This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google services won't load (all of them) [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys

 

I'm fairly new to this forum, I decided to make an account and get serious help to solve my trouble because my websearch showed me this topic on your page and I'm experiëncing the exact same problems.

 

Last week I noticed none of the services Google provides are working for me.

  • Google Search
  • Youtube
  • Google calendar
  • Google docs
  • Gmail
  • Googlerelated forums

In the meantime I tried:

  • Deleting cookies/cachefiles (Hasn't helped a bit)
  • Resetting my modem (helped bring back Google's search engine back to life but not the rest)
  • Tried using an anonymous proxy browser a friend suggested me to (This works, but I still want it fully fixed)
  • Tried running Malwarebyte Anti-malware (Hasn't helped a bit)

I've given up, I can't solve this on my own.

I hope you guys can shed some light on what's going on here.

 

I should note my first language is Dutch and don't know a whole lot about computers, internet and their problems. And although my English isn't that bad, there's a slight possibility I might have to ask some more indepth explanation on certain steps.

 

Thanks in advance,

Jean-Pierre.

 

PS: I read in the forumrules I shouldn't reply on my own posts because the helpers on this forum only reply to threads with 0 replies. I take it, if someone helping me want's me to reply he should mention so in their reply? Or does it go trough private messaging from here on?

 

PS: Here's the outcome of the scan I did:
 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-09-20 04:06:14
—————————–
04:06:14.153    OS Version: Windows x64 6.2.9200 
04:06:14.153    Number of processors: 2 586 0x3A09
04:06:14.153    ComputerName: JUPP3  UserName: JuPp3
04:06:23.321    Initialize success
04:06:23.915    VM: initialized successfully
04:06:23.915    VM: Intel CPU supported 
04:06:30.699    VM: supported disk I/O ataport.SYS
04:07:30.474    The log file has been saved successfully to "C:\Users\jantje\Desktop\aswMBR.txt"
 
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-09-20 04:06:14
—————————–
04:06:14.153    OS Version: Windows x64 6.2.9200 
04:06:14.153    Number of processors: 2 586 0x3A09
04:06:14.153    ComputerName: JUPP3  UserName: JuPp3
04:06:23.321    Initialize success
04:06:23.915    VM: initialized successfully
04:06:23.915    VM: Intel CPU supported 
04:06:30.699    VM: supported disk I/O ataport.SYS
04:07:30.474    The log file has been saved successfully to "C:\Users\jantje\Desktop\aswMBR.txt"
04:07:52.004    AVAST engine defs: 15091901
04:08:20.904    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T1L0-7
04:08:20.904    Disk 0 Vendor: WDC_WD5003AZEX-00K1GA0 80.00A80 Size: 476940MB BusType: 3
04:08:21.045    Disk 0 MBR read successfully
04:08:21.060    Disk 0 MBR scan
04:08:21.107    Disk 0 Windows 7 default MBR code
04:08:21.123    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          350 MB offset 2048
04:08:21.170    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       229650 MB offset 718848
04:08:21.216    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       120000 MB offset 471042048
04:08:21.263    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       126938 MB offset 716802048
04:08:21.357    Disk 0 scanning C:\Windows\system32\drivers
04:08:40.571    Service scanning
04:09:27.984    Modules scanning
04:09:27.984    Disk 0 trace - called modules:
04:09:27.999    
04:09:28.958    AVAST engine scan C:\Windows
04:09:30.835    AVAST engine scan C:\Windows\system32
04:14:13.629    AVAST engine scan C:\Windows\system32\drivers
04:14:34.542    AVAST engine scan C:\Users\jantje
04:15:53.743    Disk 0 MBR has been saved successfully to "C:\Users\jantje\Desktop\MBR.dat"
04:15:53.790    The log file has been saved successfully to "C:\Users\jantje\Desktop\aswMBR.txt"

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days.

:)


Hello there, Jean-Pierre

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
  • IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

    —————————————————————————————————

    Please download Farbar Recovery Scan Tool and save it to your Desktop.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Right-click FRST then click "Run as administrator" (XP users: click run after receipt of Windows Security Warning - Open File).
    • When the tool opens, click Yes to disclaimer.
    • Press the Scan button.
    • When finished, it will produce a log called FRST.txt in the same directory the tool was run from.
    • Please copy and paste the log in your next reply.
    Note 2: The first time the tool is run it generates another log (Addition.txt - also located in the same directory the tool was run from). Please also paste that, along with the FRST.txt into your next reply.

    —————————————————————————————————

Hello Consipre,

 

Thanks for taking the time to help me.

Per your request:
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by [removed] (administrator) on JUPP3 (20-09-2015 04:38:50)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 Pro (X64) Language: Engels (Verenigde Staten)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\39.0.2171.46\remoting_host.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\39.0.2171.46\remoting_host.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic Professional\ioloGovernor64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Company) C:\Program Files (x86)\Popcorn Time\Updater.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic Professional\LiveBoost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.EXE
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-18] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [iolo Startup] => C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe [4521272 2015-04-28] (iolo technologies, LLC)
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Run: [Google Update] => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Run: [GoogleChromeAutoLaunch_DEC25C6095400C38A9D2B973B9C3E508] => C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe [815944 2015-09-12] (Google Inc.)
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Tritton 720+.lnk [2014-10-13]
ShortcutTarget: Tritton 720+.lnk -> C:\Windows\Installer\{AD3320DC-2703-40EA-B0F6-1705C1A62A73}\_898F7BE9021EA09063812A.exe ()
Startup: C:\Users\jantje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2014-11-01]
ShortcutTarget: Dropbox.lnk -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{C5873AA1-CED8-488B-A735-7A3C44E01260}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E3456850-D549-4AEB-8EB5-8498E0D3AC8A}: [DhcpNameServer] [removed] [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/nl-nl/?ocid=iehp
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-19] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-19] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\jantje\AppData\Roaming\Mozilla\Firefox\Profiles\q07aj95n.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-19] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-08-17] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-08-17] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-244135331-4156006937-3082476691-1001: @tools.google.com/Google Update;version=3 -> C:\Users\jantje\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-244135331-4156006937-3082476691-1001: @tools.google.com/Google Update;version=9 -> C:\Users\jantje\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-244135331-4156006937-3082476691-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jantje\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-18] (Unity Technologies ApS)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/ig
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Presentaties) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-11]
CHR Extension: (Google Documenten) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-11]
CHR Extension: (Google Drive) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-11]
CHR Extension: (YouTube) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-11]
CHR Extension: (Klassieke Spelen) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpckajjkmjncafjlkielcgheibdlnfgc [2015-01-25]
CHR Extension: (Google Search) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-11]
CHR Extension: (Google Spreadsheets) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-11]
CHR Extension: (Chrome Remote Desktop) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2014-10-11]
CHR Extension: (Offline Documenten) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-06]
CHR Extension: (AdBlock) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-10-11]
CHR Extension: (Little Alchemy) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2014-10-11]
CHR Extension: (F.B Purity-Clean Up Facebook) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl [2015-01-24]
CHR Extension: (AgarioMods Evergreen Script) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhjgdbihpkphlammdaeicdemggagfbdo [2015-08-05]
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-11]
CHR Extension: (Gmail) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-11]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\39.0.2171.46\remoting_host.exe [56648 2014-10-29] (Google Inc.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-08-18] (NVIDIA Corporation)
R2 ioloSystemService; C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [4675896 2015-04-28] (iolo technologies, LLC)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-18] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544568 2015-08-18] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-02-25] (Electronic Arts)
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [335360 2014-12-17] (Company) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-10-13] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2014-10-13] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 KMSEmulator; temp.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-08-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [32912 2014-08-12] (EldoS Corporation)
S3 RTL8187B; C:\Windows\system32\DRIVERS\rtl8187B.sys [459336 2013-06-18] (Realtek Semiconductor Corporation                           )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
U3 aswMBR; \??\C:\Users\jantje\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\jantje\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-20 04:38 - 2015-09-20 04:39 - 00016899 _____ C:\Users\jantje\Desktop\FRST.txt
2015-09-20 04:37 - 2015-09-20 04:38 - 00000000 ____D C:\FRST
2015-09-20 04:37 - 2015-09-20 04:37 - 02191360 _____ (Farbar) C:\Users\jantje\Desktop\FRST64.exe
2015-09-20 04:15 - 2015-09-20 04:15 - 00000512 _____ C:\Users\jantje\Desktop\MBR.dat
2015-09-20 04:07 - 2015-09-20 04:15 - 00002444 _____ C:\Users\jantje\Desktop\aswMBR.txt
2015-09-20 03:56 - 2015-09-20 03:56 - 05198336 _____ (AVAST Software) C:\Users\jantje\Desktop\aswMBR.exe
2015-09-20 01:40 - 2015-09-20 04:05 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-20 01:40 - 2015-09-20 01:40 - 00001131 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-20 01:40 - 2015-09-20 01:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-20 01:40 - 2015-09-20 01:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-20 01:40 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-20 01:40 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-20 01:40 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-20 01:39 - 2015-09-20 01:39 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\jantje\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-16 16:38 - 2015-09-16 16:38 - 00002084 _____ C:\Users\jantje\Desktop\RuneScape.lnk
2015-09-16 16:38 - 2015-09-16 16:38 - 00000000 ____D C:\Users\jantje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape
2015-09-16 16:34 - 2015-09-16 16:34 - 24219648 _____ C:\Users\jantje\Desktop\RuneScape(1).msi
2015-09-14 20:46 - 2015-09-14 20:46 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0ef1daeeb551c.job
2015-09-14 20:18 - 2015-09-14 20:38 - 00000000 ____D C:\Users\jantje\AppData\Roaming\RSBot
2015-09-14 20:18 - 2015-09-14 20:18 - 00000046 _____ C:\Users\jantje\jagex_cl_runescape_LIVE2.dat
2015-09-14 20:18 - 2015-09-14 20:18 - 00000000 ____D C:\Users\jantje\jagexcache2
2015-09-14 20:17 - 2015-09-14 20:17 - 00947009 _____ C:\Users\jantje\Desktop\RSBot-6071.jar
2015-09-09 00:14 - 2015-09-03 04:18 - 02531400 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-09 00:14 - 2015-09-03 04:17 - 01903848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-09 00:14 - 2015-09-02 20:48 - 02345472 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-09 00:14 - 2015-09-02 19:09 - 01556992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-09 00:14 - 2015-07-22 16:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-09-09 00:14 - 2015-07-22 15:52 - 01633792 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-09-09 00:14 - 2015-07-17 16:15 - 00951296 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-09-09 00:14 - 2015-07-17 16:10 - 00749568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-09-09 00:13 - 2015-08-22 20:19 - 25188352 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-09 00:13 - 2015-08-22 19:35 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-09 00:13 - 2015-08-22 19:34 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-09 00:13 - 2015-08-22 19:22 - 19856384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-09 00:13 - 2015-08-22 19:21 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-09 00:13 - 2015-08-22 19:20 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-09 00:13 - 2015-08-22 18:55 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-09 00:13 - 2015-08-22 18:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-09 00:13 - 2015-08-22 18:50 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-09-09 00:13 - 2015-08-22 18:45 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-09 00:13 - 2015-08-22 18:44 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-09-09 00:13 - 2015-08-22 18:41 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-09 00:13 - 2015-08-22 18:41 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-09 00:13 - 2015-08-22 18:41 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-09 00:13 - 2015-08-22 18:41 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-09 00:13 - 2015-08-22 18:39 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-09 00:13 - 2015-08-22 18:28 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-09 00:13 - 2015-08-22 18:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-09 00:13 - 2015-08-22 18:23 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-09-09 00:13 - 2015-08-22 18:22 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-09 00:13 - 2015-08-22 18:20 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-09-09 00:13 - 2015-08-22 18:18 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-09 00:13 - 2015-08-22 18:18 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-09 00:13 - 2015-08-22 18:18 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-09 00:13 - 2015-08-22 18:14 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-09 00:13 - 2015-08-22 18:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-09 00:13 - 2015-08-22 18:00 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-09 00:13 - 2015-08-22 17:56 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-09 00:13 - 2015-08-22 17:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-09 00:13 - 2015-07-30 19:18 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-09 00:13 - 2015-07-30 18:22 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-09 00:13 - 2015-06-27 13:47 - 00118616 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-09 00:08 - 2015-09-02 04:56 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-09 00:08 - 2015-09-02 04:55 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-09 00:08 - 2015-09-02 04:50 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-09 00:08 - 2015-09-02 04:17 - 00301568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-09 00:08 - 2015-09-02 04:13 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-09 00:08 - 2015-08-03 23:15 - 00074928 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-09 00:08 - 2015-08-03 23:15 - 00065600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-09 00:08 - 2015-08-01 16:22 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-09 00:08 - 2015-08-01 05:47 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2015-09-09 00:08 - 2015-08-01 05:45 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2015-09-09 00:08 - 2015-08-01 05:38 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-09 00:08 - 2015-08-01 05:37 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2015-09-09 00:08 - 2015-08-01 05:37 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2015-09-09 00:08 - 2015-07-22 16:34 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-09 00:08 - 2015-07-22 16:33 - 01728000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-09-09 00:08 - 2015-07-22 16:25 - 02461184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-09 00:08 - 2015-07-22 16:25 - 01546752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-09-09 00:08 - 2015-07-18 20:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2015-09-09 00:08 - 2015-07-18 20:29 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2015-09-09 00:08 - 2015-07-18 20:29 - 00148480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2015-09-09 00:08 - 2015-07-18 20:27 - 00520192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2015-09-09 00:08 - 2015-07-14 05:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tzsync.exe
2015-09-09 00:08 - 2015-07-13 21:10 - 00411455 _____ C:\Windows\system32\ApnDatabase.xml
2015-09-09 00:08 - 2015-07-09 18:14 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-09-09 00:08 - 2015-07-03 23:51 - 01380056 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-09-09 00:08 - 2015-07-03 16:00 - 01097216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-09-09 00:08 - 2015-06-19 19:07 - 02819072 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-08-29 00:45 - 2015-09-14 20:46 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0e1e34c2e9265.job
2015-08-28 03:43 - 2015-08-28 03:43 - 00000000 ____D C:\Users\jantje\Tracing
2015-08-28 03:25 - 2015-08-28 03:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-25 02:57 - 2015-08-17 23:43 - 00608048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-08-25 02:54 - 2015-08-18 10:48 - 31515256 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 24200312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 22992048 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 17559240 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 15294072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 13916600 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 13828032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 12896432 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-08-25 02:54 - 2015-08-18 10:48 - 11272048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 11209376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 04245808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 03987760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 01908528 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434181.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 01556656 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434181.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00945456 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00908592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00903472 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00870008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-08-25 02:07 - 2015-08-11 06:52 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-08-25 02:07 - 2015-08-11 06:52 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-08-22 23:11 - 2015-08-22 23:12 - 00000000 ____D C:\Users\jantje\Unigine Heaven
2015-08-22 23:09 - 2015-08-22 23:09 - 00000000 ____D C:\Users\jantje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unigine
2015-08-22 23:09 - 2015-08-22 23:09 - 00000000 ____D C:\Program Files (x86)\Unigine
2015-08-22 23:08 - 2015-08-22 23:08 - 241351168 _____ C:\Users\jantje\Downloads\Unigine_Heaven-2.1.msi
2015-08-22 23:06 - 2015-08-22 23:07 - 00000000 ____D C:\Windows\SysWOW64\directx
2015-08-22 23:06 - 2015-08-22 23:06 - 00292184 _____ (Microsoft Corporation) C:\Users\jantje\Downloads\dxwebsetup.exe
2015-08-22 23:04 - 2015-08-22 23:04 - 45099266 _____ C:\Users\jantje\Downloads\DirectX_11_Technology_Update_US.zip
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-20 04:39 - 2014-10-06 15:25 - 00000000 ____D C:\ProgramData\ioloGovernor
2015-09-20 04:19 - 2014-10-06 14:07 - 02011129 _____ C:\Windows\WindowsUpdate.log
2015-09-20 04:16 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-09-20 04:12 - 2015-01-21 19:44 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-20 04:05 - 2014-10-11 00:54 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-20 04:05 - 2013-08-22 16:46 - 00047509 _____ C:\Windows\setupact.log
2015-09-20 04:04 - 2014-10-06 14:19 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-20 04:04 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-20 04:00 - 2014-10-06 14:15 - 00000000 ____D C:\Users\jantje
2015-09-20 04:00 - 2014-03-18 01:04 - 00965410 _____ C:\Windows\PFRO.log
2015-09-20 03:45 - 2014-10-11 00:28 - 00001082 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001UA.job
2015-09-20 03:05 - 2014-10-06 14:21 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-244135331-4156006937-3082476691-1001
2015-09-20 03:00 - 2015-04-04 23:21 - 00000024 _____ C:\Users\jantje\jagexappletviewer.preferences
2015-09-20 03:00 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-20 02:45 - 2014-10-12 03:01 - 00000045 _____ C:\Users\jantje\jagex_cl_runescape_LIVE.dat
2015-09-20 01:56 - 2014-10-12 03:01 - 00000024 _____ C:\Users\jantje\random.dat
2015-09-20 01:44 - 2015-06-14 00:46 - 00000000 ____D C:\Users\jantje\Downloads\PopcornTime
2015-09-20 01:43 - 2014-10-14 13:04 - 00162304 ___SH C:\Users\jantje\Downloads\Thumbs.db
2015-09-19 22:45 - 2014-10-11 00:28 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core.job
2015-09-19 18:36 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-09-19 16:53 - 2015-03-02 20:53 - 00000050 _____ C:\Users\jantje\jagex_cl_runescape_LIVE_BETA.dat
2015-09-18 17:09 - 2014-10-13 00:45 - 00000000 ____D C:\Users\jantje\AppData\Local\CrashDumps
2015-09-17 21:20 - 2015-01-24 20:21 - 00003824 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1422123684
2015-09-17 21:20 - 2015-01-24 20:21 - 00001080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-09-17 21:20 - 2015-01-24 20:21 - 00000000 ____D C:\Program Files (x86)\Opera
2015-09-17 21:17 - 2015-02-07 17:35 - 00000046 _____ C:\Users\jantje\jagex_cl_runescape_LIVE1.dat
2015-09-16 16:38 - 2015-04-04 23:17 - 00002114 _____ C:\Users\jantje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape.lnk
2015-09-16 04:31 - 2014-10-11 01:08 - 00000000 ____D C:\Users\jantje\AppData\Roaming\Skype
2015-09-16 00:10 - 2014-10-06 16:10 - 02504704 ___SH C:\Users\jantje\Desktop\Thumbs.db
2015-09-14 17:14 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2015-09-13 01:09 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2015-09-13 01:08 - 2014-10-11 00:27 - 00000000 ____D C:\Users\jantje\AppData\Local\Google
2015-09-10 22:30 - 2013-08-22 16:44 - 00347096 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-10 04:01 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2015-09-10 04:01 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\inetsrv
2015-09-10 04:01 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-09 17:55 - 2014-03-18 11:47 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-09 17:53 - 2014-10-06 15:56 - 00000000 ____D C:\Windows\system32\MRT
2015-09-09 15:56 - 2015-07-19 17:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-09 00:21 - 2014-11-01 14:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-29 00:45 - 2015-07-16 03:46 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0bf693e7fc071.job
2015-08-28 03:25 - 2014-10-11 01:07 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-28 03:25 - 2014-10-11 01:07 - 00000000 ____D C:\ProgramData\Skype
2015-08-26 18:37 - 2014-10-06 15:56 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-25 02:57 - 2014-10-06 16:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-08-25 02:08 - 2014-10-06 14:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-22 00:25 - 2014-12-19 00:36 - 00000000 ____D C:\Users\jantje\AppData\Roaming\FiraxisLive
2015-08-21 15:25 - 2014-10-06 14:27 - 00915096 _____ C:\Windows\system32\perfh013.dat
2015-08-21 15:25 - 2014-10-06 14:27 - 00205936 _____ C:\Windows\system32\perfc013.dat
2015-08-21 15:25 - 2014-03-18 12:17 - 02107908 _____ C:\Windows\system32\PerfStringBackup.INI
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-10 22:45
 
==================== End of FRST.txt ============================

Aswell as the additional file:
 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by [removed] (2015-09-20 04:39:44)
Running from C:\Users\[removed]\Desktop
Windows 8.1 Pro (X64) (2014-10-06 12:15:56)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-244135331-4156006937-3082476691-500 - Administrator - Disabled)
Guest (S-1-5-21-244135331-4156006937-3082476691-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-244135331-4156006937-3082476691-1003 - Limited - Enabled)
JuPp3 (S-1-5-21-244135331-4156006937-3082476691-1001 - Administrator - Enabled) => C:\Users\jantje
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\uTorrent) (Version: 3.4.3.40097 - BitTorrent Inc.)
720+ User Interface (HKLM\…\{AD3320DC-2703-40EA-B0F6-1705C1A62A73}) (Version: 1.2.5 - Tritton)
Adblock Plus voor IE (32-bit en 64-bit) (HKLM\…\{3156E6CF-341C-4BAB-BF93-DCE3B598C80D}) (Version: 1.4 - Eyeo GmbH)
Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.6.156 - Adobe Systems, Inc.)
Awesomenauts (HKLM-x32\…\Steam App 204300) (Version:  - Ronimo Games)
Banished (HKLM-x32\…\Steam App 242920) (Version:  - Shining Rock Software LLC)
Bing Bar (HKLM-x32\…\{16793295-2366-40F7-A045-A3E42A81365E}) (Version: 7.1.362.0 - Microsoft Corporation)
Block N Load (HKLM-x32\…\Steam App 299360) (Version:  - Jagex)
Borderlands 2 (HKLM-x32\…\Steam App 49520) (Version:  - Gearbox Software)
Broforce (HKLM-x32\…\Steam App 274190) (Version:  - Free Lives)
Call of Duty: Black Ops II - Multiplayer (HKLM-x32\…\Steam App 202990) (Version:  - Treyarch)
Chrome Remote Desktop Host (HKLM-x32\…\{8432E4EF-ABFB-48C8-B77B-24728E71D3DD}) (Version: 39.0.2171.46 - Google Inc.)
Counter-Strike: Global Offensive (HKLM-x32\…\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version:  - Valve)
Dragon Age: Origins (HKLM-x32\…\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dropbox (HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Epigenesis (HKLM-x32\…\Steam App 244590) (Version:  - Dead Shark Triplepunch)
foobar2000 v1.3.4 (HKLM-x32\…\foobar2000) (Version: 1.3.4 - Peter Pawlowski)
Goat Simulator (HKLM-x32\…\Steam App 265930) (Version:  - Coffee Stain Studios)
Google Chrome (HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Google Chrome) (Version: 45.0.2454.93 - Google Inc.)
iolo technologies' System Mechanic Professional (HKLM-x32\…\{BBD3F66B-1180-4785-B679-3F91572CD3B4}_is1) (Version: 14.5.2 - iolo technologies, LLC)
Java 8 Update 51 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Loadout (HKLM-x32\…\Steam App 208090) (Version:  - Edge of Reality)
Malwarebytes Anti-Malware versie 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
METAL GEAR SOLID V: GROUND ZEROES (HKLM-x32\…\Steam App 311340) (Version:  - Kojima Productions)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\…\{95140000-00AF-0413-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 40.0.3 (x86 nl) (HKLM-x32\…\Mozilla Firefox 40.0.3 (x86 nl)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla)
NVIDIA 3D Vision controllerstuurprogramma 340.50 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision stuurprogramma 341.81 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.81 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.5.13.6 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.13.6 - NVIDIA Corporation)
NVIDIA Grafisch stuurprogramma 341.81 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.81 - NVIDIA Corporation)
NVIDIA HD Audio-stuurprogramma 1.3.30.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX systeemsoftware 9.13.1220 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Opera Stable 32.0.1948.25 (HKLM-x32\…\Opera 32.0.1948.25) (Version: 32.0.1948.25 - Opera Software)
Origin (HKLM-x32\…\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.)
ORION: Prelude (HKLM-x32\…\Steam App 104900) (Version:  - Spiral Game Studios)
Popcorn Time (HKLM-x32\…\Popcorn Time_is1) (Version: Beta 5.2.1 - Popcorn Time)
RuneScape Launcher 1.2.7 (HKLM-x32\…\{FA52A2D0-298E-4D40-8BB7-39928627EA6A}) (Version: 1.2.7 - Jagex Ltd)
Rust (HKLM-x32\…\Steam App 252490) (Version:  - Facepunch Studios)
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.13.6 - NVIDIA Corporation) Hidden
Sid Meier's Civilization: Beyond Earth (HKLM-x32\…\Steam App 65980) (Version:  - Firaxis Games)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.8 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Spotify) (Version: 0.9.14.13.gba5645ad - Spotify AB)
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Mechanic 14 Professional (x32 Version: 14.5.2 - ) Hidden
Theme Hospital (HKLM-x32\…\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts)
Unigine Heaven Benchmark v2.1 (HKLM-x32\…\{38468127-9E6F-4FC9-B5F7-42D4AD437D96}) (Version: 2.1 - Unigine Corp.)
Unity Web Player (HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\UnityWebPlayer) (Version: 4.6.0f2 - Unity Technologies ApS)
Unreal Tournament: Game of the Year Edition (HKLM-x32\…\Steam App 13240) (Version:  - Epic Games, Inc.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.1.5 - VideoLAN)
WinRAR 5.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\jantje\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\jantje\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-244135331-4156006937-3082476691-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\jantje\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
 
==================== Restore Points =========================
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {40EBC43C-2559-42B9-A965-975943BE0E68} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe
Task: {5B6D74E1-2228-4094-B8F7-2B6232A7CDB1} - System32\Tasks\iolo Process Governor => C:\Program Files (x86)\iolo\System Mechanic Professional\iologovernor64.exe [2015-04-28] (iolo technologies, LLC)
Task: {60C41F3F-802D-455C-8391-723F0807E885} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)
Task: {62825BD8-F2A2-4E12-85FF-5C506EAEB772} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001UA => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {6DEC2DC1-E91E-4D4C-B880-EA6EAC21BCB8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {7858F0D2-DB41-4D45-97E5-098A074C2AD4} - System32\Tasks\iolo DelOnReboot => cmd.exe /c IF EXIST C:\ProgramData\iolo\ops\smrr.dll del /f C:\ProgramData\iolo\ops\smrr.dll
Task: {B98B6D14-A2EC-49F8-88C3-B5185C45802B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {E69279C8-2085-4A6C-8F9D-34BD891B418C} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {E7B529D4-42EC-41BA-877E-98EDC66BB514} - System32\Tasks\Opera scheduled Autoupdate 1422123684 => C:\Program Files (x86)\Opera\launcher.exe [2015-09-11] (Opera Software)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core.job => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d091602498f762.job => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0bf693e7fc071.job => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0e1e34c2e9265.job => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0ef1daeeb551c.job => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001UA.job => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-10-06 14:19 - 2015-08-18 02:07 - 00115376 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-03-31 23:42 - 2015-08-18 01:31 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2014-10-11 00:55 - 2015-07-03 18:12 - 00778240 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-21 12:42 - 2015-07-03 18:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2014-10-11 00:55 - 2015-08-19 22:39 - 02413248 _____ () C:\Program Files (x86)\Steam\video.dll
2015-01-21 12:42 - 2015-07-03 18:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-21 12:42 - 2015-07-03 18:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-10-11 00:55 - 2014-12-01 23:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-10-11 00:55 - 2014-12-01 23:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-10-11 00:55 - 2014-12-01 23:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-10-11 00:55 - 2014-12-01 23:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-10-11 00:55 - 2014-12-01 23:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2014-10-11 00:55 - 2015-08-19 22:39 - 00704192 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-07-22 11:22 - 2015-07-27 03:13 - 00171008 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
2015-09-16 21:46 - 2015-09-12 02:22 - 01501512 _____ () C:\Users\jantje\AppData\Local\Google\Chrome\Application\45.0.2454.93\libglesv2.dll
2015-09-16 21:46 - 2015-09-12 02:22 - 00081224 _____ () C:\Users\jantje\AppData\Local\Google\Chrome\Application\45.0.2454.93\libegl.dll
2014-10-11 00:55 - 2015-07-03 18:12 - 39553928 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\jantje\OneDrive:ms-properties
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ioloSystemService => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\jantje\AppData\Roaming\Microsoft\Windows Photo Viewer\Achtergrond van Windows Photo Viewer.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{9291E182-92CA-4408-BC61-BC3E2A173B82}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{96F55DF1-2092-47EE-ABFE-DB4403070F8A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{323782B9-16FB-4D02-9267-3FD053E3CB61}] => (Allow) LPort=1688
FirewallRules: [{D181C0A9-CA22-4701-A115-7F01FDB5489E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FF267738-C75A-4B91-85EF-AB549D40F25A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{8C8BF8C3-A598-4234-B4CA-E92E280DF75D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{95FA49FD-4F4C-463B-A9B2-29F93E3BFCEC}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{A1626F07-1AF2-4957-8D94-88FEFBF31910}] => (Allow) D:\SteamLibrary\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{6DF404CE-7483-4CBE-AD81-0A6EAD1380CE}] => (Allow) D:\SteamLibrary\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{96E38330-A13B-42AB-9B37-D4134E350829}] => (Allow) D:\SteamLibrary\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{C41D0489-E3D7-47CF-ACC0-2E49B47C2657}] => (Allow) D:\SteamLibrary\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{B31810B7-7930-4C00-9C5F-D56EA1892CC5}] => (Allow) D:\SteamLibrary\SteamApps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{D23EC44A-745E-4DF3-AF52-BBD1A9D14C10}] => (Allow) D:\SteamLibrary\SteamApps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{92C46FB3-2F3F-4006-BF1D-681A0C7EF4B7}] => (Allow) D:\SteamLibrary\SteamApps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{4890AE24-2780-4A83-8F92-FE7930FCFC1F}] => (Allow) D:\SteamLibrary\SteamApps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{7E47DC92-4012-4403-891B-031C19A2F80D}] => (Allow) D:\SteamLibrary\SteamApps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{5E8B66D2-8BCA-4E9A-83D1-C487DC60E31F}] => (Allow) D:\SteamLibrary\SteamApps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [TCP Query User{A183E097-98BB-46FD-8B6D-5455468A1998}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{EF56AAF5-5342-419B-8A34-3C68770A70D8}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{550D98EB-721F-49AA-A76C-29460E462BA0}C:\users\jantje\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jantje\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{C09EAEC3-E2D0-4D52-B6B0-ED2E39E1B661}C:\users\jantje\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jantje\appdata\roaming\spotify\spotify.exe
FirewallRules: [{BC98A63B-3536-4190-822F-F756B1FEB60E}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{FE3E85F2-7B38-4F2E-9D49-DCA051A77A79}] => (Allow) C:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [TCP Query User{CA2F9EBA-929D-4567-AC4F-5298780169F6}C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{A8B7FE21-8276-485E-8C7D-C938CF5C599C}C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{4EA0B4E4-3CBA-4C01-952F-8E1ED879ECA0}] => (Allow) D:\SteamLibrary\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{FFB2F4D4-E5E8-4EE7-A915-AD08D427BB4B}] => (Allow) D:\SteamLibrary\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{DD59928C-F6D3-454A-AAEB-7F6C3F981376}] => (Allow) C:\Users\jantje\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A49A7FC2-7206-4C36-9905-48B0436D1E18}] => (Allow) C:\Users\jantje\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{96450D55-9B51-49E2-99E7-D91668B4FF51}] => (Allow) D:\SteamLibrary\SteamApps\common\Rust\Rust.exe
FirewallRules: [{3C7D852A-6129-4740-8D01-095B35857DE4}] => (Allow) D:\SteamLibrary\SteamApps\common\Rust\Rust.exe
FirewallRules: [{F6CAFA91-3590-41A1-A1B8-A9542A0E3DA9}] => (Allow) D:\SteamLibrary\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [{2A022E23-8E7A-437D-8C5A-3A558085CC6E}] => (Allow) D:\SteamLibrary\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [{1ECDB20D-7D59-4D9D-BE94-7526835C35A0}] => (Allow) D:\SteamLibrary\SteamApps\common\Orion Dino Beatdown\Binaries\Win32\DinoHordeGame.exe
FirewallRules: [{ED88D006-CD0A-4C8E-AD0F-2FD22AF94B22}] => (Allow) D:\SteamLibrary\SteamApps\common\Orion Dino Beatdown\Binaries\Win32\DinoHordeGame.exe
FirewallRules: [{EB479594-4FF0-4499-82F5-335E305DB7C4}] => (Allow) D:\SteamLibrary\SteamApps\common\Unreal Tournament\System\UnrealTournament.exe
FirewallRules: [{697B0808-E2EA-4595-9EE8-11B16F82DC4E}] => (Allow) D:\SteamLibrary\SteamApps\common\Unreal Tournament\System\UnrealTournament.exe
FirewallRules: [{588613EA-6A38-4D87-A591-FD0D969267E1}] => (Allow) D:\SteamLibrary\SteamApps\common\Broforce\BROFORCE_Beta.exe
FirewallRules: [{FD70FF47-BC69-4A0C-9269-49C2F1A80683}] => (Allow) D:\SteamLibrary\SteamApps\common\Broforce\BROFORCE_Beta.exe
FirewallRules: [{13251547-6776-46B2-884A-70C87FE17D5C}] => (Allow) D:\SteamLibrary\SteamApps\common\Rust\legacy\rust.exe
FirewallRules: [{97C1B5E5-3F5F-4B22-8969-CF94D402C8D5}] => (Allow) D:\SteamLibrary\SteamApps\common\Rust\legacy\rust.exe
FirewallRules: [{96CEA6FA-2343-4408-A862-38425D6B6AC1}] => (Allow) D:\SteamLibrary\SteamApps\common\Banished\Application-steam-x64.exe
FirewallRules: [{FA902C3A-7B40-4EAA-90E2-88A19C667954}] => (Allow) D:\SteamLibrary\SteamApps\common\Banished\Application-steam-x64.exe
FirewallRules: [{CA4E77B9-9B88-4CEB-8EC2-7F9129110E23}] => (Allow) D:\SteamLibrary\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe
FirewallRules: [{9DC1102D-AB01-442E-A3CC-D551044C142D}] => (Allow) D:\SteamLibrary\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe
FirewallRules: [{FB96F9B0-1050-4512-B3A4-349BCDD7EF5F}] => (Allow) D:\SteamLibrary\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe
FirewallRules: [{393E90CC-3A8A-496E-911B-BBB4E1EB05CF}] => (Allow) D:\SteamLibrary\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe
FirewallRules: [{17AC8590-33F5-4EBF-B505-F7E147F7607C}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\39.0.2171.46\remoting_host.exe
FirewallRules: [{E2063EDD-418B-4C08-835F-09DC4E4597D8}] => (Allow) C:\Program Files (x86)\SwiftKit\SwiftKit.exe
FirewallRules: [{E5AA7B39-958D-4330-A805-393F009C22E3}] => (Allow) C:\Program Files (x86)\SwiftKit\SwiftKit.exe
FirewallRules: [{D3806B33-9F88-40DF-AD64-C6CFCEB818E2}] => (Allow) C:\Program Files (x86)\SwiftKit\SwiftKit.exe
FirewallRules: [{7AD3DDBD-DC01-4B11-B3A6-8FAC08BF5A0D}] => (Allow) C:\Program Files (x86)\SwiftKit\SwiftKit.exe
FirewallRules: [{FBAA22D9-994B-4FA9-A9B7-2E7350667845}] => (Allow) C:\Program Files (x86)\Origin Games\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{FE07D57E-417D-4BF4-8DA8-B5071A52AEA3}] => (Allow) C:\Program Files (x86)\Origin Games\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{5A11CB88-7C81-48F1-8D27-D475D6FFF8EB}] => (Allow) C:\Users\jantje\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{93C16717-2BCA-468D-81D7-A5424E00F680}] => (Allow) C:\Users\jantje\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C92694F4-A722-43E3-9E0A-9AA6B1D8B7BE}] => (Allow) D:\SteamLibrary\SteamApps\common\BlockNLoad\Win64\BlockNLoad.exe
FirewallRules: [{CE79E18E-0EA5-4008-B2F1-33E67B24F065}] => (Allow) D:\SteamLibrary\SteamApps\common\BlockNLoad\Win64\BlockNLoad.exe
FirewallRules: [{2D92E2AC-397A-4832-AE0A-38793B7C9519}] => (Allow) D:\SteamLibrary\SteamApps\common\Rust\legacy\rust.exe
FirewallRules: [{2C6282A3-E2DB-43AF-B674-8FE9E540F07C}] => (Allow) D:\SteamLibrary\SteamApps\common\Rust\legacy\rust.exe
FirewallRules: [TCP Query User{346FD98A-D38F-4E41-A434-D8E4F4581E36}C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [UDP Query User{EFC3831D-065D-47B5-A2D0-E6CFF16445A4}C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\jantje\appdata\local\popcorn time\node-webkit\popcorn time.exe
FirewallRules: [{2F6FF88F-B9C9-4C17-98E6-5F106C9449AB}] => (Allow) D:\SteamLibrary\SteamApps\common\Loadout\Loadout.exe
FirewallRules: [{4B103148-D083-44AD-8192-7A410C9A6818}] => (Allow) D:\SteamLibrary\SteamApps\common\Loadout\Loadout.exe
FirewallRules: [{AEF0AF34-C4CE-41D3-B993-368E3088029E}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{E4952A96-F846-488E-8EA2-190D649BA8C7}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{CA8CD2F6-B0BE-4E32-BA80-95046785987F}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{642C62E6-5406-4520-83DA-678DF798B2D3}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [TCP Query User{BF1BCFA5-9110-4E05-A8EA-3A13F2A57BD8}C:\program files (x86)\popcorn time\chromecast\node.exe] => (Allow) C:\program files (x86)\popcorn time\chromecast\node.exe
FirewallRules: [UDP Query User{D57D2B5A-FF1F-43C0-8374-EA34FDAFDD6D}C:\program files (x86)\popcorn time\chromecast\node.exe] => (Allow) C:\program files (x86)\popcorn time\chromecast\node.exe
FirewallRules: [TCP Query User{B7EA34B6-66AD-4B4E-9D58-541302C08A06}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{045530AB-6522-45B2-BB05-DDD7AD0C118A}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{60FAD44D-E340-4577-9257-2732EC81AFD3}C:\program files (x86)\popcorn time\popcorntimedesktop.exe] => (Allow) C:\program files (x86)\popcorn time\popcorntimedesktop.exe
FirewallRules: [UDP Query User{F6EEE8CA-F45F-40EB-BB5C-EAC5B2E544BE}C:\program files (x86)\popcorn time\popcorntimedesktop.exe] => (Allow) C:\program files (x86)\popcorn time\popcorntimedesktop.exe
FirewallRules: [{195058CA-D9FC-46B4-A73C-072948BA4976}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7ECDA808-7F27-4F15-A35C-8C00284356C2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E9E02AA5-4930-4495-A3E2-A5F1CD8FF91F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{A25BBF0F-C818-4F45-8AC6-DE5354F275FE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{F7852006-51EC-40C8-A79C-96633A75388B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{A1F56E15-3000-4D97-AA20-999B2AC7E3CF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6F993725-0554-464B-96AD-80473515FF0C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{1A818AA9-8AFA-4A8D-8FB7-88BBC49FD495}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Epigenesis\Binaries\Win32\Epigenesis.exe
FirewallRules: [{F5E0615A-3914-4BEB-B5E5-5B00C132BF3E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Epigenesis\Binaries\Win32\Epigenesis.exe
FirewallRules: [TCP Query User{90F4169B-0DDA-44A7-9FF7-6886B25926B6}C:\program files (x86)\steam\steamapps\common\epigenesis\binaries\win32\lochgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\epigenesis\binaries\win32\lochgame.exe
FirewallRules: [UDP Query User{503FA490-7C43-4D7F-AA88-63C9ED4CA5FB}C:\program files (x86)\steam\steamapps\common\epigenesis\binaries\win32\lochgame.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\epigenesis\binaries\win32\lochgame.exe
FirewallRules: [{DED938BF-2B40-4DD2-B8D1-CEE14C0EC3DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metal Gear Solid Ground Zeroes\MgsGroundZeroes.exe
FirewallRules: [{03E777C8-2A02-42A0-B623-CEFEC07D47EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metal Gear Solid Ground Zeroes\MgsGroundZeroes.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/18/2015 08:26:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Toegang geweigerd.
.
 
Error: (09/18/2015 05:09:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: Borderlands2.exe, versie: 1.0.29.41124, tijdstempel: 0x5395f78a
Naam van module met fout: Borderlands2.exe, versie: 1.0.29.41124, tijdstempel: 0x5395f78a
Uitzonderingscode: 0xc0000005
Foutmarge: 0x004ee8a9
Id van proces met fout: 0xe74
Starttijd van toepassing met fout: 0xBorderlands2.exe0
Pad naar toepassing met fout: Borderlands2.exe1
Pad naar module met fout: Borderlands2.exe2
Rapport-id: Borderlands2.exe3
Volledige pakketnaam met fout: Borderlands2.exe4
Relatieve toepassings-id van pakket met fout: Borderlands2.exe5
 
Error: (09/18/2015 05:07:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: Borderlands2.exe, versie: 1.0.29.41124, tijdstempel: 0x5395f78a
Naam van module met fout: Borderlands2.exe, versie: 1.0.29.41124, tijdstempel: 0x5395f78a
Uitzonderingscode: 0xc0000005
Foutmarge: 0x004ee8a9
Id van proces met fout: 0x1744
Starttijd van toepassing met fout: 0xBorderlands2.exe0
Pad naar toepassing met fout: Borderlands2.exe1
Pad naar module met fout: Borderlands2.exe2
Rapport-id: Borderlands2.exe3
Volledige pakketnaam met fout: Borderlands2.exe4
Relatieve toepassings-id van pakket met fout: Borderlands2.exe5
 
Error: (09/16/2015 04:36:55 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Toegang geweigerd.
.
 
Error: (09/14/2015 08:24:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: jp2launcher.exe, versie: 11.51.2.16, tijdstempel: 0x55763fcc
Naam van module met fout: jaclib.dll, versie: 0.0.0.0, tijdstempel: 0x52e26c31
Uitzonderingscode: 0xc000041d
Foutmarge: 0x00004829
Id van proces met fout: 0x45c
Starttijd van toepassing met fout: 0xjp2launcher.exe0
Pad naar toepassing met fout: jp2launcher.exe1
Pad naar module met fout: jp2launcher.exe2
Rapport-id: jp2launcher.exe3
Volledige pakketnaam met fout: jp2launcher.exe4
Relatieve toepassings-id van pakket met fout: jp2launcher.exe5
 
Error: (09/14/2015 08:24:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: jp2launcher.exe, versie: 11.51.2.16, tijdstempel: 0x55763fcc
Naam van module met fout: jaclib.dll, versie: 0.0.0.0, tijdstempel: 0x52e26c31
Uitzonderingscode: 0xc0000005
Foutmarge: 0x00004829
Id van proces met fout: 0x45c
Starttijd van toepassing met fout: 0xjp2launcher.exe0
Pad naar toepassing met fout: jp2launcher.exe1
Pad naar module met fout: jp2launcher.exe2
Rapport-id: jp2launcher.exe3
Volledige pakketnaam met fout: jp2launcher.exe4
Relatieve toepassings-id van pakket met fout: jp2launcher.exe5
 
Error: (09/13/2015 03:07:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: jp2launcher.exe, versie: 11.51.2.16, tijdstempel: 0x55763fcc
Naam van module met fout: jaclib.dll, versie: 0.0.0.0, tijdstempel: 0x52e26c31
Uitzonderingscode: 0xc0000005
Foutmarge: 0x00004829
Id van proces met fout: 0xa84
Starttijd van toepassing met fout: 0xjp2launcher.exe0
Pad naar toepassing met fout: jp2launcher.exe1
Pad naar module met fout: jp2launcher.exe2
Rapport-id: jp2launcher.exe3
Volledige pakketnaam met fout: jp2launcher.exe4
Relatieve toepassings-id van pakket met fout: jp2launcher.exe5
 
Error: (09/13/2015 01:09:50 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Toegang geweigerd.
.
 
Error: (09/09/2015 05:46:57 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: De service Cryptografische services is mislukt tijdens het verwerken van aanroep OnIdentity() op het object System Writer.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Toegang geweigerd.
.
 
Error: (09/09/2015 04:14:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: JagexLauncher.exe, versie: 0.0.0.0, tijdstempel: 0x55142e3e
Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode: 0xc0000005
Foutmarge: 0x00e7018c
Id van proces met fout: 0xff8
Starttijd van toepassing met fout: 0xJagexLauncher.exe0
Pad naar toepassing met fout: JagexLauncher.exe1
Pad naar module met fout: JagexLauncher.exe2
Rapport-id: JagexLauncher.exe3
Volledige pakketnaam met fout: JagexLauncher.exe4
Relatieve toepassings-id van pakket met fout: JagexLauncher.exe5
 
 
System errors:
=============
Error: (09/20/2015 04:04:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De KMSEmulator-service kan vanwege de volgende fout niet worden gestart: 
%%2
 
Error: (09/20/2015 04:04:23 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: De vorige afsluiting van het systeem om 04:00:35 op ‎20-‎9-‎2015 is onverwacht gebeurd.
 
Error: (09/20/2015 04:00:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De KMSEmulator-service kan vanwege de volgende fout niet worden gestart: 
%%2
 
Error: (09/20/2015 04:00:35 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: De vorige afsluiting van het systeem om 03:35:10 op ‎20-‎9-‎2015 is onverwacht gebeurd.
 
Error: (09/19/2015 07:50:16 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Bij de schaduwkopieën van volume C: zijn afgebroken omdat de schaduwkopieopslag niet kan worden uitgebreid vanwege een door de gebruiker opgelegde limiet.
 
Error: (09/19/2015 06:32:10 PM) (Source: DCOM) (EventID: 10010) (User: JUPP3)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
 
Error: (09/19/2015 06:31:58 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installatiefout: de volgende update kan niet worden geïnstalleerd, foutcode 0x80070002: Update for Windows 8.1 for x64-based Systems (KB3083325).
 
Error: (09/19/2015 06:31:40 PM) (Source: DCOM) (EventID: 10010) (User: JUPP3)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
 
Error: (09/19/2015 04:52:09 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: De KMSEmulator-service kan vanwege de volgende fout niet worden gestart: 
%%2
 
Error: (09/19/2015 04:51:59 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: De vorige afsluiting van het systeem om 16:49:24 op ‎19-‎9-‎2015 is onverwacht gebeurd.
 
 
CodeIntegrity:
===================================
  Date: 2015-09-16 19:11:41.890
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 19:11:41.648
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 19:11:41.402
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 19:11:41.150
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 19:11:40.906
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 19:11:40.662
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 19:11:39.719
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 19:11:39.374
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 00:10:52.319
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-09-16 00:10:52.036
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Celeron(R) CPU G1610 @ 2.60GHz
Percentage of memory in use: 23%
Total physical RAM: 10204.06 MB
Available physical RAM: 7856.68 MB
Total Virtual: 11804.06 MB
Available Virtual: 9360.58 MB
 
==================== Drives ================================
 
Drive c: (JAN WIN. 8.1 X 64) (Fixed) (Total:224.27 GB) (Free:126 GB) NTFS
Drive d: (OPSLAG & SYTEEM BACKUP) (Fixed) (Total:117.19 GB) (Free:49.75 GB) NTFS
Drive e: (OPSLAG) (Fixed) (Total:123.96 GB) (Free:123.85 GB) NTFS
Drive h: (Elements) (Fixed) (Total:596.02 GB) (Free:288.14 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5821D9C3)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=224.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=117.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=124 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 596.2 GB) (Disk ID: ACDD9B22)
Partition 1: (Not Active) - (Size=596.2 GB) - (Type=0C)
 
==================== End of Addition.txt ============================
Hi there,

Thanks for the logs. :)

You have ( µTorrent ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

===================================================

Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on I agree button.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
===================================================

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
===================================================

On your next reply please post :
AdwCleaner log
FSS log



Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

The AdwCleaner log:
 

# AdwCleaner v5.008 - Logbestand aangemaakt 21/09/2015 op 01:33:02
# Laatste update 18/09/2015 door Xplode
# Database : 2015-09-20.1 [Server]
# Besturingssysteem : Windows 8.1 Pro  (x64)
# Gebruikersnaam : JuPp3 - JUPP3
# Gestart vanuit : C:\Users\jantje\Desktop\AdwCleaner.exe
# Optie : Scannen
# Ondersteuning : http://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Mappen ] *****
 
 
***** [ Bestanden ] *****
 
 
***** [ Snelkoppelingen ] *****
 
 
***** [ geplande taken ] *****
 
 
***** [ Register ] *****
 
 
***** [ Internetbrowsers ] *****
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [578 bytes] ##########



FFS log:

Farbar Service Scanner Version: 26-07-2015
Ran by [removed] (administrator) on 21-09-2015 at 01:40:10
Running from "C:\Users\jantje\Desktop"
Microsoft Windows 8.1 Pro  (X64)
Boot Mode: Normal
****************************************************************
 
Internet Services:
============
 
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
 
 
Windows Firewall:
=============
 
Firewall Disabled Policy: 
==================
 
 
System Restore:
============
 
System Restore Policy: 
========================
 
 
Action Center:
============
 
 
Windows Update:
============
 
Windows Autoupdate Disabled Policy: 
============================
 
 
Other Services:
==============
 
 
File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\dhcpcore.dll => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\mpssvc.dll => File is digitally signed
C:\Windows\System32\bfe.dll => File is digitally signed
C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
 
 
**** End of log ****

I must add to this:

Today, right after starting up my computer, I could go to youtube, gmail and any of google's pages and they would load the way they should actually load.
(I try not to be too excited as it may be a temporary fix, so I'd like to continue untill it's all fixed)

 

Thanks again for helping me out!

I have not done anything to your computer yet. All I did was getting preliminary scan for diagnosis. Nonetheless, please run this tool. Once done, run FRST again for review.

[external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
===================================================

On your next reply please post :
JRT log
Fresh FRST log



Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

JRT log:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.2 (09.14.2015:1)
OS: Windows 8.1 Pro x64
Ran by [removed] on ma 21-09-2015 at 18:42:16,04
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
Successfully deleted: [Task] C:\Windows\system32\tasks\KMSAutoNet
 
 
 
~~~ Registry Values
 
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_DEC25C6095400C38A9D2B973B9C3E508
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Chrome
 
 
[C:\Users\jantje\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\jantje\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\jantje\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\jantje\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ma 21-09-2015 at 18:45:42,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
FRST log:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by [removed] (administrator) on JUPP3 (21-09-2015 18:59:54)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 Pro (X64) Language: Engels (Verenigde Staten)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\39.0.2171.46\remoting_host.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\39.0.2171.46\remoting_host.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-18] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [iolo Startup] => C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe [4521272 2015-04-28] (iolo technologies, LLC)
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Run: [Google Update] => C:\Users\jantje\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\…\Run: [GoogleChromeAutoLaunch_DEC25C6095400C38A9D2B973B9C3E508] => C:\Users\jantje\AppData\Local\Google\Chrome\Application\chrome.exe [815944 2015-09-12] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Tritton 720+.lnk [2014-10-13]
ShortcutTarget: Tritton 720+.lnk -> C:\Windows\Installer\{AD3320DC-2703-40EA-B0F6-1705C1A62A73}\_898F7BE9021EA09063812A.exe ()
BootExecute: autocheck autochk * 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{C5873AA1-CED8-488B-A735-7A3C44E01260}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{E3456850-D549-4AEB-8EB5-8498E0D3AC8A}: [DhcpNameServer] [removed] [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKU\S-1-5-21-244135331-4156006937-3082476691-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/nl-nl/?ocid=iehp
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-19] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-19] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\jantje\AppData\Roaming\Mozilla\Firefox\Profiles\q07aj95n.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1216156.dll [2015-01-09] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-19] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-08-17] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-08-17] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-244135331-4156006937-3082476691-1001: @tools.google.com/Google Update;version=3 -> C:\Users\jantje\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-244135331-4156006937-3082476691-1001: @tools.google.com/Google Update;version=9 -> C:\Users\jantje\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-244135331-4156006937-3082476691-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jantje\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-18] (Unity Technologies ApS)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/ig
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Presentaties) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-11]
CHR Extension: (Google Documenten) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-11]
CHR Extension: (Google Drive) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-11]
CHR Extension: (YouTube) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-11]
CHR Extension: (Klassieke Spelen) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpckajjkmjncafjlkielcgheibdlnfgc [2015-01-25]
CHR Extension: (Google Search) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-11]
CHR Extension: (Google Spreadsheets) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-11]
CHR Extension: (Chrome Remote Desktop) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2014-10-11]
CHR Extension: (Offline Documenten) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-06]
CHR Extension: (AdBlock) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-10-11]
CHR Extension: (Little Alchemy) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2014-10-11]
CHR Extension: (F.B Purity-Clean Up Facebook) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl [2015-01-24]
CHR Extension: (AgarioMods Evergreen Script) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhjgdbihpkphlammdaeicdemggagfbdo [2015-08-05]
CHR Extension: (Betalingen via Chrome Web Store) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-11]
CHR Extension: (Gmail) - C:\Users\jantje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-11]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\39.0.2171.46\remoting_host.exe [56648 2014-10-29] (Google Inc.)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-08-18] (NVIDIA Corporation)
S2 ioloSystemService; C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [4675896 2015-04-28] (iolo technologies, LLC)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-18] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544568 2015-08-18] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-02-25] (Electronic Arts)
S2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [335360 2014-12-17] (Company) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-10-13] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2014-10-13] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 KMSEmulator; temp.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [32912 2014-08-12] (EldoS Corporation)
S3 RTL8187B; C:\Windows\system32\DRIVERS\rtl8187B.sys [459336 2013-06-18] (Realtek Semiconductor Corporation                           )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-21 18:45 - 2015-09-21 18:45 - 00001298 _____ C:\Users\jantje\Desktop\JRT.txt
2015-09-21 18:25 - 2015-09-21 18:26 - 01798976 _____ (Malwarebytes) C:\Users\jantje\Desktop\JRT.exe
2015-09-21 01:40 - 2015-09-21 01:40 - 00001975 _____ C:\Users\jantje\Desktop\FSS.txt
2015-09-21 01:39 - 2015-09-21 01:39 - 00899072 _____ (Farbar) C:\Users\jantje\Desktop\FSS.exe
2015-09-21 01:32 - 2015-09-21 01:33 - 00000000 ____D C:\AdwCleaner
2015-09-21 01:31 - 2015-09-21 01:31 - 01662976 _____ C:\Users\jantje\Desktop\AdwCleaner.exe
2015-09-21 01:26 - 2015-09-21 01:26 - 00000000 ____D C:\Windows\system32\appmgmt
2015-09-20 04:50 - 2015-09-20 04:50 - 765410433 _____ C:\Windows\MEMORY.DMP
2015-09-20 04:50 - 2015-09-20 04:50 - 00295872 _____ C:\Windows\Minidump\092015-18390-01.dmp
2015-09-20 04:39 - 2015-09-20 04:40 - 00044560 _____ C:\Users\jantje\Desktop\Addition.txt
2015-09-20 04:38 - 2015-09-21 18:59 - 00014966 _____ C:\Users\jantje\Desktop\FRST.txt
2015-09-20 04:37 - 2015-09-21 18:59 - 00000000 ____D C:\FRST
2015-09-20 04:37 - 2015-09-20 04:37 - 02191360 _____ (Farbar) C:\Users\jantje\Desktop\FRST64.exe
2015-09-20 04:15 - 2015-09-20 04:15 - 00000512 _____ C:\Users\jantje\Desktop\MBR.dat
2015-09-20 04:07 - 2015-09-20 04:15 - 00002444 _____ C:\Users\jantje\Desktop\aswMBR.txt
2015-09-20 03:56 - 2015-09-20 03:56 - 05198336 _____ (AVAST Software) C:\Users\jantje\Desktop\aswMBR.exe
2015-09-20 01:40 - 2015-09-21 18:17 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-20 01:40 - 2015-09-20 01:40 - 00001131 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-20 01:40 - 2015-09-20 01:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-20 01:40 - 2015-09-20 01:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-20 01:40 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-20 01:40 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-20 01:40 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-20 01:39 - 2015-09-20 01:39 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\jantje\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-16 16:38 - 2015-09-16 16:38 - 00002084 _____ C:\Users\jantje\Desktop\RuneScape.lnk
2015-09-16 16:38 - 2015-09-16 16:38 - 00000000 ____D C:\Users\jantje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape
2015-09-16 16:34 - 2015-09-16 16:34 - 24219648 _____ C:\Users\jantje\Desktop\RuneScape(1).msi
2015-09-14 20:46 - 2015-09-14 20:46 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0ef1daeeb551c.job
2015-09-14 20:18 - 2015-09-14 20:38 - 00000000 ____D C:\Users\jantje\AppData\Roaming\RSBot
2015-09-14 20:18 - 2015-09-14 20:18 - 00000046 _____ C:\Users\jantje\jagex_cl_runescape_LIVE2.dat
2015-09-14 20:18 - 2015-09-14 20:18 - 00000000 ____D C:\Users\jantje\jagexcache2
2015-09-14 20:17 - 2015-09-14 20:17 - 00947009 _____ C:\Users\jantje\Desktop\RSBot-6071.jar
2015-09-09 00:14 - 2015-09-03 04:18 - 02531400 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-09 00:14 - 2015-09-03 04:17 - 01903848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-09 00:14 - 2015-09-02 20:48 - 02345472 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-09 00:14 - 2015-09-02 19:09 - 01556992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-09 00:14 - 2015-07-22 16:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-09-09 00:14 - 2015-07-22 15:52 - 01633792 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-09-09 00:14 - 2015-07-17 16:15 - 00951296 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-09-09 00:14 - 2015-07-17 16:10 - 00749568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-09-09 00:13 - 2015-08-22 20:19 - 25188352 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-09 00:13 - 2015-08-22 19:35 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-09 00:13 - 2015-08-22 19:34 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-09 00:13 - 2015-08-22 19:22 - 19856384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-09 00:13 - 2015-08-22 19:21 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-09 00:13 - 2015-08-22 19:20 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-09 00:13 - 2015-08-22 18:55 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-09 00:13 - 2015-08-22 18:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-09 00:13 - 2015-08-22 18:50 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-09-09 00:13 - 2015-08-22 18:45 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-09 00:13 - 2015-08-22 18:44 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-09-09 00:13 - 2015-08-22 18:41 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-09 00:13 - 2015-08-22 18:41 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-09 00:13 - 2015-08-22 18:41 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-09 00:13 - 2015-08-22 18:41 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-09 00:13 - 2015-08-22 18:39 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-09 00:13 - 2015-08-22 18:28 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-09 00:13 - 2015-08-22 18:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-09 00:13 - 2015-08-22 18:23 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-09-09 00:13 - 2015-08-22 18:22 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-09 00:13 - 2015-08-22 18:20 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-09-09 00:13 - 2015-08-22 18:18 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-09 00:13 - 2015-08-22 18:18 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-09 00:13 - 2015-08-22 18:18 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-09 00:13 - 2015-08-22 18:14 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-09 00:13 - 2015-08-22 18:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-09 00:13 - 2015-08-22 18:00 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-09 00:13 - 2015-08-22 17:56 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-09 00:13 - 2015-08-22 17:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-09 00:13 - 2015-07-30 19:18 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-09 00:13 - 2015-07-30 18:22 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-09 00:13 - 2015-06-27 13:47 - 00118616 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-09 00:08 - 2015-09-02 04:56 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-09 00:08 - 2015-09-02 04:55 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-09 00:08 - 2015-09-02 04:50 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-09 00:08 - 2015-09-02 04:17 - 00301568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-09 00:08 - 2015-09-02 04:13 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-09 00:08 - 2015-08-03 23:15 - 00074928 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-09 00:08 - 2015-08-03 23:15 - 00065600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-09 00:08 - 2015-08-01 16:22 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-09 00:08 - 2015-08-01 05:47 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2015-09-09 00:08 - 2015-08-01 05:45 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2015-09-09 00:08 - 2015-08-01 05:38 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-09 00:08 - 2015-08-01 05:37 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2015-09-09 00:08 - 2015-08-01 05:37 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2015-09-09 00:08 - 2015-07-22 16:34 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-09 00:08 - 2015-07-22 16:33 - 01728000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-09-09 00:08 - 2015-07-22 16:25 - 02461184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-09 00:08 - 2015-07-22 16:25 - 01546752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-09-09 00:08 - 2015-07-18 20:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2015-09-09 00:08 - 2015-07-18 20:29 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2015-09-09 00:08 - 2015-07-18 20:29 - 00148480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2015-09-09 00:08 - 2015-07-18 20:27 - 00520192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2015-09-09 00:08 - 2015-07-14 05:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tzsync.exe
2015-09-09 00:08 - 2015-07-13 21:10 - 00411455 _____ C:\Windows\system32\ApnDatabase.xml
2015-09-09 00:08 - 2015-07-09 18:14 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-09-09 00:08 - 2015-07-03 23:51 - 01380056 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-09-09 00:08 - 2015-07-03 16:00 - 01097216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-09-09 00:08 - 2015-06-19 19:07 - 02819072 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-08-29 00:45 - 2015-09-14 20:46 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0e1e34c2e9265.job
2015-08-28 03:43 - 2015-08-28 03:43 - 00000000 ____D C:\Users\jantje\Tracing
2015-08-28 03:25 - 2015-08-28 03:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-25 02:57 - 2015-08-17 23:43 - 00608048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-08-25 02:54 - 2015-08-18 10:48 - 31515256 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 24200312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 22992048 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 17559240 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 15294072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 13916600 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 13828032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 12896432 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-08-25 02:54 - 2015-08-18 10:48 - 11272048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 11209376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 04245808 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 03987760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 01908528 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434181.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 01556656 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434181.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00945456 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00908592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00903472 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-08-25 02:54 - 2015-08-18 10:48 - 00870008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-08-25 02:07 - 2015-08-11 06:52 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-08-25 02:07 - 2015-08-11 06:52 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-08-22 23:11 - 2015-08-22 23:12 - 00000000 ____D C:\Users\jantje\Unigine Heaven
2015-08-22 23:08 - 2015-08-22 23:08 - 241351168 _____ C:\Users\jantje\Downloads\Unigine_Heaven-2.1.msi
2015-08-22 23:06 - 2015-08-22 23:07 - 00000000 ____D C:\Windows\SysWOW64\directx
2015-08-22 23:06 - 2015-08-22 23:06 - 00292184 _____ (Microsoft Corporation) C:\Users\jantje\Downloads\dxwebsetup.exe
2015-08-22 23:04 - 2015-08-22 23:04 - 45099266 _____ C:\Users\jantje\Downloads\DirectX_11_Technology_Update_US.zip
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-21 19:00 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-21 18:45 - 2014-10-11 00:28 - 00001082 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001UA.job
2015-09-21 18:41 - 2014-10-06 15:25 - 00000000 ____D C:\ProgramData\ioloGovernor
2015-09-21 18:40 - 2014-10-13 14:42 - 00000000 ___RD C:\Users\jantje\Desktop\Games
2015-09-21 18:24 - 2014-10-06 14:07 - 01391937 _____ C:\Windows\WindowsUpdate.log
2015-09-21 18:12 - 2015-01-21 19:44 - 00000940 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-21 18:11 - 2014-10-11 00:54 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-21 18:11 - 2013-08-22 16:46 - 00049597 _____ C:\Windows\setupact.log
2015-09-21 18:10 - 2014-10-06 14:19 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-21 18:10 - 2014-10-06 14:15 - 00000000 ____D C:\Users\jantje
2015-09-21 18:10 - 2014-03-18 01:04 - 00966980 _____ C:\Windows\PFRO.log
2015-09-21 18:10 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-21 04:52 - 2015-06-14 00:46 - 00000000 ____D C:\Users\jantje\Downloads\PopcornTime
2015-09-21 04:43 - 2014-10-12 03:01 - 00000024 _____ C:\Users\jantje\random.dat
2015-09-21 04:37 - 2015-04-04 23:21 - 00000023 _____ C:\Users\jantje\jagexappletviewer.preferences
2015-09-21 04:35 - 2014-10-12 03:01 - 00000045 _____ C:\Users\jantje\jagex_cl_runescape_LIVE.dat
2015-09-21 04:14 - 2015-02-07 17:35 - 00000046 _____ C:\Users\jantje\jagex_cl_runescape_LIVE1.dat
2015-09-21 02:47 - 2014-10-06 14:21 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-244135331-4156006937-3082476691-1001
2015-09-21 02:42 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-09-21 01:21 - 2014-11-01 14:46 - 00000000 ____D C:\Users\jantje\AppData\Roaming\Dropbox
2015-09-20 04:50 - 2015-02-27 16:44 - 00000000 ____D C:\Windows\Minidump
2015-09-20 04:16 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-09-20 01:43 - 2014-10-14 13:04 - 00162304 ___SH C:\Users\jantje\Downloads\Thumbs.db
2015-09-19 22:45 - 2014-10-11 00:28 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core.job
2015-09-19 16:53 - 2015-03-02 20:53 - 00000050 _____ C:\Users\jantje\jagex_cl_runescape_LIVE_BETA.dat
2015-09-18 17:09 - 2014-10-13 00:45 - 00000000 ____D C:\Users\jantje\AppData\Local\CrashDumps
2015-09-17 21:20 - 2015-01-24 20:21 - 00003824 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1422123684
2015-09-17 21:20 - 2015-01-24 20:21 - 00001080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-09-17 21:20 - 2015-01-24 20:21 - 00000000 ____D C:\Program Files (x86)\Opera
2015-09-16 16:38 - 2015-04-04 23:17 - 00002114 _____ C:\Users\jantje\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape.lnk
2015-09-16 04:31 - 2014-10-11 01:08 - 00000000 ____D C:\Users\jantje\AppData\Roaming\Skype
2015-09-16 00:10 - 2014-10-06 16:10 - 02504704 ___SH C:\Users\jantje\Desktop\Thumbs.db
2015-09-14 17:14 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2015-09-13 01:09 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2015-09-13 01:08 - 2014-10-11 00:27 - 00000000 ____D C:\Users\jantje\AppData\Local\Google
2015-09-10 22:30 - 2013-08-22 16:44 - 00347096 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-10 04:01 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2015-09-10 04:01 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\inetsrv
2015-09-10 04:01 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-09 17:55 - 2014-03-18 11:47 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-09 17:53 - 2014-10-06 15:56 - 00000000 ____D C:\Windows\system32\MRT
2015-09-09 15:56 - 2015-07-19 17:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-09 00:21 - 2014-11-01 14:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-29 00:45 - 2015-07-16 03:46 - 00001028 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-244135331-4156006937-3082476691-1001Core1d0bf693e7fc071.job
2015-08-28 03:25 - 2014-10-11 01:07 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-28 03:25 - 2014-10-11 01:07 - 00000000 ____D C:\ProgramData\Skype
2015-08-26 18:37 - 2014-10-06 15:56 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-25 02:57 - 2014-10-06 16:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-08-25 02:08 - 2014-10-06 14:18 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-22 00:25 - 2014-12-19 00:36 - 00000000 ____D C:\Users\jantje\AppData\Roaming\FiraxisLive
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-21 01:44
 
==================== End of FRST.txt ============================

Yes, I just tried all google services I had trouble with. And all worked the way they should!

 

I'm not sure what could have happened. All I did while going trough your steps, was uninstal utorrent.

Utorrent on itself is harmless as far as I know, unless I would have downloaded a virus with it. So I'm not sure if it was a virus that blocked google's services or something else.

 

Do you have any idea what it might have been?

It could be due to network issues between your router.

Let's monitor this for 2-3 days and then we will do some housekeeping and close this thread.
I suppose that your issue has gone away.

You may remove the tools we used by dragging them to Recycle Bin.

Thank you for your patience, and performing all of the procedures requested. I would also like to take this opportunity to apologize for any delay that may have occurred.

————————————————————————————————————–

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please always ensure that you check and download all the critical updates to help prevent possible re-infection.


Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.


SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
    • How Did I Get Infected In The First Place? by TonyKlein
    • How to Prevent Malware by miekiemoes
    • PC Safety and Security–What Do I Need?
To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop

WOT has an add-on available for both Firefox and IE.

  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
    • Download Host.zip and Save it to your Desktop.
    • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
    • Follow the prompts and click 'Finish'.
    • This will open the newly created hosts folder on your Desktop.
    • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
    • Once updated you should see another prompt that the task was completed.
Follow this list and keep your antivirus program and antispyware programs updated and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so.

**Please respond this one more time to ensure it is resolved and close this topic.

Hello Conspire,

 

The problem hasn't re-occured in the past few days. So I am pretty sure it has been solved now.

Thank you for your tips and helping me fix what was somehow broken!

 

This thread can now be closed.

 

Jean-Pierre.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI