[removed]
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe
(Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2016.27.2.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist Corporate\1165\G2AWinLogon_x64.dll (Citrix Systems, Inc.)
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\Run: [Akamai NetSession Interface] => "C:\Users\DA BOSS\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3014224 2016-02-04] (Valve Corporation)
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\RunOnce: [Uninstall C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\MountPoints2: {ef953357-aab6-11e5-8627-806e6f6e6963} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL D:\autorun.exe
HKU\S-1-5-18\…\Run: [Bomgar_Cleanup_ZD8417113481] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x56951c5b" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD8417113481 /f
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-01-06]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PlutoTV.lnk [2016-01-01]
ShortcutTarget: PlutoTV.lnk -> C:\Program Files (x86)\Pluto TV\PlutoTV.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2016-01-06]
ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-01-06]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{241d82c6-d063-405d-86af-ac08c48d4ceb}: [DhcpNameServer] 192.168.10.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2016-01-21] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2016-01-21] (Oracle Corporation)
FireFox:
========
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2016-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2016-01-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @citrixonline.com/appdetectorplugin -> C:\Users\DA BOSS\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-02-22] (Citrix Online)
FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @nsroblox.roblox.com/launcher -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.e-hawks.org/
CHR StartupUrls: Default -> "hxxp://astromenda.com/?f=7&a;=ast_secureddownload_14_36_ch&cd;=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0SzyyBzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEyCzz0EtDyDtG0BtAzyyBtGzzzz0E0DtGtD0FyDyEtGtD0Ezyzy0Czz0FtA0FzzyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0F0AyCzy0DtA0CtGtA0Ezz0EtGyEtCyDtBtGzz0AtCtAtGtA0AzzzztByEtBtB0CtCyD0E2Q&cr;=284385966&ir;=","hxxp://www.dregol.com/?f=7&a;=drg_suma_15_22&cd;=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByEyEtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StCtCyDtC0B0E0A0DtGtC0DtC0BtGtCtCtC0CtGyBzytDtCtGzzyD0F0AtAtC0FzyyE0B0Ezy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FtD0C0A0ByByEtG0AtC0F0FtGyE0A0A0CtGzy0AzytCtGzyyBtDzyyEzyzztByC0F0DyD2QtN0A0LzuyE&cr;=1770093444&ir;=","hxxp://www.trovi.com/?gd=&ctid;=CT3324769&octid;=EB_ORIGINAL_CTID&ISID;=M31A5AC2F-450E-4BEE-A3CA-CAAD8FD8C08A&SearchSource;=55&CUI;=&UM;=8&UP;=SP44FB3AA5-CFC4-4DA6-9FD1-4F7E9DE3B678&D;=061315&SSPV;=","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp;=yhs-fullyhosted_003&type;=wncy_suma_15_24¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAtAtBzyyBtGyByCyE0BtG0F0D0DtDtGyB0B0A0BtGzy0EtDyDtD0CtDzyyBtDtBtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0B0EyE0CzztDtCtG0AyEtByDtGyE0DzztAtGzyyEtC0AtG0D0DyDtB0C0C0B0CtB0CyBtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26cr%3D929903380%26a%3Dwncy_suma_15_24%26os%3DWindows 7 Home Premium","hxxp://blueearthlibrary.wordpress.com/"
CHR DefaultSearchURL: Default -> hxxp://musix.searchalgo.com/search/?category=web&s;=msds&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> goMusix
CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms}
CHR Profile: C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-25]
CHR Extension: (Theme Creator) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2016-01-09]
CHR Extension: (Google Docs) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-25]
CHR Extension: (Google Drive) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-25]
CHR Extension: (Dark Skin for Youtube™) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfeknfgchonpnofdjokchhdhdnddhglm [2016-02-17]
CHR Extension: (YouTube) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-25]
CHR Extension: (Thesaurus.com - Synonyms and Antonyms) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\clljlcapeomdokpgadmegpabakieebci [2016-01-10]
CHR Extension: (Google Search) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-25]
CHR Extension: (Easy Theme Maker For YouTube™) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehljkohidokkiifnnamkgpmhjagfckig [2016-01-09]
CHR Extension: (Pizza Snake) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\eladgefgfablffmdbgbllikigaaehjbd [2016-01-19]
CHR Extension: (Google Sheets) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-25]
CHR Extension: (Google Docs Offline) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-26]
CHR Extension: (Dictionary by Dictionary.com) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2016-01-10]
CHR Extension: (TerasGames) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gllefgmldkgbcdljkifdinlimdjahilh [2016-01-10]
CHR Extension: (Paste 'Lorem ipsum…') - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihmllonaidjepimjdhjdcgodgekcmhop [2016-01-10]
CHR Extension: (Dictionary Lookup) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipdjaafajlfiopcppipdinmcjbcpofhd [2016-01-10]
CHR Extension: (Cut the Rope) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2016-01-10]
CHR Extension: (Penzu) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\khgpedpfmjojllfmmhfabemdelhncneo [2016-01-10]
CHR Extension: (Thesaurus: Synonym 4 Right Click) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpkpcliecpgjbkffooidajhakoidhidh [2016-01-10]
CHR Extension: (Quebles Emoticons) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\macpddegmcklbbnbdemccckkmhaegdlf [2016-02-23]
CHR Extension: (Google Play Books) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2016-01-10]
CHR Extension: (SiriusXM) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbbdoippffioahmjdapnadeelifajhco [2016-01-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-25]
CHR Extension: (Gmail) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-25]
CHR Profile: C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-10]
CHR Extension: (Google Docs) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-10]
CHR Extension: (Google Drive) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-10]
CHR Extension: (YouTube) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-10]
CHR Extension: (Google Search) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-10]
CHR Extension: (Google Sheets) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-10]
CHR Extension: (Google Docs Offline) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-10]
CHR Extension: (Gmail) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-10]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 GoToAssist; C:\Program Files (x86)\Citrix\GoToAssist Corporate\1165\G2AC_Service.exe [309720 2016-02-22] (Citrix Systems, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 AntiRansomwareService; C:\Users\DA BOSS\Desktop\New folder\arservice.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 8AFAE51F; C:\Windows\System32\drivers\8AFAE51F.sys [478392 2016-02-22] (Kaspersky Lab ZAO)
S3 BCMTPM; C:\Windows\System32\drivers\btpmwx64.sys [32096 2013-03-07] (Broadcom Corp.)
R3 dot4; C:\Windows\System32\drivers\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 e1kexpress; C:\Windows\system32\DRIVERS\e1k63x64.sys [498032 2013-02-20] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-02-24] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S1 KbHook; \??\C:\Users\DA BOSS\Desktop\New folder\hookdriver64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-24 09:03 - 2016-02-24 09:03 - 00003294 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003242 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003238 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003210 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003206 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
2016-02-24 09:02 - 2016-02-24 09:02 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center
2016-02-23 17:34 - 2016-02-23 19:04 - 00021851 _____ C:\Users\DA BOSS\Desktop\Addition.txt
2016-02-23 17:32 - 2016-02-24 09:05 - 00016715 _____ C:\Users\DA BOSS\Desktop\FRST.txt
2016-02-23 14:52 - 2016-02-24 08:52 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-02-23 14:48 - 2016-02-23 14:48 - 00001180 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-02-23 14:48 - 2016-02-23 14:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-02-23 14:48 - 2016-02-23 14:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-23 14:48 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-02-23 14:48 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-02-23 14:48 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-02-23 14:47 - 2016-02-23 14:48 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024 (2).exe
2016-02-23 14:47 - 2016-02-23 14:47 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024 (1).exe
2016-02-23 11:44 - 2016-02-23 11:44 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-23 11:42 - 2016-02-23 11:43 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024.exe
2016-02-23 11:40 - 2016-02-23 11:40 - 00000999 _____ C:\Users\DA BOSS\Desktop\JRT.txt
2016-02-23 11:37 - 2016-02-23 11:38 - 01609216 _____ (Malwarebytes) C:\Users\DA BOSS\Desktop\JRT.exe
2016-02-23 11:25 - 2016-02-23 11:30 - 00000000 ____D C:\AdwCleaner
2016-02-23 11:25 - 2016-02-23 11:25 - 01511936 _____ C:\Users\DA BOSS\Desktop\AdwCleaner.exe
2016-02-23 10:52 - 2016-02-23 19:39 - 00002913 _____ C:\Users\DA BOSS\Desktop\Fixlog.txt
2016-02-22 19:36 - 2016-02-22 19:37 - 14454784 _____ C:\Users\DA BOSS\Downloads\OPSWAT_GEARS_CLIENT_3445-7c867995737c1853977386e89a5560c5.msi
2016-02-22 18:03 - 2016-02-23 08:19 - 00022423 _____ C:\Users\DA BOSS\Downloads\Addition.txt
2016-02-22 17:58 - 2016-02-23 08:19 - 00047128 _____ C:\Users\DA BOSS\Downloads\FRST.txt
2016-02-22 17:58 - 2016-02-22 17:58 - 00001691 _____ C:\Users\DA BOSS\Documents\aswMBR scan.txt
2016-02-22 17:58 - 2016-02-22 17:58 - 00000512 _____ C:\Users\DA BOSS\Documents\MBR.dat
2016-02-22 17:45 - 2016-02-24 09:04 - 00000000 ____D C:\FRST
2016-02-22 17:45 - 2016-02-22 17:45 - 02371072 _____ (Farbar) C:\Users\DA BOSS\Desktop\FRST64.exe
2016-02-22 17:41 - 2016-02-22 17:42 - 05198336 _____ (AVAST Software) C:\Users\DA BOSS\Downloads\aswMBR.exe
2016-02-22 10:01 - 2016-02-22 17:27 - 00000000 ____D C:\KVRT_Data
2016-02-22 10:01 - 2016-02-22 10:01 - 00478392 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\8AFAE51F.sys
2016-02-22 09:56 - 2016-02-22 10:01 - 89499032 _____ (Kaspersky Lab ZAO) C:\Users\DA BOSS\Downloads\KVRT.exe
2016-02-22 09:54 - 2016-02-22 09:55 - 00003022 _____ C:\Users\DA BOSS\Desktop\Rkill.txt
2016-02-22 09:54 - 2016-02-22 09:54 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\DA BOSS\Downloads\rkill.exe
2016-02-22 09:46 - 2016-02-22 10:00 - 00473810 _____ C:\TDSSKiller.3.1.0.9_22.02.2016_09.46.30_log.txt
2016-02-22 09:45 - 2016-02-22 09:46 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\DA BOSS\Downloads\tdsskiller.exe
2016-02-22 09:20 - 2016-02-22 09:20 - 00000000 ____D C:\Program Files (x86)\Citrix
2016-02-22 09:08 - 2016-02-22 09:08 - 00000000 ____D C:\ProgramData\MFAData
2016-02-22 09:03 - 2016-02-22 09:42 - 00000000 ____D C:\ProgramData\Avg
2016-02-22 08:56 - 2016-02-22 08:57 - 16902256 _____ (AVG Technologies) C:\Users\DA BOSS\Downloads\avg_gsr_stb_all_ltst_103.exe
2016-02-22 08:55 - 2016-02-22 08:55 - 04721416 _____ (AVG Technologies) C:\Users\DA BOSS\Downloads\avg_avc_stb_all_2015_5267_dvd.exe
2016-02-21 20:57 - 2016-02-21 21:03 - 29562180 _____ C:\Users\DA BOSS\Desktop\mapleshade1.mp4
2016-02-21 02:24 - 2016-02-21 02:24 - 00551326 _____ C:\Users\DA BOSS\Documents\Attorney Disciplinary Board letter.pdf
2016-02-20 07:38 - 2016-02-20 07:45 - 27243939 _____ C:\Users\DA BOSS\Desktop\stickyspeed.mp4
2016-02-19 21:40 - 2016-02-19 21:49 - 25978941 _____ C:\Users\DA BOSS\Desktop\goooster.mp4
2016-02-19 10:19 - 2016-02-19 10:19 - 00969584 _____ (ROBLOX Corporation) C:\Users\DA BOSS\Downloads\RobloxPlayerLauncher (11).exe
2016-02-19 07:30 - 2016-02-19 07:30 - 17389123 _____ C:\Users\DA BOSS\Downloads\feline_reference__free_lineart_by_espherio-d6butdt.psd
2016-02-16 17:07 - 2016-02-16 17:11 - 18114011 _____ C:\Users\DA BOSS\Desktop\ty.mp4
2016-02-16 16:51 - 2016-02-16 16:51 - 00117065 _____ C:\Users\DA BOSS\Desktop\animation.mp4
2016-02-15 14:39 - 2016-02-15 14:42 - 19420551 _____ C:\Users\DA BOSS\Desktop\undynesucks.mp4
2016-02-15 09:13 - 2016-02-15 09:14 - 14115600 _____ (LogMeIn, Inc.) C:\Users\DA BOSS\Downloads\join.me.exe
2016-02-14 10:25 - 2016-02-14 10:28 - 05641248 _____ C:\Users\DA BOSS\Desktop\ripgoatmom.mp4
2016-02-09 17:07 - 2016-02-09 17:07 - 01706448 _____ C:\Users\DA BOSS\Downloads\psd_cat_line_by_kawiku-d8nuwmj.psd
2016-02-09 16:07 - 2016-01-26 23:55 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-02-09 16:07 - 2016-01-26 23:45 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-02-09 16:07 - 2016-01-26 23:45 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-02-09 16:07 - 2016-01-26 23:37 - 01998176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-02-09 16:07 - 2016-01-26 23:10 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-02-09 16:07 - 2016-01-26 23:05 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-02-09 16:07 - 2016-01-26 23:04 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-02-09 16:07 - 2016-01-26 22:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-02-09 16:07 - 2016-01-26 22:55 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-02-09 16:07 - 2016-01-26 22:54 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-02-09 16:07 - 2016-01-26 22:48 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-02-09 16:07 - 2016-01-26 22:41 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-02-09 16:07 - 2016-01-26 22:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-09 16:06 - 2016-01-29 00:57 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-09 16:06 - 2016-01-29 00:33 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-02-09 16:06 - 2016-01-27 00:15 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-02-09 16:06 - 2016-01-27 00:15 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-02-09 16:06 - 2016-01-27 00:01 - 07476064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-02-09 16:06 - 2016-01-27 00:01 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-02-09 16:06 - 2016-01-27 00:01 - 01819720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-02-09 16:06 - 2016-01-26 23:59 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-09 16:06 - 2016-01-26 23:57 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-02-09 16:06 - 2016-01-26 23:57 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-09 16:06 - 2016-01-26 23:57 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-09 16:06 - 2016-01-26 23:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-02-09 16:06 - 2016-01-26 23:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-02-09 16:06 - 2016-01-26 23:54 - 00295264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-02-09 16:06 - 2016-01-26 23:46 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-09 16:06 - 2016-01-26 23:46 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-09 16:06 - 2016-01-26 23:44 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-09 16:06 - 2016-01-26 23:44 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-09 16:06 - 2016-01-26 23:43 - 00359776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-02-09 16:06 - 2016-01-26 23:37 - 00576352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-02-09 16:06 - 2016-01-26 23:21 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-09 16:06 - 2016-01-26 23:15 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-02-09 16:06 - 2016-01-26 23:13 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-02-09 16:06 - 2016-01-26 23:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-02-09 16:06 - 2016-01-26 23:11 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-09 16:06 - 2016-01-26 23:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-09 16:06 - 2016-01-26 23:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-09 16:06 - 2016-01-26 23:08 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-09 16:06 - 2016-01-26 23:07 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-02-09 16:06 - 2016-01-26 23:05 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-02-09 16:06 - 2016-01-26 23:05 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-02-09 16:06 - 2016-01-26 23:05 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-02-09 16:06 - 2016-01-26 23:04 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-09 16:06 - 2016-01-26 23:03 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-02-09 16:06 - 2016-01-26 23:02 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-09 16:06 - 2016-01-26 23:01 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-09 16:06 - 2016-01-26 22:59 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-09 16:06 - 2016-01-26 22:57 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-02-09 16:06 - 2016-01-26 22:55 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-02-09 16:06 - 2016-01-26 22:52 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-09 16:06 - 2016-01-26 22:50 - 02230784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-02-09 16:06 - 2016-01-26 22:50 - 01504768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-02-09 16:06 - 2016-01-26 22:50 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-09 16:06 - 2016-01-26 22:49 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-02-09 16:06 - 2016-01-26 22:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-09 16:06 - 2016-01-26 22:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-09 16:06 - 2016-01-26 22:39 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-02-09 16:06 - 2016-01-26 22:38 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-02-09 16:06 - 2016-01-26 22:38 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-02-09 16:06 - 2016-01-26 22:37 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-02-09 16:06 - 2016-01-26 22:36 - 02757120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-02-09 16:06 - 2016-01-26 22:31 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-08 10:40 - 2016-02-08 10:56 - 90623834 _____ C:\Users\DA BOSS\Desktop\glados.mp4
2016-02-08 10:10 - 2016-02-08 10:22 - 21751507 _____ C:\Users\DA BOSS\Desktop\glados2.mp4
2016-02-08 09:43 - 2016-02-08 09:52 - 21788345 _____ C:\Users\DA BOSS\Desktop\glados1.mp4
2016-02-06 19:17 - 2016-02-06 19:17 - 00058773 _____ C:\Users\DA BOSS\Downloads\splat_brushes_by_mo_fox-d92re6o.zip
2016-02-06 15:52 - 2016-02-06 16:04 - 61439629 _____ C:\Users\DA BOSS\Desktop\themesongs.mp4
2016-02-06 15:38 - 2016-02-06 15:39 - 13698187 _____ C:\Users\DA BOSS\Downloads\Nyan Cat [original].mp4
2016-02-06 14:41 - 2016-02-06 14:42 - 16642767 _____ C:\Users\DA BOSS\Downloads\Undertale - Know you'll always be inside my heart (A song for Toriel).mp4
2016-02-06 14:33 - 2016-02-06 14:34 - 32445007 _____ C:\Users\DA BOSS\Downloads\Undertale - Blue Lips.mp4
2016-02-02 19:35 - 2016-02-02 19:35 - 00003334 _____ C:\Users\DA BOSS\Documents\My Movie.wlmp
2016-02-02 18:30 - 2016-02-02 18:46 - 13965500 _____ C:\Users\DA BOSS\Desktop\nightmare2.mp4
2016-02-02 18:05 - 2016-02-02 18:12 - 10262300 _____ C:\Users\DA BOSS\Desktop\nightmare1.mp4
2016-02-02 13:32 - 2016-02-02 13:32 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart (2).zip
2016-02-02 13:32 - 2016-02-02 13:32 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart (1).zip
2016-02-02 13:30 - 2016-02-02 13:30 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart.zip
2016-01-27 17:15 - 2016-01-27 17:43 - 29471433 _____ C:\Users\DA BOSS\Desktop\blue.mp4
2016-01-27 16:35 - 2016-01-16 00:37 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-01-27 16:35 - 2016-01-16 00:36 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-27 16:35 - 2016-01-16 00:36 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-01-27 16:35 - 2016-01-16 00:34 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-27 16:35 - 2016-01-16 00:24 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 08728920 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-01-27 16:35 - 2016-01-16 00:21 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-01-27 16:35 - 2016-01-16 00:20 - 06971752 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-01-27 16:35 - 2016-01-16 00:20 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-01-27 16:35 - 2016-01-16 00:20 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-01-27 16:35 - 2016-01-16 00:20 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-01-27 16:35 - 2016-01-16 00:19 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-01-27 16:35 - 2016-01-16 00:19 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-01-27 16:35 - 2016-01-16 00:12 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-01-27 16:35 - 2016-01-16 00:09 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-01-27 16:35 - 2016-01-16 00:08 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-01-27 16:35 - 2016-01-16 00:08 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-01-27 16:35 - 2016-01-15 23:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-01-27 16:35 - 2016-01-15 23:45 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-27 16:35 - 2016-01-15 23:44 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-01-27 16:35 - 2016-01-15 23:42 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-27 16:35 - 2016-01-15 23:41 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-01-27 16:35 - 2016-01-15 23:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-01-27 16:35 - 2016-01-15 23:40 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-01-27 16:35 - 2016-01-15 23:39 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-01-27 16:35 - 2016-01-15 23:38 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-01-27 16:35 - 2016-01-15 23:38 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-01-27 16:35 - 2016-01-15 23:38 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-01-27 16:35 - 2016-01-15 23:36 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-01-27 16:35 - 2016-01-15 23:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2016-01-27 16:35 - 2016-01-15 23:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-01-27 16:35 - 2016-01-15 23:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-01-27 16:35 - 2016-01-15 23:35 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-01-27 16:35 - 2016-01-15 23:35 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-27 16:35 - 2016-01-15 23:33 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-01-27 16:35 - 2016-01-15 23:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-01-27 16:35 - 2016-01-15 23:33 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-01-27 16:35 - 2016-01-15 23:32 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-01-27 16:35 - 2016-01-15 23:32 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-01-27 16:35 - 2016-01-15 23:31 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-01-27 16:35 - 2016-01-15 23:30 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-01-27 16:35 - 2016-01-15 23:30 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-01-27 16:35 - 2016-01-15 23:30 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-01-27 16:35 - 2016-01-15 23:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-01-27 16:35 - 2016-01-15 23:29 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-01-27 16:35 - 2016-01-15 23:29 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-01-27 16:35 - 2016-01-15 23:27 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-27 16:35 - 2016-01-15 23:25 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-01-27 16:35 - 2016-01-15 23:25 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-01-27 16:35 - 2016-01-15 23:25 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-01-27 16:35 - 2016-01-15 23:23 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-01-27 16:35 - 2016-01-15 23:23 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-01-27 16:35 - 2016-01-15 23:21 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-01-27 16:35 - 2016-01-15 23:18 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-27 16:35 - 2016-01-15 23:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-01-27 16:35 - 2016-01-15 23:16 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-01-27 16:35 - 2016-01-15 23:16 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-01-27 16:35 - 2016-01-15 23:15 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-01-27 16:35 - 2016-01-15 23:14 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-01-27 16:35 - 2016-01-15 23:14 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-01-27 16:35 - 2016-01-15 23:11 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-01-27 16:34 - 2016-01-15 23:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-01-27 16:34 - 2016-01-15 23:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-01-27 16:34 - 2016-01-15 23:43 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-01-27 16:34 - 2016-01-15 23:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-01-27 16:34 - 2016-01-15 23:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-01-27 16:34 - 2016-01-15 23:38 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-01-27 16:34 - 2016-01-15 23:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-01-27 16:34 - 2016-01-15 23:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-01-27 16:34 - 2016-01-15 23:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-01-27 16:34 - 2016-01-15 23:30 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-01-26 18:14 - 2016-01-26 18:14 - 04388394 _____ C:\Users\DA BOSS\Desktop\asgoresucks.mp4
2016-01-25 09:34 - 2016-01-25 09:34 - 09286495 _____ C:\Users\DA BOSS\Desktop\danceparty.mp4
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-24 08:53 - 2016-01-24 12:46 - 00000000 ____D C:\Program Files (x86)\Steam
2016-02-24 08:53 - 2015-12-25 16:18 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-24 08:49 - 2015-12-24 21:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-24 08:47 - 2015-12-24 19:24 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-02-24 07:36 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-23 22:29 - 2015-12-25 16:18 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-23 10:54 - 2016-01-18 08:48 - 00000000 ____D C:\Users\DA BOSS\AppData\LocalLow\Temp
2016-02-23 07:25 - 2015-12-24 19:41 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-23 07:21 - 2016-01-12 10:40 - 00004172 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D78140DC-BA3F-44E1-A6F3-4CE6760938C8}
2016-02-22 08:53 - 2015-12-24 19:40 - 00000000 ____D C:\WINDOWS\INF
2016-02-22 08:53 - 2015-12-24 19:38 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-21 13:24 - 2015-12-24 19:44 - 00000000 ____D C:\Users\DA BOSS
2016-02-21 12:04 - 2015-12-24 19:45 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-19 18:31 - 2015-12-25 16:19 - 00002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-19 18:31 - 2015-12-25 16:19 - 00002295 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-18 09:16 - 2016-01-05 16:49 - 00000000 ____D C:\Users\DA BOSS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2016-02-13 08:30 - 2015-12-25 02:53 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-13 08:25 - 2015-12-25 02:53 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-11 04:12 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\rescache
2016-02-11 03:31 - 2015-12-24 19:41 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-09 16:35 - 2015-12-24 19:31 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-02-04 19:32 - 2015-12-24 19:48 - 00002378 _____ C:\Users\DA BOSS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-04 19:32 - 2015-12-24 19:48 - 00000000 ___RD C:\Users\DA BOSS\OneDrive
2016-02-03 13:01 - 2015-12-24 19:44 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-02-03 13:01 - 2015-12-24 19:44 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-03 07:40 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-02 08:24 - 2015-12-25 16:18 - 00003996 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-02 08:24 - 2015-12-25 16:18 - 00003764 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\bcastdvr
==================== Files in the root of some directories =======
2016-01-06 10:55 - 2016-01-06 10:55 - 0168688 _____ () C:\Users\DA BOSS\AppData\Local\ars.cache
2016-01-06 10:55 - 2016-01-06 10:55 - 0484539 _____ () C:\Users\DA BOSS\AppData\Local\census.cache
2016-01-06 10:37 - 2016-01-06 10:37 - 0000036 _____ () C:\Users\DA BOSS\AppData\Local\housecall.guid.cache
2016-01-12 11:27 - 2015-10-31 10:09 - 0016800 _____ () C:\Users\DA BOSS\AppData\Local\Z@!-812c0ff4-c71f-4a96-bf01-72061ea46366.tmp
2016-01-12 11:27 - 2015-10-31 10:09 - 0015776 _____ () C:\Users\DA BOSS\AppData\Local\Z@S!-24ec7c9a-3b4e-46c5-83fb-48f825374dcf.tmp
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-02-22 19:48
==================== End of FRST.txt ============================
Addition
Additional scan result of Farbar Recovery Scan Tool (x64) Version:21-02-2016 01
Ran by [removed] (2016-02-24 09:06:34)
Running from C:\Users\[removed]\Desktop
Windows 10 Pro Version 1511 (X64) (2015-12-25 01:42:02)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4012266320-2666871660-1620693866-500 - Administrator - Disabled)
DA BOSS (S-1-5-21-4012266320-2666871660-1620693866-1001 - Administrator - Enabled) => C:\Users\DA BOSS
DefaultAccount (S-1-5-21-4012266320-2666871660-1620693866-503 - Limited - Disabled)
Guest (S-1-5-21-4012266320-2666871660-1620693866-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Citrix Online Launcher (HKLM-x32\…\{09DA5EE2-7E46-4DC4-96F9-BFEE50D40659}) (Version: 1.0.408 - Citrix)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
FireAlpaca 1.5.4 (HKLM-x32\…\FireAlpaca_is1) (Version: 1.5.4 - firealpaca.com)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
GoToAssist Corporate (HKLM-x32\…\GoToAssist) (Version: 11.5.0.1165 - Citrix Systems, Inc.)
Java 8 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MP3 Rocket (HKLM-x32\…\MP3 Rocket) (Version: 7.3.2 - MP3 Rocket Inc)
Pluto TV version 0.1.5 (HKLM-x32\…\Pluto TV_is1) (Version: 0.1.5 - Pluto TV)
ROBLOX Player for DA BOSS (HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
Screen Recorder Launcher (HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\ScreenRecorderLauncher) (Version: 2.0 - )
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Undertale (HKLM-x32\…\Steam App 391540) (Version: - tobyfox)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinZip 20.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EF}) (Version: 20.0.11659 - WinZip Computing, S.L. )
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4012266320-2666871660-1620693866-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4012266320-2666871660-1620693866-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\RobloxProxy64.dll (ROBLOX Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1381603E-888C-4BAC-AFCD-FF0BEE46523C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {189C82D6-61B0-4CA8-9552-BCAB4A941126} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-25] (Google Inc.)
Task: {45FE7E69-05B9-438A-BF9B-8FE739238B3F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {74A5EFF7-E6CD-4D1D-9603-4B47A0688ABC} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {75A4B00B-C858-46A3-9B53-05D77A47302C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-02-13] (Microsoft Corporation)
Task: {9B93864C-6C50-41F3-B50E-49914EA9E474} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {FBB3A31C-554C-488A-9004-FAE7010F9727} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {FE19808B-D482-4650-A0B2-5BE941CB2890} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-25] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-10-30 01:18 - 2015-10-30 01:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-15 14:29 - 2015-12-15 14:29 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-21 17:21 - 2016-01-21 17:21 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-15 14:29 - 2015-12-15 14:29 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-19 08:39 - 2015-12-06 22:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-12-19 08:39 - 2015-12-06 22:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-12-19 08:39 - 2015-12-06 22:00 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-01-13 16:43 - 2016-01-04 19:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 16:43 - 2016-01-04 19:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-27 16:35 - 2016-01-15 23:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-27 16:35 - 2016-01-15 23:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-02-11 15:16 - 2016-02-11 15:16 - 09789952 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2016.27.2.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
2016-01-21 17:21 - 2016-01-21 17:21 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 17:21 - 2016-01-21 17:21 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-01-24 12:50 - 2015-12-14 23:54 - 00782336 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2016-01-24 12:50 - 2015-07-03 10:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2016-01-24 12:50 - 2016-02-04 15:02 - 02546768 _____ () C:\Program Files (x86)\Steam\video.dll
2016-01-24 12:50 - 2015-07-03 10:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2016-01-24 12:50 - 2015-07-03 10:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 02549248 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2016-01-24 12:50 - 2016-02-04 15:01 - 00802896 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2016-01-24 12:50 - 2015-12-29 19:51 - 00208896 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
2016-01-24 12:50 - 2016-01-05 19:52 - 48387872 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2016-02-19 18:31 - 2016-02-17 22:14 - 01630360 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libglesv2.dll
2016-02-19 18:31 - 2016-02-17 22:14 - 00085656 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\8AFAE51F.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\8AFAE51F.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-12-24 19:42 - 2016-02-23 19:39 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\DA BOSS\Pictures\Saved Pictures\derp.jpg
DNS Servers: 192.168.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\…\StartupApproved\StartupFolder: => "PlutoTV.lnk"
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\StartupApproved\Run: => "Akamai NetSession Interface"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{863FC78E-490D-46AA-90D4-B59158E66BA9}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [UDP Query User{BC2C0168-839A-476D-B537-8B51BA152A2E}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [TCP Query User{5B7A5442-6A7F-4DB9-B74A-1AF185800D3B}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{321CEA1A-1FFC-4032-9E58-FE355EDE15CF}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{609E46B9-8B05-4FEF-A7C4-915FA7B73206}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{31B8E3BF-E6AD-4AEF-A4CC-23A4A945AB15}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5364B977-6148-4595-B93D-83D57D1CC971}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{B7C09D68-9DE3-4AC3-9EE2-87EA459D3F34}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{43495712-F6AD-45E9-9E58-42443766EAF0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe
FirewallRules: [{85F2C9F3-A1EF-4C1F-B582-EED0647937F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe
FirewallRules: [TCP Query User{77E6D1E3-8971-4BCD-B8C0-3452758F9205}C:\windows\temp\joi36cd.tmp\join.me.exe] => (Allow) C:\windows\temp\joi36cd.tmp\join.me.exe
FirewallRules: [UDP Query User{87AB4C41-D877-4579-9493-F55259411141}C:\windows\temp\joi36cd.tmp\join.me.exe] => (Allow) C:\windows\temp\joi36cd.tmp\join.me.exe
FirewallRules: [{B7B6F621-3BEF-444D-9123-0BC729880761}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
Could not list restore points
Check "winmgmt" service or repair WMI.
==================== Faulty Device Manager Devices =============
Could not list Devices. Check "winmgmt" service or repair WMI.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/24/2016 08:51:39 AM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
Error: (02/24/2016 07:30:42 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (02/23/2016 10:27:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (02/23/2016 07:45:35 PM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
Error: (02/23/2016 02:29:33 PM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
Error: (02/23/2016 02:23:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (02/23/2016 11:39:02 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (02/23/2016 11:35:45 AM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
Error: (02/23/2016 11:00:01 AM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
Error: (02/23/2016 10:21:52 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The rixdpcie service failed to start due to the following error:
%%1058
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The risdpcie service failed to start due to the following error:
%%1058
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The rimspci service failed to start due to the following error:
%%1058
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The rimmptsk service failed to start due to the following error:
%%1058
Error: (02/24/2016 08:49:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AntiRansomwareService service failed to start due to the following error:
%%2
Error: (02/24/2016 08:47:07 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_8c543 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (02/24/2016 08:47:06 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
Error: (02/24/2016 08:22:53 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
Error: (02/24/2016 07:30:42 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-A3GLD76)
Description: App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca
Error: (02/23/2016 11:05:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
CodeIntegrity:
===================================
Date: 2016-02-12 06:04:06.739
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-02-11 03:34:07.725
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-02-10 06:04:00.788
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-01-28 10:35:41.462
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-01-14 11:19:38.233
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-01-06 10:36:51.785
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-01-06 08:38:26.129
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-12-31 06:55:43.326
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-12-25 03:34:19.593
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2015-12-25 02:55:54.470
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E7400 @ 2.80GHz
Percentage of memory in use: 68%
Total physical RAM: 1995.61 MB
Available physical RAM: 633.81 MB
Total Virtual: 3083.61 MB
Available Virtual: 1402.91 MB
==================== Drives ================================
Drive c: (Smith) (Fixed) (Total:232.44 GB) (Free:204.64 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (AVG 2015 - b5267) (CDROM) (Total:0.55 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 9E9F8F83)
Partition 1: (Active) - (Size=232.4 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=449 MB) - (Type=27)
==================== End of Addition.txt ============================