roaming\appdataFr25.bin => moved successfully.
C:\ProgramData\DP45977C.lfl => moved successfully.
C:\Program Files (x86)\IncrementEdit => moved successfully.
C:\$Recycle.Bin\S-1-5-21-3430744594-213253022-3560247601-1000\$R24RLUG.exe => moved successfully.
C:\Users\chakotay\AppData\Roaming\sweet-page => moved successfully.
"c:\Program Files (x86)\SystemPromote" => File/Folder not found.
"c:\Program Files (x86)\BocaFunc" => File/Folder not found.
"C:\Program Files (x86)\globalUpdate" => File/Folder not found.
EmptyTemp: => 4.1 GB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 02:11:19 ====
 
 
 
 
__________________________________________________________________
 
 
C:\FRST\Quarantine\C\Program Files (x86)\IncrementEdit\IncrementEdit.dll a variant of Win32/SProtector.P potentially unwanted application
C:\FRST\Quarantine\C\Users\chakotay\AppData\Roaming\sweet-page\UninstallManager.exe a variant of Win32/ELEX.CP potentially unwanted application
C:\Program Files\Adware-Removal-Tool\ARTP3.exe MSIL/FakeTool.PS trojan
C:\Users\chakotay\AppData\Roaming\BitTorrent\updates\7.9.2_36321.exe a variant of Win32/OpenCandy.C potentially unsafe application
C:\Users\chakotay\Desktop\New folder (7)\TEMP2\New folder (2)\disable_activation.cmd BAT/HostsChanger.A potentially unsafe application
C:\Users\chakotay\Desktop\WORKING\Unlocker1.9.2.exe a variant of Win32/Toolbar.Babylon.E potentially unwanted application
C:\Users\chakotay\Desktop\WORKING\uTorrent.exe a variant of Win32/OpenCandy.C potentially unsafe application
C:\Users\chakotay\Documents\Adobe.Premiere.Pro.CS6.v6.0.1.014.Multilingual.mundomanuales.com\disable_activation.cmd BAT/HostsChanger.A potentially unsafe application
C:\Users\chakotay\Downloads\FileZilla_3.9.0.6_win32-setup.exe a variant of Win32/InstallCore.UE potentially unwanted application
C:\Users\chakotay\Downloads\FreeYouTubeDownload.exe a variant of Win32/OpenCandy.C potentially unsafe application
C:\Users\chakotay\Downloads\FreeYouTubeDownloaderOC.exe a variant of Win32/OpenCandy.A potentially unsafe application
C:\Users\chakotay\Downloads\gimp-setup.exe a variant of Win32/DownloadAdmin.H potentially unwanted application
C:\Users\chakotay\Downloads\MP3jamSetup.exe a variant of Win32/InstallCore.ZK potentially unwanted application
C:\Users\chakotay\Downloads\winzip19-dl.exe a variant of Win32/InstallCore.TS potentially unwanted application

 

C:\Program Files\Adware-Removal-Tool

Delete this.

 

The other files aren´t malware but contain security risks. I´d delete them immediately - your choice.

 

 

Then we can do the cleanup - if you are facing any issues, report that immediately.

Delete junk with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe

  • Hit Scan and wait for the scan to finish.

  • Confirm the message but don´t uncheck anything.

  • Hit Clean

  • When the run is finished, it will open up a text file

  • Please post its contents within your next reply

  • You´ll find the log file at C:\AdwCleaner[S1].txt also




Delete junk with JRT

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.

  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".

  • The tool will open and start scanning your system.

  • Please be patient as this can take a while to complete depending on your system's specifications.

  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

  • Post the contents of JRT.txt into your next message.




SecurityCheck

Reboot your system before starting!

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.

  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.



Tell me: Are any problems left now or may I post the final reply? :)

I am not sure where to find these other files you refer to below:

The other files aren´t malware but contain security risks. I´d delete them immediately - your choice.


Thanks.

# AdwCleaner v4.208 - Logfile created 21/07/2015 at 19:26:39
# Updated 09/07/2015 by Xplode
# Database : 2015-07-15.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : chakotay - BHP
# Running from : C:\Users\chakotay\Desktop\adwcleaner_4.208.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\{5b90a11d-0982-22e6-5b90-0a11d0988474}
Folder Deleted : C:\ProgramData\{7a49fa65-1e73-9b44-7a49-9fa651e7e994}
Folder Deleted : C:\ProgramData\{84db6fc2-fc2b-3154-84db-b6fc2fc2bf0b}
Folder Deleted : C:\ProgramData\{f9735180-22eb-9b1c-f973-3518022e4600}
Folder Deleted : C:\Program Files (x86)\HHApppy2Savve
Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\SearchProtect
Folder Deleted : C:\Users\chakotay\AppData\Roaming\RHEng
File Deleted : C:\END
File Deleted : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
 
***** [ Scheduled tasks ] *****
 
Task Deleted : amiupdaterExd
Task Deleted : amiupdaterExi
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\156eacdc-6be3-484e-958c-b1950c01381c
Key Deleted : HKLM\SOFTWARE\c5b48b71-a44c-a460-1342-48d12a22c068
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FEB2313-F89B-4AC6-8153-84025604A06A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{02F878DF-E2BE-4B85-8CB4-A0D2D4E2ED7F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2AF343DD-3102-4F9D-AC95-DCA4C95382C7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4CA2AC92-971B-47B1-ACB6-357B552155AC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{52C5395B-1FCD-47FA-A834-FD830701C2D5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{762D463B-C45A-456D-A80D-8689C297C91E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7A6BE473-7960-44D0-BD54-D23DA76353DF}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{803F550E-BAAE-42BB-8917-64BA0006AB17}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8D5BC51D-C9D3-43B9-B728-B30677B7C7E8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{991C9D8D-A789-4DB9-BDFC-5F33398B04BF}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A5ACC874-D943-483F-A2D1-14598D51F872}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B0474212-0D9D-4361-90B3-B89D1A44275D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D83C83BF-3EDD-4410-ADAB-5295116DD8C7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DD260902-9420-4055-A956-9152EB4F3E6A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EB1F9F3C-5526-4DAE-BD4B-3EAA7715DA9F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F1912128-469A-4138-AA26-9699C15BB13E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F68DC16C-9C2B-455B-8853-7E4D34BAA3F4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKCU\Software\AppDataLow\Software\CheckMeUp
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\hdcode
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7223EDAC-E091-B3C1-BD91-B66CE557800F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E957849A-94AC-6F46-4623-C31474E3C170}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D9BEFAE-9499-F52B-6CC4-94818CCC2AB5}
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C168639F-5810-4EC8-B1E8-0251AA8A771C}
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17909
 
 
-\\ Mozilla Firefox v
 
[5c71mnjx.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://search.delta-homes.com/favicon.ico");
[5c71mnjx.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.url", "hxxp://search.delta-homes.com/web/?type=ds&ts=1430820023&from=wpm05053&uid=ST500LT012-1DG142_S3P2KN68XXXXS3P2KN68&q={searchTerms}");
[5c71mnjx.default\prefs.js] - Line Deleted : user_pref("extensions.4L19o21B1P0wPN3Q.scode", "(function(){try{if(window.location.href.indexOf(\"rjYGrjwFrjrGrHs5qjY7pjr8pdn\")>-1){return;}}catch(e){}try{var d=[[\"trianglecash.com\",\"acebook\",\"f[…]
[5c71mnjx.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[5c71mnjx.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
 
-\\ Google Chrome v43.0.2357.134
 
[C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.shutterstock.com/cat.mhtml?autocomplete_id=14344632554638910000&language=en&lang=en&search_source=&safesearch=1&version=llv1&searchterm={searchTerms}&media_type=images
[C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
 
*************************
 
AdwCleaner[R0].txt - [8703 bytes] - [21/07/2015 19:18:29]
AdwCleaner[R1].txt - [8762 bytes] - [21/07/2015 19:20:30]
AdwCleaner[S0].txt - [8698 bytes] - [21/07/2015 19:26:39]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8757  bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.1 (07.16.2015:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Tue 07/21/2015 at 19:37:57.64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
Successfully deleted: [Task] C:\Windows\system32\tasks\EgisUpdate
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Users\chakotay\AppData\Roaming\appdataFr25.bin
Successfully deleted: [File] C:\ProgramData\1434587004.bdinstall.bin
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin
 
 
 
~~~ FireFox
 
Successfully deleted: [Folder] C:\Users\chakotay\AppData\Roaming\mozilla\firefox\profiles\5c71mnjx.default\extensions\staged
Successfully deleted the following from C:\Users\chakotay\AppData\Roaming\mozilla\firefox\profiles\5c71mnjx.default\prefs.js
 
user_pref(browser.search.searchengine.alias, delta-homes);
user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
user_pref(browser.search.searchengine.name, delta-homes);
user_pref(browser.search.searchengine.ptid, wpm05053);
user_pref(browser.search.searchengine.uid, ST500LT012-1DG142_S3P2KN68XXXXS3P2KN68);
 
 
 
~~~ Chrome
 
 
[C:\Users\chakotay\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\chakotay\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\chakotay\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\chakotay\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  ogminpmldncgcmokldnmmapddoccmhfl
]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 07/21/2015 at 19:43:58.99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Results of screen317's Security Check version 1.005  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Kingsoft Antivirus System Defense   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 SpyHunter 4    
 TuneUp Utilities Language Pack (en-US) 
 Adobe Reader 10.1.15 Adobe Reader out of Date!  
 Google Chrome (43.0.2357.132) 
 Google Chrome (43.0.2357.134) 
 Google Chrome (GoogleUpdateHelper.dll..) 
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 0% 
````````````````````End of Log`````````````````````` 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI