This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Weird and Severe Problems [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The computer really started acting up a couple of days ago - it will not allow me to disable the microphone (when I was able to do so easily in the past ) it will no long no longer allow my "DFX Audio Enhancer" to work, it tried to lock me out of my pictures and documents files, It tried to give me fake Windows updates upon shutdown . . . I applied a system restore just before I put them through - and they loaded quite differently than Windows usual updates -  the updates it wanted to install were 15 in total, but when I denied them and went to the Windows update page Windows only had 6 total updates that were it said were due to be applied!  it would not allow me to use any of the function keys (including and especially the radio antenna key)  I  first noticed the problem when I booted up the computer (Samsung laptop) and it took three times as long to boot as normal.  I have tried to use both system restore and a system repair disc (created a month earlier in January - to no avail . . . meaning that the only thing that I've been able to "fix are the function keys (by doing the system restore -  everything else has been acting really wonky. . . . This all started when I downloaded TOR and Tails.  I did not go on the deep web but I did check both files with "Virus Total" ( https://www.virustotal.com/) and both of the installation files came up clean.  Both files were loaded to and installed to a flash drive.  Computer acts wonky without either flash drive inserted.  I have already run Kaspersky, Spybot Seacrh and Destroy, Malwaebytes a- all in safe mode to 

no avail - I have also run JRT, and Malwarebytes Anti-Root Kit software, and Kasperskys tdsskiller, and Windows Defender in safe mode - also to no avail.  Microphone still cannot be disbled  - (and the network and sharing center says I am currently not connected to any network when I most definitely am (my wifi home network) and after a system restore that Windows says was not completed correctly function keys only work about 3/4 of the time and the computer "bars" show I am ofline when I really am online  Not to mention that I still cannot get my "DFX Audio Enhancer" to work despite uninstalling and reinstalling it several times!  Also - I had to uninstall and reinstall Malwarebyes because it would inexplicably cancel any and all scans after a few seconds for no reason at all . . . now it seems to be working again after it was reinstalled!

Please help as I am disabled and I use the computer to communicate without the outside word because I am so sick that I rarely leave my house nowadays.  . . . Thank You so Much for Your Valuable Time and Expertise!

Here are the log files that you requested:
 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-02-20 23:23:49
—————————–
23:23:49.804    OS Version: Windows x64 6.1.7601 Service Pack 1
23:23:49.804    Number of processors: 8 586 0x3A09
23:23:49.805    ComputerName: FEROCIOUS-PC  UserName: Ferocious
23:23:53.664    Initialize success
23:23:53.842    VM: initialized successfully
23:23:53.851    VM: Intel CPU supported 
23:24:00.728    VM: supported disk I/O iaStor.sys
23:24:27.747    AVAST engine defs: 16022002
23:24:47.969    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
23:24:47.971    Disk 0 Vendor: ST1000LM 2AR1 Size: 953869MB BusType: 3
23:24:47.973    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
23:24:47.975    Disk 1 Vendor: SanDisk_ SSD_ Size: 7641MB BusType: 3
23:24:48.360    VM: Disk 0 MBR read successfully
23:24:48.363    Disk 0 MBR scan
23:24:48.366    Disk 0 unknown MBR code
23:24:48.392    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
23:24:48.471    Disk 0 Boot: NTFS     code=1
23:24:48.505    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       624148 MB offset 206848
23:24:48.848    Disk 0 Partition - 00     0F Extended LBA            307201 MB offset 1278461952
23:24:48.905    Disk 0 Partition 3 00     27 Hidden NTFS WinRE NTFS        22419 MB offset 1907609600
23:24:48.987    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS       307200 MB offset 1278464000
23:24:49.417    Disk 0 scanning C:\windows\system32\drivers
23:25:30.214    Service scanning
23:25:32.453    Service ESProtectionDriver C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys **LOCKED** 32
23:25:40.862    Modules scanning
23:25:40.873    Disk 0 trace - called modules:
23:25:40.898    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 
23:25:40.906    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800af93790]
23:25:40.913    3 CLASSPNP.SYS[fffff8800205143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80077fc050]
23:25:42.921    AVAST engine scan C:\windows
23:27:21.586    AVAST engine scan C:\windows\system32
23:36:21.494    AVAST engine scan C:\windows\system32\drivers
23:36:43.259    AVAST engine scan C:\Users\Ferocious
00:08:28.487    File: C:\Users\Ferocious\Documents\0007\0000 portable software\AntiLoggerFree_Setup_1.8.2.320.exe **HIDDEN**
00:08:29.964    File: C:\Users\Ferocious\Documents\0007\0000 portable software\JRT.exe **HIDDEN**
00:09:04.851    AVAST engine scan C:\ProgramData
00:17:42.964    Disk 0 statistics 5709315/0/27 @ 1.04 MB/s
00:17:42.978    Scan finished successfully
00:18:02.964    Disk 0 MBR has been saved successfully to "C:\Users\Ferocious\Desktop\MBR.dat"
00:18:02.967    The log file has been saved successfully to "C:\Users\Ferocious\Desktop\aswMBR.txt"
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-02-2016
Ran by [removed] (administrator) on FEROCIOUS-PC (20-02-2016 21:55:06)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\Nexus.exe
(NETGEAR Inc.) C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\avp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\avpui.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
() C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\Ferocious\Desktop\aswMBR.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184632 2013-11-13] (Motorola Solutions, Inc.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12460136 2012-03-29] (Realtek Semiconductor)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2622432 2016-01-29] (Malwarebytes Corporation)
HKLM-x32\…\Run: [DFX] => C:\Program Files (x86)\DFX\DFX.exe [1328632 2015-12-04] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [Nexus] => C:\Program Files (x86)\Winstep\Nexus.exe [18378880 2015-10-01] (Winstep Software Technologies)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [NETGEARGenie] => C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [603392 2015-08-26] (NETGEAR Inc.)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8619224 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [appnhost] => C:\Users\Ferocious\AppData\Local\Mixesoft\AppNHost\appnhost.exe
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\MountPoints2: {ec4c6226-6cc6-11e3-a708-c4850861d43c} - E:\Autorun.exe /s
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Mystify.scr [242688 2010-11-20] (Microsoft Corporation)
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Startup: C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2016-01-23]
ShortcutTarget: ERUNT AutoBackup.lnk -> C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall Webroot RunOnce.lnk [2014-10-24]
ShortcutTarget: Uninstall Webroot RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: [S-1-5-21-3575110223-3707097088-2884409191-1001] => localhost:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{FC0B0A7D-A856-4618-8A69-4E3A4879FCBF}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.google.com/
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\x64\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
BHO: No Name -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> No File
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll [2013-09-02] ()
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
BHO-x32: No Name -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> No File
BHO-x32: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files (x86)\WOT\WOT.dll [2013-09-02] ()
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2013-09-02] ()
Toolbar: HKLM - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} -  No File
Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\x64\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll [2013-09-02] ()
Toolbar: HKLM-x32 - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} -  No File
Toolbar: HKLM-x32 - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-3575110223-3707097088-2884409191-1001 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2013-09-02] ()
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll [2013-09-02] ()
Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll [2013-09-02] ()
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\FFExt\light_plugin_firefox
FF Extension: Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\FFExt\light_plugin_firefox [2016-01-22]
 
Chrome: 
=======
CHR StartupUrls: Profile 1 -> "chrome://apps/","chrome://extensions/"
CHR DefaultSearchURL: Profile 1 -> hxxps://www.google.com/search?q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> s
CHR Profile: C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Translate) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-17]
CHR Extension: (Angry Birds) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2015-04-18]
CHR Extension: (Google Docs) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-18]
CHR Extension: (Google Drive) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (Brushed) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2015-04-18]
CHR Extension: (Adguard AdBlocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-02-19]
CHR Extension: (Pop Block Pro - The Ultimate Popup Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib [2015-04-18]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2016-02-19]
CHR Extension: (Poper Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-04-18]
CHR Extension: (YouTube) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Adblock Plus) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-19]
CHR Extension: (Google Search) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
CHR Extension: (Kaspersky Protection) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-09-21]
CHR Extension: (Kaspersky Protection) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\eahebamiopdhefndnmappcihfajigkka [2016-01-26]
CHR Extension: (hxxp://speedtest.nyroc.rr.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\edionanpdofenhkbdncggelplnokpjid [2015-09-21]
CHR Extension: (hxxps://mail.google.com/mail/u/0/?shva=1#inbo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\efkhoejpmofcicglnpndodnojkmngomb [2015-04-18]
CHR Extension: (My IP Address) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\eppbaaljfkdamofakdneaogfphnhbjlj [2015-04-18]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2016-02-19]
CHR Extension: (Full Screen Weather) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2015-05-12]
CHR Extension: (Google Docs Offline) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Dictionary by Dictionary.com) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2015-04-18]
CHR Extension: (Voice Actions for Chrome (beta)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhpjefokaphndbbidpehikcjhldaklje [2015-10-10]
CHR Extension: (JavaScript Popup Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiajdlfgbgnnjakkbnpdhmhfhklkbiol [2016-01-15]
CHR Extension: (Video Downloader [FVD]) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2015-05-06]
CHR Extension: (hxxp://www.thedarewall.com/tv/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljcbepjcbcoodflobneinbmpcgpfhmal [2015-04-18]
CHR Extension: (Flashcontrol) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfidmkgnfgnkihnjeklbekckimkipmoe [2016-02-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-18]
CHR Profile: C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Translate) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-18]
CHR Extension: (Google Slides) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-18]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2016-02-19]
CHR Extension: (News Paywall Access) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adpfpconnigelofkfenblmdhbnlaafkg [2016-01-30]
CHR Extension: (Radio) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agljkoinmcdnopnlbhhjibjiablccgoh [2015-11-18]
CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2015-11-18]
CHR Extension: (Flash Video Downloader) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc [2016-02-19]
CHR Extension: (hxxp://www.walmart.com/sign_out.jsp) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akfaildcjioacioeepojahbjlakpagad [2015-11-18]
CHR Extension: (Theme Creator) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akpelnjfckgfiplcikojhomllgombffc [2015-11-18]
CHR Extension: (Google Docs) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-18]
CHR Extension: (hxxp://www.speedtest.net/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aoimpfmicnklenmbocdgffdhgekaoohj [2015-11-18]
CHR Extension: (Google Drive) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-18]
CHR Extension: (TV) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\beobeededemalmllhkmnkinmfembdimh [2015-11-18]
CHR Extension: (Brushed) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2015-11-18]
CHR Extension: (Adguard AdBlocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-02-13]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-11-18]
CHR Extension: (Free Proxy to Unblock any sites 
 Touch VPN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bihmplhobchoageeokmgbdihknkjbknd [2016-02-19]
CHR Extension: (YOUZEEK Free Music) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce [2015-11-18]
CHR Extension: (Web2PDFConverter) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkanhckocooacphbnclgcndnpfpoppdk [2016-01-28]
CHR Extension: (Audiotool) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2015-11-18]
CHR Extension: (Poper Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-11-18]
CHR Extension: (YouTube) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-18]
CHR Extension: (Adblock Plus) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-09]
CHR Extension: (TrafficLight) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfnpidifppmenkapgihekkeednfoenal [2016-02-16]
CHR Extension: (Plugins) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chemohaemmfhjpmlgkmkanfpfbkaihop [2015-11-18]
CHR Extension: (Pixsta) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cijncchffkmlnfdbnkkfclcbnjcoegjc [2015-12-02]
CHR Extension: (Image Downloader) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2015-11-18]
CHR Extension: (Google Search) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-18]
CHR Extension: (hxxps://accounts.google.com/ServiceLogin?serv) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\copebngjgfepookfihcgelompaefmkfn [2015-11-18]
CHR Extension: (Search by Image (by Google)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2015-11-18]
CHR Extension: (Kaspersky Protection) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-11-18]
CHR Extension: (Dragon Web Extension) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ddaloccgjfibfpkalenodgehlhkgoahe [2015-11-18]
CHR Extension: (hxxp://www.worldometers.info/world-population) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dedfgchgilmmgcopcefilgingbcmbpne [2015-11-18]
CHR Extension: (UberConference Bookmark) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dlhdbjgofnajhpiakdjklonjlpbbonnc [2015-11-18]
CHR Extension: (IPvFoo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ecanpcehffngcegjmadlcijfolapggal [2016-01-28]
CHR Extension: (Pixlr-o-matic) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2015-11-18]
CHR Extension: (hxxp://www.amazon.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eicbgcfajfmpllmbdfmnnpomnnedfbop [2015-11-18]
CHR Extension: (Google Calendar) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-11-18]
CHR Extension: (Minus) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emgdobmndjcmnciellikkhigcbpgpklk [2015-11-18]
CHR Extension: (Blur) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2016-01-30]
CHR Extension: (Morphyre Designer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ephpkjhaakjclleokielmaehpknellcl [2015-11-18]
CHR Extension: (Pandora) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fbangkleohkafngihneedemihgfeikcl [2015-11-18]
CHR Extension: (Flix Plus by Lifehacker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fcjjgdnadfneaamhipplgpfkdnbfagla [2016-01-26]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2016-02-19]
CHR Extension: (Google Sheets) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-18]
CHR Extension: (Full Screen Weather) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2015-11-18]
CHR Extension: (ColorHexa Search Tool) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flnkogfheemakepeokbheholhfhgcbae [2015-11-18]
CHR Extension: (HTTPS Everywhere) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2015-12-19]
CHR Extension: (Google Docs Offline) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Planetarium) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2015-11-18]
CHR Extension: (Click&Clean;) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2016-01-27]
CHR Extension: (AdBlock) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-19]
CHR Extension: (Cryptocat) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gonbigodpnfghidmnphnadhepmbabhij [2015-11-18]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2015-11-18]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2016-02-19]
CHR Extension: (Website Destroyer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfdklionolegofhffnhoagpmlailnnni [2015-11-18]
CHR Extension: (JavaScript Popup Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hiajdlfgbgnnjakkbnpdhmhfhklkbiol [2015-11-20]
CHR Extension: (Marvel Comics) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hjhfaknohpjconjoefidanhihokmkice [2015-11-18]
CHR Extension: (Pixlr Express) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hojmjpdlmjopaeginhldhiokeidchjid [2015-11-18]
CHR Extension: (Crackle) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ibfamoapbmmmlknoopmmfofgladlinic [2015-11-18]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-11-18]
CHR Extension: (Stealthy) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ieaebnkibonmpbhdaanjkmedikadnoje [2015-11-18]
CHR Extension: (hxxp://movies.netflix.com/WiHome) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ifapaoknlkpflhgnolmimcokakmdikho [2015-11-18]
CHR Extension: (Greenhouse) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ifomhmgandipmpnelclcmbefppopfklc [2016-01-30]
CHR Extension: (Color Piano!) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ihmigmmflfcbhdpdgbkkeojchjhhphnh [2015-11-18]
CHR Extension: (Glitterboo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ikkpgihagilojnkmkkfcbhlainmnkicp [2015-11-18]
CHR Extension: (hxxp://registration.myway.com/primary_login.j) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ilkckebnfpkhkfhjdjjkhcgpiofphlkf [2015-11-18]
CHR Extension: (Cookies) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iphcomljdfghbkdcfndaijbokpgddeno [2016-01-28]
CHR Extension: (Disconnect) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2016-01-28]
CHR Extension: (Roomstyler 3D planner) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jfnniehafojoidolddmhfnpnbiolbppi [2016-01-27]
CHR Extension: (Psykogif) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jkjoklgdmjnffhmmllncmleongbhpdok [2015-11-18]
CHR Extension: (Pic3D 
 3D Converter) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jpcenahnngjklfilghhiochkndllljbj [2015-11-18]
CHR Extension: (StumbleUpon) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg [2015-11-18]
CHR Extension: (zoomWheel) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kdfgigbjonaniokmpfflpflkhahhbaej [2015-11-18]
CHR Extension: (Autodesk Homestyler) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2015-11-18]
CHR Extension: (Color Sphere!) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\knomilfbnhpkmibhmleppnkmcempglag [2015-11-18]
CHR Extension: (Until AM Web App) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kodigjkcpaoeodlnmcnekemakpnmegnk [2015-11-18]
CHR Extension: (Google Play) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2015-11-18]
CHR Extension: (hxxp://www.thedarewall.com/tv/movie-tags/boxo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\leadgdgcmfaakbmihgnippgiofmhfnbg [2015-11-18]
CHR Extension: (Video Downloader [FVD]) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2016-01-29]
CHR Extension: (ZenMate Secure Email (Beta)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lgnhdjncgaebccjldgeianajcndhingd [2016-01-30]
CHR Extension: (Minimalistic Memo Calendar) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lhammhngpacbengeachfclhcjbjfkfmf [2015-11-18]
CHR Extension: (Skype) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-02-02]
CHR Extension: (McAfee SECURE Safe Browsing) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lkdiimaiohgpacfbgedcipmgigppaofn [2016-01-28]
CHR Extension: (AudioSauna) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2015-11-18]
CHR Extension: (Video DownloadHelper) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2015-12-16]
CHR Extension: (Google Maps) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-11-18]
CHR Extension: (doubled) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lockfmhdbkjgoehpbpgbajdjphnlppco [2015-11-18]
CHR Extension: (Lazarus: Form Recovery) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\loljledaigphbcpfhfmgopdkppkifgno [2015-11-18]
CHR Extension: (Extensions Manager (aka Switcher)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lpleipinonnoibneeejgjnoeekmbopbc [2016-01-28]
CHR Extension: (3D Solar System Web) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdaaepplopehigjgkolniddiadbbkphd [2015-11-18]
CHR Extension: (Flashcontrol) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfidmkgnfgnkihnjeklbekckimkipmoe [2016-02-19]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-11-18]
CHR Extension: (hxxps://login.live.com/login.srf?wa=wsignin1.) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\miikjlbahjadjfkgcekefnkcngidmncl [2015-11-18]
CHR Extension: (Buffer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjojodpkaeeclkgaidibcbknlhjflhle [2016-01-30]
CHR Extension: (Ghostery) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-12-31]
CHR Extension: (EXIF Viewer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmbhfeiddhndihdjeganjggkmjapkffm [2016-01-28]
CHR Extension: (Google Play Books) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2015-11-18]
CHR Extension: (drumbit) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mplpmdejoamenolpcojgegminhcnmibo [2016-01-21]
CHR Extension: (deviantART muro) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\namljbfbglehfnlonjmebceimaalofei [2015-11-18]
CHR Extension: (OneDrive) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2015-11-18]
CHR Extension: (TunnelSwitch) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nfpphleklkamlblagdkbkomjmaedanoh [2016-01-30]
CHR Extension: (hxxps://accounts.google.com/ServiceLogin?pass) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nhbgdbfmjcmhpoeicmhhicakddieejca [2015-11-18]
CHR Extension: (Hotspot Shield Free VPN Proxy – Unblock Sites) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nlbejmccbhkncgokjcmghpfloaajcffj [2016-02-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-18]
CHR Extension: (Buffer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2016-02-19]
CHR Extension: (My Chrome Theme) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2015-11-18]
CHR Extension: (hxxps://www.google.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\okkolgldfknecfjnhhglfopimelbaceh [2015-11-18]
CHR Extension: (Font Size Increase) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ombpcpigmndepfckcifdblemkabaoihk [2016-02-19]
CHR Extension: (hxxp://speedtest.ohiordc.rr.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pdilcdkapdfafbofkhhjippielmcooid [2015-11-18]
CHR Extension: (Outlook.com) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2015-11-18]
CHR Extension: (Psykopaint) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2015-11-18]
CHR Extension: (Gmail) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-18]
CHR Extension: (Ambient Aurea) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkaglmndhfgdaiaccjglghcbnfinfffa [2015-11-18]
CHR Extension: (Phone Checkr - Phone Number Lookup Service) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pmdbghodmpmnoogajoijjlbnlondnnac [2016-01-29]
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\…\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\…\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 AVP16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\avp.exe [194000 2015-12-05] (Kaspersky Lab ZAO)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2011-09-23] (Diskeeper Corporation)
S2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [127216 2015-01-21] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [740832 2016-01-29] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-07] ()
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-08-26] (NETGEAR)
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed]
S3 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 vssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\x64\vssbridge64.exe [144640 2015-07-09] (AO Kaspersky Lab)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-07] (Intel® Corporation)
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [141624 2014-10-28] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [1448248 2014-11-26] (Motorola Solutions, Inc.)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1x64.sys [28008 2015-08-31] (Windows (R) Win 7 DDK provider)
R3 DFX12; C:\Windows\System32\drivers\dfx12x64.sys [29688 2015-11-12] (Windows (R) Win 7 DDK provider)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [66080 2016-01-29] ()
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2011-09-23] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [80688 2011-09-23] (Diskeeper Corporation)
R0 FSProFilter2; C:\Windows\System32\Drivers\FSPFltd2.sys [57648 2011-06-03] (FSPro Labs)
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
S3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [143904 2015-11-05] (Zemana Ltd.)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-22] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [70000 2015-06-27] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [68280 2015-06-06] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [181640 2015-12-05] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [227000 2015-12-05] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [940928 2015-12-05] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [39096 2015-06-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [41144 2015-06-06] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [41352 2015-12-05] (AO Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-06-11] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [103096 2015-06-16] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [187056 2015-06-23] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R2 NPF; C:\windows\system32\drivers\npf.sys [35344 2016-01-29] (CACE Technologies, Inc.)
S3 massfilter_hs; \??\C:\windows\system32\drivers\massfilter_hs.sys [X]
U0 SR; no ImagePath
U2 srservice; no ImagePath
S3 zghsdiag; system32\DRIVERS\zghsdiag.sys [X]
S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X]
S3 zghsnmea; system32\DRIVERS\zghsnmea.sys [X]
U3 aswMBR; \??\C:\windows\TEMP\aswMBR.sys [X]
U3 aswVmm; \??\C:\windows\TEMP\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-20 21:55 - 2016-02-20 21:55 - 00059687 _____ C:\Users\Ferocious\Desktop\FRST.txt
2016-02-20 21:52 - 2016-02-20 21:55 - 00000000 ____D C:\FRST
2016-02-20 21:49 - 2016-02-20 21:49 - 00000000 ___SH C:\DkHyperbootSync
2016-02-20 21:32 - 2016-02-20 21:32 - 02371072 _____ (Farbar) C:\Users\Ferocious\Desktop\FRST64.exe
2016-02-20 21:31 - 2016-02-20 21:31 - 05198336 _____ (AVAST Software) C:\Users\Ferocious\Desktop\aswMBR.exe
2016-02-20 21:25 - 2016-02-20 21:25 - 00000042 _____ C:\windows\JFEXRMC.INI
2016-02-20 19:49 - 2016-02-20 19:49 - 00000000 ____D C:\ProgramData\DFX
2016-02-20 19:43 - 2016-02-20 19:43 - 00001674 _____ C:\Users\Public\Desktop\DFX.lnk
2016-02-20 19:43 - 2016-02-20 19:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Max Recorder
2016-02-20 19:43 - 2016-02-20 19:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DFX Audio Enhancer
2016-02-20 19:43 - 2016-02-20 19:43 - 00000000 ____D C:\Program Files (x86)\DFX
2016-02-20 17:49 - 2016-02-20 17:49 - 00003258 _____ C:\windows\System32\Tasks\{F740D370-5C8D-4AF0-ADA2-535BF04547E4}
2016-02-20 17:04 - 2016-02-20 17:29 - 00150722 _____ C:\TDSSKiller.2.8.16.0_20.02.2016_17.04.03_log.txt
2016-02-19 23:10 - 2012-05-11 12:23 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\ieaksie.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00227840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieaksie.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakui.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\ieakui.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00160256 _____ (Microsoft Corporation) C:\windows\system32\ieakeng.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00130560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakeng.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00101888 _____ (Microsoft Corporation) C:\windows\SysWOW64\admparse.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ie4uinit.exe
2016-02-19 23:10 - 2012-02-16 08:08 - 00031216 _____ (CyberLink Corporation) C:\windows\system32\Drivers\clwvd.sys
2016-02-19 23:10 - 2011-12-08 00:43 - 00047616 _____ (Intel Corporation) C:\windows\system32\opphelper.dll
2016-02-19 23:10 - 2010-11-20 22:23 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2016-02-19 23:10 - 2009-06-10 15:45 - 00000003 _____ C:\windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
2016-02-19 23:09 - 2012-05-11 12:23 - 00114176 _____ (Microsoft Corporation) C:\windows\system32\admparse.dll
2016-02-19 23:09 - 2010-11-20 22:24 - 00412160 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2016-02-19 23:09 - 2010-11-20 22:24 - 00158720 _____ (Microsoft Corporation) C:\windows\system32\aaclient.dll
2016-02-19 22:32 - 2016-02-19 23:50 - 00119000 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-19 22:32 - 2016-02-19 23:46 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2016-02-19 22:32 - 2016-02-19 22:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-19 22:32 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-02-19 22:32 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-02-19 22:00 - 2016-02-19 22:00 - 00000000 ____D C:\Program Files\ComonFiles
2016-02-19 20:35 - 2016-02-19 20:35 - 00000000 ____D C:\windows\SysWOW64\%Data%
2016-02-18 20:54 - 2016-02-18 20:54 - 01222211 _____ C:\Users\Ferocious\Downloads\bgr-com.pdf
2016-02-16 20:42 - 2016-02-19 19:36 - 00000000 ____D C:\Users\Ferocious\Downloads\zzz Firefox Downloads
2016-02-16 20:28 - 2016-02-19 19:36 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-02-16 20:28 - 2016-02-19 19:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-16 20:28 - 2016-02-16 20:28 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Mozilla
2016-02-15 20:39 - 2016-02-15 20:39 - 00000660 _____ C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2016-02-09 08:47 - 2016-02-09 08:47 - 00000000 ____D C:\Program Files\Common Files\AV
2016-02-09 08:34 - 2016-02-09 08:34 - 00001355 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
2016-02-09 08:34 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe
2016-02-09 08:15 - 2016-02-19 19:36 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-02-09 08:15 - 2016-02-09 09:32 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-02-09 07:57 - 2016-02-09 08:00 - 00004324 _____ C:\TDSSKiller.2.8.16.0_09.02.2016_07.57.29_log.txt
2016-02-09 07:54 - 2016-02-09 07:54 - 00000000 ____D C:\TDSSKiller_Quarantine
2016-02-09 07:51 - 2016-02-09 07:54 - 00151578 _____ C:\TDSSKiller.2.8.16.0_09.02.2016_07.51.43_log.txt
2016-02-09 07:35 - 2016-02-09 00:38 - 52988120 _____ (Microsoft Corporation) C:\Users\Ferocious\Downloads\Windows-KB890830-x64-V5.32.exe
2016-02-09 07:35 - 2016-02-09 00:33 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Ferocious\Downloads\tdsskiller.exe
2016-02-05 11:43 - 2016-02-05 11:43 - 00000000 ___HD C:\$Windows.~WS
2016-02-05 11:43 - 2016-02-05 11:43 - 00000000 ____D C:\$WINDOWS.~BT
2016-02-02 13:25 - 2016-02-02 11:40 - 00000000 __SHD C:\found.000
2016-02-02 12:24 - 2016-02-02 12:24 - 00000020 ___SH C:\Users\Ferocious\ntuser.ini
2016-02-02 00:10 - 2016-02-02 00:10 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-02-01 23:21 - 2016-02-01 23:21 - 00000000 ____D C:\ProgramData\CyberLink
2016-02-01 21:44 - 2016-02-01 21:44 - 00000000 ____D C:\Users\Ferocious\Tracing
2016-02-01 21:41 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-02-01 13:19 - 2016-02-01 13:19 - 85401206 _____ C:\Users\Ferocious\Documents\sharp tv doc.pdf
2016-02-01 02:01 - 2016-02-02 12:23 - 00000000 ____D C:\Program Files (x86)\HDDScan-3.3
2016-02-01 01:57 - 2016-02-01 11:48 - 00000000 ____D C:\Program Files (x86)\Double Driver
2016-02-01 01:56 - 2016-02-20 09:48 - 00000000 ____D C:\Driver Backups
2016-02-01 01:42 - 2011-12-10 13:23 - 00976384 _____ (Quick And Easy Software) C:\Program Files (x86)\USB_Disk_Eject.exe
2016-02-01 00:40 - 2016-02-19 21:43 - 00000000 ____D C:\Utility Program Shortcuts
2016-02-01 00:29 - 2016-02-01 00:30 - 00000000 ____D C:\Users\Ferocious\Documents\zzz Misc
2016-02-01 00:29 - 2016-02-01 00:29 - 00047104 ___SH C:\Users\Ferocious\Documents\Thumbs.db
2016-02-01 00:25 - 2016-02-01 00:28 - 00000000 ____D C:\Users\Ferocious\Documents\0000 Christopher
2016-01-31 23:52 - 2011-06-03 22:59 - 00057648 _____ (FSPro Labs) C:\windows\system32\Drivers\FSPFltd2.sys
2016-01-31 22:58 - 2016-01-31 22:59 - 00000000 ___HD C:\Program Files\Win959820007810
2016-01-31 22:44 - 2016-01-31 22:44 - 00000000 ____D C:\Program Files (x86)\Security Task Manager
2016-01-31 22:09 - 2016-01-31 22:09 - 00000000 ____D C:\Users\Ferocious\AppData\LocalLow\Google
2016-01-31 20:53 - 2016-01-31 20:53 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\SubiSoft
2016-01-31 20:42 - 2016-02-01 01:52 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo6_7_3
2016-01-31 20:05 - 2016-01-31 20:05 - 00000000 ____D C:\Program Files\Axantum
2016-01-29 18:06 - 2016-01-29 18:06 - 00000000 ____D C:\Program Files (x86)\NexusFont
2016-01-29 17:07 - 2016-02-02 12:21 - 00000000 ____D C:\ProgramData\ACD Systems
2016-01-29 17:07 - 2016-01-29 17:07 - 00000000 ____D C:\Program Files (x86)\ACD Systems
2016-01-29 07:52 - 2016-01-29 08:09 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Apple Computer
2016-01-29 07:51 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\Apple Computer
2016-01-29 07:51 - 2016-01-29 07:52 - 00000000 ____D C:\Program Files\iTunes
2016-01-29 07:51 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files\iPod
2016-01-29 07:51 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-01-29 07:51 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-01-29 07:50 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-01-29 07:50 - 2016-01-29 07:50 - 00000000 ____D C:\Program Files\Bonjour
2016-01-29 07:50 - 2016-01-29 07:50 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-01-29 07:49 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\Apple
2016-01-29 06:59 - 2016-01-29 06:59 - 00000000 ____D C:\ProgramData\IntelDLM
2016-01-29 06:50 - 2016-01-29 06:50 - 00000000 ____D C:\ProgramData\Package Cache
2016-01-29 06:50 - 2016-01-29 06:50 - 00000000 ____D C:\Program Files (x86)\Intel Driver Update Utility
2016-01-29 06:15 - 2016-01-29 06:16 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Easy File Share
2016-01-28 02:23 - 2016-01-28 02:23 - 01010720 ___RS (Microsoft Corporation) C:\windows\SysWOW64\MSCHRT20.OCX
2016-01-28 02:23 - 2016-01-28 02:23 - 00224016 ___RS (Microsoft Corporation) C:\windows\SysWOW64\TABCTL32.OCX
2016-01-28 02:23 - 2016-01-28 02:23 - 00140488 ___RS (Microsoft Corporation) C:\windows\SysWOW64\COMDLG32.OCX
2016-01-28 02:23 - 2016-01-28 02:23 - 00000000 ____D C:\Program Files (x86)\Technitium
2016-01-27 16:06 - 2016-02-02 12:23 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\simplitec
2016-01-26 20:42 - 2016-01-26 20:42 - 00000000 ____D C:\Users\Ferocious\Documents\MAGIX
2016-01-26 20:41 - 2016-01-26 20:41 - 00000000 ____D C:\Users\Public\Documents\MAGIX
2016-01-26 20:40 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\simplitec
2016-01-26 20:40 - 2016-02-02 12:21 - 00000000 ____D C:\ProgramData\MAGIX
2016-01-26 20:40 - 2016-01-26 20:40 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2016-01-26 20:40 - 2016-01-26 20:40 - 00000000 ____D C:\Program Files (x86)\MAGIX
2016-01-26 19:56 - 2016-02-02 12:23 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\MAGIX
2016-01-26 19:56 - 2016-01-26 19:56 - 00000000 ____D C:\Users\Ferocious\Documents\MAGIX Downloads
2016-01-26 18:06 - 2016-01-26 18:06 - 00003174 _____ C:\windows\System32\Tasks\{395B4909-3C61-4CE4-AFD1-BFA0B6E7A98B}
2016-01-26 17:33 - 2016-02-20 19:28 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Audacity
2016-01-26 17:32 - 2016-01-26 17:32 - 00000000 ____D C:\Program Files (x86)\Audacity
2016-01-26 16:33 - 2016-01-26 16:33 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\WinRAR
2016-01-26 16:32 - 2016-01-26 17:24 - 00000000 ____D C:\Program Files\WinRAR
2016-01-26 15:51 - 2016-02-20 09:55 - 00000000 ____D C:\Reg Backup
2016-01-26 15:48 - 2016-01-26 15:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-26 15:48 - 2016-01-26 15:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-26 15:42 - 2016-01-26 15:42 - 00003184 _____ C:\windows\System32\Tasks\{262D531C-38D5-4C04-A680-DEF8F6F6CA4E}
2016-01-26 15:36 - 2016-02-20 21:06 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2016-01-26 15:36 - 2016-02-02 12:23 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2016-01-26 15:30 - 2016-01-26 15:30 - 00000000 ____D C:\Program Files (x86)\FileASSASSIN
2016-01-26 15:20 - 2016-01-26 15:20 - 01600184 _____ (Malwarebytes) C:\Program Files (x86)\JRT.exe
2016-01-26 15:20 - 2016-01-26 15:20 - 00065232 _____ (Malwarebytes) C:\Program Files (x86)\regassassin-setup-1.03.exe
2016-01-26 15:03 - 2016-01-29 06:01 - 00000000 ____D C:\Program Files (x86)\NETGEAR Genie
2016-01-26 14:43 - 2016-01-26 14:43 - 00001764 _____ C:\Program Files (x86)\mbar-1.07.0.lnk
2016-01-26 09:56 - 2016-01-26 09:56 - 00000000 ____D C:\Program Files (x86)\Winstep
2016-01-26 09:56 - 2008-02-05 15:36 - 00798208 _____ (Winstep Software Technologies) C:\windows\SysWOW64\NextControls.ocx
2016-01-26 09:56 - 2000-05-22 17:58 - 00608448 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.ocx
2016-01-26 09:56 - 1997-07-19 16:55 - 01347344 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvbvm50.dll
2016-01-26 04:48 - 2016-02-20 19:13 - 00000000 ____D C:\Users\Public\Documents\Winstep
2016-01-26 04:12 - 2016-02-20 00:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-01-26 04:02 - 2016-01-26 04:35 - 00000000 ____D C:\Program Files (x86)\mbar
2016-01-26 03:20 - 2016-01-26 03:44 - 00000000 ____D C:\Program Files (x86)\TCEcs3
2016-01-26 03:16 - 2016-02-20 19:43 - 00000000 ____D C:\Program Files (x86)\Max Recorder
2016-01-26 01:49 - 2008-08-18 19:18 - 00077824 _____ (Fox Magic Software) C:\windows\SysWOW64\fmcodec.DLL
2016-01-26 00:23 - 2014-03-22 09:21 - 12589848 _____ (Malwarebytes Corp.) C:\Program Files (x86)\mbar-1.07.0.1009.exe
2016-01-25 20:13 - 2016-01-26 12:50 - 00000000 ____D C:\TCEcs3 Plugins
2016-01-25 16:38 - 2016-02-02 12:23 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Printer
2016-01-25 05:20 - 2016-01-25 05:20 - 00000000 _____ C:\windows\EEventManager.INI
2016-01-24 00:51 - 2016-01-24 00:51 - 00000044 _____ C:\windows\XP-820.ini
2016-01-24 00:51 - 2016-01-24 00:51 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Leadertech
2016-01-24 00:33 - 2016-02-20 21:33 - 00000911 _____ C:\windows\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE}.job
2016-01-24 00:33 - 2016-01-24 00:33 - 00003978 _____ C:\windows\System32\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE}
2016-01-24 00:33 - 2016-01-24 00:33 - 00000000 ____D C:\Program Files\Common Files\EPSON
2016-01-24 00:25 - 2016-02-02 12:21 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Epson
2016-01-24 00:23 - 2016-01-24 00:27 - 00000000 ____D C:\Program Files (x86)\EPSON Software
2016-01-24 00:23 - 2016-01-24 00:27 - 00000000 ____D C:\Program Files (x86)\epson
2016-01-24 00:23 - 2016-01-24 00:23 - 00000000 ____D C:\Program Files\EpsonNet
2016-01-24 00:23 - 2014-02-25 00:00 - 00466944 _____ (Seiko Epson Corporation) C:\windows\system32\esxw2ud.dll
2016-01-24 00:23 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\windows\system32\escsvc64.exe
2016-01-24 00:22 - 2013-12-05 15:05 - 00179712 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_YLMBNME.DLL
2016-01-24 00:22 - 2011-03-14 15:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_YD4BNME.DLL
2016-01-24 00:22 - 2007-04-09 13:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\windows\system32\E_GCINST.DLL
2016-01-24 00:21 - 2016-02-02 12:21 - 00000000 ____D C:\ProgramData\EPSON
2016-01-23 22:36 - 2016-01-29 06:00 - 00369168 _____ (CACE Technologies, Inc.) C:\windows\system32\wpcap.dll
2016-01-23 22:36 - 2016-01-29 06:00 - 00281104 _____ (CACE Technologies, Inc.) C:\windows\SysWOW64\wpcap.dll
2016-01-23 22:36 - 2016-01-29 06:00 - 00106000 _____ (CACE Technologies, Inc.) C:\windows\system32\packet.dll
2016-01-23 22:36 - 2016-01-29 06:00 - 00096784 _____ (CACE Technologies, Inc.) C:\windows\SysWOW64\packet.dll
2016-01-23 22:36 - 2016-01-29 06:00 - 00035344 _____ (CACE Technologies, Inc.) C:\windows\system32\Drivers\npf.sys
2016-01-23 22:06 - 2016-02-02 12:23 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Office
2016-01-23 22:06 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Office
2016-01-23 21:59 - 2016-02-02 12:23 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\e-Sword
2016-01-23 21:34 - 2016-02-20 09:54 - 00000000 ____D C:\windows\ERDNT
2016-01-23 21:34 - 2016-01-23 18:09 - 00000000 _____ C:\Program Files (x86)\_netlib4.dl2
2016-01-23 19:30 - 2011-07-22 10:33 - 00025056 _____ (Windows (R) Win 7 DDK provider) C:\windows\system32\Drivers\SCMNdisP.sys
2016-01-23 18:09 - 2016-01-23 22:20 - 00013312 _____ C:\Program Files (x86)\_netlib2.dl2
2016-01-23 18:09 - 2016-01-23 18:36 - 00013312 _____ C:\Program Files (x86)\_netlib3.dl2
2016-01-23 18:08 - 2016-01-23 18:08 - 00000000 ____D C:\Program Files (x86)\IO3O LLC
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\vlc
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Roaming\vlc
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\HomeGroupUser$
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\Guest\AppData\Roaming\vlc
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\Guest
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\vlc
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\vlc
2016-01-23 15:20 - 2016-01-23 15:20 - 00000000 ____D C:\Users\Administrator
2016-01-23 14:42 - 2016-01-23 14:43 - 00000000 ____D C:\windows\Erunt
2016-01-23 14:41 - 2016-01-23 14:41 - 00000888 _____ C:\Users\UpdatusUser\Desktop\NTREGOPT.lnk
2016-01-23 14:41 - 2016-01-23 14:41 - 00000869 _____ C:\Users\UpdatusUser\Desktop\ERUNT.lnk
2016-01-23 14:41 - 2016-01-23 14:41 - 00000000 ____D C:\Program Files (x86)\ERUNT
2016-01-23 14:17 - 2016-02-20 21:35 - 00000000 ____D C:\Users\Ferocious\Downloads\zzz sorted
2016-01-23 10:40 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\SecTaskMan
2016-01-23 10:06 - 2016-01-23 10:06 - 00000000 __SHD C:\windows\SysWOW64\AI_RecycleBin
2016-01-23 10:06 - 2016-01-23 10:06 - 00000000 ____D C:\Program Files (x86)\Reason
2016-01-23 07:09 - 2015-11-05 15:00 - 00143904 _____ (Zemana Ltd.) C:\windows\system32\Drivers\KeyCrypt64.sys
2016-01-23 06:15 - 2016-02-19 21:42 - 00000000 ____D C:\zzzzScan Logs
2016-01-23 01:47 - 2016-01-23 01:47 - 08799792 _____ ( ) C:\Program Files\ipscan24.exe
2016-01-23 01:27 - 2016-02-05 11:31 - 00000000 ____D C:\Users\Ferocious\Downloads\zzz unsorted
2016-01-22 21:33 - 2016-01-22 21:33 - 00000000 ____D C:\windows\ELAMBKUP
2016-01-22 21:33 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\windows\system32\klfphc.dll
2016-01-22 21:32 - 2015-12-05 03:51 - 00940928 _____ (AO Kaspersky Lab) C:\windows\system32\Drivers\klif.sys
2016-01-22 21:32 - 2015-12-05 03:51 - 00227000 _____ (AO Kaspersky Lab) C:\windows\system32\Drivers\klhk.sys
2016-01-22 21:32 - 2015-12-05 03:51 - 00181640 _____ (AO Kaspersky Lab) C:\windows\system32\Drivers\klflt.sys
2016-01-22 18:33 - 2016-02-20 21:50 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-01-21 23:40 - 2016-02-03 14:37 - 00000000 ____D C:\Users\Ferocious\Documents\Chris
2016-01-21 22:46 - 2016-01-21 22:46 - 00003044 _____ C:\windows\System32\Tasks\{E4C0C50D-3DC8-48CA-BE17-EF08C245F070}
2016-01-21 22:46 - 2016-01-21 22:46 - 00003044 _____ C:\windows\System32\Tasks\{73AE8EC3-CB80-4B1B-8696-F3E93DD7913F}
2016-01-21 22:45 - 2016-01-21 22:45 - 00003044 _____ C:\windows\System32\Tasks\{F7F049FE-5F44-4F5F-BA92-76F1861D1E6E}
2016-01-21 22:27 - 2016-01-21 22:27 - 00003044 _____ C:\windows\System32\Tasks\{F1B8E449-E35C-4479-9F05-F79654024F40}
2016-01-21 22:27 - 2016-01-21 22:27 - 00003044 _____ C:\windows\System32\Tasks\{95153E2A-AE05-402F-8C06-B832F4C36AB5}
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-20 21:49 - 2013-09-25 14:44 - 00000944 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001UA.job
2016-02-20 21:12 - 2013-09-23 14:35 - 00000904 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-20 21:06 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\NDF
2016-02-20 20:57 - 2014-10-24 18:23 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-02-20 20:39 - 2009-07-13 23:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-20 20:39 - 2009-07-13 23:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-20 20:23 - 2009-07-14 00:13 - 00782430 _____ C:\windows\system32\PerfStringBackup.INI
2016-02-20 20:23 - 2009-07-13 22:20 - 00000000 ____D C:\windows\inf
2016-02-20 20:17 - 2013-09-23 14:35 - 00000900 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-20 20:17 - 2012-05-10 20:31 - 00000828 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2016-02-20 20:17 - 2009-07-14 00:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-02-20 19:43 - 2013-09-23 12:12 - 00000000 ____D C:\Program Files (x86)\JetAudio
2016-02-20 15:49 - 2013-09-25 14:44 - 00000922 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001Core.job
2016-02-20 11:51 - 2012-05-10 20:31 - 00000830 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2016-02-19 22:32 - 2013-09-23 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security
2016-02-19 21:22 - 2009-07-13 23:45 - 00306176 _____ C:\windows\system32\FNTCACHE.DAT
2016-02-19 20:32 - 2012-05-10 20:34 - 00000000 ____D C:\Users\UpdatusUser
2016-02-19 19:39 - 2013-09-21 15:43 - 00000000 ____D C:\Users\Ferocious
2016-02-19 19:37 - 2014-12-09 19:51 - 00000000 ____D C:\windows\system32\appraiser
2016-02-19 19:37 - 2014-05-06 20:32 - 00000000 ___SD C:\windows\system32\CompatTel
2016-02-19 19:37 - 2012-05-11 12:21 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-19 19:37 - 2009-07-13 22:20 - 00000000 ____D C:\windows\PolicyDefinitions
2016-02-19 19:36 - 2012-05-10 21:24 - 00000000 ___HD C:\windows\system32\WLANProfiles
2016-02-19 19:36 - 2012-05-10 20:55 - 00000000 ____D C:\ProgramData\WinClon
2016-02-19 19:36 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-02-19 19:35 - 2009-07-13 22:20 - 00000000 ____D C:\windows\registration
2016-02-13 12:58 - 2014-10-24 18:23 - 00796864 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-02-13 12:58 - 2014-10-24 18:23 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-13 12:58 - 2014-10-24 18:23 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2016-02-09 10:00 - 2013-09-21 16:19 - 143671360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-02-05 11:43 - 2011-02-11 14:57 - 00000000 ____D C:\windows\Panther
2016-02-03 14:20 - 2016-01-13 15:42 - 00071128 _____ C:\Users\Ferocious\AppData\Roaming\GDIPFONTCACHEV1.DAT
2016-02-02 12:24 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\System
2016-02-02 12:23 - 2015-04-04 18:53 - 00000000 ___SD C:\windows\system32\GWX
2016-02-02 12:23 - 2013-09-25 14:58 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-02-02 12:23 - 2013-09-25 06:13 - 00000000 ____D C:\windows\pss
2016-02-02 12:23 - 2013-09-25 06:00 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Skype
2016-02-02 12:23 - 2013-09-23 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-02 12:23 - 2013-09-23 09:57 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video
2016-02-02 12:23 - 2013-09-23 09:56 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet
2016-02-02 12:23 - 2013-09-23 09:56 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Photo
2016-02-02 12:23 - 2013-09-23 09:23 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows
2016-02-02 12:23 - 2013-09-23 09:23 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet
2016-02-02 12:23 - 2013-09-23 09:22 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer
2016-02-02 12:23 - 2013-09-23 09:22 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security
2016-02-02 12:23 - 2012-05-10 21:37 - 00000000 ____D C:\Program Files (x86)\Windows Live
2016-02-02 12:23 - 2012-05-10 21:35 - 00000000 ____D C:\Program Files\Windows Live
2016-02-02 12:23 - 2012-05-10 21:00 - 00000000 ____D C:\ProgramData\Skype
2016-02-02 12:23 - 2012-05-10 20:50 - 00000000 ____D C:\ProgramData\SAMSUNG
2016-02-02 12:21 - 2015-12-17 10:54 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\AVG
2016-02-02 12:21 - 2014-10-24 18:37 - 00000000 ____D C:\ProgramData\Adobe
2016-02-02 12:21 - 2014-08-10 14:34 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\SoftGrid Client
2016-02-02 12:21 - 2013-09-23 12:13 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\COWON
2016-02-02 12:21 - 2013-09-23 10:58 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\ACD Systems
2016-02-02 12:21 - 2013-09-21 16:27 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Adobe
2016-02-02 12:21 - 2013-09-21 15:43 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Intel
2016-02-02 12:21 - 2012-05-10 20:34 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-02 12:21 - 2012-05-10 20:31 - 00000000 ____D C:\ProgramData\Intel
2016-02-01 19:53 - 2015-05-05 23:10 - 00000000 ____D C:\Users\Ferocious\Downloads\0000 Chris
2016-02-01 17:56 - 2013-09-23 15:17 - 00000189 _____ C:\windows\ScreenHunter.INI
2016-02-01 02:02 - 2015-05-05 23:10 - 00000000 ____D C:\Users\Ferocious\Downloads\0000 Patrick
2016-02-01 01:35 - 2013-09-23 14:43 - 00000000 ___HD C:\Patricks Do Not Touch
2016-01-31 22:08 - 2013-09-23 14:35 - 00000000 ____D C:\Program Files (x86)\Google
2016-01-31 22:07 - 2013-09-23 14:35 - 00003900 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-01-31 22:07 - 2013-09-23 14:35 - 00003648 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-30 19:16 - 2013-09-23 09:59 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo
2016-01-29 08:38 - 2013-09-23 09:53 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Computer
2016-01-29 07:05 - 2012-05-10 20:30 - 00000000 ____D C:\Program Files (x86)\Intel
2016-01-29 06:36 - 2012-05-10 20:49 - 00000000 ____D C:\Program Files (x86)\Samsung
2016-01-29 06:29 - 2012-05-10 20:30 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-01-26 20:59 - 2009-07-13 21:34 - 00000491 _____ C:\windows\win.ini
2016-01-26 20:41 - 2007-04-27 10:43 - 00120200 _____ () C:\windows\SysWOW64\DLLDEV32i.dll
2016-01-26 17:24 - 2012-05-10 21:42 - 00000000 ____D C:\windows\hr
2016-01-26 12:39 - 2013-09-23 09:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video
2016-01-26 02:57 - 2013-09-23 12:22 - 00000000 ____D C:\Toons
2016-01-24 00:52 - 2009-07-14 00:32 - 00000000 ____D C:\windows\system32\FxsTmp
2016-01-23 22:08 - 2013-09-23 09:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows
2016-01-23 11:19 - 2009-07-14 00:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2016-01-23 11:15 - 2015-04-17 10:21 - 00000000 __SHD C:\Users\Ferocious\AppData\LocalLow\EmieUserList
2016-01-23 11:15 - 2015-04-17 10:21 - 00000000 __SHD C:\Users\Ferocious\AppData\LocalLow\EmieSiteList
2016-01-23 11:15 - 2015-04-17 10:21 - 00000000 __SHD C:\Users\Ferocious\AppData\LocalLow\EmieBrowserModeList
2016-01-22 21:34 - 2014-10-24 13:56 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2016-01-22 00:55 - 2009-07-14 00:08 - 00022650 _____ C:\windows\Tasks\SCHEDLGU.TXT
2016-01-21 22:34 - 2015-12-17 10:48 - 00000000 ____D C:\ProgramData\Avg
2016-01-21 22:31 - 2015-12-17 10:50 - 00000000 ____D C:\ProgramData\MFAData
 
==================== Files in the root of some directories =======
 
2016-01-23 01:47 - 2016-01-23 01:47 - 8799792 _____ (                                                            ) C:\Program Files\ipscan24.exe
2016-01-26 15:20 - 2016-01-26 15:20 - 1600184 _____ (Malwarebytes) C:\Program Files (x86)\JRT.exe
2016-01-26 00:23 - 2014-03-22 09:21 - 12589848 _____ (Malwarebytes Corp.) C:\Program Files (x86)\mbar-1.07.0.1009.exe
2016-01-26 14:43 - 2016-01-26 14:43 - 0001764 _____ () C:\Program Files (x86)\mbar-1.07.0.lnk
2016-01-26 15:20 - 2016-01-26 15:20 - 0065232 _____ (Malwarebytes) C:\Program Files (x86)\regassassin-setup-1.03.exe
2016-02-01 01:42 - 2011-12-10 13:23 - 0976384 _____ (Quick And Easy Software) C:\Program Files (x86)\USB_Disk_Eject.exe
2016-01-23 18:09 - 2016-01-23 22:20 - 0013312 _____ () C:\Program Files (x86)\_netlib2.dl2
2016-01-23 18:09 - 2016-01-23 18:36 - 0013312 _____ () C:\Program Files (x86)\_netlib3.dl2
2016-01-23 21:34 - 2016-01-23 18:09 - 0000000 _____ () C:\Program Files (x86)\_netlib4.dl2
2013-12-22 17:31 - 2015-04-28 13:16 - 0013312 _____ () C:\Users\Ferocious\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-16 12:20 - 2016-01-28 03:02 - 0007604 _____ () C:\Users\Ferocious\AppData\Local\Resmon.ResmonCfg
2016-02-18 19:50 - 2016-02-18 19:50 - 0000000 _____ () C:\Users\Ferocious\AppData\Local\{4D70EDDC-477B-44B0-AAEB-27F8D212B998}
2012-05-10 20:45 - 2012-05-10 20:46 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2012-05-10 20:41 - 2012-05-10 20:41 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
2012-05-10 20:43 - 2012-05-10 20:44 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2012-05-10 20:42 - 2012-05-10 20:43 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2012-05-10 20:44 - 2012-05-10 20:45 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-02-19 23:23
 
==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version:20-02-2016
Ran by [removed] (2016-02-20 21:55:56)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-09-21 20:43:09)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3575110223-3707097088-2884409191-500 - Administrator - Disabled)
Ferocious (S-1-5-21-3575110223-3707097088-2884409191-1001 - Administrator - Enabled) => C:\Users\Ferocious
Guest (S-1-5-21-3575110223-3707097088-2884409191-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3575110223-3707097088-2884409191-1003 - Limited - Enabled)
UpdatusUser (S-1-5-21-3575110223-3707097088-2884409191-1000 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
ACDSee 15 (HKLM-x32\…\{B580C89C-F7F8-4A78-BAF0-5560C6E9E76D}) (Version: 15.0.169 - ACD Systems International Inc.)
Adobe Flash Player 20 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.14) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.14 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\…\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
aTube Catcher (HKLM-x32\…\aTube Catcher) (Version: 2.9.4272 - DsNET Corp)
aTube Catcher version 3.8 (HKLM-x32\…\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.1.0 (HKLM-x32\…\Audacity_is1) (Version: 2.1.0 - Audacity Team)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.14 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DFX (HKLM-x32\…\DFX) (Version: 12.014.0.0 - Power Technology)
Easy Photo Scan (HKLM-x32\…\{2D76CB3C-AC17-4143-891E-F4C3BCDC78B6}) (Version: 1.00.0001 - Seiko Epson Corporation)
Easy Settings (HKLM-x32\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.1 - Samsung Electronics CO., LTD.)
Easy Support Center (HKLM\…\{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}) (Version: 1.2.23 - Samsung Electronics CO., LTD.)
Epson Event Manager (HKLM-x32\…\{86B4A6B9-07FD-48EC-8730-1EC82E80C3D7}) (Version: 3.10.0030 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.50.00 - SEIKO EPSON CORPORATION)
Epson Print CD (HKLM-x32\…\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.31.00 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON XP-820 Series Printer Uninstall (HKLM\…\EPSON XP-820 Series) (Version:  - SEIKO EPSON Corporation)
Epson XP-820 User’s Guide version 1.0 (HKLM-x32\…\UsersGuideEpson XP-820 User’s Guide_is1) (Version: 1.0 - )
EpsonNet Print (HKLM\…\{F983229B-587E-4322-BCB9-D7A49734E5CD}) (Version: 3.0.0.0 - SEIKO EPSON CORPORATION)
ERUNT 1.1j (HKLM-x32\…\ERUNT_is1) (Version:  - Lars Hederer)
e-Sword (HKLM-x32\…\{463178C4-E707-41EE-BE8A-080C62BF526D}) (Version: 10.04.0000 - Rick Meyers)
e-Sword Module Installer version .5 (HKLM\…\{6E442F8C-3EB1-4911-BB65-F3AD73438F52}_is1) (Version: .5 - BibleSupport.com)
ExpressCache (HKLM\…\{F9EB0DDE-931C-4E89-96B2-DE8286EDFA6C}) (Version: 1.0.64 - Diskeeper Corporation)
FileASSASSIN (HKLM-x32\…\FileASSASSIN) (Version: 1.06 - Malwarebytes)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Earth Pro (HKLM-x32\…\{35DAA04C-1720-4BE3-A920-A03731EC6A1D}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Intel(R) Driver Update Utility 2.4 (x32 Version: 2.4.0.5 - Intel) Hidden
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2618 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\…\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation)
Intel(R) WiDi (HKLM-x32\…\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation)
Intel(R) Wireless Bluetooth(R)(patch version 17.1.1504.516) (HKLM\…\{302600C1-6BDF-4FD1-1411-148929CC1385}) (Version: 17.1.1411.0506 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® Driver Update Utility (HKLM-x32\…\{270e4d1a-19f9-46c3-93b3-e61d4a24ab9f}) (Version: 2.4.0.5 - Intel)
Intel® PROSet/Wireless WiFi Software (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\…\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
iTunes (HKLM\…\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
jetAudio Plus (HKLM-x32\…\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}) (Version: 8.1.0 - COWON)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kaspersky Internet Security (HKLM-x32\…\InstallWIX_{77E7AE5C-181C-4CAF-ADBF-946F11C1CE26}) (Version: 16.0.0.614 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 16.0.0.614 - Kaspersky Lab) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\…\MAGIX_{A8A090CA-5FBE-4CA3-B596-7DA41BE11DE8}) (Version: 7.0.1.27 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.1.27 - MAGIX AG) Hidden
Malwarebytes Anti-Exploit version 1.8.1.1189 (HKLM\…\Malwarebytes Anti-Exploit_is1) (Version: 1.8.1.1189 - Malwarebytes)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Max Recorder (HKLM-x32\…\Max Recorder) (Version: 2.006.0.0 - Silver Vine, LLC)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM-x32\…\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Multimedia POP (HKLM-x32\…\{119B7882-19D7-4BE7-A417-29BB479D3ABE}) (Version: 1.0 - )
NETGEAR Genie (HKLM-x32\…\NETGEAR Genie) (Version: 2.4.18.00 - NETGEAR Inc.)
Nexus 15.9 (HKLM-x32\…\Winstep Xtreme_is1) (Version:  - )
NexusFont 2.5 (ver 2.5.8.1582) (HKLM-x32\…\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version:  - xiles)
NVIDIA Graphics Driver 296.32 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 296.32 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0213 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6608 - Realtek Semiconductor Corp.)
Samplitude Music Studio 2013 (HKLM-x32\…\MAGIX_{30AEB310-7BAE-4735-96EA-5536B9CFE334}) (Version: 19.0.1.18 - MAGIX AG)
Samplitude Music Studio 2013 (Version: 19.0.1.18 - MAGIX AG) Hidden
Samsung Kies (HKLM-x32\…\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.0.11044_11 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.0.0.11044_11 - Samsung Electronics Co., Ltd.) Hidden
Samsung Recovery Solution 5 (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.2.7 - Samsung Electronics CO., LTD.)
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.4.10.0 - SAMSUNG Electronics Co., Ltd.)
Scofield, Cyrus I. - The Biggest Failure of the Church Age.top version 0 (HKLM-x32\…\{D7F1A6E9-5A60-4573-AFBD-4A047A57635E}_is1) (Version: 0 - BibleSupport.com)
Should I Remove It (HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.)
Should I Remove It (x32 Version: 1.0.4 - Reason Software Company Inc.) Hidden
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.109 - Skype Technologies S.A.)
Software Updater (HKLM-x32\…\{E07D7C7B-F424-4EEF-BA17-B2C32BD1C107}) (Version: 4.3.0 - SEIKO EPSON CORPORATION)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Technitium MAC Address Changer v6.0 (HKLM-x32\…\TMACv6.0) (Version: 6.0 - Technitium)
User Guide (HKLM-x32\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 2.0 - Samsung Electronics CO., LTD.)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Who Is On My Wifi version 3.0.4 (HKLM-x32\…\{010D45A1-093D-4534-8147-4E10E80F81CC}_is1) (Version: 3.0.4 - IO3O LLC)
Windows Live 程式集 (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
WinRAR 5.31 beta 1 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.31.1 - win.rar GmbH)
Wisdom-soft ScreenHunter 6.0 Free (HKLM-x32\…\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
WOT for Internet Explorer (HKLM\…\{373B90E1-A28C-434C-92B6-7281AFA6115A}) (Version: 13.9.2.0 - WOT Services Oy)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0BDE8B08-367C-419C-8C40-C3F595491DE5} - System32\Tasks\{395B4909-3C61-4CE4-AFD1-BFA0B6E7A98B} => pcalua.exe -a C:\Users\Ferocious\Downloads\ExpensiveHiFiSony.exe -d C:\Users\Ferocious\Downloads
Task: {13190DF4-45E9-440E-B9AD-AB72C5B00D14} - System32\Tasks\{262D531C-38D5-4C04-A680-DEF8F6F6CA4E} => pcalua.exe -a C:\Users\Ferocious\Downloads\regassassin-setup-1.03.exe -d C:\Users\Ferocious\Downloads
Task: {1B14E284-6155-442F-8C0B-2BDD6DFF31B7} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001UA => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {1C4E48DE-68C6-4457-9A0A-48E52632841C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001Core => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {23ACAC42-1D01-4502-B505-C4AECC892FCF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {3885036D-8265-4BBC-82CE-3BA628D3877E} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-04-24] (Samsung Electronics Co., Ltd.)
Task: {393DCB84-92E2-47A1-B32D-D31FF825D9CE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-01-15] (Piriform Ltd)
Task: {3ED9E4DF-4D01-47AB-BD0D-1C33CBB61C5E} - System32\Tasks\{73AE8EC3-CB80-4B1B-8696-F3E93DD7913F} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {4578B798-9D15-490A-8571-A031B461905D} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-05-01] (Samsung Electronics Co., Ltd.)
Task: {471A5EF3-A694-4154-A623-5A6E3D1E9D4C} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-05-08] (Samsung Electronics Co., Ltd.)
Task: {593BC1E9-7EFF-4E00-9627-7D7E89525282} - System32\Tasks\{F0FE69E6-E47A-456F-A0A5-24F6DC53BA73} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {5B136CE7-1B0E-49A4-B4D3-185118D291E4} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2012-01-28] (SEC)
Task: {5B172D0F-9887-4206-B622-1D441ACA5681} - System32\Tasks\{F740D370-5C8D-4AF0-ADA2-535BF04547E4} => pcalua.exe -a "C:\Users\Ferocious\Downloads\zzz sorted\DFX pro\ExpensiveHiFiSony.exe" -d "C:\Users\Ferocious\Downloads\zzz sorted\DFX pro"
Task: {70C72B5B-8515-4B73-B222-35EF348E5284} - System32\Tasks\{1370B2F3-FBCA-452D-8635-0A5B862A38BC} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {71FBF791-4B2C-49B9-A4C9-F885EB13C8C0} - System32\Tasks\{7EC19467-EF4D-41A5-AFF6-2B2A7A8C1756} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {78E51283-DAD3-4368-BC41-5F894A873FBE} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [2012-04-19] (Samsung Electronics CO., LTD.)
Task: {83CBF6BB-946E-4102-BBB7-DFF12E6F175B} - System32\Tasks\{E111225C-3339-44B3-B7BD-9FD19A8A72A7} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {973C4109-06A5-4F41-965A-8A4269D70C78} - System32\Tasks\{F7F049FE-5F44-4F5F-BA92-76F1861D1E6E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {9AEB661D-5231-4FC3-BF24-067BECED9C0D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-18] (Google Inc.)
Task: {9BC18E4E-9D20-46B4-839B-26AA8DDB60C1} - System32\Tasks\{F1B8E449-E35C-4479-9F05-F79654024F40} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {9FBE1B20-79AC-4C10-A0D0-AA398067233A} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-24] (Intel Corporation)
Task: {9FE0C03E-94F7-443E-A1CA-CE8C94862A46} - System32\Tasks\{33B87CCE-EADC-48F7-B577-AC9EB6B49210} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {A5849DEF-CD95-410A-9900-CBD8B95E9301} - System32\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSNME.EXE [2013-11-21] (SEIKO EPSON CORPORATION)
Task: {A6CB98D8-469A-458C-B7A0-ED72763D57ED} - System32\Tasks\{433D8004-3057-482B-B00E-EC896D580758} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {A8E3F7C5-3455-4828-9751-3842BBCAFA93} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-18] (Google Inc.)
Task: {B3E1D197-2B76-45BA-9A3B-3924D042C1B6} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-24] (Intel Corporation)
Task: {BAA559F9-98AC-48D9-BF81-2A156640F0E9} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics)
Task: {BF19807D-8DB4-4940-819F-4F356F609C01} - System32\Tasks\{8FD53A26-2282-4D14-9DBE-950A72B7BFA8} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {C0D438E2-6450-4C92-8C99-1A7C49D74398} - System32\Tasks\{95153E2A-AE05-402F-8C06-B832F4C36AB5} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {CBE04C6D-AD53-40A3-91E9-0B126A3B0E31} - System32\Tasks\KiesHelper => C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [2011-12-12] (Samsung)
Task: {CF40DA2F-D679-42CC-891D-2C70F0D4969B} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.)
Task: {E34F4E5D-B453-4396-BFC0-E33F31927C7D} - System32\Tasks\{06517B3D-517B-4D4F-8C82-3DED43B22BC0} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {E48FB71A-F476-4493-8583-B6F57B6253DC} - System32\Tasks\{E4C0C50D-3DC8-48CA-BE17-EF08C245F070} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {E6BB207A-284F-4B02-B735-5B505F97C560} - System32\Tasks\{EC424B58-393E-4DAE-AA7B-D56D0BC995A9} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/go/help.faq.installer?source=lightinstaller&LastError;=1618
Task: {EEE8405C-8BBE-460D-BAB3-75A1C95287C0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-13] (Adobe Systems Incorporated)
Task: {F16B4839-B11D-4F68-BF99-7E71E6500219} - System32\Tasks\{86F6B50B-41C7-40FD-AE58-E4E3F2C97F07} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {FB70526A-065E-4B51-B018-33DBEA097CDB} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSNME.EXE:/EXE:{4DAAF32C-C745-4E16-B15C-52A5DA429FBE} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001Core.job => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001UA.job => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music\MAGIX\Samplitude Music Studio 2013\Service and Support\Register online.lnk -> C:\Program Files (x86)\MAGIX\Samplitude Music Studio 2013\explore.exe () -> hxxp://www.magix.com/user/register/product_registration/login_screen.php3?VARPROGRAM=SMS2013&VARCHARGE;=19.0.1.18&VARREGISTER;=onlineregister&VARLAND;=II
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-12-17 18:38 - 2015-12-17 18:38 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-12-17 18:38 - 2015-12-17 18:38 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-05-10 20:31 - 2012-02-07 21:03 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2012-05-10 20:49 - 2012-02-13 01:02 - 00031624 _____ () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
2015-08-26 09:21 - 2015-08-26 09:21 - 00105216 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
2012-02-05 23:42 - 2012-01-05 03:24 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
2016-01-26 09:56 - 2012-06-08 20:40 - 01086176 _____ () C:\Program Files (x86)\Winstep\wodTelnetDLX.dll
2012-05-10 20:50 - 2011-02-16 11:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 03369922 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\icuin51.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00544817 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00989805 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libstdc++-6.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01978690 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\icuuc51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 22378434 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\icudt51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01233408 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\platforms\qwindows.dll
2015-11-17 03:23 - 2015-11-17 03:23 - 00672256 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll
2015-11-17 03:08 - 2015-11-17 03:08 - 01691136 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll
2015-11-10 04:52 - 2015-11-10 04:52 - 00192512 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll
2015-11-10 04:53 - 2015-11-10 04:53 - 00631296 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll
2015-11-17 03:13 - 2015-11-17 03:13 - 06942208 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll
2014-06-29 20:55 - 2014-06-29 20:55 - 00068608 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll
2015-11-10 05:49 - 2015-11-10 05:49 - 01165312 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\qwt.dll
2015-11-15 22:34 - 2015-11-15 22:34 - 02979854 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_MyMedia.dll
2012-10-15 15:27 - 2012-10-15 15:27 - 00111616 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libvlc.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 02286592 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libvlccore.dll
2015-11-17 03:14 - 2015-11-17 03:14 - 01058304 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll
2014-09-11 03:39 - 2014-09-11 03:39 - 00144896 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll
2015-11-15 22:34 - 2015-11-15 22:34 - 01205248 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll
2015-11-10 02:55 - 2015-11-10 02:55 - 11147776 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll
2015-11-15 22:35 - 2015-11-15 22:35 - 02593280 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll
2015-11-17 03:15 - 2015-11-17 03:15 - 00200192 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll
2015-11-17 03:16 - 2015-11-17 03:16 - 00892928 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll
2015-11-10 05:17 - 2015-11-10 05:17 - 00438272 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00051200 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qgif.dll
2013-08-25 14:07 - 2013-08-25 14:07 - 00052224 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qico.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00261120 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qjpeg.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00381952 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qmng.dll
2013-08-25 14:09 - 2013-08-25 14:09 - 00046080 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qsvg.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00046080 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qtga.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00390144 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qtiff.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00045056 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qwbmp.dll
2015-11-10 04:52 - 2015-11-10 04:52 - 00081408 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll
2015-04-17 05:36 - 2015-04-17 05:36 - 00146944 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll
2015-08-24 03:41 - 2015-08-24 03:41 - 02360622 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\drivers\libntgr_api.dll
2015-03-28 09:50 - 2015-03-28 09:50 - 00113152 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\drivers\NETGEAR_PLC_L2_API.dll
2015-02-03 05:09 - 2015-02-03 05:09 - 00072192 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00074240 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00136704 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00219648 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\access\libdshow_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00049664 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libaout_directx_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00051200 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libwaveout_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00070144 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\video_output\libdirectx_plugin.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00040960 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\printsupport\windowsprintersupport.dll
2015-11-17 03:16 - 2015-11-17 03:16 - 00642560 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll
2015-11-10 05:18 - 2015-11-10 05:18 - 00458752 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll
2014-06-29 21:33 - 2014-06-29 21:33 - 00046080 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00066560 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll
2016-02-09 08:15 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2016-02-09 08:15 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2016-02-09 08:15 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-07-08 23:18 - 2015-07-08 23:18 - 00794920 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\kpcengine.2.3.dll
2012-05-10 20:50 - 2006-08-11 22:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll
2012-05-10 20:55 - 2011-09-08 05:40 - 01645056 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
2012-05-10 20:31 - 2012-02-07 20:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2016-02-20 20:14 - 2016-02-17 23:14 - 01630360 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libglesv2.dll
2016-02-20 20:14 - 2016-02-17 23:14 - 00085656 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMR322 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: ) (EnableLUA: 0)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk => C:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
MSCONFIG\startupreg: EPLTarget => 
MSCONFIG\startupreg: mylbx => C:\Program Files\My Lockbox\mylbx.exe /a
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{86C385A8-8760-42CA-A8DA-E553C92D43A7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{1B7B98E1-68F7-4F92-A3A1-7CB38ADC01DD}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{97EA9AF7-186D-44C7-BE8C-4C1CAAF965D5}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{25C8B60A-6C6A-4ADE-8464-08B0B33F93C7}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{61D89D74-4C54-4587-8832-0D7B3AEE8A4F}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{06BAB177-ED63-48E0-AA10-80A1123B24AD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{FE3C2576-E305-4F07-B62D-3D24DAEE833B}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BA102CC0-6A3C-4F2F-96BE-D7E14C40D09F}] => (Allow) LPort=2869
FirewallRules: [{3A56A74A-58FE-483A-BEC5-81F450180A7E}] => (Allow) LPort=1900
FirewallRules: [{BE58F9CE-4691-4D9B-A4D7-C87C85E68B5B}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{E143C391-D93A-4DF0-9F5D-E4BCE24E712D}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{3D4CE169-B4A8-4BEE-81B3-AC0549CD0169}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [TCP Query User{1BEB12EE-5C8A-4084-8D18-741FFABCFABB}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{F1616EEC-4256-4815-B7BF-FA9716B4355F}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{CEDA5835-C52B-477D-B391-E763FE0AA774}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{F6BAB604-5789-4515-8352-944ED752FAF1}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{D3B14403-62F6-4515-AA31-21A893567426}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{DD28A9CD-9491-45A5-8B96-0E38B4203DB2}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{56A785EB-4AF1-458C-BDB3-4CB95696CB3F}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{5E7739EA-71C4-4E87-9A54-5B7B0615DEEE}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [TCP Query User{A47C2BBD-1C00-4377-B45D-6DD920A26D6D}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{64B61A1D-6068-4E6B-A700-DB944086735B}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{882F2C4A-3530-4EB2-916B-24C5B8919714}] => (Allow) C:\Program Files (x86)\Samsung\Easy File Share\EasyFileShare.EXE
FirewallRules: [{952F1B33-0929-4F13-92A9-178D394BC972}] => (Allow) C:\Program Files (x86)\Samsung\Easy File Share\EasyFileShare.EXE
FirewallRules: [{79299DA1-3BC0-4671-8EB8-DA3C9EBBEED6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AAA1DE69-804D-49FC-AB90-33CF91CC27B9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E51B0592-E0C6-45AC-B645-3F42B631C226}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6F98F00B-C38E-4FEC-8E96-349C8ED5FB0B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{86FB6165-7401-4F7D-9A2A-BCD1C8DF8E81}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{137C0497-9E6B-4004-8905-9C1C01F622C7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
 
==================== Restore Points =========================
 
15-02-2016 19:04:09 Windows Update
15-02-2016 21:52:13 2 15 16
15-02-2016 21:58:56 Windows Update
15-02-2016 22:28:54 Windows Update
15-02-2016 23:11:02 Restore Operation
16-02-2016 13:08:34 Windows Update
16-02-2016 16:22:11 Windows Update
16-02-2016 18:04:56 Restore Operation
16-02-2016 18:20:57 pre win update
16-02-2016 18:37:17 Windows Update
19-02-2016 13:14:40 2 19 16
19-02-2016 17:28:44 JRT Pre-Junkware Removal
19-02-2016 21:27:40 Windows Update
20-02-2016 10:12:21 Windows Backup
20-02-2016 10:14:13 Windows Backup
20-02-2016 20:27:25 pre net
20-02-2016 20:31:05 pre up2
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/20/2016 08:58:06 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 [removed].in-addr.arpa. PTR Ferocious-PC.local.
 
Error: (02/20/2016 08:58:06 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.3:5353   22 [removed].in-addr.arpa. PTR Ferocious-PC-2.local.
 
Error: (02/20/2016 08:17:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/20/2016 07:43:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dmhkcore.exe, version: 3.2.8.38, time stamp: 0x4fa9eb8e
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00000000
Faulting process id: 0xdd4
Faulting application start time: 0xdmhkcore.exe0
Faulting application path: dmhkcore.exe1
Faulting module path: dmhkcore.exe2
Report Id: dmhkcore.exe3
 
Error: (02/20/2016 06:57:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dmhkcore.exe, version: 3.2.8.38, time stamp: 0x4fa9eb8e
Faulting module name: MMDevApi.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b892
Exception code: 0xc0000005
Fault offset: 0x00023b0f
Faulting process id: 0x4978
Faulting application start time: 0xdmhkcore.exe0
Faulting application path: dmhkcore.exe1
Faulting module path: dmhkcore.exe2
Report Id: dmhkcore.exe3
 
Error: (02/20/2016 05:56:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 [removed].in-addr.arpa. PTR Ferocious-PC.local.
 
Error: (02/20/2016 05:56:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.3:5353   22 [removed].in-addr.arpa. PTR Ferocious-PC-2.local.
 
Error: (02/20/2016 05:55:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/20/2016 05:47:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 [removed].in-addr.arpa. PTR Ferocious-PC.local.
 
Error: (02/20/2016 05:47:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.3:5353   22 [removed].in-addr.arpa. PTR Ferocious-PC-2.local.
 
 
System errors:
=============
Error: (02/20/2016 08:19:38 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 07:52:30 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 07:52:30 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 07:44:11 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 07:44:11 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 07:21:17 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 07:21:17 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 05:58:20 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 09:32:24 AM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/20/2016 09:24:36 AM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
 
CodeIntegrity:
===================================
  Date: 2015-02-12 05:42:37.576
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-02-12 05:42:37.483
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-12-12 16:45:03.853
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-12-12 16:45:03.843
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-12-12 16:37:18.434
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-12-12 16:37:18.356
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-16 13:11:25.450
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-16 13:11:25.448
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-16 13:11:25.427
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-16 13:11:25.424
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-3615QM CPU @ 2.30GHz
Percentage of memory in use: 45%
Total physical RAM: 7973.53 MB
Available physical RAM: 4323.05 MB
Total Virtual: 15945.27 MB
Available Virtual: 10772.93 MB
 
==================== Drives ================================
 
Drive b: (Backup) (Fixed) (Total:300 GB) (Free:299.9 GB) NTFS
Drive c: () (Fixed) (Total:609.52 GB) (Free:329.99 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 816B67ED)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=609.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=300 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=21.9 GB) - (Type=27)
 
========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: 74F02DEA)
Partition 1: (Not Active) - (Size=7.5 GB) - (Type=73)
 
==================== End of Addition.txt ============================

 




 

:welcome:

 

Lets run this fix , it should fix some of your problems, then we are going to run some other tools, lets see what they find and remove 

 

 

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
CMD: ipconfig /flushdns
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
 
 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
[external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
 
 
 
[external image: MBAM220_zpsox89gdej.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 
 
 

Hi,

 

We dont help with malware removal through PMs, just post in the in this thread so other people that maybe reading it are aware of whats going on. 

 

There are a lot of Anti Virus programs that flag some of our tools and scanners as bad, but there not. This happens now and then, nothing to be alarmed about 

 

So go ahead and post the FIXLOG from the FRST Fix, then run those other programs . If your antivirus blocks them from downloading or from running that disable you anti virus 

Fix result of Farbar Recovery Scan Tool (x64) Version:20-02-2016
Ran by [removed] (2016-02-22 18:20:19) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
HKLM\…\Policies\Explorer: [NoViewOnDrive] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\…\Policies\Explorer: [NoViewContextMenu] 0
HKLM\…\Policies\Explorer: [NoShellSearchButton] 0
HKLM\…\Policies\Explorer: [NoFind] 0
HKLM\…\Policies\Explorer: [NoFile] 0
HKLM\…\Policies\Explorer: [HideClock] 0
HKLM\…\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\…\Policies\Explorer: [NoSetFolders] 0
HKLM\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\…\Policies\Explorer: [NoSetTaskbar] 0
HKLM\…\Policies\Explorer: [NoDeletePrinter] 0
HKLM\…\Policies\Explorer: [NoDFSTab] 0
HKLM\…\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\…\Policies\Explorer: [NoLogoff] 0
HKLM\…\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\…\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\…\Policies\Explorer: [NoResolveSearch] 0
HKLM\…\Policies\Explorer: [NoSaveSettings] 0
HKLM\…\Policies\Explorer: [NoHardwareTab] 0
HKLM\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\…\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDesktop => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
EmptyTemp: => 291.1 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 18:20:45 ====

I used Virus Total ( https://www.virustotal.com/) on the AdwCleaner and JRT files that you linked to and it came up with: 

for:JRT.EXE:  Antivirus Result Update Rising PE:Malware.Generic(Thunder)!1.A1C4 [F] 20160222

And
for AdwCleaner.exe:  Antivirus Result Update AegisLab Troj.W32.Agent 20160222 Bkav W32.HfsAtITA.66B4 20122
602

I don't know if these are false positives or if you were somehow unaware (or perhaps the owners of "Bleeping Computer" were somehow unaware of this - OR if it is my computer that is causing this!  I just thought that you should know about it.  I ran the Fixlist.txt  notepad script through FRST/FRST64 according to your instructions, but have not yet run JRT or AdwCleaner until I hear back from you.

Thank You "ken 545" for your time and Expertise!  It is very much appreciated  :)

  •  
 
 
Waiting for Malwarebytes to finish - Here are the 2 other logs you requested:
 
 
# AdwCleaner v5.036 - Logfile created 22/02/2016 at 21:13:05
# Updated 22/02/2016 by Xplode
# Database : 2016-02-22.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Ferocious - FEROCIOUS-PC
# Running from : C:\Users\Ferocious\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\ProgramData\SecTaskMan
[-] Folder Deleted : C:\ProgramData\simplitec
[-] Folder Deleted : C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp
[-] Folder Deleted : C:\Users\Ferocious\AppData\Roaming\simplitec
 
***** [ Files ] *****
 
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : lfmhcpmkbdkbgbmkjoiopeeegenkdikp
 
*************************
 
:: "Tracing" keys removed
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [1390 bytes] - [22/02/2016 21:13:05]
C:\AdwCleaner\AdwCleaner[S1].txt - [1408 bytes] - [22/02/2016 21:07:54]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1536 bytes] ##########







~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.3 (02.09.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on Mon 02/22/2016 at 21:16:20.92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 8 
 
Successfully deleted: C:\Users\Ferocious\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H1NT64OW (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Ferocious\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UEUQJUK5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Ferocious\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YSACULWS (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Ferocious\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z7728UMY (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H1NT64OW (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UEUQJUK5 (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YSACULWS (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z7728UMY (Temporary Internet Files Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 02/22/2016 at 21:19:56.13
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
 
Thank You Again for Your Time and Expertise! :)
 

and Finally !  The Malwarebytes log:
 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 2/22/2016
Scan Time: 9:26 PM
Logfile: MBAM.txt
Administrator: Yes
 
Version: 2.2.0.1024
Malware Database: v2016.02.22.06
Rootkit Database: v2016.02.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Ferocious
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 466465
Time Elapsed: 41 min, 34 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

 

Good Morning,

 

Good job running the scans. Lets do this

 

The first time FRST is run it creates an Additions log the second time it does not so we will have to make  it create one by doing this

 

Open up FRST64 by right clicking on it and select RUN AS ADMINISTRATOR, then put a checkmark in Additions, leave everything else as is. Then click SCAN, when its done the two logs will be created, post them please

Thank You Again ken545!  Here are the logs you requested:
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-02-2016
Ran by [removed] (administrator) on FEROCIOUS-PC (23-02-2016 15:58:00)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\Nexus.exe
(NETGEAR Inc.) C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
() C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\avpui.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [BLEServicesCtrl] => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184632 2013-11-13] (Motorola Solutions, Inc.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12460136 2012-03-29] (Realtek Semiconductor)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2622432 2016-01-29] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [Nexus] => C:\Program Files (x86)\Winstep\Nexus.exe [18378880 2015-10-01] (Winstep Software Technologies)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [NETGEARGenie] => C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [603392 2015-08-26] (NETGEAR Inc.)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8619224 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Run: [appnhost] => C:\Users\Ferocious\AppData\Local\Mixesoft\AppNHost\appnhost.exe
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\MountPoints2: {ec4c6226-6cc6-11e3-a708-c4850861d43c} - E:\Autorun.exe /s
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Mystify.scr [242688 2010-11-20] (Microsoft Corporation)
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Startup: C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2016-01-23]
ShortcutTarget: ERUNT AutoBackup.lnk -> C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Uninstall Webroot RunOnce.lnk [2014-10-24]
ShortcutTarget: Uninstall Webroot RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: [S-1-5-21-3575110223-3707097088-2884409191-1001] => localhost:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{FC0B0A7D-A856-4618-8A69-4E3A4879FCBF}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung.msn.com
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.google.com/
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\x64\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
BHO: No Name -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> No File
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll [2013-09-02] ()
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Kaspersky Protection plugin -> {C66D064F-82FE-4E1A-B06A-B2490BA48B18} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
BHO-x32: No Name -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> No File
BHO-x32: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files (x86)\WOT\WOT.dll [2013-09-02] ()
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2013-09-02] ()
Toolbar: HKLM - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} -  No File
Toolbar: HKLM - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\x64\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll [2013-09-02] ()
Toolbar: HKLM-x32 - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} -  No File
Toolbar: HKLM-x32 - Kaspersky Protection toolbar - {3507FA00-ADA2-4A02-99B9-51AD26CA9120} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\IEExt\ie_plugin.dll [2015-12-05] (AO Kaspersky Lab)
Toolbar: HKU\S-1-5-21-3575110223-3707097088-2884409191-1001 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2013-09-02] ()
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll [2013-09-02] ()
Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll [2013-09-02] ()
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-13] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\FFExt\light_plugin_firefox
FF Extension: Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\FFExt\light_plugin_firefox [2016-01-22]
 
Chrome: 
=======
CHR StartupUrls: Profile 1 -> "chrome://apps/","chrome://extensions/"
CHR DefaultSearchURL: Profile 1 -> hxxps://www.google.com/search?q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> s
CHR Profile: C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Translate) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-17]
CHR Extension: (Angry Birds) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2015-04-18]
CHR Extension: (Google Docs) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-18]
CHR Extension: (Google Drive) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (Brushed) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2015-04-18]
CHR Extension: (Adguard AdBlocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-02-19]
CHR Extension: (Pop Block Pro - The Ultimate Popup Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib [2015-04-18]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2016-02-19]
CHR Extension: (Poper Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-04-18]
CHR Extension: (YouTube) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Adblock Plus) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-19]
CHR Extension: (Google Search) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
CHR Extension: (Kaspersky Protection) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-09-21]
CHR Extension: (Kaspersky Protection) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\eahebamiopdhefndnmappcihfajigkka [2016-01-26]
CHR Extension: (hxxp://speedtest.nyroc.rr.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\edionanpdofenhkbdncggelplnokpjid [2015-09-21]
CHR Extension: (hxxps://mail.google.com/mail/u/0/?shva=1#inbo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\efkhoejpmofcicglnpndodnojkmngomb [2015-04-18]
CHR Extension: (My IP Address) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\eppbaaljfkdamofakdneaogfphnhbjlj [2015-04-18]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2016-02-19]
CHR Extension: (Full Screen Weather) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2015-05-12]
CHR Extension: (Google Docs Offline) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Dictionary by Dictionary.com) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2015-04-18]
CHR Extension: (Voice Actions for Chrome (beta)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhpjefokaphndbbidpehikcjhldaklje [2015-10-10]
CHR Extension: (JavaScript Popup Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiajdlfgbgnnjakkbnpdhmhfhklkbiol [2016-01-15]
CHR Extension: (hxxp://www.thedarewall.com/tv/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljcbepjcbcoodflobneinbmpcgpfhmal [2015-04-18]
CHR Extension: (Flashcontrol) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfidmkgnfgnkihnjeklbekckimkipmoe [2016-02-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-18]
CHR Profile: C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Translate) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-18]
CHR Extension: (Google Slides) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-18]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2016-02-19]
CHR Extension: (News Paywall Access) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\adpfpconnigelofkfenblmdhbnlaafkg [2016-01-30]
CHR Extension: (Radio) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agljkoinmcdnopnlbhhjibjiablccgoh [2015-11-18]
CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2015-11-18]
CHR Extension: (Flash Video Downloader) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc [2016-02-19]
CHR Extension: (hxxp://www.walmart.com/sign_out.jsp) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akfaildcjioacioeepojahbjlakpagad [2015-11-18]
CHR Extension: (Theme Creator) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\akpelnjfckgfiplcikojhomllgombffc [2015-11-18]
CHR Extension: (Google Docs) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-18]
CHR Extension: (hxxp://www.speedtest.net/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aoimpfmicnklenmbocdgffdhgekaoohj [2015-11-18]
CHR Extension: (Google Drive) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-18]
CHR Extension: (TV) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\beobeededemalmllhkmnkinmfembdimh [2015-11-18]
CHR Extension: (Brushed) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2015-11-18]
CHR Extension: (Adguard AdBlocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-02-13]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-11-18]
CHR Extension: (Free Proxy to Unblock any sites 
 Touch VPN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bihmplhobchoageeokmgbdihknkjbknd [2016-02-19]
CHR Extension: (YOUZEEK Free Music) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bjcgpdkighmjfjlplcighhgamlhkimce [2015-11-18]
CHR Extension: (Web2PDFConverter) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkanhckocooacphbnclgcndnpfpoppdk [2016-01-28]
CHR Extension: (Audiotool) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2015-11-18]
CHR Extension: (Poper Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-11-18]
CHR Extension: (YouTube) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-18]
CHR Extension: (Adblock Plus) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-09]
CHR Extension: (TrafficLight) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfnpidifppmenkapgihekkeednfoenal [2016-02-16]
CHR Extension: (Plugins) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chemohaemmfhjpmlgkmkanfpfbkaihop [2015-11-18]
CHR Extension: (Pixsta) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cijncchffkmlnfdbnkkfclcbnjcoegjc [2015-12-02]
CHR Extension: (Image Downloader) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2015-11-18]
CHR Extension: (Google Search) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-18]
CHR Extension: (hxxps://accounts.google.com/ServiceLogin?serv) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\copebngjgfepookfihcgelompaefmkfn [2015-11-18]
CHR Extension: (Search by Image (by Google)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dajedkncpodkggklbegccjpmnglmnflm [2015-11-18]
CHR Extension: (Kaspersky Protection) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-11-18]
CHR Extension: (Dragon Web Extension) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ddaloccgjfibfpkalenodgehlhkgoahe [2015-11-18]
CHR Extension: (hxxp://www.worldometers.info/world-population) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dedfgchgilmmgcopcefilgingbcmbpne [2015-11-18]
CHR Extension: (UberConference Bookmark) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dlhdbjgofnajhpiakdjklonjlpbbonnc [2015-11-18]
CHR Extension: (IPvFoo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ecanpcehffngcegjmadlcijfolapggal [2016-01-28]
CHR Extension: (Pixlr-o-matic) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2015-11-18]
CHR Extension: (hxxp://www.amazon.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eicbgcfajfmpllmbdfmnnpomnnedfbop [2015-11-18]
CHR Extension: (Google Calendar) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-11-18]
CHR Extension: (Minus) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emgdobmndjcmnciellikkhigcbpgpklk [2015-11-18]
CHR Extension: (Blur) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2016-01-30]
CHR Extension: (Morphyre Designer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ephpkjhaakjclleokielmaehpknellcl [2015-11-18]
CHR Extension: (Pandora) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fbangkleohkafngihneedemihgfeikcl [2015-11-18]
CHR Extension: (Flix Plus by Lifehacker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fcjjgdnadfneaamhipplgpfkdnbfagla [2016-01-26]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2016-02-19]
CHR Extension: (Google Sheets) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-18]
CHR Extension: (Full Screen Weather) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fkkaebihfmbofclegkcfkkemepfehibg [2015-11-18]
CHR Extension: (ColorHexa Search Tool) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flnkogfheemakepeokbheholhfhgcbae [2015-11-18]
CHR Extension: (HTTPS Everywhere) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2016-02-21]
CHR Extension: (Google Docs Offline) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Planetarium) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2015-11-18]
CHR Extension: (Click&Clean;) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghgabhipcejejjmhhchfonmamedcbeod [2016-01-27]
CHR Extension: (AdBlock) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-19]
CHR Extension: (Cryptocat) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gonbigodpnfghidmnphnadhepmbabhij [2015-11-18]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2015-11-18]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2016-02-19]
CHR Extension: (Website Destroyer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hfdklionolegofhffnhoagpmlailnnni [2015-11-18]
CHR Extension: (JavaScript Popup Blocker) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hiajdlfgbgnnjakkbnpdhmhfhklkbiol [2015-11-20]
CHR Extension: (Marvel Comics) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hjhfaknohpjconjoefidanhihokmkice [2015-11-18]
CHR Extension: (Pixlr Express) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hojmjpdlmjopaeginhldhiokeidchjid [2015-11-18]
CHR Extension: (Crackle) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ibfamoapbmmmlknoopmmfofgladlinic [2015-11-18]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-11-18]
CHR Extension: (Stealthy) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ieaebnkibonmpbhdaanjkmedikadnoje [2015-11-18]
CHR Extension: (hxxp://movies.netflix.com/WiHome) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ifapaoknlkpflhgnolmimcokakmdikho [2015-11-18]
CHR Extension: (Greenhouse) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ifomhmgandipmpnelclcmbefppopfklc [2016-01-30]
CHR Extension: (Color Piano!) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ihmigmmflfcbhdpdgbkkeojchjhhphnh [2015-11-18]
CHR Extension: (Glitterboo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ikkpgihagilojnkmkkfcbhlainmnkicp [2015-11-18]
CHR Extension: (hxxp://registration.myway.com/primary_login.j) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ilkckebnfpkhkfhjdjjkhcgpiofphlkf [2015-11-18]
CHR Extension: (Cookies) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iphcomljdfghbkdcfndaijbokpgddeno [2016-01-28]
CHR Extension: (Disconnect) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2016-01-28]
CHR Extension: (Roomstyler 3D planner) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jfnniehafojoidolddmhfnpnbiolbppi [2016-01-27]
CHR Extension: (Psykogif) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jkjoklgdmjnffhmmllncmleongbhpdok [2015-11-18]
CHR Extension: (Pic3D 
 3D Converter) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jpcenahnngjklfilghhiochkndllljbj [2015-11-18]
CHR Extension: (StumbleUpon) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg [2015-11-18]
CHR Extension: (zoomWheel) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kdfgigbjonaniokmpfflpflkhahhbaej [2015-11-18]
CHR Extension: (Autodesk Homestyler) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2015-11-18]
CHR Extension: (Color Sphere!) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\knomilfbnhpkmibhmleppnkmcempglag [2015-11-18]
CHR Extension: (Until AM Web App) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kodigjkcpaoeodlnmcnekemakpnmegnk [2015-11-18]
CHR Extension: (Google Play) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2015-11-18]
CHR Extension: (hxxp://www.thedarewall.com/tv/movie-tags/boxo) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\leadgdgcmfaakbmihgnippgiofmhfnbg [2015-11-18]
CHR Extension: (Video Downloader [FVD]) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2016-01-29]
CHR Extension: (ZenMate Secure Email (Beta)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lgnhdjncgaebccjldgeianajcndhingd [2016-01-30]
CHR Extension: (Minimalistic Memo Calendar) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lhammhngpacbengeachfclhcjbjfkfmf [2015-11-18]
CHR Extension: (Skype) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-02-02]
CHR Extension: (McAfee SECURE Safe Browsing) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lkdiimaiohgpacfbgedcipmgigppaofn [2016-01-28]
CHR Extension: (AudioSauna) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2015-11-18]
CHR Extension: (Video DownloadHelper) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2015-12-16]
CHR Extension: (Google Maps) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-11-18]
CHR Extension: (doubled) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lockfmhdbkjgoehpbpgbajdjphnlppco [2015-11-18]
CHR Extension: (Lazarus: Form Recovery) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\loljledaigphbcpfhfmgopdkppkifgno [2015-11-18]
CHR Extension: (Extensions Manager (aka Switcher)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lpleipinonnoibneeejgjnoeekmbopbc [2016-01-28]
CHR Extension: (3D Solar System Web) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mdaaepplopehigjgkolniddiadbbkphd [2015-11-18]
CHR Extension: (Flashcontrol) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfidmkgnfgnkihnjeklbekckimkipmoe [2016-02-19]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-11-18]
CHR Extension: (hxxps://login.live.com/login.srf?wa=wsignin1.) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\miikjlbahjadjfkgcekefnkcngidmncl [2015-11-18]
CHR Extension: (Buffer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjojodpkaeeclkgaidibcbknlhjflhle [2016-01-30]
CHR Extension: (Ghostery) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2016-02-21]
CHR Extension: (EXIF Viewer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmbhfeiddhndihdjeganjggkmjapkffm [2016-01-28]
CHR Extension: (Google Play Books) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2015-11-18]
CHR Extension: (drumbit) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mplpmdejoamenolpcojgegminhcnmibo [2016-01-21]
CHR Extension: (deviantART muro) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\namljbfbglehfnlonjmebceimaalofei [2015-11-18]
CHR Extension: (OneDrive) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2015-11-18]
CHR Extension: (TunnelSwitch) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nfpphleklkamlblagdkbkomjmaedanoh [2016-01-30]
CHR Extension: (hxxps://accounts.google.com/ServiceLogin?pass) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nhbgdbfmjcmhpoeicmhhicakddieejca [2015-11-18]
CHR Extension: (Hotspot Shield Free VPN Proxy – Unblock Sites) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nlbejmccbhkncgokjcmghpfloaajcffj [2016-02-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-18]
CHR Extension: (Buffer) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2016-02-19]
CHR Extension: (My Chrome Theme) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2015-11-18]
CHR Extension: (hxxps://www.google.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\okkolgldfknecfjnhhglfopimelbaceh [2015-11-18]
CHR Extension: (Font Size Increase) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ombpcpigmndepfckcifdblemkabaoihk [2016-02-19]
CHR Extension: (hxxp://speedtest.ohiordc.rr.com/) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pdilcdkapdfafbofkhhjippielmcooid [2015-11-18]
CHR Extension: (Outlook.com) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2015-11-18]
CHR Extension: (Psykopaint) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2015-11-18]
CHR Extension: (Gmail) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-18]
CHR Extension: (Ambient Aurea) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkaglmndhfgdaiaccjglghcbnfinfffa [2015-11-18]
CHR Extension: (Phone Checkr - Phone Number Lookup Service) - C:\Users\Ferocious\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pmdbghodmpmnoogajoijjlbnlondnnac [2016-01-29]
CHR HKLM\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\…\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\…\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\…\Chrome\Extension: [eahebamiopdhefndnmappcihfajigkka] - hxxps://chrome.google.com/webstore/detail/eahebamiopdhefndnmappcihfajigkka
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 AVP16.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\avp.exe [194000 2015-12-05] (Kaspersky Lab ZAO)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2011-09-23] (Diskeeper Corporation)
S2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [127216 2015-01-21] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [740832 2016-01-29] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-07] ()
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-08-26] (NETGEAR)
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed]
S3 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 vssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\x64\vssbridge64.exe [144640 2015-07-09] (AO Kaspersky Lab)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-07] (Intel® Corporation)
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [141624 2014-10-28] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [1448248 2014-11-26] (Motorola Solutions, Inc.)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1x64.sys [28008 2015-08-31] (Windows (R) Win 7 DDK provider)
R3 DFX12; C:\Windows\System32\drivers\dfx12x64.sys [29688 2015-11-12] (Windows (R) Win 7 DDK provider)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [66080 2016-01-29] ()
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2011-09-23] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [80688 2011-09-23] (Diskeeper Corporation)
R0 FSProFilter2; C:\Windows\System32\Drivers\FSPFltd2.sys [57648 2011-06-03] (FSPro Labs)
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
S3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [143904 2015-11-05] (Zemana Ltd.)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-06-22] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [70000 2015-06-27] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [68280 2015-06-06] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [181640 2015-12-05] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [227000 2015-12-05] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [940928 2015-12-05] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [39096 2015-06-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [41144 2015-06-06] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [41352 2015-12-05] (AO Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-06-11] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [103096 2015-06-16] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [187056 2015-06-23] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R2 NPF; C:\windows\system32\drivers\npf.sys [35344 2016-01-29] (CACE Technologies, Inc.)
S3 massfilter_hs; \??\C:\windows\system32\drivers\massfilter_hs.sys [X]
U0 SR; no ImagePath
U2 srservice; no ImagePath
S3 zghsdiag; system32\DRIVERS\zghsdiag.sys [X]
S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X]
S3 zghsnmea; system32\DRIVERS\zghsnmea.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-23 15:58 - 2016-02-23 15:58 - 00047623 _____ C:\Users\Ferocious\Desktop\FRST.txt
2016-02-23 15:56 - 2016-02-23 15:57 - 00000000 ____D C:\Users\Ferocious\Desktop\SL 2 2016
2016-02-23 01:23 - 2016-02-23 01:23 - 00001674 _____ C:\Users\Public\Desktop\DFX.lnk
2016-02-23 01:23 - 2016-02-23 01:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DFX Audio Enhancer
2016-02-23 01:23 - 2016-02-23 01:23 - 00000000 ____D C:\Program Files (x86)\DFX
2016-02-22 23:13 - 2016-02-22 23:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jetAudio
2016-02-22 21:32 - 2016-02-22 21:32 - 08524424 _____ (Sandboxie Holdings, LLC) C:\Users\Ferocious\Downloads\SandboxieInstall.exe
2016-02-22 21:07 - 2016-02-22 21:13 - 00000000 ____D C:\AdwCleaner
2016-02-22 21:05 - 2016-02-22 21:05 - 01511936 _____ C:\Users\Ferocious\Desktop\AdwCleaner.exe
2016-02-22 18:31 - 2016-02-22 18:31 - 01609216 _____ (Malwarebytes) C:\Users\Ferocious\Desktop\JRT.exe
2016-02-21 17:35 - 2016-02-21 17:35 - 00002052 _____ C:\windows\epplauncher.mif
2016-02-21 17:22 - 2016-02-06 05:48 - 25839104 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-02-21 17:22 - 2016-02-06 05:32 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-02-21 17:22 - 2016-02-06 05:24 - 02887680 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-02-21 17:22 - 2016-02-06 05:11 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-02-21 17:22 - 2016-02-06 05:10 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-02-21 17:22 - 2016-02-06 05:01 - 20366848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-02-21 17:22 - 2016-02-06 04:54 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-02-21 17:22 - 2016-02-06 04:43 - 02280448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-02-21 17:22 - 2016-02-06 04:38 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-02-21 17:22 - 2016-02-06 04:37 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-02-21 17:22 - 2016-02-06 04:32 - 14458368 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-02-21 17:22 - 2016-02-06 04:16 - 12857856 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-02-21 17:22 - 2016-02-06 04:09 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-02-21 17:22 - 2016-02-06 03:54 - 01312256 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-02-21 17:22 - 2016-01-22 15:31 - 00387784 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-02-21 17:22 - 2016-01-22 15:10 - 00341200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-02-21 17:22 - 2016-01-22 01:56 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-02-21 17:22 - 2016-01-22 01:41 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-02-21 17:22 - 2016-01-22 01:40 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-02-21 17:22 - 2016-01-22 01:40 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-02-21 17:22 - 2016-01-22 01:40 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-02-21 17:22 - 2016-01-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-02-21 17:22 - 2016-01-22 01:33 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-02-21 17:22 - 2016-01-22 01:32 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-02-21 17:22 - 2016-01-22 01:29 - 06052352 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-02-21 17:22 - 2016-01-22 01:27 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-02-21 17:22 - 2016-01-22 01:27 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-02-21 17:22 - 2016-01-22 01:27 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-02-21 17:22 - 2016-01-22 01:20 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-02-21 17:22 - 2016-01-22 01:17 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-02-21 17:22 - 2016-01-22 01:09 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-02-21 17:22 - 2016-01-22 01:08 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2016-02-21 17:22 - 2016-01-22 01:05 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-02-21 17:22 - 2016-01-22 01:04 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-02-21 17:22 - 2016-01-22 01:02 - 00496640 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-02-21 17:22 - 2016-01-22 01:02 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-02-21 17:22 - 2016-01-22 01:02 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-02-21 17:22 - 2016-01-22 01:01 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-02-21 17:22 - 2016-01-22 01:01 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-02-21 17:22 - 2016-01-22 01:00 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-02-21 17:22 - 2016-01-22 01:00 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-02-21 17:22 - 2016-01-22 00:55 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-02-21 17:22 - 2016-01-22 00:55 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-02-21 17:22 - 2016-01-22 00:51 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-02-21 17:22 - 2016-01-22 00:51 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-02-21 17:22 - 2016-01-22 00:50 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-02-21 17:22 - 2016-01-22 00:48 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-02-21 17:22 - 2016-01-22 00:47 - 00798208 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-02-21 17:22 - 2016-01-22 00:46 - 02123264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-02-21 17:22 - 2016-01-22 00:46 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-02-21 17:22 - 2016-01-22 00:43 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-02-21 17:22 - 2016-01-22 00:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-02-21 17:22 - 2016-01-22 00:38 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2016-02-21 17:22 - 2016-01-22 00:37 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-02-21 17:22 - 2016-01-22 00:35 - 04611072 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-02-21 17:22 - 2016-01-22 00:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-02-21 17:22 - 2016-01-22 00:34 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-02-21 17:22 - 2016-01-22 00:33 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-02-21 17:22 - 2016-01-22 00:31 - 02597376 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-02-21 17:22 - 2016-01-22 00:27 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-02-21 17:22 - 2016-01-22 00:25 - 00687104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-02-21 17:22 - 2016-01-22 00:24 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-02-21 17:22 - 2016-01-22 00:24 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-02-21 17:22 - 2016-01-22 00:08 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-02-21 17:22 - 2016-01-22 00:07 - 02120704 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-02-21 17:22 - 2016-01-22 00:02 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-02-21 17:21 - 2016-01-16 14:06 - 00025024 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-02-21 17:21 - 2016-01-16 13:54 - 01162240 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-02-21 17:21 - 2016-01-11 14:11 - 01684416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2016-02-21 17:21 - 2016-01-11 09:08 - 01362944 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-02-21 17:21 - 2016-01-11 09:08 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-02-21 17:21 - 2016-01-11 09:08 - 00677376 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-02-21 17:21 - 2016-01-11 09:08 - 00499200 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-02-21 17:21 - 2016-01-11 09:08 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00994760 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2016-02-21 17:21 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2016-02-21 17:20 - 2016-01-11 14:05 - 03169792 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2016-02-21 17:20 - 2016-01-11 14:05 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2016-02-21 17:20 - 2016-01-11 14:05 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2016-02-21 17:20 - 2016-01-11 13:52 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2016-02-21 17:20 - 2016-01-11 13:47 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2016-02-21 17:20 - 2016-01-11 13:26 - 02610176 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2016-02-21 17:20 - 2016-01-11 13:24 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2016-02-21 17:20 - 2016-01-11 13:23 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2016-02-21 17:20 - 2016-01-11 13:23 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2016-02-21 17:20 - 2016-01-11 13:23 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2016-02-21 17:20 - 2016-01-11 13:23 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2016-02-21 17:20 - 2016-01-11 13:23 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2016-02-21 17:20 - 2016-01-11 13:14 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2016-02-21 17:20 - 2016-01-11 13:14 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2016-02-21 17:20 - 2016-01-11 13:14 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2016-02-21 17:20 - 2016-01-11 13:14 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2016-02-21 17:20 - 2016-01-06 14:02 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2016-02-21 17:20 - 2016-01-06 14:02 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\jnwmon.dll
2016-02-21 17:20 - 2016-01-06 13:41 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2016-02-21 17:20 - 2015-12-16 13:55 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\nlsbres.dll
2016-02-21 17:20 - 2015-12-16 13:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\kbdgeoqw.dll
2016-02-21 17:20 - 2015-12-16 13:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZEL.DLL
2016-02-21 17:20 - 2015-12-16 13:53 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDAZE.DLL
2016-02-21 17:20 - 2015-12-16 13:48 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZE.DLL
2016-02-21 17:20 - 2015-12-16 13:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\kbdgeoqw.dll
2016-02-21 17:20 - 2015-12-16 13:48 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDAZEL.DLL
2016-02-21 17:20 - 2015-12-16 13:47 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlsbres.dll
2016-02-21 17:20 - 2015-12-16 09:38 - 00419928 _____ C:\windows\SysWOW64\locale.nls
2016-02-21 17:20 - 2015-12-16 09:37 - 00419928 _____ C:\windows\system32\locale.nls
2016-02-21 17:20 - 2015-08-05 12:56 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\icaapi.dll
2016-02-21 17:20 - 2015-08-05 12:06 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2016-02-21 17:19 - 2016-01-07 12:42 - 00141312 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2016-02-21 17:18 - 2016-01-22 01:27 - 05573056 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-02-21 17:18 - 2016-01-22 01:24 - 01733592 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-02-21 17:18 - 2016-01-22 01:18 - 00961024 _____ (Microsoft Corporation) C:\windows\system32\CPFilters.dll
2016-02-21 17:18 - 2016-01-22 01:18 - 00723968 _____ (Microsoft Corporation) C:\windows\system32\EncDec.dll
2016-02-21 17:18 - 2016-01-22 01:17 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\mtxoci.dll
2016-02-21 17:18 - 2016-01-22 01:15 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2016-02-21 17:18 - 2016-01-22 01:15 - 00730112 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2016-02-21 17:18 - 2016-01-22 01:15 - 00422400 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-02-21 17:18 - 2016-01-22 01:13 - 03993536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2016-02-21 17:18 - 2016-01-22 01:13 - 03938752 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2016-02-21 17:18 - 2016-01-22 01:12 - 00880128 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2016-02-21 17:18 - 2016-01-22 01:09 - 01314328 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-02-21 17:18 - 2016-01-22 01:04 - 00642048 _____ (Microsoft Corporation) C:\windows\SysWOW64\CPFilters.dll
2016-02-21 17:18 - 2016-01-22 01:04 - 00535040 _____ (Microsoft Corporation) C:\windows\SysWOW64\EncDec.dll
2016-02-21 17:18 - 2016-01-07 12:53 - 03211776 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-02-21 17:18 - 2015-12-20 13:50 - 03180544 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2016-02-21 17:18 - 2015-12-20 13:50 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2016-02-21 17:18 - 2015-12-20 09:08 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2016-02-21 17:17 - 2016-01-22 01:27 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-02-21 17:17 - 2016-01-22 01:27 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2016-02-21 17:17 - 2016-01-22 01:20 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2016-02-21 17:17 - 2016-01-22 01:20 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2016-02-21 17:17 - 2016-01-22 01:19 - 01214464 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2016-02-21 17:17 - 2016-01-22 01:19 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2016-02-21 17:17 - 2016-01-22 01:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2016-02-21 17:17 - 2016-01-22 01:18 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2016-02-21 17:17 - 2016-01-22 01:17 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-02-21 17:17 - 2016-01-22 01:17 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2016-02-21 17:17 - 2016-01-22 01:16 - 01461248 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2016-02-21 17:17 - 2016-01-22 01:16 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2016-02-21 17:17 - 2016-01-22 01:16 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2016-02-21 17:17 - 2016-01-22 01:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2016-02-21 17:17 - 2016-01-22 01:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2016-02-21 17:17 - 2016-01-22 01:13 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2016-02-21 17:17 - 2016-01-22 01:06 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2016-02-21 17:17 - 2016-01-22 01:05 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2016-02-21 17:17 - 2016-01-22 01:05 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2016-02-21 17:17 - 2016-01-22 01:02 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2016-02-21 17:17 - 2016-01-22 01:02 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-02-21 17:17 - 2016-01-22 01:02 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2016-02-21 17:17 - 2016-01-22 01:02 - 00176128 _____ (Microsoft Corporation) C:\windows\SysWOW64\msorcl32.dll
2016-02-21 17:17 - 2016-01-22 01:02 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2016-02-21 17:17 - 2016-01-22 01:02 - 00114176 _____ (Microsoft Corporation) C:\windows\SysWOW64\mtxoci.dll
2016-02-21 17:17 - 2016-01-22 01:02 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00642560 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-02-21 17:17 - 2016-01-22 00:13 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2016-02-21 17:17 - 2016-01-22 00:07 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2016-02-21 17:17 - 2016-01-22 00:07 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2016-02-21 17:17 - 2016-01-22 00:05 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2016-02-21 17:17 - 2016-01-21 23:59 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-02-21 17:17 - 2016-01-21 23:58 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-02-21 17:17 - 2016-01-21 23:58 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2016-02-21 17:17 - 2016-01-21 23:57 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2016-02-21 17:17 - 2016-01-21 23:57 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2016-02-21 17:17 - 2016-01-21 23:53 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2016-02-21 17:17 - 2016-01-21 23:53 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2016-02-21 17:17 - 2016-01-21 23:53 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2016-02-21 17:17 - 2016-01-21 23:53 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2016-02-21 17:17 - 2016-01-21 23:51 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2016-02-21 17:17 - 2016-01-21 23:51 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-02-21 17:17 - 2016-01-21 23:51 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-21 17:17 - 2016-01-21 23:51 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-02-21 17:17 - 2016-01-21 23:51 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-02-20 21:52 - 2016-02-23 15:58 - 00000000 ____D C:\FRST
2016-02-20 21:32 - 2016-02-20 21:32 - 02371072 _____ (Farbar) C:\Users\Ferocious\Desktop\FRST64.exe
2016-02-20 21:31 - 2016-02-20 21:31 - 05198336 _____ (AVAST Software) C:\Users\Ferocious\Desktop\aswMBR.exe
2016-02-20 21:25 - 2016-02-20 21:25 - 00000042 _____ C:\windows\JFEXRMC.INI
2016-02-20 19:49 - 2016-02-20 19:49 - 00000000 ____D C:\ProgramData\DFX
2016-02-20 17:49 - 2016-02-20 17:49 - 00003258 _____ C:\windows\System32\Tasks\{F740D370-5C8D-4AF0-ADA2-535BF04547E4}
2016-02-20 17:04 - 2016-02-20 17:29 - 00150722 _____ C:\TDSSKiller.2.8.16.0_20.02.2016_17.04.03_log.txt
2016-02-19 23:10 - 2012-05-11 12:23 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\ieaksie.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00227840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieaksie.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakui.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\ieakui.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00160256 _____ (Microsoft Corporation) C:\windows\system32\ieakeng.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00130560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakeng.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00101888 _____ (Microsoft Corporation) C:\windows\SysWOW64\admparse.dll
2016-02-19 23:10 - 2012-05-11 12:23 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ie4uinit.exe
2016-02-19 23:10 - 2012-02-16 08:08 - 00031216 _____ (CyberLink Corporation) C:\windows\system32\Drivers\clwvd.sys
2016-02-19 23:10 - 2011-12-08 00:43 - 00047616 _____ (Intel Corporation) C:\windows\system32\opphelper.dll
2016-02-19 23:10 - 2010-11-20 22:23 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2016-02-19 23:10 - 2009-06-10 15:45 - 00000003 _____ C:\windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
2016-02-19 23:09 - 2012-05-11 12:23 - 00114176 _____ (Microsoft Corporation) C:\windows\system32\admparse.dll
2016-02-19 23:09 - 2010-11-20 22:24 - 00412160 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2016-02-19 23:09 - 2010-11-20 22:24 - 00158720 _____ (Microsoft Corporation) C:\windows\system32\aaclient.dll
2016-02-19 22:32 - 2016-02-22 22:26 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-19 22:32 - 2016-02-20 22:42 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2016-02-19 22:32 - 2016-02-19 22:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-19 22:32 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-02-19 22:32 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-02-19 22:27 - 2016-01-22 01:19 - 14179840 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2016-02-19 22:27 - 2016-01-22 01:15 - 01866752 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2016-02-19 22:27 - 2016-01-22 01:12 - 01940992 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2016-02-19 22:27 - 2016-01-22 01:05 - 12877824 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2016-02-19 22:27 - 2016-01-22 01:00 - 01498624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2016-02-19 22:27 - 2016-01-22 00:59 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2016-02-19 22:27 - 2016-01-22 00:19 - 03231232 _____ (Microsoft Corporation) C:\windows\explorer.exe
2016-02-19 22:27 - 2016-01-22 00:12 - 02973184 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
2016-02-19 22:26 - 2016-01-16 14:01 - 02085888 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2016-02-19 22:26 - 2016-01-16 13:36 - 01413632 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2016-02-19 22:00 - 2016-02-19 22:00 - 00000000 ____D C:\Program Files\ComonFiles
2016-02-19 20:35 - 2016-02-19 20:35 - 00000000 ____D C:\windows\SysWOW64\%Data%
2016-02-18 20:54 - 2016-02-18 20:54 - 01222211 _____ C:\Users\Ferocious\Downloads\bgr-com.pdf
2016-02-16 20:42 - 2016-02-19 19:36 - 00000000 ____D C:\Users\Ferocious\Downloads\zzz Firefox Downloads
2016-02-16 20:28 - 2016-02-19 19:36 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-02-16 20:28 - 2016-02-19 19:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-16 20:28 - 2016-02-16 20:28 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Mozilla
2016-02-15 20:39 - 2016-02-15 20:39 - 00000660 _____ C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2016-02-09 08:47 - 2016-02-09 08:47 - 00000000 ____D C:\Program Files\Common Files\AV
2016-02-09 08:34 - 2016-02-09 08:34 - 00001355 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
2016-02-09 08:34 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe
2016-02-09 08:15 - 2016-02-19 19:36 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-02-09 08:15 - 2016-02-09 09:32 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-02-09 07:57 - 2016-02-09 08:00 - 00004324 _____ C:\TDSSKiller.2.8.16.0_09.02.2016_07.57.29_log.txt
2016-02-09 07:54 - 2016-02-09 07:54 - 00000000 ____D C:\TDSSKiller_Quarantine
2016-02-09 07:51 - 2016-02-09 07:54 - 00151578 _____ C:\TDSSKiller.2.8.16.0_09.02.2016_07.51.43_log.txt
2016-02-05 11:43 - 2016-02-05 11:43 - 00000000 ___HD C:\$Windows.~WS
2016-02-05 11:43 - 2016-02-05 11:43 - 00000000 ____D C:\$WINDOWS.~BT
2016-02-02 13:25 - 2016-02-02 11:40 - 00000000 __SHD C:\found.000
2016-02-02 12:24 - 2016-02-02 12:24 - 00000020 ___SH C:\Users\Ferocious\ntuser.ini
2016-02-02 00:10 - 2016-02-02 00:10 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-02-01 23:21 - 2016-02-01 23:21 - 00000000 ____D C:\ProgramData\CyberLink
2016-02-01 21:44 - 2016-02-01 21:44 - 00000000 ____D C:\Users\Ferocious\Tracing
2016-02-01 13:19 - 2016-02-01 13:19 - 85401206 _____ C:\Users\Ferocious\Documents\sharp tv doc.pdf
2016-02-01 02:01 - 2016-02-02 12:23 - 00000000 ____D C:\Program Files (x86)\HDDScan-3.3
2016-02-01 01:57 - 2016-02-01 11:48 - 00000000 ____D C:\Program Files (x86)\Double Driver
2016-02-01 01:56 - 2016-02-20 09:48 - 00000000 ____D C:\Driver Backups
2016-02-01 01:42 - 2011-12-10 13:23 - 00976384 _____ (Quick And Easy Software) C:\Program Files (x86)\USB_Disk_Eject.exe
2016-02-01 00:40 - 2016-02-19 21:43 - 00000000 ____D C:\Utility Program Shortcuts
2016-02-01 00:29 - 2016-02-01 00:30 - 00000000 ____D C:\Users\Ferocious\Documents\zzz Misc
2016-02-01 00:29 - 2016-02-01 00:29 - 00047104 ___SH C:\Users\Ferocious\Documents\Thumbs.db
2016-02-01 00:25 - 2016-02-01 00:28 - 00000000 ____D C:\Users\Ferocious\Documents\0000 Christopher
2016-01-31 23:52 - 2011-06-03 22:59 - 00057648 _____ (FSPro Labs) C:\windows\system32\Drivers\FSPFltd2.sys
2016-01-31 22:58 - 2016-01-31 22:59 - 00000000 ___HD C:\Program Files\Win959820007810
2016-01-31 22:44 - 2016-01-31 22:44 - 00000000 ____D C:\Program Files (x86)\Security Task Manager
2016-01-31 22:09 - 2016-01-31 22:09 - 00000000 ____D C:\Users\Ferocious\AppData\LocalLow\Google
2016-01-31 20:53 - 2016-01-31 20:53 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\SubiSoft
2016-01-31 20:42 - 2016-02-01 01:52 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo6_7_3
2016-01-31 20:05 - 2016-01-31 20:05 - 00000000 ____D C:\Program Files\Axantum
2016-01-29 18:06 - 2016-01-29 18:06 - 00000000 ____D C:\Program Files (x86)\NexusFont
2016-01-29 17:07 - 2016-02-02 12:21 - 00000000 ____D C:\ProgramData\ACD Systems
2016-01-29 17:07 - 2016-01-29 17:07 - 00000000 ____D C:\Program Files (x86)\ACD Systems
2016-01-29 07:52 - 2016-01-29 08:09 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Apple Computer
2016-01-29 07:51 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\Apple Computer
2016-01-29 07:51 - 2016-01-29 07:52 - 00000000 ____D C:\Program Files\iTunes
2016-01-29 07:51 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files\iPod
2016-01-29 07:51 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-01-29 07:51 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-01-29 07:50 - 2016-01-29 07:51 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-01-29 07:50 - 2016-01-29 07:50 - 00000000 ____D C:\Program Files\Bonjour
2016-01-29 07:50 - 2016-01-29 07:50 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-01-29 07:49 - 2016-02-02 12:23 - 00000000 ____D C:\ProgramData\Apple
2016-01-29 06:59 - 2016-01-29 06:59 - 00000000 ____D C:\ProgramData\IntelDLM
2016-01-29 06:50 - 2016-01-29 06:50 - 00000000 ____D C:\ProgramData\Package Cache
2016-01-29 06:50 - 2016-01-29 06:50 - 00000000 ____D C:\Program Files (x86)\Intel Driver Update Utility
2016-01-29 06:15 - 2016-01-29 06:16 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Easy File Share
2016-01-28 02:23 - 2016-01-28 02:23 - 01010720 ___RS (Microsoft Corporation) C:\windows\SysWOW64\MSCHRT20.OCX
2016-01-28 02:23 - 2016-01-28 02:23 - 00224016 ___RS (Microsoft Corporation) C:\windows\SysWOW64\TABCTL32.OCX
2016-01-28 02:23 - 2016-01-28 02:23 - 00140488 ___RS (Microsoft Corporation) C:\windows\SysWOW64\COMDLG32.OCX
2016-01-28 02:23 - 2016-01-28 02:23 - 00000000 ____D C:\Program Files (x86)\Technitium
2016-01-26 20:42 - 2016-01-26 20:42 - 00000000 ____D C:\Users\Ferocious\Documents\MAGIX
2016-01-26 20:41 - 2016-01-26 20:41 - 00000000 ____D C:\Users\Public\Documents\MAGIX
2016-01-26 20:40 - 2016-02-02 12:21 - 00000000 ____D C:\ProgramData\MAGIX
2016-01-26 20:40 - 2016-01-26 20:40 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
2016-01-26 20:40 - 2016-01-26 20:40 - 00000000 ____D C:\Program Files (x86)\MAGIX
2016-01-26 19:56 - 2016-02-02 12:23 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\MAGIX
2016-01-26 19:56 - 2016-01-26 19:56 - 00000000 ____D C:\Users\Ferocious\Documents\MAGIX Downloads
2016-01-26 18:06 - 2016-01-26 18:06 - 00003174 _____ C:\windows\System32\Tasks\{395B4909-3C61-4CE4-AFD1-BFA0B6E7A98B}
2016-01-26 17:33 - 2016-02-20 19:28 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Audacity
2016-01-26 17:32 - 2016-01-26 17:32 - 00000000 ____D C:\Program Files (x86)\Audacity
2016-01-26 16:33 - 2016-01-26 16:33 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\WinRAR
2016-01-26 16:32 - 2016-01-26 17:24 - 00000000 ____D C:\Program Files\WinRAR
2016-01-26 15:51 - 2016-02-20 09:55 - 00000000 ____D C:\Reg Backup
2016-01-26 15:48 - 2016-01-26 15:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-26 15:48 - 2016-01-26 15:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-26 15:42 - 2016-01-26 15:42 - 00003184 _____ C:\windows\System32\Tasks\{262D531C-38D5-4C04-A680-DEF8F6F6CA4E}
2016-01-26 15:36 - 2016-02-22 23:07 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2016-01-26 15:36 - 2016-02-02 12:23 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Exploit
2016-01-26 15:30 - 2016-01-26 15:30 - 00000000 ____D C:\Program Files (x86)\FileASSASSIN
2016-01-26 15:20 - 2016-01-26 15:20 - 01600184 _____ (Malwarebytes) C:\Program Files (x86)\JRT.exe
2016-01-26 15:20 - 2016-01-26 15:20 - 00065232 _____ (Malwarebytes) C:\Program Files (x86)\regassassin-setup-1.03.exe
2016-01-26 15:03 - 2016-01-29 06:01 - 00000000 ____D C:\Program Files (x86)\NETGEAR Genie
2016-01-26 14:43 - 2016-01-26 14:43 - 00001764 _____ C:\Program Files (x86)\mbar-1.07.0.lnk
2016-01-26 09:56 - 2016-01-26 09:56 - 00000000 ____D C:\Program Files (x86)\Winstep
2016-01-26 09:56 - 2008-02-05 15:36 - 00798208 _____ (Winstep Software Technologies) C:\windows\SysWOW64\NextControls.ocx
2016-01-26 09:56 - 2000-05-22 17:58 - 00608448 _____ (Microsoft Corporation) C:\windows\SysWOW64\comctl32.ocx
2016-01-26 09:56 - 1997-07-19 16:55 - 01347344 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvbvm50.dll
2016-01-26 04:48 - 2016-02-23 00:22 - 00000000 ____D C:\Users\Public\Documents\Winstep
2016-01-26 04:12 - 2016-02-20 00:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-01-26 04:02 - 2016-01-26 04:35 - 00000000 ____D C:\Program Files (x86)\mbar
2016-01-26 03:20 - 2016-01-26 03:44 - 00000000 ____D C:\Program Files (x86)\TCEcs3
2016-01-26 03:16 - 2016-02-20 19:43 - 00000000 ____D C:\Program Files (x86)\Max Recorder
2016-01-26 01:49 - 2008-08-18 19:18 - 00077824 _____ (Fox Magic Software) C:\windows\SysWOW64\fmcodec.DLL
2016-01-26 00:23 - 2014-03-22 09:21 - 12589848 _____ (Malwarebytes Corp.) C:\Program Files (x86)\mbar-1.07.0.1009.exe
2016-01-25 20:13 - 2016-01-26 12:50 - 00000000 ____D C:\TCEcs3 Plugins
2016-01-25 16:38 - 2016-02-02 12:23 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Printer
2016-01-25 05:20 - 2016-01-25 05:20 - 00000000 _____ C:\windows\EEventManager.INI
2016-01-24 00:51 - 2016-01-24 00:51 - 00000044 _____ C:\windows\XP-820.ini
2016-01-24 00:51 - 2016-01-24 00:51 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Leadertech
2016-01-24 00:33 - 2016-02-23 15:33 - 00000911 _____ C:\windows\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE}.job
2016-01-24 00:33 - 2016-01-24 00:33 - 00003978 _____ C:\windows\System32\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE}
2016-01-24 00:33 - 2016-01-24 00:33 - 00000000 ____D C:\Program Files\Common Files\EPSON
2016-01-24 00:25 - 2016-02-02 12:21 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Epson
2016-01-24 00:23 - 2016-01-24 00:27 - 00000000 ____D C:\Program Files (x86)\EPSON Software
2016-01-24 00:23 - 2016-01-24 00:27 - 00000000 ____D C:\Program Files (x86)\epson
2016-01-24 00:23 - 2016-01-24 00:23 - 00000000 ____D C:\Program Files\EpsonNet
2016-01-24 00:23 - 2014-02-25 00:00 - 00466944 _____ (Seiko Epson Corporation) C:\windows\system32\esxw2ud.dll
2016-01-24 00:23 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\windows\system32\escsvc64.exe
2016-01-24 00:22 - 2013-12-05 15:05 - 00179712 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_YLMBNME.DLL
2016-01-24 00:22 - 2011-03-14 15:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\windows\system32\E_YD4BNME.DLL
2016-01-24 00:22 - 2007-04-09 13:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\windows\system32\E_GCINST.DLL
2016-01-24 00:21 - 2016-02-02 12:21 - 00000000 ____D C:\ProgramData\EPSON
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-23 15:57 - 2014-10-24 18:23 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-02-23 15:49 - 2013-09-25 14:44 - 00000944 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001UA.job
2016-02-23 15:49 - 2013-09-25 14:44 - 00000922 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001Core.job
2016-02-23 15:48 - 2016-01-22 18:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2016-02-23 15:48 - 2009-07-14 00:13 - 00782430 _____ C:\windows\system32\PerfStringBackup.INI
2016-02-23 15:48 - 2009-07-13 22:20 - 00000000 ____D C:\windows\inf
2016-02-23 15:39 - 2009-07-13 23:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-23 15:39 - 2009-07-13 23:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-23 15:30 - 2013-09-23 14:35 - 00000900 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-23 15:30 - 2012-05-10 20:31 - 00000828 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2016-02-23 15:30 - 2009-07-14 00:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-02-23 02:12 - 2013-09-23 14:35 - 00000904 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-23 01:23 - 2013-09-23 12:12 - 00000000 ____D C:\Program Files (x86)\JetAudio
2016-02-23 00:48 - 2016-01-23 14:17 - 00000000 ____D C:\Users\Ferocious\Downloads\zzz sorted
2016-02-22 23:03 - 2013-09-23 12:13 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\COWON
2016-02-22 23:01 - 2012-05-10 20:30 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-02-22 22:55 - 2013-09-23 12:22 - 00000000 ____D C:\Toons
2016-02-22 18:25 - 2012-05-10 20:34 - 00000000 ____D C:\Users\UpdatusUser
2016-02-22 18:20 - 2015-10-11 18:05 - 00000000 ____D C:\Users\Ferocious\AppData\LocalLow\Temp
2016-02-22 18:10 - 2013-09-23 09:22 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Computer
2016-02-22 18:10 - 2013-09-23 09:22 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security
2016-02-22 11:51 - 2012-05-10 20:31 - 00000830 _____ C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2016-02-21 23:06 - 2009-07-13 22:20 - 00000000 ____D C:\windows\rescache
2016-02-21 21:19 - 2009-07-13 23:45 - 00306176 _____ C:\windows\system32\FNTCACHE.DAT
2016-02-21 21:17 - 2014-12-09 19:51 - 00000000 ____D C:\windows\system32\appraiser
2016-02-21 21:17 - 2014-05-06 20:32 - 00000000 ___SD C:\windows\system32\CompatTel
2016-02-21 21:17 - 2012-05-11 12:21 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-21 21:14 - 2013-09-21 16:19 - 00000000 ____D C:\windows\system32\MRT
2016-02-21 21:03 - 2013-09-21 16:19 - 146614896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-02-21 20:54 - 2014-02-25 21:29 - 00775044 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2016-02-20 21:06 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\NDF
2016-02-20 09:54 - 2016-01-23 21:34 - 00000000 ____D C:\windows\ERDNT
2016-02-19 22:32 - 2013-09-23 13:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security
2016-02-19 21:42 - 2016-01-23 06:15 - 00000000 ____D C:\zzzzScan Logs
2016-02-19 19:39 - 2013-09-21 15:43 - 00000000 ____D C:\Users\Ferocious
2016-02-19 19:37 - 2009-07-13 22:20 - 00000000 ____D C:\windows\PolicyDefinitions
2016-02-19 19:36 - 2012-05-10 21:24 - 00000000 ___HD C:\windows\system32\WLANProfiles
2016-02-19 19:36 - 2012-05-10 20:55 - 00000000 ____D C:\ProgramData\WinClon
2016-02-19 19:36 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-02-19 19:35 - 2009-07-13 22:20 - 00000000 ____D C:\windows\registration
2016-02-13 12:58 - 2014-10-24 18:23 - 00796864 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-02-13 12:58 - 2014-10-24 18:23 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-13 12:58 - 2014-10-24 18:23 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2016-02-05 11:43 - 2011-02-11 14:57 - 00000000 ____D C:\windows\Panther
2016-02-05 11:31 - 2016-01-23 01:27 - 00000000 ____D C:\Users\Ferocious\Downloads\zzz unsorted
2016-02-03 14:37 - 2016-01-21 23:40 - 00000000 ____D C:\Users\Ferocious\Documents\Chris
2016-02-03 14:20 - 2016-01-13 15:42 - 00071128 _____ C:\Users\Ferocious\AppData\Roaming\GDIPFONTCACHEV1.DAT
2016-02-02 12:24 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\System
2016-02-02 12:23 - 2016-01-23 22:06 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Office
2016-02-02 12:23 - 2016-01-23 22:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Office
2016-02-02 12:23 - 2016-01-23 21:59 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\e-Sword
2016-02-02 12:23 - 2015-04-04 18:53 - 00000000 ___SD C:\windows\system32\GWX
2016-02-02 12:23 - 2013-09-25 14:58 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-02-02 12:23 - 2013-09-25 06:13 - 00000000 ____D C:\windows\pss
2016-02-02 12:23 - 2013-09-25 06:00 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Skype
2016-02-02 12:23 - 2013-09-23 13:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-02 12:23 - 2013-09-23 09:57 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video
2016-02-02 12:23 - 2013-09-23 09:56 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet
2016-02-02 12:23 - 2013-09-23 09:56 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Photo
2016-02-02 12:23 - 2013-09-23 09:23 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows
2016-02-02 12:23 - 2013-09-23 09:23 - 00000000 ___RD C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet
2016-02-02 12:23 - 2012-05-10 21:37 - 00000000 ____D C:\Program Files (x86)\Windows Live
2016-02-02 12:23 - 2012-05-10 21:35 - 00000000 ____D C:\Program Files\Windows Live
2016-02-02 12:23 - 2012-05-10 21:00 - 00000000 ____D C:\ProgramData\Skype
2016-02-02 12:23 - 2012-05-10 20:50 - 00000000 ____D C:\ProgramData\SAMSUNG
2016-02-02 12:21 - 2015-12-17 10:54 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\AVG
2016-02-02 12:21 - 2014-10-24 18:37 - 00000000 ____D C:\ProgramData\Adobe
2016-02-02 12:21 - 2014-08-10 14:34 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\SoftGrid Client
2016-02-02 12:21 - 2013-09-23 10:58 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\ACD Systems
2016-02-02 12:21 - 2013-09-21 16:27 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Adobe
2016-02-02 12:21 - 2013-09-21 15:43 - 00000000 ____D C:\Users\Ferocious\AppData\Roaming\Intel
2016-02-02 12:21 - 2012-05-10 20:34 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-02 12:21 - 2012-05-10 20:31 - 00000000 ____D C:\ProgramData\Intel
2016-02-01 19:53 - 2015-05-05 23:10 - 00000000 ____D C:\Users\Ferocious\Downloads\0000 Chris
2016-02-01 17:56 - 2013-09-23 15:17 - 00000189 _____ C:\windows\ScreenHunter.INI
2016-02-01 02:02 - 2015-05-05 23:10 - 00000000 ____D C:\Users\Ferocious\Downloads\0000 Patrick
2016-02-01 01:35 - 2013-09-23 14:43 - 00000000 ___HD C:\Patricks Do Not Touch
2016-01-31 22:08 - 2013-09-23 14:35 - 00000000 ____D C:\Program Files (x86)\Google
2016-01-31 22:07 - 2013-09-23 14:35 - 00003900 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-01-31 22:07 - 2013-09-23 14:35 - 00003648 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-30 19:16 - 2013-09-23 09:59 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo
2016-01-29 08:38 - 2013-09-23 09:53 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Computer
2016-01-29 07:05 - 2012-05-10 20:30 - 00000000 ____D C:\Program Files (x86)\Intel
2016-01-29 06:36 - 2012-05-10 20:49 - 00000000 ____D C:\Program Files (x86)\Samsung
2016-01-29 06:00 - 2016-01-23 22:36 - 00369168 _____ (CACE Technologies, Inc.) C:\windows\system32\wpcap.dll
2016-01-29 06:00 - 2016-01-23 22:36 - 00281104 _____ (CACE Technologies, Inc.) C:\windows\SysWOW64\wpcap.dll
2016-01-29 06:00 - 2016-01-23 22:36 - 00106000 _____ (CACE Technologies, Inc.) C:\windows\system32\packet.dll
2016-01-29 06:00 - 2016-01-23 22:36 - 00096784 _____ (CACE Technologies, Inc.) C:\windows\SysWOW64\packet.dll
2016-01-29 06:00 - 2016-01-23 22:36 - 00035344 _____ (CACE Technologies, Inc.) C:\windows\system32\Drivers\npf.sys
2016-01-26 20:59 - 2009-07-13 21:34 - 00000491 _____ C:\windows\win.ini
2016-01-26 20:41 - 2007-04-27 10:43 - 00120200 _____ () C:\windows\SysWOW64\DLLDEV32i.dll
2016-01-26 17:24 - 2012-05-10 21:42 - 00000000 ____D C:\windows\hr
2016-01-26 12:39 - 2013-09-23 09:57 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video
2016-01-24 00:52 - 2009-07-14 00:32 - 00000000 ____D C:\windows\system32\FxsTmp
 
==================== Files in the root of some directories =======
 
2016-01-23 01:47 - 2016-01-23 01:47 - 8799792 _____ (                                                            ) C:\Program Files\ipscan24.exe
2016-01-26 15:20 - 2016-01-26 15:20 - 1600184 _____ (Malwarebytes) C:\Program Files (x86)\JRT.exe
2016-01-26 00:23 - 2014-03-22 09:21 - 12589848 _____ (Malwarebytes Corp.) C:\Program Files (x86)\mbar-1.07.0.1009.exe
2016-01-26 14:43 - 2016-01-26 14:43 - 0001764 _____ () C:\Program Files (x86)\mbar-1.07.0.lnk
2016-01-26 15:20 - 2016-01-26 15:20 - 0065232 _____ (Malwarebytes) C:\Program Files (x86)\regassassin-setup-1.03.exe
2016-02-01 01:42 - 2011-12-10 13:23 - 0976384 _____ (Quick And Easy Software) C:\Program Files (x86)\USB_Disk_Eject.exe
2016-01-23 18:09 - 2016-01-23 22:20 - 0013312 _____ () C:\Program Files (x86)\_netlib2.dl2
2016-01-23 18:09 - 2016-01-23 18:36 - 0013312 _____ () C:\Program Files (x86)\_netlib3.dl2
2016-01-23 21:34 - 2016-01-23 18:09 - 0000000 _____ () C:\Program Files (x86)\_netlib4.dl2
2013-12-22 17:31 - 2015-04-28 13:16 - 0013312 _____ () C:\Users\Ferocious\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-16 12:20 - 2016-01-28 03:02 - 0007604 _____ () C:\Users\Ferocious\AppData\Local\Resmon.ResmonCfg
2016-02-18 19:50 - 2016-02-18 19:50 - 0000000 _____ () C:\Users\Ferocious\AppData\Local\{4D70EDDC-477B-44B0-AAEB-27F8D212B998}
2012-05-10 20:45 - 2012-05-10 20:46 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2012-05-10 20:41 - 2012-05-10 20:41 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
2012-05-10 20:43 - 2012-05-10 20:44 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2012-05-10 20:42 - 2012-05-10 20:43 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2012-05-10 20:44 - 2012-05-10 20:45 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-02-19 23:23
 
==================== End of FRST.txt ============================



And:




Additional scan result of Farbar Recovery Scan Tool (x64) Version:20-02-2016
Ran by [removed] (2016-02-23 15:58:53)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-09-21 20:43:09)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3575110223-3707097088-2884409191-500 - Administrator - Disabled)
Ferocious (S-1-5-21-3575110223-3707097088-2884409191-1001 - Administrator - Enabled) => C:\Users\Ferocious
Guest (S-1-5-21-3575110223-3707097088-2884409191-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3575110223-3707097088-2884409191-1003 - Limited - Enabled)
UpdatusUser (S-1-5-21-3575110223-3707097088-2884409191-1000 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
ACDSee 15 (HKLM-x32\…\{B580C89C-F7F8-4A78-BAF0-5560C6E9E76D}) (Version: 15.0.169 - ACD Systems International Inc.)
Adobe Flash Player 20 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.14) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.14 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\…\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
aTube Catcher (HKLM-x32\…\aTube Catcher) (Version: 2.9.4272 - DsNET Corp)
aTube Catcher version 3.8 (HKLM-x32\…\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.1.0 (HKLM-x32\…\Audacity_is1) (Version: 2.1.0 - Audacity Team)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.14 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DFX (HKLM-x32\…\DFX) (Version: 12.014.0.0 - Power Technology)
Easy Photo Scan (HKLM-x32\…\{2D76CB3C-AC17-4143-891E-F4C3BCDC78B6}) (Version: 1.00.0001 - Seiko Epson Corporation)
Easy Settings (HKLM-x32\…\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.1 - Samsung Electronics CO., LTD.)
Easy Support Center (HKLM\…\{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}) (Version: 1.2.23 - Samsung Electronics CO., LTD.)
Epson Event Manager (HKLM-x32\…\{86B4A6B9-07FD-48EC-8730-1EC82E80C3D7}) (Version: 3.10.0030 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.50.00 - SEIKO EPSON CORPORATION)
Epson Print CD (HKLM-x32\…\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.31.00 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON XP-820 Series Printer Uninstall (HKLM\…\EPSON XP-820 Series) (Version:  - SEIKO EPSON Corporation)
Epson XP-820 User’s Guide version 1.0 (HKLM-x32\…\UsersGuideEpson XP-820 User’s Guide_is1) (Version: 1.0 - )
EpsonNet Print (HKLM\…\{F983229B-587E-4322-BCB9-D7A49734E5CD}) (Version: 3.0.0.0 - SEIKO EPSON CORPORATION)
ERUNT 1.1j (HKLM-x32\…\ERUNT_is1) (Version:  - Lars Hederer)
e-Sword (HKLM-x32\…\{463178C4-E707-41EE-BE8A-080C62BF526D}) (Version: 10.04.0000 - Rick Meyers)
e-Sword Module Installer version .5 (HKLM\…\{6E442F8C-3EB1-4911-BB65-F3AD73438F52}_is1) (Version: .5 - BibleSupport.com)
ExpressCache (HKLM\…\{F9EB0DDE-931C-4E89-96B2-DE8286EDFA6C}) (Version: 1.0.64 - Diskeeper Corporation)
FileASSASSIN (HKLM-x32\…\FileASSASSIN) (Version: 1.06 - Malwarebytes)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Earth Pro (HKLM-x32\…\{35DAA04C-1720-4BE3-A920-A03731EC6A1D}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Intel(R) Driver Update Utility 2.4 (x32 Version: 2.4.0.5 - Intel) Hidden
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version:  - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2618 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\…\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation)
Intel(R) WiDi (HKLM-x32\…\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation)
Intel(R) Wireless Bluetooth(R)(patch version 17.1.1504.516) (HKLM\…\{302600C1-6BDF-4FD1-1411-148929CC1385}) (Version: 17.1.1411.0506 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® Driver Update Utility (HKLM-x32\…\{270e4d1a-19f9-46c3-93b3-e61d4a24ab9f}) (Version: 2.4.0.5 - Intel)
Intel® PROSet/Wireless WiFi Software (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\…\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
iTunes (HKLM\…\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
jetAudio Plus (HKLM-x32\…\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}) (Version: 8.1.0 - COWON)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kaspersky Internet Security (HKLM-x32\…\InstallWIX_{77E7AE5C-181C-4CAF-ADBF-946F11C1CE26}) (Version: 16.0.0.614 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 16.0.0.614 - Kaspersky Lab) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\…\MAGIX_{A8A090CA-5FBE-4CA3-B596-7DA41BE11DE8}) (Version: 7.0.1.27 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.1.27 - MAGIX AG) Hidden
Malwarebytes Anti-Exploit version 1.8.1.1189 (HKLM\…\Malwarebytes Anti-Exploit_is1) (Version: 1.8.1.1189 - Malwarebytes)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Max Recorder (HKLM-x32\…\Max Recorder) (Version: 2.006.0.0 - Silver Vine, LLC)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM-x32\…\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Multimedia POP (HKLM-x32\…\{119B7882-19D7-4BE7-A417-29BB479D3ABE}) (Version: 1.0 - )
NETGEAR Genie (HKLM-x32\…\NETGEAR Genie) (Version: 2.4.18.00 - NETGEAR Inc.)
Nexus 15.9 (HKLM-x32\…\Winstep Xtreme_is1) (Version:  - )
NexusFont 2.5 (ver 2.5.8.1582) (HKLM-x32\…\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version:  - xiles)
NVIDIA Graphics Driver 296.32 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 296.32 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0213 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6608 - Realtek Semiconductor Corp.)
Samplitude Music Studio 2013 (HKLM-x32\…\MAGIX_{30AEB310-7BAE-4735-96EA-5536B9CFE334}) (Version: 19.0.1.18 - MAGIX AG)
Samplitude Music Studio 2013 (Version: 19.0.1.18 - MAGIX AG) Hidden
Samsung Kies (HKLM-x32\…\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.0.0.11044_11 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.0.0.11044_11 - Samsung Electronics Co., Ltd.) Hidden
Samsung Recovery Solution 5 (HKLM-x32\…\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.2.7 - Samsung Electronics CO., LTD.)
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.4.10.0 - SAMSUNG Electronics Co., Ltd.)
Scofield, Cyrus I. - The Biggest Failure of the Church Age.top version 0 (HKLM-x32\…\{D7F1A6E9-5A60-4573-AFBD-4A047A57635E}_is1) (Version: 0 - BibleSupport.com)
Should I Remove It (HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\…\Should I Remove It 1.0.4) (Version: 1.0.4 - Reason Software Company Inc.)
Should I Remove It (x32 Version: 1.0.4 - Reason Software Company Inc.) Hidden
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.109 - Skype Technologies S.A.)
Software Updater (HKLM-x32\…\{E07D7C7B-F424-4EEF-BA17-B2C32BD1C107}) (Version: 4.3.0 - SEIKO EPSON CORPORATION)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Technitium MAC Address Changer v6.0 (HKLM-x32\…\TMACv6.0) (Version: 6.0 - Technitium)
User Guide (HKLM-x32\…\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 2.0 - Samsung Electronics CO., LTD.)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Who Is On My Wifi version 3.0.4 (HKLM-x32\…\{010D45A1-093D-4534-8147-4E10E80F81CC}_is1) (Version: 3.0.4 - IO3O LLC)
Windows Live 程式集 (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
WinRAR 5.31 beta 1 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.31.1 - win.rar GmbH)
Wisdom-soft ScreenHunter 6.0 Free (HKLM-x32\…\Wisdom-soft ScreenHunter 6.0 Free) (Version:  - Wisdom Software Inc.)
WOT for Internet Explorer (HKLM\…\{373B90E1-A28C-434C-92B6-7281AFA6115A}) (Version: 13.9.2.0 - WOT Services Oy)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0BDE8B08-367C-419C-8C40-C3F595491DE5} - System32\Tasks\{395B4909-3C61-4CE4-AFD1-BFA0B6E7A98B} => pcalua.exe -a C:\Users\Ferocious\Downloads\ExpensiveHiFiSony.exe -d C:\Users\Ferocious\Downloads
Task: {13190DF4-45E9-440E-B9AD-AB72C5B00D14} - System32\Tasks\{262D531C-38D5-4C04-A680-DEF8F6F6CA4E} => pcalua.exe -a C:\Users\Ferocious\Downloads\regassassin-setup-1.03.exe -d C:\Users\Ferocious\Downloads
Task: {1B14E284-6155-442F-8C0B-2BDD6DFF31B7} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001UA => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {1C4E48DE-68C6-4457-9A0A-48E52632841C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001Core => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {23ACAC42-1D01-4502-B505-C4AECC892FCF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
Task: {3885036D-8265-4BBC-82CE-3BA628D3877E} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-04-24] (Samsung Electronics Co., Ltd.)
Task: {393DCB84-92E2-47A1-B32D-D31FF825D9CE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-01-15] (Piriform Ltd)
Task: {3ED9E4DF-4D01-47AB-BD0D-1C33CBB61C5E} - System32\Tasks\{73AE8EC3-CB80-4B1B-8696-F3E93DD7913F} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {4578B798-9D15-490A-8571-A031B461905D} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-05-01] (Samsung Electronics Co., Ltd.)
Task: {471A5EF3-A694-4154-A623-5A6E3D1E9D4C} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-05-08] (Samsung Electronics Co., Ltd.)
Task: {593BC1E9-7EFF-4E00-9627-7D7E89525282} - System32\Tasks\{F0FE69E6-E47A-456F-A0A5-24F6DC53BA73} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {5B136CE7-1B0E-49A4-B4D3-185118D291E4} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2012-01-28] (SEC)
Task: {5B172D0F-9887-4206-B622-1D441ACA5681} - System32\Tasks\{F740D370-5C8D-4AF0-ADA2-535BF04547E4} => pcalua.exe -a "C:\Users\Ferocious\Downloads\zzz sorted\DFX pro\ExpensiveHiFiSony.exe" -d "C:\Users\Ferocious\Downloads\zzz sorted\DFX pro"
Task: {70C72B5B-8515-4B73-B222-35EF348E5284} - System32\Tasks\{1370B2F3-FBCA-452D-8635-0A5B862A38BC} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {71FBF791-4B2C-49B9-A4C9-F885EB13C8C0} - System32\Tasks\{7EC19467-EF4D-41A5-AFF6-2B2A7A8C1756} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {78E51283-DAD3-4368-BC41-5F894A873FBE} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [2012-04-19] (Samsung Electronics CO., LTD.)
Task: {83CBF6BB-946E-4102-BBB7-DFF12E6F175B} - System32\Tasks\{E111225C-3339-44B3-B7BD-9FD19A8A72A7} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {973C4109-06A5-4F41-965A-8A4269D70C78} - System32\Tasks\{F7F049FE-5F44-4F5F-BA92-76F1861D1E6E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {9AEB661D-5231-4FC3-BF24-067BECED9C0D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-18] (Google Inc.)
Task: {9BC18E4E-9D20-46B4-839B-26AA8DDB60C1} - System32\Tasks\{F1B8E449-E35C-4479-9F05-F79654024F40} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {9FBE1B20-79AC-4C10-A0D0-AA398067233A} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-24] (Intel Corporation)
Task: {9FE0C03E-94F7-443E-A1CA-CE8C94862A46} - System32\Tasks\{33B87CCE-EADC-48F7-B577-AC9EB6B49210} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {A5849DEF-CD95-410A-9900-CBD8B95E9301} - System32\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE} => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSNME.EXE [2013-11-21] (SEIKO EPSON CORPORATION)
Task: {A6CB98D8-469A-458C-B7A0-ED72763D57ED} - System32\Tasks\{433D8004-3057-482B-B00E-EC896D580758} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {A8E3F7C5-3455-4828-9751-3842BBCAFA93} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-18] (Google Inc.)
Task: {B3E1D197-2B76-45BA-9A3B-3924D042C1B6} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-24] (Intel Corporation)
Task: {BAA559F9-98AC-48D9-BF81-2A156640F0E9} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics)
Task: {BF19807D-8DB4-4940-819F-4F356F609C01} - System32\Tasks\{8FD53A26-2282-4D14-9DBE-950A72B7BFA8} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {C0D438E2-6450-4C92-8C99-1A7C49D74398} - System32\Tasks\{95153E2A-AE05-402F-8C06-B832F4C36AB5} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {CBE04C6D-AD53-40A3-91E9-0B126A3B0E31} - System32\Tasks\KiesHelper => C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe [2011-12-12] (Samsung)
Task: {CF40DA2F-D679-42CC-891D-2C70F0D4969B} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.)
Task: {E34F4E5D-B453-4396-BFC0-E33F31927C7D} - System32\Tasks\{06517B3D-517B-4D4F-8C82-3DED43B22BC0} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?source=lightinstaller&page;=tsProgressBar
Task: {E48FB71A-F476-4493-8583-B6F57B6253DC} - System32\Tasks\{E4C0C50D-3DC8-48CA-BE17-EF08C245F070} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {E6BB207A-284F-4B02-B735-5B505F97C560} - System32\Tasks\{EC424B58-393E-4DAE-AA7B-D56D0BC995A9} => Chrome.exe hxxp://ui.skype.com/ui/0/6.7.0.102/en/go/help.faq.installer?source=lightinstaller&LastError;=1618
Task: {EEE8405C-8BBE-460D-BAB3-75A1C95287C0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-13] (Adobe Systems Incorporated)
Task: {F16B4839-B11D-4F68-BF99-7E71E6500219} - System32\Tasks\{86F6B50B-41C7-40FD-AE58-E4E3F2C97F07} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\avpui.exe
Task: {FB70526A-065E-4B51-B018-33DBEA097CDB} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\EPSON XP-820 Series Update {4DAAF32C-C745-4E16-B15C-52A5DA429FBE}.job => C:\windows\system32\spool\DRIVERS\x64\3\E_YTSNME.EXE:/EXE:{4DAAF32C-C745-4E16-B15C-52A5DA429FBE} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001Core.job => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3575110223-3707097088-2884409191-1001UA.job => C:\Users\Ferocious\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music\MAGIX\Samplitude Music Studio 2013\Service and Support\Register online.lnk -> C:\Program Files (x86)\MAGIX\Samplitude Music Studio 2013\explore.exe () -> hxxp://www.magix.com/user/register/product_registration/login_screen.php3?VARPROGRAM=SMS2013&VARCHARGE;=19.0.1.18&VARREGISTER;=onlineregister&VARLAND;=II
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-12-17 18:38 - 2015-12-17 18:38 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-12-17 18:38 - 2015-12-17 18:38 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-05-10 20:31 - 2012-02-07 21:03 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2015-08-26 09:21 - 2015-08-26 09:21 - 00105216 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
2012-05-10 20:49 - 2012-02-13 01:02 - 00031624 _____ () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
2012-02-05 23:42 - 2012-01-05 03:24 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
2016-01-26 09:56 - 2012-06-08 20:40 - 01086176 _____ () C:\Program Files (x86)\Winstep\wodTelnetDLX.dll
2012-05-10 20:50 - 2011-02-16 11:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 03369922 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\icuin51.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00544817 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00989805 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libstdc++-6.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01978690 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\icuuc51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 22378434 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\icudt51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01233408 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\platforms\qwindows.dll
2015-11-17 03:23 - 2015-11-17 03:23 - 00672256 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll
2015-11-17 03:08 - 2015-11-17 03:08 - 01691136 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll
2015-11-10 04:52 - 2015-11-10 04:52 - 00192512 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll
2015-11-10 04:53 - 2015-11-10 04:53 - 00631296 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll
2015-11-17 03:13 - 2015-11-17 03:13 - 06942208 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll
2014-06-29 20:55 - 2014-06-29 20:55 - 00068608 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll
2015-11-10 05:49 - 2015-11-10 05:49 - 01165312 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\qwt.dll
2015-11-15 22:34 - 2015-11-15 22:34 - 02979854 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_MyMedia.dll
2012-10-15 15:27 - 2012-10-15 15:27 - 00111616 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libvlc.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 02286592 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libvlccore.dll
2015-11-17 03:14 - 2015-11-17 03:14 - 01058304 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll
2014-09-11 03:39 - 2014-09-11 03:39 - 00144896 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll
2015-11-15 22:34 - 2015-11-15 22:34 - 01205248 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll
2015-11-10 02:55 - 2015-11-10 02:55 - 11147776 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll
2015-11-15 22:35 - 2015-11-15 22:35 - 02593280 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll
2015-11-17 03:15 - 2015-11-17 03:15 - 00200192 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll
2015-11-17 03:16 - 2015-11-17 03:16 - 00892928 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll
2015-11-10 05:17 - 2015-11-10 05:17 - 00438272 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00051200 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qgif.dll
2013-08-25 14:07 - 2013-08-25 14:07 - 00052224 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qico.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00261120 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qjpeg.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00381952 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qmng.dll
2013-08-25 14:09 - 2013-08-25 14:09 - 00046080 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qsvg.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00046080 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qtga.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00390144 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qtiff.dll
2013-08-25 14:16 - 2013-08-25 14:16 - 00045056 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\imageformats\qwbmp.dll
2015-11-10 04:52 - 2015-11-10 04:52 - 00081408 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll
2015-04-17 05:36 - 2015-04-17 05:36 - 00146944 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll
2015-08-24 03:41 - 2015-08-24 03:41 - 02360622 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\drivers\libntgr_api.dll
2015-03-28 09:50 - 2015-03-28 09:50 - 00113152 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\drivers\NETGEAR_PLC_L2_API.dll
2015-02-03 05:09 - 2015-02-03 05:09 - 00072192 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00074240 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00136704 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00219648 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\access\libdshow_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00049664 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libaout_directx_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00051200 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libwaveout_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00070144 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\video_output\libdirectx_plugin.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00040960 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\printsupport\windowsprintersupport.dll
2015-11-17 03:16 - 2015-11-17 03:16 - 00642560 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll
2015-11-10 05:18 - 2015-11-10 05:18 - 00458752 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll
2014-06-29 21:33 - 2014-06-29 21:33 - 00046080 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00066560 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll
2015-07-08 23:18 - 2015-07-08 23:18 - 00794920 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0 (1)\kpcengine.2.3.dll
2016-02-09 08:15 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2016-02-09 08:15 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2016-02-09 08:15 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2012-05-10 20:50 - 2006-08-11 22:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll
2012-05-10 20:55 - 2011-09-08 05:40 - 01645056 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
2012-05-10 20:31 - 2012-02-07 20:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMR322 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Ferocious\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: ) (EnableLUA: 0)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: RemoteRegistry => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk => C:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
MSCONFIG\startupreg: DFX => C:\Program Files (x86)\DFX\DFX.exe -startup
MSCONFIG\startupreg: EPLTarget => 
MSCONFIG\startupreg: mylbx => C:\Program Files\My Lockbox\mylbx.exe /a
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{86C385A8-8760-42CA-A8DA-E553C92D43A7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{1B7B98E1-68F7-4F92-A3A1-7CB38ADC01DD}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{97EA9AF7-186D-44C7-BE8C-4C1CAAF965D5}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{25C8B60A-6C6A-4ADE-8464-08B0B33F93C7}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{61D89D74-4C54-4587-8832-0D7B3AEE8A4F}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{06BAB177-ED63-48E0-AA10-80A1123B24AD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{FE3C2576-E305-4F07-B62D-3D24DAEE833B}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BA102CC0-6A3C-4F2F-96BE-D7E14C40D09F}] => (Allow) LPort=2869
FirewallRules: [{3A56A74A-58FE-483A-BEC5-81F450180A7E}] => (Allow) LPort=1900
FirewallRules: [{BE58F9CE-4691-4D9B-A4D7-C87C85E68B5B}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{E143C391-D93A-4DF0-9F5D-E4BCE24E712D}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{3D4CE169-B4A8-4BEE-81B3-AC0549CD0169}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [TCP Query User{1BEB12EE-5C8A-4084-8D18-741FFABCFABB}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{F1616EEC-4256-4815-B7BF-FA9716B4355F}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{CEDA5835-C52B-477D-B391-E763FE0AA774}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{F6BAB604-5789-4515-8352-944ED752FAF1}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{D3B14403-62F6-4515-AA31-21A893567426}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{DD28A9CD-9491-45A5-8B96-0E38B4203DB2}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{56A785EB-4AF1-458C-BDB3-4CB95696CB3F}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{5E7739EA-71C4-4E87-9A54-5B7B0615DEEE}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [TCP Query User{A47C2BBD-1C00-4377-B45D-6DD920A26D6D}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{64B61A1D-6068-4E6B-A700-DB944086735B}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{882F2C4A-3530-4EB2-916B-24C5B8919714}] => (Allow) C:\Program Files (x86)\Samsung\Easy File Share\EasyFileShare.EXE
FirewallRules: [{952F1B33-0929-4F13-92A9-178D394BC972}] => (Allow) C:\Program Files (x86)\Samsung\Easy File Share\EasyFileShare.EXE
FirewallRules: [{79299DA1-3BC0-4671-8EB8-DA3C9EBBEED6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AAA1DE69-804D-49FC-AB90-33CF91CC27B9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E51B0592-E0C6-45AC-B645-3F42B631C226}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6F98F00B-C38E-4FEC-8E96-349C8ED5FB0B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{86FB6165-7401-4F7D-9A2A-BCD1C8DF8E81}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{137C0497-9E6B-4004-8905-9C1C01F622C7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
 
==================== Restore Points =========================
 
19-02-2016 13:14:40 2 19 16
19-02-2016 17:28:44 JRT Pre-Junkware Removal
19-02-2016 21:27:40 Windows Update
20-02-2016 10:12:21 Windows Backup
20-02-2016 10:14:13 Windows Backup
20-02-2016 20:27:25 pre net
20-02-2016 20:31:05 pre up2
21-02-2016 17:23:07 Windows Update
21-02-2016 18:33:47 pre update win 2 21 16
21-02-2016 20:49:33 Windows Update
22-02-2016 18:15:19 fix 2 22 16
22-02-2016 18:20:21 Restore Point Created by FRST
22-02-2016 21:16:26 JRT Pre-Junkware Removal
22-02-2016 22:56:00 Removed jetAudio Plus
22-02-2016 23:01:28 Installed COWON Media Center - jetAudio Plus VX
22-02-2016 23:13:32 Configured jetAudio Plus
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/23/2016 03:47:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 [removed].in-addr.arpa. PTR Ferocious-PC.local.
 
Error: (02/23/2016 03:47:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.3:5353   22 [removed].in-addr.arpa. PTR Ferocious-PC-2.local.
 
Error: (02/23/2016 03:30:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 [removed].in-addr.arpa. PTR Ferocious-PC.local.
 
Error: (02/23/2016 03:30:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.3:5353   22 [removed].in-addr.arpa. PTR Ferocious-PC-2.local.
 
Error: (02/23/2016 03:30:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/23/2016 03:24:59 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 [removed].in-addr.arpa. PTR Ferocious-PC.local.
 
Error: (02/23/2016 03:24:59 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.3:5353   22 [removed].in-addr.arpa. PTR Ferocious-PC-2.local.
 
Error: (02/23/2016 03:24:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (02/23/2016 02:07:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: dmhkcore.exe, version: 3.2.8.38, time stamp: 0x4fa9eb8e
Faulting module name: MMDevApi.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b892
Exception code: 0xc0000005
Fault offset: 0x00023b0f
Faulting process id: 0x16c8
Faulting application start time: 0xdmhkcore.exe0
Faulting application path: dmhkcore.exe1
Faulting module path: dmhkcore.exe2
Report Id: dmhkcore.exe3
 
Error: (02/23/2016 02:05:27 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   20 [removed].in-addr.arpa. PTR Ferocious-PC.local.
 
 
System errors:
=============
Error: (02/23/2016 03:33:30 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/23/2016 03:26:41 PM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/23/2016 02:06:42 AM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/23/2016 01:52:48 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Intel(R) PROSet/Wireless Zero Configuration Service service terminated with the following error: 
%%-2147196306
 
Error: (02/23/2016 01:52:35 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: 
%%1058
 
Error: (02/23/2016 01:52:31 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Windows Firewall service depends on the Base Filtering Engine service which failed to start because of the following error: 
%%1058
 
Error: (02/23/2016 01:52:30 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The System Event Notification Service service depends on the COM+ Event System service which failed to start because of the following error: 
%%1058
 
Error: (02/23/2016 01:23:03 AM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/23/2016 01:16:44 AM) (Source: WMPNetworkSvc) (EventID: 14329) (User: )
Description: WMPNetworkSvc0x80070006
 
Error: (02/23/2016 01:15:08 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AVP16.0.0 service.
 
 
CodeIntegrity:
===================================
  Date: 2016-02-23 15:47:25.565
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 15:47:25.489
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 15:31:41.145
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 15:31:41.020
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 15:24:52.034
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 15:24:51.954
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 02:06:20.738
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 02:06:20.627
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 01:53:10.761
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
  Date: 2016-02-23 01:53:10.657
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\btmaux.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-3615QM CPU @ 2.30GHz
Percentage of memory in use: 29%
Total physical RAM: 7973.53 MB
Available physical RAM: 5658.3 MB
Total Virtual: 15945.27 MB
Available Virtual: 13324.95 MB
 
==================== Drives ================================
 
Drive b: (Backup) (Fixed) (Total:300 GB) (Free:299.9 GB) NTFS
Drive c: () (Fixed) (Total:609.52 GB) (Free:329.57 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 816B67ED)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=609.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=300 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=21.9 GB) - (Type=27)
 
========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: 74F02DEA)
Partition 1: (Not Active) - (Size=7.5 GB) - (Type=73)
 
==================== End of Addition.txt ============================

You have Microsoft Essentials that may be infected as I see many entries from all different parts of the world. I am including them in the new fix, it wont remove them but they are hidden in your Programs and Features in the Control Panel, after you run the fix I would uninstall them and lets see if it helps

 

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
SearchScopes: HKLM-x32 -> DefaultScope value is missing
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Saving the file as "Fixlist.txt" to "Notepad" says:  

"This file contains characters in Unicode format which will be lost if you save this file as an ANSI encoded text file.  To keep the Unicode information, click Cancel below and then select one of the Unicode options from the Encoding drop down list. Continue?"

The options given are: ANSI, Unicode, Unicode big endian, and UTF-8

 

ken 545, which option should I use?

Also, I use the paid version of Zenmate as a proxy server, would this have anything to do with -  ken545 said: "

 

You have Microsoft Essentials that may be infected as I see many entries from all different parts of the world."

_________________________________________________________________

I also use Technitium (TMAC 6) MAC address changer (which is currently turned off and blocked by Kaspersky Application Control (which I did when I first started having trouble with the computer (I got the file from "Gizmo's freeware" (a site for open source software - which I checked with "Virus Total" before installing). But I have noticed some weird stuff that I didn't install that was in a different language I don't understand (e.g. mawebcontrol.exe had some non-english characters following it which seem to have disappeared since the first "
Fixlist.txt " script you had me run) but that I did not uninstall it - but I did block it with Kaspersky's Application Control and Firewall.

Whatever the issue may be I will follow your directions because you are the expert - not me!

Thank You again ken545 for Your Time and Expertise! :)

As far as Microsoft Essentials, I would err on the bad side and uninstall  it just to be sure

 

When you save Fixlist, on the Unicode tab , just save it as unicode

Thank You Again ken545! :)

Here is the log you requested:
 

Fix result of Farbar Recovery Scan Tool (x64) Version:20-02-2016
Ran by [removed] (2016-02-24 08:10:35) Run:2
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\…\Policies\Explorer: [NoStartMenuSubFolders] 0
SearchScopes: HKLM-x32 -> DefaultScope value is missing
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value not found.
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{19ADD3BF-C42B-47DC-81C6-5E9731B668C4}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2720009D-9566-45A7-A370-0E6DAC313F3F}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{122800FE-3AAF-4974-9FBD-54B023FA756A}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C877E454-FA36-409A-A00E-1240CEC61BBD}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C00C2A91-6CB3-483F-80B3-2958E29468F1}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E83DC314-C926-4214-AD58-147691D6FE9F}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B63F0CE3-CCD0-490A-9A9C-E1A3B3A17137}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{77F69CA1-E53D-4D77-8BA3-FA07606CC851}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4444F27C-B1A8-464E-9486-4C37BAB39A09}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CE929F09-3853-4180-BD90-30764BFF7136}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0A4C4B29-5A9D-4910-A13C-B920D5758744}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FBCA06D2-4642-4F33-B20A-A7AB3F0D2E69}\\SystemComponent => value removed successfully
"HKU\.DEFAULT\Software\Classes\exefile" => key removed successfully
"HKU\.DEFAULT\Software\Classes\.exe" => key removed successfully
HKU\.DEFAULT\Software\Classes\exefile => key not found. 
"HKU\S-1-5-19\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-19\Software\Classes\.exe" => key removed successfully
HKU\S-1-5-19\Software\Classes\exefile => key not found. 
"HKU\S-1-5-20\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-20\Software\Classes\.exe" => key removed successfully
HKU\S-1-5-20\Software\Classes\exefile => key not found. 
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\.exe => key not found. 
HKU\S-1-5-21-3575110223-3707097088-2884409191-1000\Software\Classes\exefile => key not found. 
"HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\exefile" => key removed successfully
"HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\.exe" => key removed successfully
HKU\S-1-5-21-3575110223-3707097088-2884409191-1001\Software\Classes\exefile => key not found. 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not restore Hosts.
EmptyTemp: => 75 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 08:11:21 ====



Are you saying that I should uninstall "Windows Live Essentials 2011"?  It is the only thing on the "Programs and Features" section that says anything about "Windows Essentials" . . . . . or are you talking about something else?

Thank You Again for Your Time and Expertise!  You will never know how much I truly appreciate Your help ! ! ! ! !

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI