This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My children are click happy and have destroyed my computer. Cannot ins

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:21-02-2016 01
Ran by [removed] (administrator) on DESKTOP-A3GLD76 (24-02-2016 09:04:41)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe
(Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2016.27.2.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist Corporate\1165\G2AWinLogon_x64.dll (Citrix Systems, Inc.)
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\Run: [Akamai NetSession Interface] => "C:\Users\DA BOSS\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3014224 2016-02-04] (Valve Corporation)
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\RunOnce: [Uninstall C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\MountPoints2: {ef953357-aab6-11e5-8627-806e6f6e6963} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL D:\autorun.exe
HKU\S-1-5-18\…\Run: [Bomgar_Cleanup_ZD8417113481] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x56951c5b" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD8417113481 /f
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-01-06]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PlutoTV.lnk [2016-01-01]
ShortcutTarget: PlutoTV.lnk -> C:\Program Files (x86)\Pluto TV\PlutoTV.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2016-01-06]
ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-01-06]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{241d82c6-d063-405d-86af-ac08c48d4ceb}: [DhcpNameServer] 192.168.10.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2016-01-21] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2016-01-21] (Oracle Corporation)
 
FireFox:
========
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2016-01-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2016-01-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @citrixonline.com/appdetectorplugin -> C:\Users\DA BOSS\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-02-22] (Citrix Online)
FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @nsroblox.roblox.com/launcher -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.e-hawks.org/
CHR StartupUrls: Default -> "hxxp://astromenda.com/?f=7&a;=ast_secureddownload_14_36_ch&cd;=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0SzyyBzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEyCzz0EtDyDtG0BtAzyyBtGzzzz0E0DtGtD0FyDyEtGtD0Ezyzy0Czz0FtA0FzzyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0F0AyCzy0DtA0CtGtA0Ezz0EtGyEtCyDtBtGzz0AtCtAtGtA0AzzzztByEtBtB0CtCyD0E2Q&cr;=284385966&ir;=","hxxp://www.dregol.com/?f=7&a;=drg_suma_15_22&cd;=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByEyEtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StCtCyDtC0B0E0A0DtGtC0DtC0BtGtCtCtC0CtGyBzytDtCtGzzyD0F0AtAtC0FzyyE0B0Ezy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FtD0C0A0ByByEtG0AtC0F0FtGyE0A0A0CtGzy0AzytCtGzyyBtDzyyEzyzztByC0F0DyD2QtN0A0LzuyE&cr;=1770093444&ir;=","hxxp://www.trovi.com/?gd=&ctid;=CT3324769&octid;=EB_ORIGINAL_CTID&ISID;=M31A5AC2F-450E-4BEE-A3CA-CAAD8FD8C08A&SearchSource;=55&CUI;=&UM;=8&UP;=SP44FB3AA5-CFC4-4DA6-9FD1-4F7E9DE3B678&D;=061315&SSPV;=","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp;=yhs-fullyhosted_003&type;=wncy_suma_15_24¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAtAtBzyyBtGyByCyE0BtG0F0D0DtDtGyB0B0A0BtGzy0EtDyDtD0CtDzyyBtDtBtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0B0EyE0CzztDtCtG0AyEtByDtGyE0DzztAtGzyyEtC0AtG0D0DyDtB0C0C0B0CtB0CyBtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26cr%3D929903380%26a%3Dwncy_suma_15_24%26os%3DWindows 7 Home Premium","hxxp://blueearthlibrary.wordpress.com/"
CHR DefaultSearchURL: Default -> hxxp://musix.searchalgo.com/search/?category=web&s;=msds&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> goMusix
CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms}
CHR Profile: C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-25]
CHR Extension: (Theme Creator) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2016-01-09]
CHR Extension: (Google Docs) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-25]
CHR Extension: (Google Drive) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-25]
CHR Extension: (Dark Skin for Youtube™) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfeknfgchonpnofdjokchhdhdnddhglm [2016-02-17]
CHR Extension: (YouTube) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-25]
CHR Extension: (Thesaurus.com - Synonyms and Antonyms) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\clljlcapeomdokpgadmegpabakieebci [2016-01-10]
CHR Extension: (Google Search) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-25]
CHR Extension: (Easy Theme Maker For YouTube™) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehljkohidokkiifnnamkgpmhjagfckig [2016-01-09]
CHR Extension: (Pizza Snake) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\eladgefgfablffmdbgbllikigaaehjbd [2016-01-19]
CHR Extension: (Google Sheets) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-25]
CHR Extension: (Google Docs Offline) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-26]
CHR Extension: (Dictionary by Dictionary.com) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2016-01-10]
CHR Extension: (TerasGames) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gllefgmldkgbcdljkifdinlimdjahilh [2016-01-10]
CHR Extension: (Paste 'Lorem ipsum…') - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihmllonaidjepimjdhjdcgodgekcmhop [2016-01-10]
CHR Extension: (Dictionary Lookup) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipdjaafajlfiopcppipdinmcjbcpofhd [2016-01-10]
CHR Extension: (Cut the Rope) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2016-01-10]
CHR Extension: (Penzu) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\khgpedpfmjojllfmmhfabemdelhncneo [2016-01-10]
CHR Extension: (Thesaurus: Synonym 4 Right Click) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpkpcliecpgjbkffooidajhakoidhidh [2016-01-10]
CHR Extension: (Quebles Emoticons) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\macpddegmcklbbnbdemccckkmhaegdlf [2016-02-23]
CHR Extension: (Google Play Books) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2016-01-10]
CHR Extension: (SiriusXM) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbbdoippffioahmjdapnadeelifajhco [2016-01-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-25]
CHR Extension: (Gmail) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-25]
CHR Profile: C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-10]
CHR Extension: (Google Docs) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-10]
CHR Extension: (Google Drive) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-10]
CHR Extension: (YouTube) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-10]
CHR Extension: (Google Search) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-10]
CHR Extension: (Google Sheets) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-10]
CHR Extension: (Google Docs Offline) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-10]
CHR Extension: (Gmail) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-10]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 GoToAssist; C:\Program Files (x86)\Citrix\GoToAssist Corporate\1165\G2AC_Service.exe [309720 2016-02-22] (Citrix Systems, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S2 AntiRansomwareService; C:\Users\DA BOSS\Desktop\New folder\arservice.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 8AFAE51F; C:\Windows\System32\drivers\8AFAE51F.sys [478392 2016-02-22] (Kaspersky Lab ZAO)
S3 BCMTPM; C:\Windows\System32\drivers\btpmwx64.sys [32096 2013-03-07] (Broadcom Corp.)
R3 dot4; C:\Windows\System32\drivers\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 e1kexpress; C:\Windows\system32\DRIVERS\e1k63x64.sys [498032 2013-02-20] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-02-24] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S1 KbHook; \??\C:\Users\DA BOSS\Desktop\New folder\hookdriver64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-24 09:03 - 2016-02-24 09:03 - 00003294 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003242 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003238 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003210 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00003206 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2016-02-24 09:03 - 2016-02-24 09:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
2016-02-24 09:02 - 2016-02-24 09:02 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center
2016-02-23 17:34 - 2016-02-23 19:04 - 00021851 _____ C:\Users\DA BOSS\Desktop\Addition.txt
2016-02-23 17:32 - 2016-02-24 09:05 - 00016715 _____ C:\Users\DA BOSS\Desktop\FRST.txt
2016-02-23 14:52 - 2016-02-24 08:52 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-02-23 14:48 - 2016-02-23 14:48 - 00001180 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-02-23 14:48 - 2016-02-23 14:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-02-23 14:48 - 2016-02-23 14:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-23 14:48 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-02-23 14:48 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-02-23 14:48 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-02-23 14:47 - 2016-02-23 14:48 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024 (2).exe
2016-02-23 14:47 - 2016-02-23 14:47 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024 (1).exe
2016-02-23 11:44 - 2016-02-23 11:44 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-23 11:42 - 2016-02-23 11:43 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024.exe
2016-02-23 11:40 - 2016-02-23 11:40 - 00000999 _____ C:\Users\DA BOSS\Desktop\JRT.txt
2016-02-23 11:37 - 2016-02-23 11:38 - 01609216 _____ (Malwarebytes) C:\Users\DA BOSS\Desktop\JRT.exe
2016-02-23 11:25 - 2016-02-23 11:30 - 00000000 ____D C:\AdwCleaner
2016-02-23 11:25 - 2016-02-23 11:25 - 01511936 _____ C:\Users\DA BOSS\Desktop\AdwCleaner.exe
2016-02-23 10:52 - 2016-02-23 19:39 - 00002913 _____ C:\Users\DA BOSS\Desktop\Fixlog.txt
2016-02-22 19:36 - 2016-02-22 19:37 - 14454784 _____ C:\Users\DA BOSS\Downloads\OPSWAT_GEARS_CLIENT_3445-7c867995737c1853977386e89a5560c5.msi
2016-02-22 18:03 - 2016-02-23 08:19 - 00022423 _____ C:\Users\DA BOSS\Downloads\Addition.txt
2016-02-22 17:58 - 2016-02-23 08:19 - 00047128 _____ C:\Users\DA BOSS\Downloads\FRST.txt
2016-02-22 17:58 - 2016-02-22 17:58 - 00001691 _____ C:\Users\DA BOSS\Documents\aswMBR scan.txt
2016-02-22 17:58 - 2016-02-22 17:58 - 00000512 _____ C:\Users\DA BOSS\Documents\MBR.dat
2016-02-22 17:45 - 2016-02-24 09:04 - 00000000 ____D C:\FRST
2016-02-22 17:45 - 2016-02-22 17:45 - 02371072 _____ (Farbar) C:\Users\DA BOSS\Desktop\FRST64.exe
2016-02-22 17:41 - 2016-02-22 17:42 - 05198336 _____ (AVAST Software) C:\Users\DA BOSS\Downloads\aswMBR.exe
2016-02-22 10:01 - 2016-02-22 17:27 - 00000000 ____D C:\KVRT_Data
2016-02-22 10:01 - 2016-02-22 10:01 - 00478392 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\8AFAE51F.sys
2016-02-22 09:56 - 2016-02-22 10:01 - 89499032 _____ (Kaspersky Lab ZAO) C:\Users\DA BOSS\Downloads\KVRT.exe
2016-02-22 09:54 - 2016-02-22 09:55 - 00003022 _____ C:\Users\DA BOSS\Desktop\Rkill.txt
2016-02-22 09:54 - 2016-02-22 09:54 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\DA BOSS\Downloads\rkill.exe
2016-02-22 09:46 - 2016-02-22 10:00 - 00473810 _____ C:\TDSSKiller.3.1.0.9_22.02.2016_09.46.30_log.txt
2016-02-22 09:45 - 2016-02-22 09:46 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\DA BOSS\Downloads\tdsskiller.exe
2016-02-22 09:20 - 2016-02-22 09:20 - 00000000 ____D C:\Program Files (x86)\Citrix
2016-02-22 09:08 - 2016-02-22 09:08 - 00000000 ____D C:\ProgramData\MFAData
2016-02-22 09:03 - 2016-02-22 09:42 - 00000000 ____D C:\ProgramData\Avg
2016-02-22 08:56 - 2016-02-22 08:57 - 16902256 _____ (AVG Technologies) C:\Users\DA BOSS\Downloads\avg_gsr_stb_all_ltst_103.exe
2016-02-22 08:55 - 2016-02-22 08:55 - 04721416 _____ (AVG Technologies) C:\Users\DA BOSS\Downloads\avg_avc_stb_all_2015_5267_dvd.exe
2016-02-21 20:57 - 2016-02-21 21:03 - 29562180 _____ C:\Users\DA BOSS\Desktop\mapleshade1.mp4
2016-02-21 02:24 - 2016-02-21 02:24 - 00551326 _____ C:\Users\DA BOSS\Documents\Attorney Disciplinary Board letter.pdf
2016-02-20 07:38 - 2016-02-20 07:45 - 27243939 _____ C:\Users\DA BOSS\Desktop\stickyspeed.mp4
2016-02-19 21:40 - 2016-02-19 21:49 - 25978941 _____ C:\Users\DA BOSS\Desktop\goooster.mp4
2016-02-19 10:19 - 2016-02-19 10:19 - 00969584 _____ (ROBLOX Corporation) C:\Users\DA BOSS\Downloads\RobloxPlayerLauncher (11).exe
2016-02-19 07:30 - 2016-02-19 07:30 - 17389123 _____ C:\Users\DA BOSS\Downloads\feline_reference__free_lineart_by_espherio-d6butdt.psd
2016-02-16 17:07 - 2016-02-16 17:11 - 18114011 _____ C:\Users\DA BOSS\Desktop\ty.mp4
2016-02-16 16:51 - 2016-02-16 16:51 - 00117065 _____ C:\Users\DA BOSS\Desktop\animation.mp4
2016-02-15 14:39 - 2016-02-15 14:42 - 19420551 _____ C:\Users\DA BOSS\Desktop\undynesucks.mp4
2016-02-15 09:13 - 2016-02-15 09:14 - 14115600 _____ (LogMeIn, Inc.) C:\Users\DA BOSS\Downloads\join.me.exe
2016-02-14 10:25 - 2016-02-14 10:28 - 05641248 _____ C:\Users\DA BOSS\Desktop\ripgoatmom.mp4
2016-02-09 17:07 - 2016-02-09 17:07 - 01706448 _____ C:\Users\DA BOSS\Downloads\psd_cat_line_by_kawiku-d8nuwmj.psd
2016-02-09 16:07 - 2016-01-26 23:55 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-02-09 16:07 - 2016-01-26 23:45 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-02-09 16:07 - 2016-01-26 23:45 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-02-09 16:07 - 2016-01-26 23:37 - 01998176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-02-09 16:07 - 2016-01-26 23:10 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-02-09 16:07 - 2016-01-26 23:05 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-02-09 16:07 - 2016-01-26 23:04 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-02-09 16:07 - 2016-01-26 22:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-02-09 16:07 - 2016-01-26 22:55 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-02-09 16:07 - 2016-01-26 22:54 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-02-09 16:07 - 2016-01-26 22:48 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-02-09 16:07 - 2016-01-26 22:41 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-02-09 16:07 - 2016-01-26 22:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-09 16:06 - 2016-01-29 00:57 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-09 16:06 - 2016-01-29 00:33 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-02-09 16:06 - 2016-01-27 00:15 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-02-09 16:06 - 2016-01-27 00:15 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-02-09 16:06 - 2016-01-27 00:01 - 07476064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-02-09 16:06 - 2016-01-27 00:01 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-02-09 16:06 - 2016-01-27 00:01 - 01819720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-02-09 16:06 - 2016-01-26 23:59 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-09 16:06 - 2016-01-26 23:57 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-02-09 16:06 - 2016-01-26 23:57 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-09 16:06 - 2016-01-26 23:57 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-09 16:06 - 2016-01-26 23:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-02-09 16:06 - 2016-01-26 23:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-02-09 16:06 - 2016-01-26 23:54 - 00295264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-02-09 16:06 - 2016-01-26 23:46 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-09 16:06 - 2016-01-26 23:46 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-09 16:06 - 2016-01-26 23:44 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-09 16:06 - 2016-01-26 23:44 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-09 16:06 - 2016-01-26 23:43 - 00359776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-02-09 16:06 - 2016-01-26 23:37 - 00576352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-02-09 16:06 - 2016-01-26 23:21 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-09 16:06 - 2016-01-26 23:15 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-02-09 16:06 - 2016-01-26 23:13 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-02-09 16:06 - 2016-01-26 23:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-02-09 16:06 - 2016-01-26 23:11 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-09 16:06 - 2016-01-26 23:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-09 16:06 - 2016-01-26 23:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-09 16:06 - 2016-01-26 23:08 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-09 16:06 - 2016-01-26 23:07 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-02-09 16:06 - 2016-01-26 23:05 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-02-09 16:06 - 2016-01-26 23:05 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-02-09 16:06 - 2016-01-26 23:05 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-02-09 16:06 - 2016-01-26 23:04 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-09 16:06 - 2016-01-26 23:03 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-02-09 16:06 - 2016-01-26 23:02 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-09 16:06 - 2016-01-26 23:01 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-09 16:06 - 2016-01-26 22:59 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-09 16:06 - 2016-01-26 22:57 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-02-09 16:06 - 2016-01-26 22:55 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-02-09 16:06 - 2016-01-26 22:52 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-09 16:06 - 2016-01-26 22:50 - 02230784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-02-09 16:06 - 2016-01-26 22:50 - 01504768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-02-09 16:06 - 2016-01-26 22:50 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-09 16:06 - 2016-01-26 22:49 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-02-09 16:06 - 2016-01-26 22:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-09 16:06 - 2016-01-26 22:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-09 16:06 - 2016-01-26 22:39 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-02-09 16:06 - 2016-01-26 22:38 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-02-09 16:06 - 2016-01-26 22:38 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-02-09 16:06 - 2016-01-26 22:37 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-02-09 16:06 - 2016-01-26 22:36 - 02757120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-02-09 16:06 - 2016-01-26 22:31 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-08 10:40 - 2016-02-08 10:56 - 90623834 _____ C:\Users\DA BOSS\Desktop\glados.mp4
2016-02-08 10:10 - 2016-02-08 10:22 - 21751507 _____ C:\Users\DA BOSS\Desktop\glados2.mp4
2016-02-08 09:43 - 2016-02-08 09:52 - 21788345 _____ C:\Users\DA BOSS\Desktop\glados1.mp4
2016-02-06 19:17 - 2016-02-06 19:17 - 00058773 _____ C:\Users\DA BOSS\Downloads\splat_brushes_by_mo_fox-d92re6o.zip
2016-02-06 15:52 - 2016-02-06 16:04 - 61439629 _____ C:\Users\DA BOSS\Desktop\themesongs.mp4
2016-02-06 15:38 - 2016-02-06 15:39 - 13698187 _____ C:\Users\DA BOSS\Downloads\Nyan Cat [original].mp4
2016-02-06 14:41 - 2016-02-06 14:42 - 16642767 _____ C:\Users\DA BOSS\Downloads\Undertale - Know you'll always be inside my heart (A song for Toriel).mp4
2016-02-06 14:33 - 2016-02-06 14:34 - 32445007 _____ C:\Users\DA BOSS\Downloads\Undertale - Blue Lips.mp4
2016-02-02 19:35 - 2016-02-02 19:35 - 00003334 _____ C:\Users\DA BOSS\Documents\My Movie.wlmp
2016-02-02 18:30 - 2016-02-02 18:46 - 13965500 _____ C:\Users\DA BOSS\Desktop\nightmare2.mp4
2016-02-02 18:05 - 2016-02-02 18:12 - 10262300 _____ C:\Users\DA BOSS\Desktop\nightmare1.mp4
2016-02-02 13:32 - 2016-02-02 13:32 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart (2).zip
2016-02-02 13:32 - 2016-02-02 13:32 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart (1).zip
2016-02-02 13:30 - 2016-02-02 13:30 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart.zip
2016-01-27 17:15 - 2016-01-27 17:43 - 29471433 _____ C:\Users\DA BOSS\Desktop\blue.mp4
2016-01-27 16:35 - 2016-01-16 00:37 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-01-27 16:35 - 2016-01-16 00:36 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-27 16:35 - 2016-01-16 00:36 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-01-27 16:35 - 2016-01-16 00:34 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-27 16:35 - 2016-01-16 00:24 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 08728920 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-27 16:35 - 2016-01-16 00:23 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-01-27 16:35 - 2016-01-16 00:21 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-01-27 16:35 - 2016-01-16 00:20 - 06971752 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-01-27 16:35 - 2016-01-16 00:20 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-01-27 16:35 - 2016-01-16 00:20 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-01-27 16:35 - 2016-01-16 00:20 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-01-27 16:35 - 2016-01-16 00:19 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-01-27 16:35 - 2016-01-16 00:19 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-01-27 16:35 - 2016-01-16 00:12 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-01-27 16:35 - 2016-01-16 00:09 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-01-27 16:35 - 2016-01-16 00:08 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-01-27 16:35 - 2016-01-16 00:08 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-01-27 16:35 - 2016-01-15 23:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-01-27 16:35 - 2016-01-15 23:45 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-27 16:35 - 2016-01-15 23:44 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-01-27 16:35 - 2016-01-15 23:42 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-27 16:35 - 2016-01-15 23:41 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-01-27 16:35 - 2016-01-15 23:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-01-27 16:35 - 2016-01-15 23:40 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-01-27 16:35 - 2016-01-15 23:39 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-01-27 16:35 - 2016-01-15 23:38 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-01-27 16:35 - 2016-01-15 23:38 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-01-27 16:35 - 2016-01-15 23:38 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-01-27 16:35 - 2016-01-15 23:37 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-01-27 16:35 - 2016-01-15 23:36 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-01-27 16:35 - 2016-01-15 23:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2016-01-27 16:35 - 2016-01-15 23:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-01-27 16:35 - 2016-01-15 23:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-01-27 16:35 - 2016-01-15 23:35 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-01-27 16:35 - 2016-01-15 23:35 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-01-27 16:35 - 2016-01-15 23:34 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-27 16:35 - 2016-01-15 23:33 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-01-27 16:35 - 2016-01-15 23:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-01-27 16:35 - 2016-01-15 23:33 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-01-27 16:35 - 2016-01-15 23:32 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-01-27 16:35 - 2016-01-15 23:32 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-01-27 16:35 - 2016-01-15 23:31 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-01-27 16:35 - 2016-01-15 23:31 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-01-27 16:35 - 2016-01-15 23:30 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-01-27 16:35 - 2016-01-15 23:30 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-01-27 16:35 - 2016-01-15 23:30 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-01-27 16:35 - 2016-01-15 23:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-01-27 16:35 - 2016-01-15 23:29 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-01-27 16:35 - 2016-01-15 23:29 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-01-27 16:35 - 2016-01-15 23:28 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-01-27 16:35 - 2016-01-15 23:27 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-01-27 16:35 - 2016-01-15 23:26 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-27 16:35 - 2016-01-15 23:25 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-01-27 16:35 - 2016-01-15 23:25 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-01-27 16:35 - 2016-01-15 23:25 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-01-27 16:35 - 2016-01-15 23:24 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-01-27 16:35 - 2016-01-15 23:23 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-01-27 16:35 - 2016-01-15 23:23 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-01-27 16:35 - 2016-01-15 23:21 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-01-27 16:35 - 2016-01-15 23:20 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-01-27 16:35 - 2016-01-15 23:19 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-01-27 16:35 - 2016-01-15 23:18 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-27 16:35 - 2016-01-15 23:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-01-27 16:35 - 2016-01-15 23:16 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-01-27 16:35 - 2016-01-15 23:16 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-01-27 16:35 - 2016-01-15 23:15 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-01-27 16:35 - 2016-01-15 23:14 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-01-27 16:35 - 2016-01-15 23:14 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-01-27 16:35 - 2016-01-15 23:11 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-01-27 16:34 - 2016-01-15 23:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-01-27 16:34 - 2016-01-15 23:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-01-27 16:34 - 2016-01-15 23:43 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-01-27 16:34 - 2016-01-15 23:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-01-27 16:34 - 2016-01-15 23:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-01-27 16:34 - 2016-01-15 23:38 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-01-27 16:34 - 2016-01-15 23:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-01-27 16:34 - 2016-01-15 23:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-01-27 16:34 - 2016-01-15 23:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-01-27 16:34 - 2016-01-15 23:30 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-01-26 18:14 - 2016-01-26 18:14 - 04388394 _____ C:\Users\DA BOSS\Desktop\asgoresucks.mp4
2016-01-25 09:34 - 2016-01-25 09:34 - 09286495 _____ C:\Users\DA BOSS\Desktop\danceparty.mp4
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-24 08:53 - 2016-01-24 12:46 - 00000000 ____D C:\Program Files (x86)\Steam
2016-02-24 08:53 - 2015-12-25 16:18 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-24 08:49 - 2015-12-24 21:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-24 08:47 - 2015-12-24 19:24 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-02-24 07:36 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-23 22:29 - 2015-12-25 16:18 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-23 10:54 - 2016-01-18 08:48 - 00000000 ____D C:\Users\DA BOSS\AppData\LocalLow\Temp
2016-02-23 07:25 - 2015-12-24 19:41 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-23 07:21 - 2016-01-12 10:40 - 00004172 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D78140DC-BA3F-44E1-A6F3-4CE6760938C8}
2016-02-22 08:53 - 2015-12-24 19:40 - 00000000 ____D C:\WINDOWS\INF
2016-02-22 08:53 - 2015-12-24 19:38 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-21 13:24 - 2015-12-24 19:44 - 00000000 ____D C:\Users\DA BOSS
2016-02-21 12:04 - 2015-12-24 19:45 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-19 18:31 - 2015-12-25 16:19 - 00002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-19 18:31 - 2015-12-25 16:19 - 00002295 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-18 09:16 - 2016-01-05 16:49 - 00000000 ____D C:\Users\DA BOSS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2016-02-13 08:30 - 2015-12-25 02:53 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-13 08:25 - 2015-12-25 02:53 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-11 04:12 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\rescache
2016-02-11 03:31 - 2015-12-24 19:41 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-09 16:35 - 2015-12-24 19:31 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-02-04 19:32 - 2015-12-24 19:48 - 00002378 _____ C:\Users\DA BOSS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-04 19:32 - 2015-12-24 19:48 - 00000000 ___RD C:\Users\DA BOSS\OneDrive
2016-02-03 13:01 - 2015-12-24 19:44 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-02-03 13:01 - 2015-12-24 19:44 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-03 07:40 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-02 08:24 - 2015-12-25 16:18 - 00003996 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-02 08:24 - 2015-12-25 16:18 - 00003764 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\bcastdvr
 
==================== Files in the root of some directories =======
 
2016-01-06 10:55 - 2016-01-06 10:55 - 0168688 _____ () C:\Users\DA BOSS\AppData\Local\ars.cache
2016-01-06 10:55 - 2016-01-06 10:55 - 0484539 _____ () C:\Users\DA BOSS\AppData\Local\census.cache
2016-01-06 10:37 - 2016-01-06 10:37 - 0000036 _____ () C:\Users\DA BOSS\AppData\Local\housecall.guid.cache
2016-01-12 11:27 - 2015-10-31 10:09 - 0016800 _____ () C:\Users\DA BOSS\AppData\Local\Z@!-812c0ff4-c71f-4a96-bf01-72061ea46366.tmp
2016-01-12 11:27 - 2015-10-31 10:09 - 0015776 _____ () C:\Users\DA BOSS\AppData\Local\Z@S!-24ec7c9a-3b4e-46c5-83fb-48f825374dcf.tmp
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-02-22 19:48
 
==================== End of FRST.txt ============================
 
Addition
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:21-02-2016 01
Ran by [removed] (2016-02-24 09:06:34)
Running from C:\Users\[removed]\Desktop
Windows 10 Pro Version 1511 (X64) (2015-12-25 01:42:02)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-4012266320-2666871660-1620693866-500 - Administrator - Disabled)
DA BOSS (S-1-5-21-4012266320-2666871660-1620693866-1001 - Administrator - Enabled) => C:\Users\DA BOSS
DefaultAccount (S-1-5-21-4012266320-2666871660-1620693866-503 - Limited - Disabled)
Guest (S-1-5-21-4012266320-2666871660-1620693866-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Citrix Online Launcher (HKLM-x32\…\{09DA5EE2-7E46-4DC4-96F9-BFEE50D40659}) (Version: 1.0.408 - Citrix)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
FireAlpaca 1.5.4 (HKLM-x32\…\FireAlpaca_is1) (Version: 1.5.4 - firealpaca.com)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
GoToAssist Corporate (HKLM-x32\…\GoToAssist) (Version: 11.5.0.1165 - Citrix Systems, Inc.)
Java 8 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MP3 Rocket (HKLM-x32\…\MP3 Rocket) (Version: 7.3.2 - MP3 Rocket Inc)
Pluto TV version 0.1.5 (HKLM-x32\…\Pluto TV_is1) (Version: 0.1.5 - Pluto TV)
ROBLOX Player for DA BOSS (HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
Screen Recorder Launcher (HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\ScreenRecorderLauncher) (Version: 2.0 - )
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Undertale (HKLM-x32\…\Steam App 391540) (Version:  - tobyfox)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinZip 20.0 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EF}) (Version: 20.0.11659 - WinZip Computing, S.L. )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-4012266320-2666871660-1620693866-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4012266320-2666871660-1620693866-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\RobloxProxy64.dll (ROBLOX Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1381603E-888C-4BAC-AFCD-FF0BEE46523C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {189C82D6-61B0-4CA8-9552-BCAB4A941126} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-25] (Google Inc.)
Task: {45FE7E69-05B9-438A-BF9B-8FE739238B3F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {74A5EFF7-E6CD-4D1D-9603-4B47A0688ABC} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {75A4B00B-C858-46A3-9B53-05D77A47302C} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-02-13] (Microsoft Corporation)
Task: {9B93864C-6C50-41F3-B50E-49914EA9E474} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {FBB3A31C-554C-488A-9004-FAE7010F9727} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {FE19808B-D482-4650-A0B2-5BE941CB2890} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-25] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-30 01:18 - 2015-10-30 01:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-15 14:29 - 2015-12-15 14:29 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-01-21 17:21 - 2016-01-21 17:21 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-15 14:29 - 2015-12-15 14:29 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-12-19 08:39 - 2015-12-06 22:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-12-19 08:39 - 2015-12-06 22:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-12-19 08:39 - 2015-12-06 22:00 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-01-13 16:43 - 2016-01-04 19:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 16:43 - 2016-01-04 19:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-27 16:35 - 2016-01-15 23:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-27 16:35 - 2016-01-15 23:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-02-11 15:16 - 2016-02-11 15:16 - 09789952 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2016.27.2.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
2016-01-21 17:21 - 2016-01-21 17:21 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 17:21 - 2016-01-21 17:21 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-01-24 12:50 - 2015-12-14 23:54 - 00782336 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2016-01-24 12:50 - 2015-07-03 10:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2016-01-24 12:50 - 2016-02-04 15:02 - 02546768 _____ () C:\Program Files (x86)\Steam\video.dll
2016-01-24 12:50 - 2015-07-03 10:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2016-01-24 12:50 - 2015-07-03 10:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 02549248 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2016-01-24 12:50 - 2015-09-23 18:33 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2016-01-24 12:50 - 2016-02-04 15:01 - 00802896 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2016-01-24 12:50 - 2015-12-29 19:51 - 00208896 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
2016-01-24 12:50 - 2016-01-05 19:52 - 48387872 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2016-02-19 18:31 - 2016-02-17 22:14 - 01630360 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libglesv2.dll
2016-02-19 18:31 - 2016-02-17 22:14 - 00085656 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\8AFAE51F.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\8AFAE51F.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-12-24 19:42 - 2016-02-23 19:39 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\DA BOSS\Pictures\Saved Pictures\derp.jpg
DNS Servers: 192.168.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\…\StartupApproved\StartupFolder: => "PlutoTV.lnk"
HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\StartupApproved\Run: => "Akamai NetSession Interface"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{863FC78E-490D-46AA-90D4-B59158E66BA9}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [UDP Query User{BC2C0168-839A-476D-B537-8B51BA152A2E}C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [TCP Query User{5B7A5442-6A7F-4DB9-B74A-1AF185800D3B}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{321CEA1A-1FFC-4032-9E58-FE355EDE15CF}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{609E46B9-8B05-4FEF-A7C4-915FA7B73206}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{31B8E3BF-E6AD-4AEF-A4CC-23A4A945AB15}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{5364B977-6148-4595-B93D-83D57D1CC971}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{B7C09D68-9DE3-4AC3-9EE2-87EA459D3F34}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{43495712-F6AD-45E9-9E58-42443766EAF0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe
FirewallRules: [{85F2C9F3-A1EF-4C1F-B582-EED0647937F1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Undertale\UNDERTALE.exe
FirewallRules: [TCP Query User{77E6D1E3-8971-4BCD-B8C0-3452758F9205}C:\windows\temp\joi36cd.tmp\join.me.exe] => (Allow) C:\windows\temp\joi36cd.tmp\join.me.exe
FirewallRules: [UDP Query User{87AB4C41-D877-4579-9493-F55259411141}C:\windows\temp\joi36cd.tmp\join.me.exe] => (Allow) C:\windows\temp\joi36cd.tmp\join.me.exe
FirewallRules: [{B7B6F621-3BEF-444D-9123-0BC729880761}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
Could not list restore points
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
Could not list Devices. Check "winmgmt" service or repair WMI.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/24/2016 08:51:39 AM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
 
Error: (02/24/2016 07:30:42 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (02/23/2016 10:27:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (02/23/2016 07:45:35 PM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
 
Error: (02/23/2016 02:29:33 PM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
 
Error: (02/23/2016 02:23:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (02/23/2016 11:39:02 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (02/23/2016 11:35:45 AM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
 
Error: (02/23/2016 11:00:01 AM) (Source: SecurityCenter) (EventID: 3) (User: )
Description: The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.
 
Error: (02/23/2016 10:21:52 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-A3GLD76)
Description: Activation of app Microsoft.Windows.Photos_8wekyb3d8bbwe!App failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
 
System errors:
=============
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The rixdpcie service failed to start due to the following error: 
%%1058
 
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The risdpcie service failed to start due to the following error: 
%%1058
 
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The rimspci service failed to start due to the following error: 
%%1058
 
Error: (02/24/2016 08:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The rimmptsk service failed to start due to the following error: 
%%1058
 
Error: (02/24/2016 08:49:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The AntiRansomwareService service failed to start due to the following error: 
%%2
 
Error: (02/24/2016 08:47:07 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_8c543 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (02/24/2016 08:47:06 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (02/24/2016 08:22:53 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (02/24/2016 07:30:42 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-A3GLD76)
Description: App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca
 
Error: (02/23/2016 11:05:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
 
CodeIntegrity:
===================================
  Date: 2016-02-12 06:04:06.739
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-02-11 03:34:07.725
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-02-10 06:04:00.788
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-28 10:35:41.462
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-14 11:19:38.233
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-06 10:36:51.785
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-06 08:38:26.129
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-31 06:55:43.326
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 03:34:19.593
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-12-25 02:55:54.470
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM)2 Duo CPU E7400 @ 2.80GHz
Percentage of memory in use: 68%
Total physical RAM: 1995.61 MB
Available physical RAM: 633.81 MB
Total Virtual: 3083.61 MB
Available Virtual: 1402.91 MB
 
==================== Drives ================================
 
Drive c: (Smith) (Fixed) (Total:232.44 GB) (Free:204.64 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (AVG 2015 - b5267) (CDROM) (Total:0.55 GB) (Free:0 GB) CDFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 9E9F8F83)
Partition 1: (Active) - (Size=232.4 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=449 MB) - (Type=27)
 
==================== End of Addition.txt ============================

Your going to have to reset Chome back to company default

 

  • Click the Chrome menu [external image: Clipboard01_zps2e55f676.jpg]on the browser toolbar.
  • Select Settings.
  • Scroll down to Show advanced settings…
  • Down on the bottom you will see an option for RESET BROWSER SETTINGS
  • Click on it and it will set Chome back to defaults
  • Close Chome
  •  
     
    Then reboot your system, run a new scan with FRST, dont need additions this time, just the main log

    Ok. I just got home. Before I left I started the AdwCleaner and this is what it found.

     

    reated 24/02/2016 at 09:46:07
    # Updated 22/02/2016 by Xplode
    # Database : 2016-02-22.2 [Server]
    # Operating system : Windows 10 Pro  (x64)
    # Username : DA BOSS - DESKTOP-A3GLD76
    # Running from : C:\Users\DA BOSS\Desktop\AdwCleaner.exe
    # Option : Scan
    # Support : http://toolslib.net/forum
     
    ***** [ Services ] *****
     
     
    ***** [ Folders ] *****
     
    Folder Found : C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\macpddegmcklbbnbdemccckkmhaegdlf
     
    ***** [ Files ] *****
     
     
    ***** [ DLL ] *****
     
     
    ***** [ Shortcuts ] *****
     
     
    ***** [ Scheduled tasks ] *****
     
     
    ***** [ Registry ] *****
     
     
    ***** [ Web browsers ] *****
     
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://astromenda.com/?f=7&a=ast_secureddownload_14_36_ch&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0SzyyBzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEyCzz0EtDyDtG0BtAzyyBtGzzzz0E0DtGtD0FyDyEtGtD0Ezyzy0Czz0FtA0FzzyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0F0AyCzy0DtA0CtGtA0Ezz0EtGyEtCyDtBtGzz0AtCtAtGtA0AzzzztByEtBtB0CtCyD0E2Q&cr=284385966&ir=
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.dregol.com/?f=7&a=drg_suma_15_22&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByEyEtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StCtCyDtC0B0E0A0DtGtC0DtC0BtGtCtCtC0CtGyBzytDtCtGzzyD0F0AtAtC0FzyyE0B0Ezy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FtD0C0A0ByByEtG0AtC0F0FtGyE0A0A0CtGzy0AzytCtGzyyBtDzyyEzyzztByC0F0DyD2QtN0A0LzuyE&cr=1770093444&ir=
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.trovi.com/?gd=&ctid=CT3324769&octid=EB_ORIGINAL_CTID&ISID=M31A5AC2F-450E-4BEE-A3CA-CAAD8FD8C08A&SearchSource=55&CUI=&UM=8&UP=SP44FB3AA5-CFC4-4DA6-9FD1-4F7E9DE3B678&D=061315&SSPV=
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_suma_15_24¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAtAtBzyyBtGyByCyE0BtG0F0D0DtDtGyB0B0A0BtGzy0EtDyDtD0CtDzyyBtDtBtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0B0EyE0CzztDtCtG0AyEtByDtGyE0DzztAtGzyyEtC0AtG0D0DyDtB0C0C0B0CtB0CyBtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26cr%3D929903380%26a%3Dwncy_suma_15_24%26os%3DWindows 7 Home Premium
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : macpddegmcklbbnbdemccckkmhaegdlf
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : mfpcpilhpbdgmnfaoonnnofhdmcbejhh
     
    *************************
     
    C:\AdwCleaner\AdwCleaner[C1].txt - [4524 bytes] - [23/02/2016 11:30:38]
    C:\AdwCleaner\AdwCleaner[S1].txt - [4257 bytes] - [23/02/2016 11:27:20]
    C:\AdwCleaner\AdwCleaner[S2].txt - [3099 bytes] - [24/02/2016 09:46:07]
     
    ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3172 bytes] ##########

     

    I will restore settings now

    Ugh!! This is the second time in a row where my mouse stopped working after rebooting. Earlier all I had to do was unplug it from the power and then plug it back in, but this time that is not working. I am on my phone

    Ok, I just left it unplugged from tower for a few and it came back on when I plugged it back in. My spyware was turned off again after reboot. I thought resetting was going to remove favorites and stuff. I started AdwCleaner and then I will run FRST again.

     

    Think I might have some yucky virus going through and just screwing things up right behind us??

    AdwCleaner

     

    # AdwCleaner v5.036 - Logfile created 24/02/2016 at 11:48:35
    # Updated 22/02/2016 by Xplode
    # Database : 2016-02-24.1 [Server]
    # Operating system : Windows 10 Pro  (x64)
    # Username : DA BOSS - DESKTOP-A3GLD76
    # Running from : C:\Users\DA BOSS\Desktop\AdwCleaner.exe
    # Option : Scan
    # Support : http://toolslib.net/forum
     
    ***** [ Services ] *****
     
     
    ***** [ Folders ] *****
     
    Folder Found : C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\macpddegmcklbbnbdemccckkmhaegdlf
     
    ***** [ Files ] *****
     
     
    ***** [ DLL ] *****
     
     
    ***** [ Shortcuts ] *****
     
     
    ***** [ Scheduled tasks ] *****
     
     
    ***** [ Registry ] *****
     
     
    ***** [ Web browsers ] *****
     
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://astromenda.com/?f=7&a=ast_secureddownload_14_36_ch&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0SzyyBzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEyCzz0EtDyDtG0BtAzyyBtGzzzz0E0DtGtD0FyDyEtGtD0Ezyzy0Czz0FtA0FzzyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0F0AyCzy0DtA0CtGtA0Ezz0EtGyEtCyDtBtGzz0AtCtAtGtA0AzzzztByEtBtB0CtCyD0E2Q&cr=284385966&ir=
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.dregol.com/?f=7&a=drg_suma_15_22&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByEyEtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StCtCyDtC0B0E0A0DtGtC0DtC0BtGtCtCtC0CtGyBzytDtCtGzzyD0F0AtAtC0FzyyE0B0Ezy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FtD0C0A0ByByEtG0AtC0F0FtGyE0A0A0CtGzy0AzytCtGzyyBtDzyyEzyzztByC0F0DyD2QtN0A0LzuyE&cr=1770093444&ir=
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.trovi.com/?gd=&ctid=CT3324769&octid=EB_ORIGINAL_CTID&ISID=M31A5AC2F-450E-4BEE-A3CA-CAAD8FD8C08A&SearchSource=55&CUI=&UM=8&UP=SP44FB3AA5-CFC4-4DA6-9FD1-4F7E9DE3B678&D=061315&SSPV=
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_suma_15_24¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAtAtBzyyBtGyByCyE0BtG0F0D0DtDtGyB0B0A0BtGzy0EtDyDtD0CtDzyyBtDtBtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0B0EyE0CzztDtCtG0AyEtByDtGyE0DzztAtGzyyEtC0AtG0D0DyDtB0C0C0B0CtB0CyBtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26cr%3D929903380%26a%3Dwncy_suma_15_24%26os%3DWindows 7 Home Premium
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : macpddegmcklbbnbdemccckkmhaegdlf
    [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : mfpcpilhpbdgmnfaoonnnofhdmcbejhh
     
    *************************
     
    C:\AdwCleaner\AdwCleaner[C1].txt - [4524 bytes] - [23/02/2016 11:30:38]
    C:\AdwCleaner\AdwCleaner[S1].txt - [4257 bytes] - [23/02/2016 11:27:20]
    C:\AdwCleaner\AdwCleaner[S2].txt - [3251 bytes] - [24/02/2016 09:46:07]
    C:\AdwCleaner\AdwCleaner[S3].txt - [3324 bytes] - [24/02/2016 11:42:07]
    C:\AdwCleaner\AdwCleaner[S4].txt - [3245 bytes] - [24/02/2016 11:48:35]
     
    ########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [3318 bytes] ##########

    Crap! I'm sorry!!! I will do that.

    Spyware turned off on restart again

     

    Here is FRST 

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:21-02-2016 01
    Ran by [removed] (administrator) on DESKTOP-A3GLD76 (24-02-2016 11:59:59)
    Running from C:\Users\[removed]\Desktop
    [removed]
    Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
     
    ==================== Processes (Whitelisted) =================
     
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
     
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Nico Mak Computing) C:\Program Files\WinZip\FAHWindow64.exe
    (Nico Mak Computing) C:\Program Files\WinZip\WZUpdateNotifier.exe
    (WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
     
     
    ==================== Registry (Whitelisted) ===========================
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
     
    HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
    Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist Corporate\1165\G2AWinLogon_x64.dll (Citrix Systems, Inc.)
    HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\Run: [Akamai NetSession Interface] => "C:\Users\DA BOSS\AppData\Local\Akamai\netsession_win.exe"
    HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3014224 2016-02-04] (Valve Corporation)
    HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\RunOnce: [Uninstall C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\DA BOSS\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
    HKU\S-1-5-21-4012266320-2666871660-1620693866-1001\…\MountPoints2: {ef953357-aab6-11e5-8627-806e6f6e6963} - "C:\WINDOWS\system32\RunDLL32.EXE" Shell32.DLL,ShellExec_RunDLL D:\autorun.exe
    HKU\S-1-5-18\…\Run: [Bomgar_Cleanup_ZD8417113481] => cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-0x56951c5b" & reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD8417113481 /f
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-01-06]
    ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (Nico Mak Computing)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PlutoTV.lnk [2016-01-01]
    ShortcutTarget: PlutoTV.lnk -> C:\Program Files (x86)\Pluto TV\PlutoTV.exe ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2016-01-06]
    ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (Nico Mak Computing)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-01-06]
    ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
     
    ==================== Internet (Whitelisted) ====================
     
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
     
    Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
    Tcpip\..\Interfaces\{241d82c6-d063-405d-86af-ac08c48d4ceb}: [DhcpNameServer] 192.168.10.1
     
    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2016-01-21] (Oracle Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2016-01-21] (Oracle Corporation)
     
    FireFox:
    ========
    FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2016-01-21] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2016-01-21] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
    FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @citrixonline.com/appdetectorplugin -> C:\Users\DA BOSS\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-02-22] (Citrix Online)
    FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @nsroblox.roblox.com/launcher -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
    FF Plugin HKU\S-1-5-21-4012266320-2666871660-1620693866-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\DA BOSS\AppData\Local\Roblox\Versions\version-a1b8c1edf45b4959\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
     
    Chrome: 
    =======
    CHR HomePage: Default -> hxxp://www.e-hawks.org/
    CHR StartupUrls: Default -> "hxxp://blueearthlibrary.wordpress.com/"
    CHR DefaultSearchURL: Default -> hxxp://musix.searchalgo.com/search/?category=web&s=msds&q={searchTerms}
    CHR DefaultSearchKeyword: Default -> goMusix
    CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms}
    CHR Profile: C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Slides) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-25]
    CHR Extension: (Theme Creator) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2016-01-09]
    CHR Extension: (Google Docs) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-25]
    CHR Extension: (Google Drive) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-25]
    CHR Extension: (Dark Skin for Youtube™) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfeknfgchonpnofdjokchhdhdnddhglm [2016-02-17]
    CHR Extension: (YouTube) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-25]
    CHR Extension: (Thesaurus.com - Synonyms and Antonyms) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\clljlcapeomdokpgadmegpabakieebci [2016-01-10]
    CHR Extension: (Google Search) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-25]
    CHR Extension: (Easy Theme Maker For YouTube™) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehljkohidokkiifnnamkgpmhjagfckig [2016-01-09]
    CHR Extension: (Pizza Snake) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\eladgefgfablffmdbgbllikigaaehjbd [2016-01-19]
    CHR Extension: (Google Sheets) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-25]
    CHR Extension: (Google Docs Offline) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-26]
    CHR Extension: (Dictionary by Dictionary.com) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2016-01-10]
    CHR Extension: (TerasGames) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\gllefgmldkgbcdljkifdinlimdjahilh [2016-01-10]
    CHR Extension: (Paste 'Lorem ipsum…') - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihmllonaidjepimjdhjdcgodgekcmhop [2016-01-10]
    CHR Extension: (Dictionary Lookup) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipdjaafajlfiopcppipdinmcjbcpofhd [2016-01-10]
    CHR Extension: (Cut the Rope) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfbadlndcminbkfojhlimnkgaackjmdo [2016-01-10]
    CHR Extension: (Penzu) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\khgpedpfmjojllfmmhfabemdelhncneo [2016-01-10]
    CHR Extension: (Thesaurus: Synonym 4 Right Click) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpkpcliecpgjbkffooidajhakoidhidh [2016-01-10]
    CHR Extension: (Google Play Books) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2016-01-10]
    CHR Extension: (SiriusXM) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbbdoippffioahmjdapnadeelifajhco [2016-01-10]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-25]
    CHR Extension: (Gmail) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-25]
    CHR Profile: C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1
    CHR Extension: (Google Slides) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-10]
    CHR Extension: (Google Docs) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-10]
    CHR Extension: (Google Drive) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-10]
    CHR Extension: (YouTube) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-10]
    CHR Extension: (Google Search) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-10]
    CHR Extension: (Google Sheets) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-10]
    CHR Extension: (Google Docs Offline) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-10]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-10]
    CHR Extension: (Gmail) - C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-10]
     
    ==================== Services (Whitelisted) ========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    S3 GoToAssist; C:\Program Files (x86)\Citrix\GoToAssist Corporate\1165\G2AC_Service.exe [309720 2016-02-22] (Citrix Systems, Inc.)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
    S2 AntiRansomwareService; C:\Users\DA BOSS\Desktop\New folder\arservice.exe [X]
     
    ===================== Drivers (Whitelisted) ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    R0 8AFAE51F; C:\Windows\System32\drivers\8AFAE51F.sys [478392 2016-02-22] (Kaspersky Lab ZAO)
    S3 BCMTPM; C:\Windows\System32\drivers\btpmwx64.sys [32096 2013-03-07] (Broadcom Corp.)
    R3 dot4; C:\Windows\System32\drivers\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
    R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
    R3 e1kexpress; C:\Windows\system32\DRIVERS\e1k63x64.sys [498032 2013-02-20] (Intel Corporation)
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-02-24] (Malwarebytes)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
    S1 KbHook; \??\C:\Users\DA BOSS\Desktop\New folder\hookdriver64.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== One Month Created files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-02-24 09:03 - 2016-02-24 09:03 - 00003294 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
    2016-02-24 09:03 - 2016-02-24 09:03 - 00003242 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
    2016-02-24 09:03 - 2016-02-24 09:03 - 00003238 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
    2016-02-24 09:03 - 2016-02-24 09:03 - 00003210 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
    2016-02-24 09:03 - 2016-02-24 09:03 - 00003206 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
    2016-02-24 09:03 - 2016-02-24 09:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
    2016-02-24 09:02 - 2016-02-24 09:02 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center
    2016-02-23 17:34 - 2016-02-24 09:07 - 00022894 _____ C:\Users\DA BOSS\Desktop\Addition.txt
    2016-02-23 17:32 - 2016-02-24 11:59 - 00014671 _____ C:\Users\DA BOSS\Desktop\FRST.txt
    2016-02-23 14:52 - 2016-02-24 11:56 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2016-02-23 14:48 - 2016-02-23 14:48 - 00001180 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2016-02-23 14:48 - 2016-02-23 14:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2016-02-23 14:48 - 2016-02-23 14:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-02-23 14:48 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2016-02-23 14:48 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2016-02-23 14:48 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2016-02-23 14:47 - 2016-02-23 14:48 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024 (2).exe
    2016-02-23 14:47 - 2016-02-23 14:47 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024 (1).exe
    2016-02-23 11:44 - 2016-02-23 11:44 - 00000000 ____D C:\ProgramData\Malwarebytes
    2016-02-23 11:42 - 2016-02-23 11:43 - 22908888 _____ (Malwarebytes ) C:\Users\DA BOSS\Downloads\mbam-setup-2.2.0.1024.exe
    2016-02-23 11:40 - 2016-02-23 11:40 - 00000999 _____ C:\Users\DA BOSS\Desktop\JRT.txt
    2016-02-23 11:37 - 2016-02-23 11:38 - 01609216 _____ (Malwarebytes) C:\Users\DA BOSS\Desktop\JRT.exe
    2016-02-23 11:25 - 2016-02-24 11:50 - 00000000 ____D C:\AdwCleaner
    2016-02-23 11:25 - 2016-02-23 11:25 - 01511936 _____ C:\Users\DA BOSS\Desktop\AdwCleaner.exe
    2016-02-23 10:52 - 2016-02-23 19:39 - 00002913 _____ C:\Users\DA BOSS\Desktop\Fixlog.txt
    2016-02-22 19:36 - 2016-02-22 19:37 - 14454784 _____ C:\Users\DA BOSS\Downloads\OPSWAT_GEARS_CLIENT_3445-7c867995737c1853977386e89a5560c5.msi
    2016-02-22 18:03 - 2016-02-23 08:19 - 00022423 _____ C:\Users\DA BOSS\Downloads\Addition.txt
    2016-02-22 17:58 - 2016-02-23 08:19 - 00047128 _____ C:\Users\DA BOSS\Downloads\FRST.txt
    2016-02-22 17:58 - 2016-02-22 17:58 - 00001691 _____ C:\Users\DA BOSS\Documents\aswMBR scan.txt
    2016-02-22 17:58 - 2016-02-22 17:58 - 00000512 _____ C:\Users\DA BOSS\Documents\MBR.dat
    2016-02-22 17:45 - 2016-02-24 11:59 - 00000000 ____D C:\FRST
    2016-02-22 17:45 - 2016-02-22 17:45 - 02371072 _____ (Farbar) C:\Users\DA BOSS\Desktop\FRST64.exe
    2016-02-22 17:41 - 2016-02-22 17:42 - 05198336 _____ (AVAST Software) C:\Users\DA BOSS\Downloads\aswMBR.exe
    2016-02-22 10:01 - 2016-02-22 17:27 - 00000000 ____D C:\KVRT_Data
    2016-02-22 10:01 - 2016-02-22 10:01 - 00478392 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\8AFAE51F.sys
    2016-02-22 09:56 - 2016-02-22 10:01 - 89499032 _____ (Kaspersky Lab ZAO) C:\Users\DA BOSS\Downloads\KVRT.exe
    2016-02-22 09:54 - 2016-02-22 09:55 - 00003022 _____ C:\Users\DA BOSS\Desktop\Rkill.txt
    2016-02-22 09:54 - 2016-02-22 09:54 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\DA BOSS\Downloads\rkill.exe
    2016-02-22 09:46 - 2016-02-22 10:00 - 00473810 _____ C:\TDSSKiller.3.1.0.9_22.02.2016_09.46.30_log.txt
    2016-02-22 09:45 - 2016-02-22 09:46 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\DA BOSS\Downloads\tdsskiller.exe
    2016-02-22 09:20 - 2016-02-22 09:20 - 00000000 ____D C:\Program Files (x86)\Citrix
    2016-02-22 09:08 - 2016-02-22 09:08 - 00000000 ____D C:\ProgramData\MFAData
    2016-02-22 09:03 - 2016-02-22 09:42 - 00000000 ____D C:\ProgramData\Avg
    2016-02-22 08:56 - 2016-02-22 08:57 - 16902256 _____ (AVG Technologies) C:\Users\DA BOSS\Downloads\avg_gsr_stb_all_ltst_103.exe
    2016-02-22 08:55 - 2016-02-22 08:55 - 04721416 _____ (AVG Technologies) C:\Users\DA BOSS\Downloads\avg_avc_stb_all_2015_5267_dvd.exe
    2016-02-21 20:57 - 2016-02-21 21:03 - 29562180 _____ C:\Users\DA BOSS\Desktop\mapleshade1.mp4
    2016-02-21 02:24 - 2016-02-21 02:24 - 00551326 _____ C:\Users\DA BOSS\Documents\Attorney Disciplinary Board letter.pdf
    2016-02-20 07:38 - 2016-02-20 07:45 - 27243939 _____ C:\Users\DA BOSS\Desktop\stickyspeed.mp4
    2016-02-19 21:40 - 2016-02-19 21:49 - 25978941 _____ C:\Users\DA BOSS\Desktop\goooster.mp4
    2016-02-19 10:19 - 2016-02-19 10:19 - 00969584 _____ (ROBLOX Corporation) C:\Users\DA BOSS\Downloads\RobloxPlayerLauncher (11).exe
    2016-02-19 07:30 - 2016-02-19 07:30 - 17389123 _____ C:\Users\DA BOSS\Downloads\feline_reference__free_lineart_by_espherio-d6butdt.psd
    2016-02-16 17:07 - 2016-02-16 17:11 - 18114011 _____ C:\Users\DA BOSS\Desktop\ty.mp4
    2016-02-16 16:51 - 2016-02-16 16:51 - 00117065 _____ C:\Users\DA BOSS\Desktop\animation.mp4
    2016-02-15 14:39 - 2016-02-15 14:42 - 19420551 _____ C:\Users\DA BOSS\Desktop\undynesucks.mp4
    2016-02-15 09:13 - 2016-02-15 09:14 - 14115600 _____ (LogMeIn, Inc.) C:\Users\DA BOSS\Downloads\join.me.exe
    2016-02-14 10:25 - 2016-02-14 10:28 - 05641248 _____ C:\Users\DA BOSS\Desktop\ripgoatmom.mp4
    2016-02-09 17:07 - 2016-02-09 17:07 - 01706448 _____ C:\Users\DA BOSS\Downloads\psd_cat_line_by_kawiku-d8nuwmj.psd
    2016-02-09 16:07 - 2016-01-26 23:55 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2016-02-09 16:07 - 2016-01-26 23:45 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2016-02-09 16:07 - 2016-01-26 23:45 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2016-02-09 16:07 - 2016-01-26 23:37 - 01998176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2016-02-09 16:07 - 2016-01-26 23:10 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2016-02-09 16:07 - 2016-01-26 23:05 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2016-02-09 16:07 - 2016-01-26 23:04 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2016-02-09 16:07 - 2016-01-26 22:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2016-02-09 16:07 - 2016-01-26 22:55 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2016-02-09 16:07 - 2016-01-26 22:54 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2016-02-09 16:07 - 2016-01-26 22:48 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2016-02-09 16:07 - 2016-01-26 22:41 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2016-02-09 16:07 - 2016-01-26 22:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
    2016-02-09 16:06 - 2016-01-29 00:57 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2016-02-09 16:06 - 2016-01-29 00:33 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2016-02-09 16:06 - 2016-01-27 00:15 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2016-02-09 16:06 - 2016-01-27 00:15 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2016-02-09 16:06 - 2016-01-27 00:01 - 07476064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2016-02-09 16:06 - 2016-01-27 00:01 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2016-02-09 16:06 - 2016-01-27 00:01 - 01819720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2016-02-09 16:06 - 2016-01-26 23:59 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
    2016-02-09 16:06 - 2016-01-26 23:57 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2016-02-09 16:06 - 2016-01-26 23:57 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
    2016-02-09 16:06 - 2016-01-26 23:57 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
    2016-02-09 16:06 - 2016-01-26 23:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2016-02-09 16:06 - 2016-01-26 23:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
    2016-02-09 16:06 - 2016-01-26 23:54 - 00295264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
    2016-02-09 16:06 - 2016-01-26 23:46 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
    2016-02-09 16:06 - 2016-01-26 23:46 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
    2016-02-09 16:06 - 2016-01-26 23:44 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2016-02-09 16:06 - 2016-01-26 23:44 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
    2016-02-09 16:06 - 2016-01-26 23:43 - 00359776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
    2016-02-09 16:06 - 2016-01-26 23:37 - 00576352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
    2016-02-09 16:06 - 2016-01-26 23:21 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
    2016-02-09 16:06 - 2016-01-26 23:15 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
    2016-02-09 16:06 - 2016-01-26 23:13 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2016-02-09 16:06 - 2016-01-26 23:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2016-02-09 16:06 - 2016-01-26 23:11 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
    2016-02-09 16:06 - 2016-01-26 23:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
    2016-02-09 16:06 - 2016-01-26 23:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
    2016-02-09 16:06 - 2016-01-26 23:08 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
    2016-02-09 16:06 - 2016-01-26 23:07 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
    2016-02-09 16:06 - 2016-01-26 23:05 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2016-02-09 16:06 - 2016-01-26 23:05 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2016-02-09 16:06 - 2016-01-26 23:05 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2016-02-09 16:06 - 2016-01-26 23:04 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
    2016-02-09 16:06 - 2016-01-26 23:03 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
    2016-02-09 16:06 - 2016-01-26 23:02 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
    2016-02-09 16:06 - 2016-01-26 23:01 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2016-02-09 16:06 - 2016-01-26 22:59 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
    2016-02-09 16:06 - 2016-01-26 22:57 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
    2016-02-09 16:06 - 2016-01-26 22:55 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2016-02-09 16:06 - 2016-01-26 22:52 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2016-02-09 16:06 - 2016-01-26 22:50 - 02230784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2016-02-09 16:06 - 2016-01-26 22:50 - 01504768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2016-02-09 16:06 - 2016-01-26 22:50 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
    2016-02-09 16:06 - 2016-01-26 22:49 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2016-02-09 16:06 - 2016-01-26 22:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
    2016-02-09 16:06 - 2016-01-26 22:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2016-02-09 16:06 - 2016-01-26 22:39 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2016-02-09 16:06 - 2016-01-26 22:38 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2016-02-09 16:06 - 2016-01-26 22:38 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2016-02-09 16:06 - 2016-01-26 22:37 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2016-02-09 16:06 - 2016-01-26 22:36 - 02757120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2016-02-09 16:06 - 2016-01-26 22:31 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
    2016-02-08 10:40 - 2016-02-08 10:56 - 90623834 _____ C:\Users\DA BOSS\Desktop\glados.mp4
    2016-02-08 10:10 - 2016-02-08 10:22 - 21751507 _____ C:\Users\DA BOSS\Desktop\glados2.mp4
    2016-02-08 09:43 - 2016-02-08 09:52 - 21788345 _____ C:\Users\DA BOSS\Desktop\glados1.mp4
    2016-02-06 19:17 - 2016-02-06 19:17 - 00058773 _____ C:\Users\DA BOSS\Downloads\splat_brushes_by_mo_fox-d92re6o.zip
    2016-02-06 15:52 - 2016-02-06 16:04 - 61439629 _____ C:\Users\DA BOSS\Desktop\themesongs.mp4
    2016-02-06 15:38 - 2016-02-06 15:39 - 13698187 _____ C:\Users\DA BOSS\Downloads\Nyan Cat [original].mp4
    2016-02-06 14:41 - 2016-02-06 14:42 - 16642767 _____ C:\Users\DA BOSS\Downloads\Undertale - Know you'll always be inside my heart (A song for Toriel).mp4
    2016-02-06 14:33 - 2016-02-06 14:34 - 32445007 _____ C:\Users\DA BOSS\Downloads\Undertale - Blue Lips.mp4
    2016-02-02 19:35 - 2016-02-02 19:35 - 00003334 _____ C:\Users\DA BOSS\Documents\My Movie.wlmp
    2016-02-02 18:30 - 2016-02-02 18:46 - 13965500 _____ C:\Users\DA BOSS\Desktop\nightmare2.mp4
    2016-02-02 18:05 - 2016-02-02 18:12 - 10262300 _____ C:\Users\DA BOSS\Desktop\nightmare1.mp4
    2016-02-02 13:32 - 2016-02-02 13:32 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart (2).zip
    2016-02-02 13:32 - 2016-02-02 13:32 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart (1).zip
    2016-02-02 13:30 - 2016-02-02 13:30 - 00393943 _____ C:\Users\DA BOSS\Downloads\-p2u-_cat_lineart.zip
    2016-01-27 17:15 - 2016-01-27 17:43 - 29471433 _____ C:\Users\DA BOSS\Desktop\blue.mp4
    2016-01-27 16:35 - 2016-01-16 00:37 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
    2016-01-27 16:35 - 2016-01-16 00:36 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2016-01-27 16:35 - 2016-01-16 00:36 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
    2016-01-27 16:35 - 2016-01-16 00:34 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2016-01-27 16:35 - 2016-01-16 00:24 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2016-01-27 16:35 - 2016-01-16 00:23 - 08728920 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2016-01-27 16:35 - 2016-01-16 00:23 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
    2016-01-27 16:35 - 2016-01-16 00:23 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
    2016-01-27 16:35 - 2016-01-16 00:23 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2016-01-27 16:35 - 2016-01-16 00:23 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2016-01-27 16:35 - 2016-01-16 00:23 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2016-01-27 16:35 - 2016-01-16 00:21 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
    2016-01-27 16:35 - 2016-01-16 00:20 - 06971752 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2016-01-27 16:35 - 2016-01-16 00:20 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
    2016-01-27 16:35 - 2016-01-16 00:20 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2016-01-27 16:35 - 2016-01-16 00:20 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2016-01-27 16:35 - 2016-01-16 00:19 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
    2016-01-27 16:35 - 2016-01-16 00:19 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2016-01-27 16:35 - 2016-01-16 00:12 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
    2016-01-27 16:35 - 2016-01-16 00:09 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
    2016-01-27 16:35 - 2016-01-16 00:08 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
    2016-01-27 16:35 - 2016-01-16 00:08 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2016-01-27 16:35 - 2016-01-15 23:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
    2016-01-27 16:35 - 2016-01-15 23:45 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2016-01-27 16:35 - 2016-01-15 23:44 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
    2016-01-27 16:35 - 2016-01-15 23:42 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2016-01-27 16:35 - 2016-01-15 23:41 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
    2016-01-27 16:35 - 2016-01-15 23:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
    2016-01-27 16:35 - 2016-01-15 23:40 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
    2016-01-27 16:35 - 2016-01-15 23:39 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
    2016-01-27 16:35 - 2016-01-15 23:38 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2016-01-27 16:35 - 2016-01-15 23:38 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
    2016-01-27 16:35 - 2016-01-15 23:38 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
    2016-01-27 16:35 - 2016-01-15 23:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2016-01-27 16:35 - 2016-01-15 23:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
    2016-01-27 16:35 - 2016-01-15 23:37 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
    2016-01-27 16:35 - 2016-01-15 23:37 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
    2016-01-27 16:35 - 2016-01-15 23:36 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2016-01-27 16:35 - 2016-01-15 23:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
    2016-01-27 16:35 - 2016-01-15 23:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2016-01-27 16:35 - 2016-01-15 23:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
    2016-01-27 16:35 - 2016-01-15 23:35 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2016-01-27 16:35 - 2016-01-15 23:35 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2016-01-27 16:35 - 2016-01-15 23:34 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
    2016-01-27 16:35 - 2016-01-15 23:34 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
    2016-01-27 16:35 - 2016-01-15 23:34 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
    2016-01-27 16:35 - 2016-01-15 23:34 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2016-01-27 16:35 - 2016-01-15 23:33 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
    2016-01-27 16:35 - 2016-01-15 23:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
    2016-01-27 16:35 - 2016-01-15 23:33 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
    2016-01-27 16:35 - 2016-01-15 23:32 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
    2016-01-27 16:35 - 2016-01-15 23:32 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
    2016-01-27 16:35 - 2016-01-15 23:31 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2016-01-27 16:35 - 2016-01-15 23:31 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
    2016-01-27 16:35 - 2016-01-15 23:31 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
    2016-01-27 16:35 - 2016-01-15 23:31 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
    2016-01-27 16:35 - 2016-01-15 23:31 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
    2016-01-27 16:35 - 2016-01-15 23:30 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2016-01-27 16:35 - 2016-01-15 23:30 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2016-01-27 16:35 - 2016-01-15 23:30 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2016-01-27 16:35 - 2016-01-15 23:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
    2016-01-27 16:35 - 2016-01-15 23:29 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
    2016-01-27 16:35 - 2016-01-15 23:29 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
    2016-01-27 16:35 - 2016-01-15 23:28 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2016-01-27 16:35 - 2016-01-15 23:28 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2016-01-27 16:35 - 2016-01-15 23:28 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
    2016-01-27 16:35 - 2016-01-15 23:28 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
    2016-01-27 16:35 - 2016-01-15 23:27 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2016-01-27 16:35 - 2016-01-15 23:26 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
    2016-01-27 16:35 - 2016-01-15 23:26 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2016-01-27 16:35 - 2016-01-15 23:26 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
    2016-01-27 16:35 - 2016-01-15 23:26 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2016-01-27 16:35 - 2016-01-15 23:25 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
    2016-01-27 16:35 - 2016-01-15 23:25 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
    2016-01-27 16:35 - 2016-01-15 23:25 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
    2016-01-27 16:35 - 2016-01-15 23:24 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
    2016-01-27 16:35 - 2016-01-15 23:24 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
    2016-01-27 16:35 - 2016-01-15 23:24 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
    2016-01-27 16:35 - 2016-01-15 23:24 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
    2016-01-27 16:35 - 2016-01-15 23:23 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2016-01-27 16:35 - 2016-01-15 23:23 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2016-01-27 16:35 - 2016-01-15 23:21 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2016-01-27 16:35 - 2016-01-15 23:20 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2016-01-27 16:35 - 2016-01-15 23:20 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2016-01-27 16:35 - 2016-01-15 23:20 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2016-01-27 16:35 - 2016-01-15 23:20 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
    2016-01-27 16:35 - 2016-01-15 23:19 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
    2016-01-27 16:35 - 2016-01-15 23:19 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2016-01-27 16:35 - 2016-01-15 23:19 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
    2016-01-27 16:35 - 2016-01-15 23:19 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2016-01-27 16:35 - 2016-01-15 23:18 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
    2016-01-27 16:35 - 2016-01-15 23:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
    2016-01-27 16:35 - 2016-01-15 23:16 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2016-01-27 16:35 - 2016-01-15 23:16 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
    2016-01-27 16:35 - 2016-01-15 23:15 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
    2016-01-27 16:35 - 2016-01-15 23:14 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2016-01-27 16:35 - 2016-01-15 23:14 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2016-01-27 16:35 - 2016-01-15 23:11 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
    2016-01-27 16:34 - 2016-01-15 23:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
    2016-01-27 16:34 - 2016-01-15 23:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
    2016-01-27 16:34 - 2016-01-15 23:43 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
    2016-01-27 16:34 - 2016-01-15 23:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
    2016-01-27 16:34 - 2016-01-15 23:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
    2016-01-27 16:34 - 2016-01-15 23:38 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
    2016-01-27 16:34 - 2016-01-15 23:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
    2016-01-27 16:34 - 2016-01-15 23:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
    2016-01-27 16:34 - 2016-01-15 23:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
    2016-01-27 16:34 - 2016-01-15 23:30 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
    2016-01-26 18:14 - 2016-01-26 18:14 - 04388394 _____ C:\Users\DA BOSS\Desktop\asgoresucks.mp4
    2016-01-25 09:34 - 2016-01-25 09:34 - 09286495 _____ C:\Users\DA BOSS\Desktop\danceparty.mp4
     
    ==================== One Month Modified files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-02-24 11:57 - 2016-01-24 12:46 - 00000000 ____D C:\Program Files (x86)\Steam
    2016-02-24 11:56 - 2015-12-25 16:18 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2016-02-24 11:53 - 2015-12-24 21:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2016-02-24 11:51 - 2015-12-24 19:24 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
    2016-02-24 11:37 - 2015-12-24 21:24 - 00189264 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2016-02-24 11:29 - 2015-12-25 16:18 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2016-02-24 07:36 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\AppReadiness
    2016-02-23 10:54 - 2016-01-18 08:48 - 00000000 ____D C:\Users\DA BOSS\AppData\LocalLow\Temp
    2016-02-23 07:25 - 2015-12-24 19:41 - 00000000 ___HD C:\Program Files\WindowsApps
    2016-02-23 07:21 - 2016-01-12 10:40 - 00004172 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D78140DC-BA3F-44E1-A6F3-4CE6760938C8}
    2016-02-22 08:53 - 2015-12-24 19:40 - 00000000 ____D C:\WINDOWS\INF
    2016-02-22 08:53 - 2015-12-24 19:38 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2016-02-21 13:24 - 2015-12-24 19:44 - 00000000 ____D C:\Users\DA BOSS
    2016-02-21 12:04 - 2015-12-24 19:45 - 00000000 __RHD C:\Users\Public\AccountPictures
    2016-02-19 18:31 - 2015-12-25 16:19 - 00002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2016-02-19 18:31 - 2015-12-25 16:19 - 00002295 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2016-02-18 09:16 - 2016-01-05 16:49 - 00000000 ____D C:\Users\DA BOSS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
    2016-02-13 08:30 - 2015-12-25 02:53 - 00000000 ____D C:\WINDOWS\system32\MRT
    2016-02-13 08:25 - 2015-12-25 02:53 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2016-02-11 04:12 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\rescache
    2016-02-11 03:31 - 2015-12-24 19:41 - 00000000 ____D C:\Program Files\Windows Journal
    2016-02-09 16:35 - 2015-12-24 19:31 - 00000000 ____D C:\WINDOWS\CbsTemp
    2016-02-04 19:32 - 2015-12-24 19:48 - 00002378 _____ C:\Users\DA BOSS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2016-02-04 19:32 - 2015-12-24 19:48 - 00000000 ___RD C:\Users\DA BOSS\OneDrive
    2016-02-03 13:01 - 2015-12-24 19:44 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2016-02-03 13:01 - 2015-12-24 19:44 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2016-02-03 07:40 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\NDF
    2016-02-02 08:24 - 2015-12-25 16:18 - 00003996 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2016-02-02 08:24 - 2015-12-25 16:18 - 00003764 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___SD C:\WINDOWS\system32\F12
    2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\oobe
    2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2016-01-28 10:30 - 2015-12-24 19:41 - 00000000 ____D C:\WINDOWS\bcastdvr
     
    ==================== Files in the root of some directories =======
     
    2016-01-06 10:55 - 2016-01-06 10:55 - 0168688 _____ () C:\Users\DA BOSS\AppData\Local\ars.cache
    2016-01-06 10:55 - 2016-01-06 10:55 - 0484539 _____ () C:\Users\DA BOSS\AppData\Local\census.cache
    2016-01-06 10:37 - 2016-01-06 10:37 - 0000036 _____ () C:\Users\DA BOSS\AppData\Local\housecall.guid.cache
    2016-01-12 11:27 - 2015-10-31 10:09 - 0016800 _____ () C:\Users\DA BOSS\AppData\Local\Z@!-812c0ff4-c71f-4a96-bf01-72061ea46366.tmp
    2016-01-12 11:27 - 2015-10-31 10:09 - 0015776 _____ () C:\Users\DA BOSS\AppData\Local\Z@S!-24ec7c9a-3b4e-46c5-83fb-48f825374dcf.tmp
     
    ==================== Bamital & volsnap =================
     
    (There is no automatic fix for files that do not pass verification.)
     
    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
     
     
    LastRegBack: 2016-02-22 19:48
     
     
    My children play Roblox, I've heard a LOT of questionable things about that. Do you know anything about it? Should I maybe uninstall?
    ==================== End of FRST.txt ============================

    Make sure AdwCleaner comes up clean , after the scan make sure you click on CLEAN

     

    Then run Junkware Removal Tool again

     

    [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
      After AdwCleaning and running Junkware removal go ahead and post a new FRST log again I mostly will not need additions
       
       
      Roblox seems ok but its what kids do with it can be the problem, it opens a door on your computer for other players , not good

      AdwCleaner

       

      # AdwCleaner v5.036 - Logfile created 24/02/2016 at 12:07:15
      # Updated 22/02/2016 by Xplode
      # Database : 2016-02-24.1 [Server]
      # Operating system : Windows 10 Pro  (x64)
      # Username : DA BOSS - DESKTOP-A3GLD76
      # Running from : C:\Users\DA BOSS\Desktop\AdwCleaner.exe
      # Option : Cleaning
      # Support : http://toolslib.net/forum
       
      ***** [ Services ] *****
       
       
      ***** [ Folders ] *****
       
      [-] Folder Deleted : C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\macpddegmcklbbnbdemccckkmhaegdlf
       
      ***** [ Files ] *****
       
       
      ***** [ DLLs ] *****
       
       
      ***** [ Shortcuts ] *****
       
       
      ***** [ Scheduled tasks ] *****
       
       
      ***** [ Registry ] *****
       
       
      ***** [ Web browsers ] *****
       
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://astromenda.com/?f=7&a=ast_secureddownload_14_36_ch&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0SzyyBzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEyCzz0EtDyDtG0BtAzyyBtGzzzz0E0DtGtD0FyDyEtGtD0Ezyzy0Czz0FtA0FzzyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0F0AyCzy0DtA0CtGtA0Ezz0EtGyEtCyDtBtGzz0AtCtAtGtA0AzzzztByEtBtB0CtCyD0E2Q&cr=284385966&ir=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.dregol.com/?f=7&a=drg_suma_15_22&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByEyEtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StCtCyDtC0B0E0A0DtGtC0DtC0BtGtCtCtC0CtGyBzytDtCtGzzyD0F0AtAtC0FzyyE0B0Ezy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FtD0C0A0ByByEtG0AtC0F0FtGyE0A0A0CtGzy0AzytCtGzyyBtDzyyEzyzztByC0F0DyD2QtN0A0LzuyE&cr=1770093444&ir=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.trovi.com/?gd=&ctid=CT3324769&octid=EB_ORIGINAL_CTID&ISID=M31A5AC2F-450E-4BEE-A3CA-CAAD8FD8C08A&SearchSource=55&CUI=&UM=8&UP=SP44FB3AA5-CFC4-4DA6-9FD1-4F7E9DE3B678&D=061315&SSPV=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_suma_15_24¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAtAtBzyyBtGyByCyE0BtG0F0D0DtDtGyB0B0A0BtGzy0EtDyDtD0CtDzyyBtDtBtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0B0EyE0CzztDtCtG0AyEtByDtGyE0DzztAtGzyyEtC0AtG0D0DyDtB0C0C0B0CtB0CyBtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26cr%3D929903380%26a%3Dwncy_suma_15_24%26os%3DWindows 7 Home Premium
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : macpddegmcklbbnbdemccckkmhaegdlf
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mfpcpilhpbdgmnfaoonnnofhdmcbejhh
       
      *************************
       
      :: "Tracing" keys removed
      :: Winsock settings cleared
       
      *************************
       
      C:\AdwCleaner\AdwCleaner[C1].txt - [4524 bytes] - [23/02/2016 11:30:38]
      C:\AdwCleaner\AdwCleaner[C2].txt - [3604 bytes] - [24/02/2016 11:50:56]
      C:\AdwCleaner\AdwCleaner[C3].txt - [3233 bytes] - [24/02/2016 12:07:15]
      C:\AdwCleaner\AdwCleaner[S1].txt - [4257 bytes] - [23/02/2016 11:27:20]
      C:\AdwCleaner\AdwCleaner[S2].txt - [3251 bytes] - [24/02/2016 09:46:07]
      C:\AdwCleaner\AdwCleaner[S3].txt - [3324 bytes] - [24/02/2016 11:42:07]
      C:\AdwCleaner\AdwCleaner[S4].txt - [3397 bytes] - [24/02/2016 11:48:35]
      C:\AdwCleaner\AdwCleaner[S5].txt - [3543 bytes] - [24/02/2016 12:05:07]
       
      ########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [3671 bytes] ##########

      AdwCleaner 

       

      # AdwCleaner v5.036 - Logfile created 24/02/2016 at 12:20:25
      # Updated 22/02/2016 by Xplode
      # Database : 2016-02-24.1 [Server]
      # Operating system : Windows 10 Pro  (x64)
      # Username : DA BOSS - DESKTOP-A3GLD76
      # Running from : C:\Users\DA BOSS\Desktop\AdwCleaner.exe
      # Option : Cleaning
      # Support : http://toolslib.net/forum
       
      ***** [ Services ] *****
       
       
      ***** [ Folders ] *****
       
      [-] Folder Deleted : C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\macpddegmcklbbnbdemccckkmhaegdlf
       
      ***** [ Files ] *****
       
       
      ***** [ DLLs ] *****
       
       
      ***** [ Shortcuts ] *****
       
       
      ***** [ Scheduled tasks ] *****
       
       
      ***** [ Registry ] *****
       
       
      ***** [ Web browsers ] *****
       
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://astromenda.com/?f=7&a=ast_secureddownload_14_36_ch&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0SzyyBzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEyCzz0EtDyDtG0BtAzyyBtGzzzz0E0DtGtD0FyDyEtGtD0Ezyzy0Czz0FtA0FzzyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0F0AyCzy0DtA0CtGtA0Ezz0EtGyEtCyDtBtGzz0AtCtAtGtA0AzzzztByEtBtB0CtCyD0E2Q&cr=284385966&ir=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.dregol.com/?f=7&a=drg_suma_15_22&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByEyEtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StCtCyDtC0B0E0A0DtGtC0DtC0BtGtCtCtC0CtGyBzytDtCtGzzyD0F0AtAtC0FzyyE0B0Ezy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FtD0C0A0ByByEtG0AtC0F0FtGyE0A0A0CtGzy0AzytCtGzyyBtDzyyEzyzztByC0F0DyD2QtN0A0LzuyE&cr=1770093444&ir=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.trovi.com/?gd=&ctid=CT3324769&octid=EB_ORIGINAL_CTID&ISID=M31A5AC2F-450E-4BEE-A3CA-CAAD8FD8C08A&SearchSource=55&CUI=&UM=8&UP=SP44FB3AA5-CFC4-4DA6-9FD1-4F7E9DE3B678&D=061315&SSPV=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_suma_15_24¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAtAtBzyyBtGyByCyE0BtG0F0D0DtDtGyB0B0A0BtGzy0EtDyDtD0CtDzyyBtDtBtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0B0EyE0CzztDtCtG0AyEtByDtGyE0DzztAtGzyyEtC0AtG0D0DyDtB0C0C0B0CtB0CyBtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26cr%3D929903380%26a%3Dwncy_suma_15_24%26os%3DWindows 7 Home Premium
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : macpddegmcklbbnbdemccckkmhaegdlf
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mfpcpilhpbdgmnfaoonnnofhdmcbejhh
       
      *************************
       
      :: "Tracing" keys removed
      :: Winsock settings cleared
       
      *************************
       
      C:\AdwCleaner\AdwCleaner[C1].txt - [4524 bytes] - [23/02/2016 11:30:38]
      C:\AdwCleaner\AdwCleaner[C2].txt - [3604 bytes] - [24/02/2016 11:50:56]
      C:\AdwCleaner\AdwCleaner[C3].txt - [3750 bytes] - [24/02/2016 12:07:15]
      C:\AdwCleaner\AdwCleaner[C4].txt - [3306 bytes] - [24/02/2016 12:20:25]
      C:\AdwCleaner\AdwCleaner[S1].txt - [4257 bytes] - [23/02/2016 11:27:20]
      C:\AdwCleaner\AdwCleaner[S2].txt - [3251 bytes] - [24/02/2016 09:46:07]
      C:\AdwCleaner\AdwCleaner[S3].txt - [3324 bytes] - [24/02/2016 11:42:07]
      C:\AdwCleaner\AdwCleaner[S4].txt - [3397 bytes] - [24/02/2016 11:48:35]
      C:\AdwCleaner\AdwCleaner[S5].txt - [3543 bytes] - [24/02/2016 12:05:07]
      C:\AdwCleaner\AdwCleaner[S6].txt - [3689 bytes] - [24/02/2016 12:18:45]
       
      ########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt - [3817 bytes] ##########
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Junkware Removal Tool (JRT) by Malwarebytes
      Version: 8.0.3 (02.09.2016)
      Operating System: Windows 10 Pro x64 
      Ran by [removed] (Administrator) on Wed 02/24/2016 at 12:37:05.18
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
       
       
       
       
      File System: 1 
       
      Successfully deleted: C:\Users\DA BOSS\AppData\Local\nico mak computing (Folder) 
       
       
       
      Registry: 0 
       
       
       
       
       
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Scan was completed on Wed 02/24/2016 at 12:39:28.41
      End of JRT log
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      # AdwCleaner v5.036 - Logfile created 24/02/2016 at 12:41:25
      # Updated 22/02/2016 by Xplode
      # Database : 2016-02-24.1 [Server]
      # Operating system : Windows 10 Pro  (x64)
      # Username : DA BOSS - DESKTOP-A3GLD76
      # Running from : C:\Users\DA BOSS\Desktop\AdwCleaner.exe
      # Option : Cleaning
      # Support : http://toolslib.net/forum
       
      ***** [ Services ] *****
       
       
      ***** [ Folders ] *****
       
      [-] Folder Deleted : C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Extensions\macpddegmcklbbnbdemccckkmhaegdlf
       
      ***** [ Files ] *****
       
       
      ***** [ DLLs ] *****
       
       
      ***** [ Shortcuts ] *****
       
       
      ***** [ Scheduled tasks ] *****
       
       
      ***** [ Registry ] *****
       
       
      ***** [ Web browsers ] *****
       
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://astromenda.com/?f=7&a=ast_secureddownload_14_36_ch&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0SzyyBzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StB0ByEyCzz0EtDyDtG0BtAzyyBtGzzzz0E0DtGtD0FyDyEtGtD0Ezyzy0Czz0FtA0FzzyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0F0AyCzy0DtA0CtGtA0Ezz0EtGyEtCyDtBtGzz0AtCtAtGtA0AzzzztByEtBtB0CtCyD0E2Q&cr=284385966&ir=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.dregol.com/?f=7&a=drg_suma_15_22&cd=2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByEyEtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StCtCyDtC0B0E0A0DtGtC0DtC0BtGtCtCtC0CtGyBzytDtCtGzzyD0F0AtAtC0FzyyE0B0Ezy2QtN1M1F1B2Z1V1N2Y1L1Qzu2StC0FtD0C0A0ByByEtG0AtC0F0FtGyE0A0A0CtGzy0AzytCtGzyyBtDzyyEzyzztByC0F0DyD2QtN0A0LzuyE&cr=1770093444&ir=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.trovi.com/?gd=&ctid=CT3324769&octid=EB_ORIGINAL_CTID&ISID=M31A5AC2F-450E-4BEE-A3CA-CAAD8FD8C08A&SearchSource=55&CUI=&UM=8&UP=SP44FB3AA5-CFC4-4DA6-9FD1-4F7E9DE3B678&D=061315&SSPV=
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_suma_15_24¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0Czz0DyBtCzytB0C0EtDtAzzyBtB0E0CtN0D0Tzu0StCtByCtDtN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyC0A0BtAtAtBzyyBtGyByCyE0BtG0F0D0DtDtGyB0B0A0BtGzy0EtDyDtD0CtDzyyBtDtBtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0B0EyE0CzztDtCtG0AyEtByDtGyE0DzztAtGzyyEtC0AtG0D0DyDtB0C0C0B0CtB0CyBtC2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBzyyD%26cr%3D929903380%26a%3Dwncy_suma_15_24%26os%3DWindows 7 Home Premium
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : macpddegmcklbbnbdemccckkmhaegdlf
      [-] [C:\Users\DA BOSS\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mfpcpilhpbdgmnfaoonnnofhdmcbejhh
       
      *************************
       
      :: "Tracing" keys removed
      :: Winsock settings cleared
       
      *************************
       
      C:\AdwCleaner\AdwCleaner[C1].txt - [4524 bytes] - [23/02/2016 11:30:38]
      C:\AdwCleaner\AdwCleaner[C2].txt - [3604 bytes] - [24/02/2016 11:50:56]
      C:\AdwCleaner\AdwCleaner[C3].txt - [3750 bytes] - [24/02/2016 12:07:15]
      C:\AdwCleaner\AdwCleaner[C4].txt - [3896 bytes] - [24/02/2016 12:20:25]
      C:\AdwCleaner\AdwCleaner[C5].txt - [3379 bytes] - [24/02/2016 12:41:25]
      C:\AdwCleaner\AdwCleaner[S1].txt - [4257 bytes] - [23/02/2016 11:27:20]
      C:\AdwCleaner\AdwCleaner[S2].txt - [3251 bytes] - [24/02/2016 09:46:07]
      C:\AdwCleaner\AdwCleaner[S3].txt - [3324 bytes] - [24/02/2016 11:42:07]
      C:\AdwCleaner\AdwCleaner[S4].txt - [3397 bytes] - [24/02/2016 11:48:35]
      C:\AdwCleaner\AdwCleaner[S5].txt - [3543 bytes] - [24/02/2016 12:05:07]
      C:\AdwCleaner\AdwCleaner[S6].txt - [3689 bytes] - [24/02/2016 12:18:45]
      C:\AdwCleaner\AdwCleaner[S7].txt - [3835 bytes] - [24/02/2016 12:34:29]
       
      ########## EOF - C:\AdwCleaner\AdwCleaner[C5].txt - [3963 bytes] ##########

      Ask AI

      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI