[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(Kingsoft Corporation) C:\Program Files (x86)\kingsoft\kingsoft antivirus\kxescore.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
() C:\ProgramData\DatacardService\DCService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Kingsoft Corporation) C:\Program Files (x86)\kingsoft\kingsoft antivirus\kxetray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDirector11\PDR11.exe
(CyberLink) C:\Program Files\CyberLink\PowerDirector11\PDHanumanSvr.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmprph.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2864016 2012-08-10] (ELAN Microelectronics Corp.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM\…\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters).
HKLM-x32\…\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297024 2012-09-26] (NTI Corporation)
HKLM-x32\…\Run: [LManager] => [X]
HKLM-x32\…\Run: [kxesc] => c:\program files (x86)\kingsoft\kingsoft antivirus\kxetray.exe [1595056 2014-11-28] (Kingsoft Corporation)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\…\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-11-29] (Qualcomm®Atheros®)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: F - F:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {377237db-0f84-11e5-b616-2025648ad16f} - E:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {cf758d48-0996-11e5-9c81-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {cf758dc4-0996-11e5-9c81-2025648ad16f} - F:\AutoRun.exe
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\MountPoints2: {cf758ddc-0996-11e5-9c81-2025648ad16f} - F:\AutoRun.exe
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (
http://tortoisesvn.net)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = facebook.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\Software\Microsoft\Internet Explorer\Main,Start Page = facebook.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-22] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-10-15] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{2BF3A20D-9269-4620-A48C-CDAC8C9EEC48}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{FAE97252-6038-418F-804C-1DCC4B89A53E}: [NameServer] 10.235.35.162 10.235.35.163
FireFox:
========
FF ProfilePath: C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: delta-homes
FF SelectedSearchEngine: delta-homes
FF Homepage: hxxp://www.delta-homes.com/?type=hp&ts;=1430820023&from;=wpm05053&uid;=ST500LT012-1DG142_S3P2KN68XXXXS3P2KN68
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-04-22] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-04-22] (Microsoft Corporation)
FF Extension: ReadyCoupon - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] [2015-05-05]
FF Extension: DealSSpacie - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\Extensions\[removed] [2015-05-05]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\extensions\[removed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Users\chakotay\AppData\Roaming\Mozilla\Firefox\Profiles\5c71mnjx.default\extensions\[removed]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]
Chrome:
=======
CHR Profile: C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-13]
CHR Extension: (Google Docs) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-13]
CHR Extension: (Google Drive) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-28]
CHR Extension: (YouTube) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-28]
CHR Extension: (Google Search) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-28]
CHR Extension: (Google Sheets) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-13]
CHR Extension: (Ed2kHelper) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmeeplonmihpchdbfccgmjhcnpecbppk [2015-05-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-17]
CHR Extension: (SaveFrom.net helper) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdpljndcmbeikfnlflcggaipgnhiedbl [2015-06-03]
CHR Extension: (Google Wallet) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-28]
CHR Extension: (Gmail) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-28]
CHR Profile: C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-25]
CHR Extension: (Google Docs) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-25]
CHR Extension: (Google Drive) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-25]
CHR Extension: (YouTube) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-25]
CHR Extension: (チャットワーク) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cdnfjpioepnoeojoighemmpnaogcfagj [2015-06-25]
CHR Extension: (Google Search) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-25]
CHR Extension: (HelloSign for Gmail) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dciflieigdmogpmamcgbigingaodhnil [2015-06-25]
CHR Extension: (Google+) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2015-06-25]
CHR Extension: (Google Sheets) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-25]
CHR Extension: (HelloSign: Online signatures made easy) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kajjckmbclbffbpecfbiecehkfgopppd [2015-06-25]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-13]
CHR Extension: (SaveFrom.net helper) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdpljndcmbeikfnlflcggaipgnhiedbl [2015-06-25]
CHR Extension: (Hangouts) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-06-25]
CHR Extension: (Google Wallet) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-25]
CHR Extension: (Gmail) - C:\Users\chakotay\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [318592 2013-11-29] (Windows (R) Win 7 DDK provider) [File not signed]
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 kxescore; c:\program files (x86)\kingsoft\kingsoft antivirus\kxescore.exe [123992 2014-11-28] (Kingsoft Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256576 2012-09-26] (NTI Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-09-12] ()
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026944 2015-07-08] (Enigma Software Group USA, LLC.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 41218fb7; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\SystemPromote\SystemPromote.dll",serv
S2 81bd61f5; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\BocaFunc\BocaFunc.dll",serv
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-11-29] (Qualcomm Atheros)
S3 CXPLRCAP; C:\Windows\System32\drivers\CxPlrCap.sys [235904 2010-01-06] (Conexant Systems, Inc.) [File not signed]
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-07-08] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-07-08] ()
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [252928 2010-04-30] (Huawei Technologies Co., Ltd.)
R0 kavbootc; C:\Windows\System32\drivers\kavbootc64.sys [31848 2014-11-28] (Kingsoft Corporation)
R1 KDHacker; c:\program files (x86)\kingsoft\kingsoft antivirus\security\kxescan\kdhacker64.sys [164696 2014-11-28] (Kingsoft Corporation)
R2 kisknl; C:\Windows\system32\drivers\kisknl.sys [210296 2014-11-28] (Kingsoft Corporation)
R4 KUsbGuard; C:\Program Files (x86)\kingsoft\kingsoft antivirus\kusbquery64.sys [18296 2014-11-28] (Kingsoft Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [128200 2013-06-19] (Qualcomm Atheros Co., Ltd.)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2004-04-01] (Padus, Inc.) [File not signed]
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S2 sbapifs; system32\DRIVERS\sbapifs.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-16 13:50 - 2015-07-16 13:50 - 00025753 _____ C:\Users\chakotay\Desktop\FRST.txt
2015-07-16 13:49 - 2015-07-16 13:50 - 00000000 ____D C:\FRST
2015-07-16 13:48 - 2015-07-16 13:48 - 02133504 _____ (Farbar) C:\Users\chakotay\Desktop\FRST64.exe
2015-07-16 07:25 - 2015-07-16 07:25 - 09494290 _____ C:\Users\chakotay\Downloads\After Effects Template - Broadcast News Package - Intro.mp4
2015-07-16 06:57 - 2015-07-16 07:28 - 00000000 ____D C:\Users\chakotay\Desktop\Cropover
2015-07-15 19:56 - 2014-06-08 01:31 - 00000644 _____ C:\Users\chakotay\Downloads\addon.xml
2015-07-15 19:54 - 2015-07-15 19:54 - 01008766 _____ C:\Users\chakotay\Downloads\PluginCreator.zip
2015-07-15 19:54 - 2015-07-15 19:54 - 00000000 ____D C:\Users\chakotay\Downloads\PluginCreator
2015-07-15 06:47 - 2015-07-09 13:58 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-15 06:47 - 2015-07-09 13:58 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-15 06:47 - 2015-07-09 13:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-15 06:47 - 2015-07-09 13:58 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-15 06:47 - 2015-07-09 13:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-15 06:47 - 2015-07-09 13:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-15 06:47 - 2015-07-02 17:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-07-15 06:47 - 2015-07-02 17:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-07-15 06:47 - 2015-07-02 16:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-07-15 06:47 - 2015-07-02 16:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-07-15 06:47 - 2015-07-02 16:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-07-15 06:47 - 2015-07-02 15:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-07-15 06:47 - 2015-06-26 22:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-07-15 06:47 - 2015-06-26 22:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-07-15 06:47 - 2015-06-26 21:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-07-15 06:47 - 2015-06-26 21:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-07-15 06:47 - 2015-06-25 04:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-15 06:47 - 2015-06-17 13:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-15 06:47 - 2015-06-17 13:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-07-15 06:47 - 2015-06-09 14:03 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-07-15 06:47 - 2015-06-09 14:03 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-07-15 06:47 - 2015-06-01 20:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-15 06:47 - 2015-06-01 19:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll
2015-07-15 06:46 - 2015-07-02 16:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-07-15 06:46 - 2015-07-02 16:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-07-15 06:46 - 2015-07-02 16:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-07-15 06:46 - 2015-07-02 16:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-07-15 06:46 - 2015-07-02 15:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-07-15 06:46 - 2015-07-02 14:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-07-15 06:46 - 2015-06-25 14:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-07-15 06:46 - 2015-06-25 13:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-07-15 06:46 - 2015-06-20 16:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-07-15 06:46 - 2015-06-20 15:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-07-15 06:46 - 2015-06-20 15:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-07-15 06:46 - 2015-06-20 15:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-07-15 06:46 - 2015-06-20 15:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-07-15 06:46 - 2015-06-20 15:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-07-15 06:46 - 2015-06-20 15:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-07-15 06:46 - 2015-06-20 15:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-07-15 06:46 - 2015-06-20 15:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-07-15 06:46 - 2015-06-20 15:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-07-15 06:46 - 2015-06-20 15:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-07-15 06:46 - 2015-06-20 15:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-07-15 06:46 - 2015-06-20 15:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-07-15 06:46 - 2015-06-20 15:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-07-15 06:46 - 2015-06-20 15:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-07-15 06:46 - 2015-06-20 15:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-07-15 06:46 - 2015-06-20 15:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-07-15 06:46 - 2015-06-20 14:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-07-15 06:46 - 2015-06-20 14:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-07-15 06:46 - 2015-06-20 14:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-07-15 06:46 - 2015-06-20 14:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-07-15 06:46 - 2015-06-20 14:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-07-15 06:46 - 2015-06-20 14:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-07-15 06:46 - 2015-06-19 14:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-07-15 06:46 - 2015-06-19 14:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-07-15 06:46 - 2015-06-19 14:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-07-15 06:46 - 2015-06-19 14:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-07-15 06:46 - 2015-06-19 14:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-07-15 06:46 - 2015-06-19 14:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-07-15 06:46 - 2015-06-19 14:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-07-15 06:46 - 2015-06-19 14:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-07-15 06:46 - 2015-06-19 14:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-07-15 06:46 - 2015-06-19 14:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-07-15 06:46 - 2015-06-19 13:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-07-15 06:46 - 2015-06-19 13:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-07-15 06:46 - 2015-06-19 13:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-07-15 06:46 - 2015-06-19 13:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-07-15 06:46 - 2015-06-19 13:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-07-15 06:46 - 2015-06-19 13:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-07-15 06:46 - 2015-06-19 13:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-07-15 06:46 - 2015-06-19 13:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-07-15 06:46 - 2015-06-19 13:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-07-15 06:45 - 2015-06-11 13:57 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-07-15 06:45 - 2015-06-11 13:57 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-07-15 06:45 - 2015-06-11 13:57 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-07-15 06:45 - 2015-06-11 13:56 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-07-15 06:45 - 2015-06-11 13:56 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-07-15 06:45 - 2015-06-11 13:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-07-15 06:45 - 2015-06-11 09:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-07-15 06:44 - 2015-07-09 13:59 - 00017856 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-07-15 06:44 - 2015-07-09 13:58 - 01085440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-07-15 06:44 - 2015-07-09 13:58 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-07-15 06:44 - 2015-07-09 13:50 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-07-15 06:44 - 2015-07-04 14:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-15 06:44 - 2015-07-04 13:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-07-15 06:44 - 2015-07-03 14:05 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-07-15 06:44 - 2015-07-03 13:56 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-07-15 06:44 - 2015-07-03 13:56 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-15 06:44 - 2015-07-03 13:56 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-07-15 06:44 - 2015-07-03 13:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-07-15 06:44 - 2015-07-03 12:52 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-15 06:44 - 2015-07-03 12:42 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-15 06:44 - 2015-07-01 16:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-07-15 06:44 - 2015-07-01 16:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-15 06:44 - 2015-07-01 16:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-07-15 06:44 - 2015-07-01 16:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-07-15 06:44 - 2015-07-01 16:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-07-15 06:44 - 2015-07-01 16:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-07-15 06:44 - 2015-07-01 16:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-07-15 06:44 - 2015-07-01 16:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-07-15 06:44 - 2015-07-01 16:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-07-15 06:44 - 2015-07-01 16:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-07-15 06:44 - 2015-07-01 16:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-07-15 06:44 - 2015-07-01 16:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-07-15 06:44 - 2015-07-01 16:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-07-15 06:44 - 2015-07-01 16:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-07-15 06:44 - 2015-07-01 16:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-07-15 06:44 - 2015-07-01 16:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-07-15 06:44 - 2015-07-01 16:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-07-15 06:44 - 2015-07-01 16:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-07-15 06:44 - 2015-07-01 15:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-15 06:44 - 2015-07-01 15:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-15 06:44 - 2015-07-01 15:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-15 06:44 - 2015-06-15 17:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-07-15 06:44 - 2015-06-15 17:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-15 06:44 - 2015-06-15 17:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-07-15 06:44 - 2015-06-15 17:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-07-15 06:44 - 2015-06-15 17:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-07-15 06:44 - 2015-06-15 17:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-15 06:44 - 2015-06-15 17:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-07-15 06:44 - 2015-06-15 17:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-07-15 06:44 - 2015-06-15 17:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-07-15 06:44 - 2015-06-15 17:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-07-15 06:44 - 2015-06-15 17:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-07-15 06:44 - 2015-06-15 17:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-07-15 06:44 - 2015-04-27 15:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-07-15 06:44 - 2015-04-27 15:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-07-15 06:44 - 2015-04-27 15:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-07-15 06:44 - 2015-04-27 15:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-07-15 06:44 - 2015-04-27 15:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-07-13 22:42 - 2015-07-13 22:42 - 00003472 _____ C:\Windows\system32\Wimbledon Champions Novak Djokovic of Serbia, right, and Serena Williams of the US, dance on stage at the Wimbledon Champion dinner, at the Guildhall, London, Sunday, July 12, 2015. (Thomas Lov.jpg.lnk
2015-07-12 07:37 - 2015-07-12 07:37 - 00036313 _____ C:\Users\chakotay\.recently-used.xbel
2015-07-11 21:46 - 2015-07-11 21:46 - 06483456 _____ (Tim Kosse) C:\Users\chakotay\Downloads\FileZilla_3.12.0.2_win64-setup.exe
2015-07-11 21:32 - 2015-07-11 21:32 - 101356557 _____ C:\Users\chakotay\Desktop\Poetic7-11.mp4
2015-07-11 21:16 - 2015-07-11 21:24 - 683879516 _____ C:\Users\chakotay\Desktop\Poetic.m2ts
2015-07-08 15:23 - 2015-07-11 23:06 - 00001135 _____ C:\Users\chakotay\Desktop\SpyHunter.lnk
2015-07-08 15:23 - 2015-07-08 15:23 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Enigma Software Group
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\sh4ldr
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 _____ C:\autoexec.bat
2015-07-08 15:22 - 2015-07-08 15:22 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\chakotay\Downloads\SpyHunter-Installer.exe
2015-07-07 07:21 - 2015-07-07 07:21 - 00000000 _____ C:\Users\chakotay\Desktop\Live.csv
2015-07-06 07:59 - 2015-07-06 07:59 - 00013073 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day3.Highlights.Sat.Feed.MotorsTV.720p.X264.English.French-BF.torrent
2015-07-06 07:57 - 2015-07-06 07:57 - 00012813 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day2.Highlights.Sat.Feed.MotorsTV.720p.X264.English.French-BF.torrent
2015-07-06 07:56 - 2015-07-06 07:56 - 00012232 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day1.Highlights.Sat.Feed.720p.X264.English.Natural.Sounds-BF.torrent
2015-07-06 07:56 - 2015-07-06 07:56 - 00012232 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day1.Highlights.Sat.Feed.720p.X264.English.Natural.Sounds-BF (1).torrent
2015-07-06 07:49 - 2015-07-06 07:49 - 00012898 _____ C:\Users\chakotay\Downloads\WRC.2015.Round07.Poland.Day3.Highlights.BTSportHD.1080i.H264.English-BF.torrent
2015-07-02 10:51 - 2015-07-02 10:51 - 00000000 _____ C:\Users\chakotay\Downloads\noname
2015-07-01 14:52 - 2015-07-01 14:54 - 114225037 _____ C:\Users\chakotay\Downloads\Two.mp4
2015-07-01 10:23 - 2015-07-01 10:40 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (8)
2015-06-30 03:24 - 2015-06-30 03:24 - 11595328 _____ (New IT Solutions) C:\Users\chakotay\Downloads\4shared_Desktop_4.0.14.27377.exe
2015-06-27 00:37 - 2015-06-27 00:38 - 10060670 _____ C:\Users\chakotay\Downloads\RacingPostAndroid.apk
2015-06-25 13:28 - 2015-07-09 11:32 - 00000000 ____D C:\Users\chakotay\Desktop\OPEN
2015-06-25 13:27 - 2015-06-25 13:27 - 00000000 ____D C:\Users\chakotay\Downloads\plugin.video.france24 (1)
2015-06-25 13:26 - 2015-06-25 13:26 - 00121971 _____ C:\Users\chakotay\Downloads\plugin.video.france24.zip
2015-06-25 13:26 - 2015-06-25 13:26 - 00121971 _____ C:\Users\chakotay\Downloads\plugin.video.france24 (1).zip
2015-06-25 00:48 - 2015-06-25 00:48 - 00002986 _____ C:\Windows\System32\Tasks\{0750E579-12D8-41F8-ABE7-245FA68EE652}
2015-06-21 11:19 - 2015-06-24 06:58 - 00000000 ____D C:\Users\chakotay\Desktop\clothes
2015-06-20 06:48 - 2015-06-20 06:50 - 00171642 _____ C:\Users\chakotay\Desktop\Untitled.xcf
2015-06-17 21:41 - 2015-06-18 06:52 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (6)
2015-06-17 20:29 - 2015-06-17 20:29 - 00251963 _____ C:\ProgramData\1434587004.bdinstall.bin
2015-06-17 20:13 - 2015-06-17 20:13 - 00284176 _____ C:\Windows\Minidump\061715-26130-01.dmp
2015-06-17 18:57 - 2015-06-17 18:57 - 00519016 _____ (Biztree Inc.) C:\Users\chakotay\Downloads\Business-in-a-Box_setup.exe
2015-06-17 16:55 - 2015-06-17 17:12 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (3)
2015-06-17 12:25 - 2015-06-17 12:25 - 00170534 _____ C:\Users\chakotay\Desktop\Rocket Lawyer Interview.html
2015-06-17 12:25 - 2015-06-17 12:25 - 00000000 ____D C:\Users\chakotay\Desktop\Rocket Lawyer Interview_files
2015-06-17 12:15 - 2015-06-17 12:15 - 00284176 _____ C:\Windows\Minidump\061715-27861-01.dmp
2015-06-17 12:08 - 2015-06-17 12:08 - 00284176 _____ C:\Windows\Minidump\061715-28657-01.dmp
2015-06-17 10:46 - 2015-06-17 10:46 - 00074000 _____ (BitDefender SRL) C:\Windows\system32\bdsandboxuiskin32.dll
2015-06-17 10:16 - 2015-06-17 10:16 - 00000385 _____ C:\Windows\system32\user_gensett.xml
2015-06-17 10:16 - 2015-06-17 10:16 - 00000385 _____ C:\Users\chakotay\AppData\Roaminguser_gensett.xml
2015-06-17 10:16 - 2015-06-17 10:16 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2015-06-17 10:15 - 2015-06-17 10:15 - 00000000 ____D C:\ProgramData\BDLogging
2015-06-17 10:15 - 2015-01-09 11:44 - 00074000 _____ (BitDefender SRL) C:\Windows\SysWOW64\bdsandboxuiskin32.dll
2015-06-17 10:15 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\Windows\capicom.dll
2015-06-17 10:00 - 2015-06-17 20:30 - 00000000 ____D C:\Program Files\Bitdefender
2015-06-17 10:00 - 2015-01-09 11:44 - 00084848 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUISkin.dll
2015-06-17 10:00 - 2015-01-09 11:44 - 00033360 _____ (BitDefender SRL) C:\Windows\system32\BDSandBoxUH.dll
2015-06-17 09:59 - 2015-06-17 20:29 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2015-06-17 09:59 - 2015-06-17 09:59 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\QuickScan
2015-06-17 09:36 - 2015-06-17 09:36 - 02868840 _____ C:\Users\chakotay\Downloads\bitdefender_antivirus.exe
2015-06-17 08:56 - 2015-07-15 10:36 - 00000024 _____ C:\Users\chakotay\AppData\Roaming\appdataFr25.bin
2015-06-17 08:48 - 2015-06-17 08:48 - 00005933 _____ C:\Users\chakotay\Desktop\JRT.txt
2015-06-17 08:42 - 2015-06-17 08:42 - 00000207 _____ C:\Windows\tweaking.com-regbackup-BHP-Windows-7-Home-Premium-(64-bit).dat
2015-06-17 08:42 - 2015-06-17 08:42 - 00000000 ____D C:\RegBackup
2015-06-17 08:39 - 2015-06-17 08:39 - 02949914 _____ (Thisisu) C:\Users\chakotay\Downloads\JRT.exe
2015-06-16 16:31 - 2015-06-16 16:31 - 01691816 _____ (Microsoft Corporation) C:\Windows\system32\FM20.DLL
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-16 13:34 - 2015-01-26 23:51 - 00000000 ____D C:\Users\chakotay\Desktop\WORKING
2015-07-16 13:08 - 2014-04-02 06:27 - 01439161 _____ C:\Windows\WindowsUpdate.log
2015-07-16 13:06 - 2015-04-22 22:50 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-16 13:03 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-16 13:03 - 2009-07-14 00:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-16 12:58 - 2015-04-22 22:50 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-16 12:58 - 2015-01-18 09:22 - 00000000 ____D C:\Users\chakotay\AppData\Local\TSVNCache
2015-07-16 10:07 - 2015-05-30 05:16 - 00016046 _____ C:\Windows\setupact.log
2015-07-16 10:07 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-15 21:25 - 2009-07-14 00:45 - 05065680 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-15 21:21 - 2014-12-10 07:23 - 00000000 ____D C:\Windows\system32\appraiser
2015-07-15 21:21 - 2014-09-21 00:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-07-15 21:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-07-15 21:20 - 2015-06-13 19:23 - 00006212 _____ C:\Windows\PFRO.log
2015-07-15 20:41 - 2014-11-23 20:39 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-07-15 20:41 - 2014-11-23 20:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-15 20:34 - 2009-07-13 22:34 - 00000633 _____ C:\Windows\win.ini
2015-07-15 20:30 - 2014-09-21 22:17 - 00000000 ____D C:\Windows\system32\MRT
2015-07-15 18:29 - 2015-01-04 06:53 - 00000000 ____D C:\Users\chakotay\.gimp-2.6
2015-07-15 18:01 - 2015-04-22 22:50 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-15 18:01 - 2015-04-22 22:50 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-15 17:44 - 2015-05-28 21:33 - 00000000 ____D C:\Users\chakotay\Desktop\Ads
2015-07-15 17:43 - 2014-11-23 20:11 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\NCH Software
2015-07-15 17:43 - 2014-11-23 20:10 - 00000000 ____D C:\Program Files (x86)\NCH Software
2015-07-15 17:40 - 2014-12-15 21:17 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\uTorrent
2015-07-14 13:08 - 2015-04-22 22:50 - 00002147 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-12 09:26 - 2009-07-14 01:13 - 00723326 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-12 07:37 - 2015-01-04 07:01 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\gtk-2.0
2015-07-12 07:37 - 2014-09-17 15:34 - 00000000 ____D C:\Users\chakotay
2015-07-12 07:34 - 2015-01-04 07:00 - 00000000 ____D C:\Users\chakotay\.thumbnails
2015-07-12 07:29 - 2015-04-06 13:35 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-07-12 07:29 - 2015-04-06 13:35 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-12 00:31 - 2015-01-04 09:00 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\FileZilla
2015-07-11 21:46 - 2015-01-04 09:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-07-11 21:46 - 2015-01-04 09:00 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2015-07-11 16:18 - 2015-01-05 18:42 - 00000000 ____D C:\Users\chakotay\Documents\vMixStorage
2015-07-11 16:17 - 2013-12-10 09:45 - 00000000 ____D C:\ProgramData\Temp
2015-07-11 16:13 - 2014-10-29 16:34 - 00000000 ____D C:\Users\chakotay\AppData\Local\CrashDumps
2015-07-11 16:11 - 2015-01-05 18:42 - 00019969 _____ C:\Users\chakotay\AppData\Roaming\last.vmix
2015-07-11 11:28 - 2015-05-30 18:18 - 00000000 ____D C:\Users\chakotay\Desktop\RallyPics
2015-07-10 00:03 - 2014-09-21 00:20 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\vlc
2015-07-09 11:20 - 2015-05-13 15:31 - 00000000 ____D C:\Users\chakotay\Desktop\INVOICE
2015-07-09 06:22 - 2015-01-05 21:53 - 00000107 _____ C:\Users\chakotay\AppData\default.pls
2015-07-08 17:13 - 2015-05-19 05:56 - 00000000 ____D C:\Users\chakotay\Desktop\NANCY
2015-07-08 16:08 - 2015-04-10 07:55 - 00000000 ____D C:\Users\chakotay\Desktop\New folder (7)
2015-07-08 16:04 - 2015-01-16 11:18 - 00000000 ____D C:\Program Files (x86)\BitLord
2015-07-06 11:05 - 2015-01-16 07:22 - 00000000 ____D C:\Users\chakotay\Documents\ConvertXtoDVD
2015-07-05 15:17 - 2015-05-31 14:15 - 00000000 ____D C:\Users\chakotay\Desktop\Sheena
2015-07-03 08:43 - 2014-09-21 22:17 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-07-03 08:10 - 2015-06-13 19:15 - 00290304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\subinacl.exe
2015-06-30 23:31 - 2014-09-17 22:56 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Skype
2015-06-27 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2015-06-27 06:26 - 2014-11-21 19:35 - 00000000 __SHD C:\Users\chakotay\AppData\Local\EmieBrowserModeList
2015-06-27 06:26 - 2014-09-21 00:25 - 00000000 __SHD C:\Users\chakotay\AppData\Local\EmieUserList
2015-06-27 06:26 - 2014-09-21 00:25 - 00000000 __SHD C:\Users\chakotay\AppData\Local\EmieSiteList
2015-06-26 09:31 - 2015-02-02 00:51 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\Audacity
2015-06-25 08:30 - 2015-04-22 22:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-25 08:30 - 2014-11-23 20:40 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-06-25 08:30 - 2014-10-17 20:28 - 00000000 ____D C:\Users\chakotay\AppData\Roaming\dvdcss
2015-06-25 08:30 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\registration
2015-06-25 08:07 - 2010-11-21 03:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-06-23 13:30 - 2010-11-20 23:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-06-19 19:55 - 2014-12-31 16:13 - 00000000 ____D C:\ProgramData\SmartSound Software Inc
2015-06-19 00:02 - 2013-12-10 09:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-06-18 23:51 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-17 20:13 - 2015-06-02 22:18 - 634715340 _____ C:\Windows\MEMORY.DMP
2015-06-17 20:13 - 2014-12-08 08:36 - 00000000 ____D C:\Windows\Minidump
2015-06-17 13:09 - 2015-03-23 06:31 - 00000000 ____D C:\Program Files (x86)\Pin Search Image Search on Pinterest
2015-06-16 05:18 - 2015-06-12 12:45 - 00000000 ____D C:\Users\chakotay\Desktop\IMAGE2
==================== Files in the root of some directories =======
2015-06-17 08:56 - 2015-07-15 10:36 - 0000024 _____ () C:\Users\chakotay\AppData\Roaming\appdataFr25.bin
2014-09-21 00:25 - 2014-09-21 00:25 - 0099384 _____ () C:\Users\chakotay\AppData\Roaming\inst.exe
2015-01-05 18:42 - 2015-07-11 16:11 - 0019969 _____ () C:\Users\chakotay\AppData\Roaming\last.vmix
2014-09-21 00:25 - 2014-09-21 00:25 - 0007859 _____ () C:\Users\chakotay\AppData\Roaming\pcouffin.cat
2014-09-21 00:25 - 2014-09-21 00:25 - 0001167 _____ () C:\Users\chakotay\AppData\Roaming\pcouffin.inf
2014-09-21 00:25 - 2014-09-21 00:25 - 0000055 _____ () C:\Users\chakotay\AppData\Roaming\pcouffin.log
2014-09-21 00:25 - 2014-09-21 00:25 - 0082816 _____ (VSO Software) C:\Users\chakotay\AppData\Roaming\pcouffin.sys
2015-05-21 14:01 - 2015-05-21 14:01 - 0033193 _____ () C:\Users\chakotay\AppData\Roaming\UserTile.png
2015-05-05 11:40 - 2015-05-05 11:40 - 0011838 _____ () C:\Users\chakotay\AppData\Local\Temp-log.txt
2015-06-17 20:29 - 2015-06-17 20:29 - 0251963 _____ () C:\ProgramData\1434587004.bdinstall.bin
2014-04-02 07:00 - 2014-04-02 07:02 - 0002439 _____ () C:\ProgramData\clear.fiSDK20.log
2014-04-02 06:48 - 2014-04-02 06:48 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-04-02 07:01 - 2014-04-02 07:01 - 0000032 _____ () C:\ProgramData\PS.log
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-13 12:44
==================== End of log ============================aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2015-07-16 18:14:19
—————————–
18:14:19.240 OS Version: Windows x64 6.1.7601 Service Pack 1
18:14:19.241 Number of processors: 4 586 0x3A09
18:14:19.242 ComputerName: BHP UserName:
18:14:23.898 Initialize success
18:14:23.998 VM: initialized successfully
18:14:24.000 VM: Intel CPU supported
18:15:13.933 VM: supported disk I/O iaStor.sys
18:17:35.289 AVAST engine defs: 15071603
18:18:28.595 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:18:28.599 Disk 0 Vendor: ST500LT0 0001 Size: 476940MB BusType: 3
18:18:28.603 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000083
18:18:28.609 Disk 1 Vendor: Realtek_ 1.00 Size: 476940MB BusType: 1
18:18:28.776 VM: Disk 0 MBR read successfully
18:18:28.781 Disk 0 MBR scan
18:18:28.791 Disk 0 Windows 7 default MBR code
18:18:28.806 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 19456 MB offset 2048
18:18:28.830 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 39847936
18:18:28.842 Disk 0 default boot code
18:18:28.864 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 457383 MB offset 40052736
18:18:29.034 Disk 0 scanning C:\Windows\system32\drivers
18:18:44.607 Service scanning
18:19:14.743 Modules scanning
18:19:14.752 Disk 0 trace - called modules:
18:19:14.776 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
18:19:14.784 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008bea060]
18:19:14.791 3 CLASSPNP.SYS[fffff88001c9c43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062be050]
18:19:16.014 AVAST engine scan C:\
18:19:16.654 File: C:\$Recycle.Bin\S-1-5-21-3430744594-213253022-3560247601-1000\$R24RLUG.exe **INFECTED** Win32:Dropper-gen [Drp]
18:43:30.300 File: C:\Program Files (x86)\IncrementEdit\IncrementEdit.dll **INFECTED** Win32:Malware-gen
18:47:21.768 Disk 0 statistics 8232598/0/22 @ 3.46 MB/s
18:47:21.778 Scan stopped
18:47:32.238 Disk 0 MBR has been saved successfully to "C:\Users\chakotay\Desktop\MBR.dat"
18:47:32.244 The log file has been saved successfully to "C:\Users\chakotay\Desktop\aswMBR.txt"
18:51:16.629 Disk 0 MBR has been saved successfully to "C:\Users\chakotay\Desktop\MBR.dat"
18:51:16.645 The log file has been saved successfully to "C:\Users\chakotay\Desktop\FRST.txt"
Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by [removed] at 2015-07-16 13:51:14
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3430744594-213253022-3560247601-500 - Administrator - Disabled)
chakotay (S-1-5-21-3430744594-213253022-3560247601-1000 - Administrator - Enabled) => C:\Users\chakotay
Guest (S-1-5-21-3430744594-213253022-3560247601-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3430744594-213253022-3560247601-1002 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kingsoft Antivirus System Defense (Enabled - Up to date) {B6A51389-A795-5AC9-13BA-F569D73F3FE8}
AS: Kingsoft Antivirus System Defense (Enabled - Up to date) {0DC4F26D-81AF-5547-290A-CE1BACB87555}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.38 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0938-000001000000}) (Version: 9.38.00.0 - Igor Pavlov)
AC3Filter 2.6.0b (HKLM-x32\…\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky)
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.105 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2904.00 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.5.2904.00 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3508 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.04.3507 - Acer Incorporated)
Acer Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3502 - Acer Incorporated)
Acoustica Mixcraft 7 (64-bit) (HKLM-x32\…\Mixcraft 7-64) (Version: 7.0.0.251 - Acoustica)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Media Live Encoder 3.2 (HKLM-x32\…\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\…\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.0.6 (HKLM-x32\…\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Backup Manager V3 (x32 Version: 3.0.0.105 - NTI Corporation) Hidden
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.00 - Piriform)
clear.fi SDK - MVP 2 (x32 Version: 2.0.1702 - CyberLink Corp.) Hidden
clear.fi SDK- Movie 2 (x32 Version: 2.0.1707 - CyberLink Corp.) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.2727_43992 - CyberLink Corp.)
CyberLink PowerDirector 11 (HKLM-x32\…\InstallShield_{551F492A-01B0-4DC4-866F-875EC4EDC0A8}) (Version: 11.0.0.2418 - CyberLink Corp.)
CyberLink PowerDirector 11 (Version: 11.0.0.2418 - CyberLink Corp.) Hidden
DVD Shrink 3.2 (HKLM-x32\…\DVD Shrink_is1) (Version: - DVD Shrink)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
ETDWare PS/2-X64 11.6.4.001_WHQL (HKLM\…\Elantech) (Version: 11.6.4.001 - ELAN Microelectronic Corp.)
Evernote v. 4.5.2 (HKLM-x32\…\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
EZ Grabber (HKLM-x32\…\{8543A572-5993-4101-BACC-C83884E183A4}) (Version: 2.00.0000 - EZ Grabber)
File Association Helper (HKLM\…\{C168639F-5810-4EC8-B1E8-0251AA8A771C}) (Version: 1.2.225.65451 - WinZip Computing International, LLC)
FileZilla Client 3.12.0.2 (HKLM-x32\…\FileZilla Client) (Version: 3.12.0.2 - Tim Kosse)
GIMP 2.6.10 (HKLM-x32\…\WinGimp-2.0_is1) (Version: 2.6.10 - The GIMP Team)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\…\HaaliMkx) (Version: - )
HandBrake 0.10.0 (HKLM-x32\…\HandBrake) (Version: 0.10.0 - )
iCloud (HKLM\…\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3503 - Acer Incorporated)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2752 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Kingsoft Antivirus 2012 (HKLM-x32\…\Kingsoft Internet Security) (Version: 2012.5.7 - Kingsoft Internet Security)
LAME v3.99.3 (for Windows) (HKLM-x32\…\LAME_is1) (Version: - )
Launch Manager (HKLM-x32\…\LManager) (Version: 7.0.12 - Acer Inc.)
Livestream Producer (HKLM-x32\…\{0017632B-E77C-43F2-9FE5-CAB59206FA6F}) (Version: 1.0.0 - Livestream)
MagicYUV Lossless Video Codec version 1.0 (HKLM-x32\…\{90410593-E0EB-4F9B-B984-65BEA8F07B91}_is1) (Version: 1.0 - INNOMAGIC, Ltd.)
Malwarebytes' Anti-Malware (HKLM-x32\…\Malwarebytes' Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Camera Codec Pack (HKLM\…\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\…\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MP3jam 1.1.1.10 (HKLM-x32\…\MP3jam_is1) (Version: 1.1.1.10 - MP3jam)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden
Nero 7 Ultra Edition (HKLM-x32\…\{CF097717-F174-4144-954A-FBC4BF301033}) (Version: 7.02.9753 - Nero AG)
Nero Backup Drivers (HKLM\…\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}) (Version: 1.0.11100.8.0 - Nero AG)
Newblue Art Effects for PowerDirector (HKLM\…\NewBlue Art Effects for PowerDirector) (Version: 2.0 - NewBlue)
newsXpresso (HKLM-x32\…\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.)
newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.6.9575 - Barnesandnoble.com)
Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.7.3 - Notepad++ Team)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9006 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9006 - NTI Corporation) Hidden
One Touch Video Capture (HKLM-x32\…\{C3A6202F-8F3E-424C-83B8-189F92A1AB43}) (Version: - )
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PowerDirector (Version: 11.0 - CyberLink Corp.) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.312 - Qualcomm Atheros Communications)
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.19 - Qualcomm Atheros Inc.)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.21 - Qualcomm Atheros)
QuickTime 7 (HKLM-x32\…\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RadioBOSS 5.0.0.9 (HKLM-x32\…\RadioBOSS) (Version: 5.0.0.9 - DJSoft.Net)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.28145 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\…\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Skype™ 7.2 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
SmartSound Quicktracks 5 (HKLM-x32\…\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.8 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (x32 Version: 5.1.8 - SmartSound Software Inc.) Hidden
SpyHunter 4 (HKLM-x32\…\SpyHunter) (Version: 4.20.9.4533 - Enigma Software Group, LLC)
TortoiseSVN 1.8.10.26129 (64 bit) (HKLM\…\{A9E679EC-8FD4-49D8-A5A5-ACE462515A9E}) (Version: 1.8.26129 - TortoiseSVN)
TuneUp Utilities Language Pack (en-US) (x32 Version: 12.0.3600.181 - TuneUp Software) Hidden
Turbonett móvil (HKLM-x32\…\Turbonett móvil) (Version: 11.302.09.09.519 - Huawei Technologies Co.,Ltd)
Unlocker 1.9.2 (HKLM\…\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\…\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{40930C8E-A677-414C-A72F-DFDEB10738FB}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3054791) 64-Bit Edition (HKLM\…\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{591150FB-47D4-495C-9E76-F8D354A2577D}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3054791) 64-Bit Edition (HKLM\…\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{591150FB-47D4-495C-9E76-F8D354A2577D}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3054791) 64-Bit Edition (HKLM\…\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{591150FB-47D4-495C-9E76-F8D354A2577D}) (Version: - Microsoft)
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VidBlaster (HKU\S-1-5-21-3430744594-213253022-3560247601-1000\…\VidBlaster) (Version: - )
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
vMix (HKLM-x32\…\{93D664E9-E81E-4277-9E90-6CDABAC7208F}_is1) (Version: - StudioCoast)
vMix Social (HKLM-x32\…\{1A0C8557-EB4A-4DD1-B4F9-A974ADEFE05F}_is1) (Version: - StudioCoast Pty Ltd)
VSO ConvertXToDVD (HKLM-x32\…\{CE1F93C0-4353-4C9D-84DA-AB4E7C63ED32}_is1) (Version: 5.1.0.12 - VSO Software)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
Winamp (HKLM-x32\…\Winamp) (Version: 5.666 - Nullsoft, Inc)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
10-07-2015 09:24:41 Windows Update
12-07-2015 07:28:04 Windows Update
15-07-2015 20:24:02 Windows Update
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-07-08 15:23 - 2015-07-08 15:23 - 00000000 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {2D721CE7-DE86-483F-9AD0-A7B60287D6AE} - System32\Tasks\{CA6A25F2-B0ED-4BB5-8969-283D4FD9584E} => pcalua.exe -a C:\Users\chakotay\Downloads\QuickTimeInstaller.exe -d C:\Users\chakotay\Downloads
Task: {3738A5A8-2B99-4B8C-8E1A-8C44B1148DD6} - System32\Tasks\{0750E579-12D8-41F8-ABE7-245FA68EE652} => C:\Program Files (x86)\kingsoft\kingsoft antivirus\kismain.exe [2014-11-28] (Kingsoft Corporation)
Task: {3AF0A0F3-40DE-47B1-B7B4-0EF79D097CB3} - System32\Tasks\{A3C7E78D-B6B7-4135-A935-E03E31EFF19E} => pcalua.exe -a "C:\Program Files (x86)\CombiTech\VidBlaster\Uninstal.exe" -d "C:\Program Files (x86)\CombiTech\VidBlaster"
Task: {4B590BBB-19EF-454A-B4FF-29A5BE7F5520} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-22] (Google Inc.)
Task: {69273BCF-C266-4606-B93F-A728C405322B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {6F44620D-B2FF-46F2-AA07-5522C34F8C39} - System32\Tasks\{B472276A-A9B2-42D6-BABF-6EFC38DA4A1F} => pcalua.exe -a "C:\Program Files (x86)\Picexa\uninstall.exe"
Task: {79262722-605C-49AA-BBBF-EA704250D666} - System32\Tasks\{121251DE-FBB3-419E-9EDB-24189CD589F5} => C:\Program Files (x86)\DVD Shrink\DVD Shrink 3.2.exe [2004-07-26] (DVD Shrink)
Task: {7AA29476-3887-44CF-AE0A-1A79DBABAC9F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-22] (Google Inc.)
Task: {8B48926E-86F5-40C9-9A14-DE742D711B04} - System32\Tasks\{CAA64F76-9505-49A7-9930-2ECBBDBAC512} => pcalua.exe -a C:\Users\chakotay\AppData\Local\TNT2\2.0.0.1918\TNT2User.exe -c /UNINSTALL PARTNER=11187
Task: {91F2CEA2-ADAD-4BB3-9CFB-3D6ABC02B51E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A82D1DC5-9944-403F-BE80-690340FC37DC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
Task: {A8D83114-AEFD-4CD3-935F-33A82845BBD9} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {AE6E3F71-83ED-4740-B39C-7DE59B160636} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {AE91A892-3F73-494E-A77B-3ED15EBAC8A1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {B634ADD5-D2FE-4E37-B9BD-EA1F453FBE34} - System32\Tasks\{6545B3D7-8D40-4C4C-A44E-A33EB8BFB88D} => pcalua.exe -a C:\Users\chakotay\Downloads\SetupVidBlaster.exe -d C:\Users\chakotay\Downloads
Task: {B656EF60-87CC-4D07-88B8-3DC5A2BE2B4F} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-03-28] (CyberLink)
Task: {CBF1F544-8AC3-4D7F-BB11-4AC5F3613D82} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {CD0B4B59-4C7A-4C14-A8C7-F289BE9C03CF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {EF5B9E02-56AD-4BB9-9ADD-08196330AB69} - System32\Tasks\{5AD7CDEE-B7D9-487F-8894-DD0D27086285} => pcalua.exe -a C:\Users\chakotay\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Task: {F27C63A4-8D91-497F-81BD-0749B2DFC46C} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-28] (Egis Technology Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2010-05-08 07:48 - 2010-05-08 07:48 - 00229376 _____ () C:\ProgramData\DatacardService\DCService.exe
2014-12-31 16:13 - 2012-09-12 03:14 - 00390672 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-12-31 16:13 - 2012-09-12 03:14 - 00024080 _____ () C:\Program Files\Cyberlink\Shared files\RichVideops64.dll
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-12-17 21:31 - 2014-12-17 21:31 - 00076032 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
2014-12-17 21:30 - 2014-12-17 21:30 - 00088832 _____ () C:\Program Files\TortoiseSVN\bin\libsasl.dll
2015-07-09 13:32 - 2015-07-09 13:32 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2010-07-15 00:44 - 2010-07-15 00:44 - 00020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2009-01-21 20:45 - 2009-01-21 20:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2014-05-12 05:49 - 2014-05-12 05:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2013-11-29 01:32 - 2013-11-29 01:32 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2013-12-10 08:29 - 2012-05-09 19:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-26 14:17 - 2012-12-26 14:17 - 01604312 _____ () C:\Program Files\CyberLink\PowerDirector11\Language\ENU\PDrt.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00303616 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\mediacache\libebml.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00672256 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\mediacache\libmatroska.dll
2012-09-12 03:13 - 2012-09-12 03:13 - 00160784 _____ () C:\Program Files\CyberLink\PowerDirector11\CLVistaAudioMixer.dll
2012-09-12 03:13 - 2012-09-12 03:13 - 00230928 _____ () C:\Program Files\CyberLink\PowerDirector11\HanumanCache.dll
2015-01-05 18:36 - 2014-10-27 14:10 - 00029696 _____ () C:\Program Files (x86)\vMix\VCMWrapper.dll
2015-01-05 18:36 - 2010-02-21 14:12 - 00303104 _____ () C:\Program Files (x86)\vMix\DirectShowLib-2005.dll
2015-01-05 18:36 - 2014-11-06 22:15 - 00037376 _____ () C:\Program Files (x86)\vMix\MJPEGDMO.dll
2015-01-05 18:36 - 2014-10-25 14:18 - 00108032 _____ () C:\Program Files (x86)\vMix\x64\vMixNative.dll
2012-07-26 13:33 - 2012-07-26 13:33 - 00061440 _____ () C:\Program Files\CyberLink\Shared files\PlugIn\NewBlue\NewBlue_PlugIn_ArtEffectsBundleForPDR.dll
2012-07-26 13:32 - 2012-07-26 13:32 - 00136704 _____ () C:\Program Files\CyberLink\Shared files\Plugin\NewBlue\NewBlueResources64.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 01485312 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\magicModule\cv110_64.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 01597440 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\magicModule\cxcore110_64.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00620544 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\magicModule\highgui110_64.dll
2014-12-31 16:10 - 2012-07-11 06:11 - 00096784 _____ () C:\Program Files\CyberLink\Shared files\PlugIn\9.0\AEJ_Converter.dll
2012-12-26 14:17 - 2012-12-26 14:17 - 02173984 _____ () C:\Program Files\CyberLink\PowerDirector11\runtime\authoring\AuroraU.dll
2012-09-12 03:14 - 2012-09-12 03:14 - 00018960 _____ () C:\Program Files\CyberLink\PowerDirector11\S3Dutility.dll
2015-03-29 00:26 - 2013-04-05 21:27 - 02231296 _____ () C:\Windows\system32\ac3filter64.acm
2012-09-26 19:41 - 2012-09-26 19:41 - 00465384 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2012-09-26 19:41 - 2012-09-26 19:41 - 01081408 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2012-09-26 19:41 - 2012-09-26 19:41 - 00125504 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2014-04-02 06:43 - 2012-06-24 22:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-12-17 20:53 - 2014-12-17 20:53 - 00065792 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub32.dll
2014-12-17 20:53 - 2014-12-17 20:53 - 00071936 _____ () C:\Program Files\TortoiseSVN\bin\libsasl32.dll
2014-07-31 12:16 - 2014-07-31 12:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-05 18:36 - 2014-08-06 18:54 - 00968192 _____ () C:\Program Files (x86)\vMix\filters\vMixVideo.ax
2013-04-26 05:39 - 2010-11-19 09:01 - 00093936 _____ () C:\Program Files (x86)\CombiTech\VidBlaster\DatasteadVirtualStream.ax
2015-07-09 13:32 - 2015-07-09 13:32 - 00039384 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2015-07-14 13:08 - 2015-07-13 17:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-14 13:08 - 2015-07-13 17:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll
2015-07-14 13:08 - 2015-07-13 17:55 - 16308040 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:8E236DBE
AlternateDataStreams: C:\ProgramData\Temp:A7D26093
AlternateDataStreams: C:\Users\chakotay\Downloads\Business-in-a-Box_setup.exe:BDU
AlternateDataStreams: C:\Users\chakotay\AppData\Local\Temporary Internet Files:e4HGVDlquN4U2E0PgNO1fHY1Twz
AlternateDataStreams: C:\Users\chakotay\AppData\Local\y3MRxgN3l:RKFHd2Pgq95QDNJ71iNHKHckksBM
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3430744594-213253022-3560247601-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\chakotay\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^Users^chakotay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Audition CC 2014 7.0 Multilanguage (64-Bit) + Patch [ATOM].lnk => C:\Windows\pss\Adobe Audition CC 2014 7.0 Multilanguage (64-Bit) + Patch [ATOM].lnk.Startup
MSCONFIG\startupfolder: C:^Users^chakotay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Karaoke-4,499 songs.lnk => C:\Windows\pss\Karaoke-4,499 songs.lnk.Startup
MSCONFIG\startupfolder: C:^Users^chakotay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^peter tosh - Downpressor man.lnk => C:\Windows\pss\peter tosh - Downpressor man.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{A91A2C36-4235-47CA-9544-7C67A0FC47DD}] => (Allow) %SystemRoot%\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
FirewallRules: [{F554F7A1-01E4-4196-8917-B3DB32125C22}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{696900F2-C519-451C-8FFC-B59D8F1F58FD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{2631D757-D086-4091-8658-23D29A0E69C7}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{2EDE97B0-8031-4C54-A000-803CB50C19D5}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{2BF4D63B-15C7-4208-9114-08104003B544}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{1230DA12-5580-429A-A002-B356ADED78A0}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{799F77FF-8752-43D1-8447-E514F9AF2A48}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{7F5417A2-A2F3-46D9-B84C-B0294BC33169}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{BDCA150D-A8B0-4174-8D6B-B31DDEF44CED}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{E89E51C4-E005-428B-8CFD-5427B985FE9A}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\Movie\PlayMovie.exe
FirewallRules: [{216BEFD4-94C1-4C3A-ABAC-E9EDBA388FF2}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\VideoPlayer.exe
FirewallRules: [{5B00ED62-A053-4F02-8009-F9AF44B8A2C2}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\MusicPlayer.exe
FirewallRules: [{E1DFA818-46BF-486F-A597-F82C2815C107}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{86107616-037E-42A8-86F1-CA89D9EBCA1C}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{FDE280EB-CDA0-4DAE-A523-90CAC900C1ED}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{C55A959B-219A-4D68-8CE3-AAC19B63D10D}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{E03024F2-32FF-4490-84CB-EBEEB121D894}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{88D48036-EA14-4D22-8CE1-8366EF38186E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{41D7EE51-7C31-40A3-B0B9-B84766B391D7}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{12B85B91-A17C-47F1-AF49-C14CADEFCDE2}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{9A4FBAB3-84B4-4EEB-A1A3-75AC466EBB2B}] => (Allow) C:\Program Files\CyberLink\PowerDirector11\PDR10.EXE
FirewallRules: [{EE586337-D102-46BF-A853-79AA47636F21}] => (Allow) C:\Users\chakotay\AppData\Local\TNT2\2.0.0.1918\TNT2User.exe
FirewallRules: [TCP Query User{B7AD81D1-065A-4C70-9B05-97FFCDA38E56}C:\program files (x86)\combitech\vidblaster\vidblaster.exe] => (Block) C:\program files (x86)\combitech\vidblaster\vidblaster.exe
FirewallRules: [UDP Query User{25C0F8CA-8B4B-4906-A54E-7E0B97F6AE85}C:\program files (x86)\combitech\vidblaster\vidblaster.exe] => (Block) C:\program files (x86)\combitech\vidblaster\vidblaster.exe
FirewallRules: [TCP Query User{A09F173D-F041-4D93-8028-CB772ED4AD35}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [UDP Query User{4C2B69A1-E07D-4B70-B84B-EEB1BFCBEA66}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [TCP Query User{4D1180A2-36E5-4CB6-BE18-25341AE2744A}C:\program files (x86)\vmix\vmix.exe] => (Allow) C:\program files (x86)\vmix\vmix.exe
FirewallRules: [UDP Query User{75851E82-10CC-443A-B3D7-D956E949769C}C:\program files (x86)\vmix\vmix.exe] => (Allow) C:\program files (x86)\vmix\vmix.exe
FirewallRules: [TCP Query User{D3881386-B789-4CA4-BA8D-018C17657DED}C:\program files (x86)\vmix\vmixdesktopcapture.exe] => (Allow) C:\program files (x86)\vmix\vmixdesktopcapture.exe
FirewallRules: [UDP Query User{973CEB0F-3A2D-4663-9294-6179AFE2CA93}C:\program files (x86)\vmix\vmixdesktopcapture.exe] => (Allow) C:\program files (x86)\vmix\vmixdesktopcapture.exe
FirewallRules: [TCP Query User{AAC6DEF4-64EA-40C0-9CC1-D86E4BB45813}C:\program files (x86)\vmixsocial\vmixsocial.exe] => (Allow) C:\program files (x86)\vmixsocial\vmixsocial.exe
FirewallRules: [UDP Query User{76EA0F6E-EAB2-4972-8533-90041086A072}C:\program files (x86)\vmixsocial\vmixsocial.exe] => (Allow) C:\program files (x86)\vmixsocial\vmixsocial.exe
FirewallRules: [{BBD5F3D9-394E-4E1F-BB98-C2232D96BC20}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{383C7871-75E6-4831-BB4C-CA5D158CA99E}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{62A423FF-38B9-4D80-A1A6-06B6A43D23A0}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{067A6EC2-BBC3-4123-9CC8-7BB9C6E75067}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{94AEC4B2-F89C-4B56-91C8-6F2C2C77308B}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [UDP Query User{A6F85450-3BA9-4A3A-BA03-81774D48210A}C:\program files (x86)\vmix\vmix64.exe] => (Allow) C:\program files (x86)\vmix\vmix64.exe
FirewallRules: [TCP Query User{6146B76E-36BE-4E2F-9B46-F6756FDE7A90}C:\program files (x86)\radioboss\radioboss.exe] => (Allow) C:\program files (x86)\radioboss\radioboss.exe
FirewallRules: [UDP Query User{9EF9FFAC-883F-4A5D-889E-F884B4E4CDD3}C:\program files (x86)\radioboss\radioboss.exe] => (Allow) C:\program files (x86)\radioboss\radioboss.exe
FirewallRules: [TCP Query User{D850F216-C68E-4D8D-9C98-D0B3625291CD}C:\program files (x86)\miniget\miniget.exe] => (Allow) C:\program files (x86)\miniget\miniget.exe
FirewallRules: [UDP Query User{65344B1F-6731-425D-9EF6-BDD8B462D468}C:\program files (x86)\miniget\miniget.exe] => (Allow) C:\program files (x86)\miniget\miniget.exe
FirewallRules: [{99C5F9CF-FFFB-470D-A0ED-743EAF0AAF3C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{F668A504-BE5A-4B1E-B6AB-F00D071A5D6C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{96355800-5F68-4CE5-99EB-F92B62FF8F95}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{8F7B4D63-4AFF-4337-A5A5-EAEFDB0E1B87}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{7C03C433-FA7D-40C1-84DC-DF72F0A0576A}C:\program files (x86)\nero\nero 7\nero home\nerohome.exe] => (Block) C:\program files (x86)\nero\nero 7\nero home\nerohome.exe
FirewallRules: [UDP Query User{973A5C17-4611-42EE-BC26-1F1C397BD695}C:\program files (x86)\nero\nero 7\nero home\nerohome.exe] => (Block) C:\program files (x86)\nero\nero 7\nero home\nerohome.exe
FirewallRules: [TCP Query User{D3F31BAC-4B4E-4B8B-9A9D-F8A9DA3CBDFE}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [UDP Query User{B09943F6-9AF8-403D-AC89-89ACD633588F}C:\program files (x86)\youwave android\vb\vboxsdl.exe] => (Allow) C:\program files (x86)\youwave android\vb\vboxsdl.exe
FirewallRules: [{A567DB28-0987-4D7D-9603-208602ABBF8F}] => (Allow) C:\Users\chakotay\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{55A172A6-B82E-4929-BDA8-6EB3ACDD2466}] => (Allow) C:\Users\chakotay\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{4B87595F-A1A2-48BE-9383-0F07F382172F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: HD WebCam
Description: USB Video Device
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/16/2015 10:08:37 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/16/2015 06:35:28 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
Error: (07/15/2015 09:28:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 09:25:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 05:40:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 11:28:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 10:51:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 06:01:30 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
Error: (07/14/2015 06:57:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/14/2015 12:59:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (07/16/2015 10:08:22 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the BocaFunc service to connect.
Error: (07/16/2015 10:07:52 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SystemPromote service to connect.
Error: (07/16/2015 10:07:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The sbapifs service failed to start due to the following error:
%%2
Error: (07/16/2015 10:06:51 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
Error: (07/15/2015 09:28:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the BocaFunc service to connect.
Error: (07/15/2015 09:27:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SystemPromote service to connect.
Error: (07/15/2015 09:27:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The sbapifs service failed to start due to the following error:
%%2
Error: (07/15/2015 09:25:52 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
Error: (07/15/2015 09:25:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the BocaFunc service to connect.
Error: (07/15/2015 09:24:31 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the SystemPromote service to connect.
Microsoft Office:
=========================
Error: (07/16/2015 10:08:37 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/16/2015 06:35:28 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
Error: (07/15/2015 09:28:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 09:25:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 05:40:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 11:28:38 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 10:51:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/15/2015 06:01:30 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
Error: (07/14/2015 06:57:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/14/2015 12:59:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 56%
Total physical RAM: 5982.36 MB
Available physical RAM: 2618.37 MB
Total Virtual: 11962.92 MB
Available Virtual: 6945.7 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:446.66 GB) (Free:34.47 GB) NTFS
Drive f: (EOS_DIGITAL) (Removable) (Total:29.82 GB) (Free:17.76 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7C819AB2)
Partition 1: (Not Active) - (Size=19 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=446.7 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 29.8 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End of log ============================
aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2015-07-16 18:14:19
—————————–
18:14:19.240 OS Version: Windows x64 6.1.7601 Service Pack 1
18:14:19.241 Number of processors: 4 586 0x3A09
18:14:19.242 ComputerName: BHP UserName:
18:14:23.898 Initialize success
18:14:23.998 VM: initialized successfully
18:14:24.000 VM: Intel CPU supported
18:15:13.933 VM: supported disk I/O iaStor.sys
18:17:35.289 AVAST engine defs: 15071603
18:18:28.595 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:18:28.599 Disk 0 Vendor: ST500LT0 0001 Size: 476940MB BusType: 3
18:18:28.603 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000083
18:18:28.609 Disk 1 Vendor: Realtek_ 1.00 Size: 476940MB BusType: 1
18:18:28.776 VM: Disk 0 MBR read successfully
18:18:28.781 Disk 0 MBR scan
18:18:28.791 Disk 0 Windows 7 default MBR code
18:18:28.806 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 19456 MB offset 2048
18:18:28.830 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 39847936
18:18:28.842 Disk 0 default boot code
18:18:28.864 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 457383 MB offset 40052736
18:18:29.034 Disk 0 scanning C:\Windows\system32\drivers
18:18:44.607 Service scanning
18:19:14.743 Modules scanning
18:19:14.752 Disk 0 trace - called modules:
18:19:14.776 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
18:19:14.784 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008bea060]
18:19:14.791 3 CLASSPNP.SYS[fffff88001c9c43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062be050]
18:19:16.014 AVAST engine scan C:\
18:19:16.654 File: C:\$Recycle.Bin\S-1-5-21-3430744594-213253022-3560247601-1000\$R24RLUG.exe **INFECTED** Win32:Dropper-gen [Drp]
18:43:30.300 File: C:\Program Files (x86)\IncrementEdit\IncrementEdit.dll **INFECTED** Win32:Malware-gen
18:47:21.768 Disk 0 statistics 8232598/0/22 @ 3.46 MB/s
18:47:21.778 Scan stopped
18:47:32.238 Disk 0 MBR has been saved successfully to "C:\Users\chakotay\Desktop\MBR.dat"
18:47:32.244 The log file has been saved successfully to "C:\Users\chakotay\Desktop\aswMBR.txt"