Hi, thanks in advance for your help.
My son has an Inspiron 15r with a pretty decent infection i'm sure. Touch pad doesn't work. No networking at all, ethernet, wifi, usb(wifi)dongle. Gives the Failed to connect to a windows service error on start up. Cannot view system event log. Cannot get admin privileges. In network just states dependency service or group failed to start. When i try to use aswMBR to scan i get the error avast Antirootkit has stopped working. I have included the log from frst.
Every thing i have read on the internet to fix failed to connect to a windows service and dependency or service group failed to start
I tried using combo fix(before i read your instructions) wouldn't let me anyway no admin priveledges
Again thanks for the help. I am almost resigned that i am going to need to reinstall windows, but i dont want to as i dont have the recovery disks and it will be a mission.
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotect
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotectall
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3220468
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3306061
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update lucky leap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util lucky leap
Successfully disinfected: [Shortcut] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Successfully disinfected: [Shortcut] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Successfully disinfected: [Shortcut] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{130A331A-146D-45CE-AA46-0418128A7D09}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{28459633-034C-4E3C-A122-96901C724EC4}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{4D1B3448-BFCC-40BD-8355-737986A16921}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{B33802BE-2E48-42C8-8D0C-04B1487639C8}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{B6C7B800-8C9E-44C8-9815-B827B893302C}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{C53AFFB1-6346-4B78-9A26-DBF44ECDD7F8}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{C885A46C-1057-4578-8EBE-C79A1D563EDF}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{D790316F-57E6-4F7D-B24E-49277B0B05DE}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{F44D68FF-9217-4535-BECE-67BB530161CA}
Successfully deleted: [Empty Folder] C:\Users\Tomton98\Appdata\Local\{F5ADF7CC-8DDB-4775-A595-1B1FA3C50FE7}
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\Local\avg safeguard toolbar
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\LocalLow\avg safeguard toolbar
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\LocalLow\utorrentcontrol_v2
Successfully deleted: [Folder] C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\arcadeparlor
Successfully deleted: [Folder] C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ijblflkdjdopkpdgllkmlbgcffjbnfda
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Tomton98\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-06-2016 02
Ran by [removed] (administrator) on TOMTON98-PC (28-06-2016 07:06:46)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\CxUtilSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\SmartAudio3.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
() C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe
(Facebook Inc.) C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\Grid64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(GoPro) C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2878728 2014-04-17] (ELAN Microelectronics Corp.)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5729648 2012-02-08] (Dell Inc.)
HKLM\…\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SA3\SACpl.exe [1628288 2011-09-09] (Conexant Systems, Inc.)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\…\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\…\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-23] (Apple Inc.)
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-30] (Intel Corporation)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-17] (Intel Corporation)
HKLM-x32\…\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-14] (Creative Technology Ltd)
HKLM-x32\…\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.)
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-06-27] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-20] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM-x32\…\Run: [NeroLauncher] => C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [67496 2012-08-21] ()
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-09-23] (Apple Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-07-23] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6108752 2015-11-12] (AVAST Software)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
HKLM-x32\…\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2016-04-05] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3077712 2016-04-30] (Valve Corporation)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-28] (Electronic Arts)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [RGSC] => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-07-23] (AMD)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Grid] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe [401408 2013-07-23] ()
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [News.net] => C:\Program Files\News.net\BreakingNews\DesktopContainer.exe
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Facebook Update] => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-01-12] (Facebook Inc.)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50670720 2016-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Run: [uTorrent] => "C:\Users\Tomton98\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\MountPoints2: {c1049b66-68da-11e2-8874-685d432459a0} - E:\setup_vmb_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\MountPoints2: {c1049b6c-68da-11e2-8874-685d432459a0} - E:\setup_vmb_lite.exe /checkApplicationPresence
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-21] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk [2014-01-10]
ShortcutTarget: CineForm Status.lnk -> C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
Startup: C:\Users\GUEST DAWW\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.0.lnk [2012-05-16]
ShortcutTarget: Intel(R) Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 09 No File
Winsock: -> Catalog5 - Broken internet access due to missing entry. <===== ATTENTION
Tcpip\..\Interfaces\{D8A27A5F-3916-43BC-B7D9-A5FAAE7F9BC8}: [NameServer] 10.143.147.147 10.143.147.148
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.news.net/index.php?referid=118
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
URLSearchHook: HKLM-x32 - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
URLSearchHook: HKLM-x32 - (No Name) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - No File
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {7F8CCD3E-6F4E-4BA1-9F04-908D189BA03F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM;=AVASDF&PC;=AV01
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001 -> {7F8CCD3E-6F4E-4BA1-9F04-908D189BA03F} URL =
BHO: No Name -> {1346D119-159F-2B54-51CC-ABEF9A4BE183} -> No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-03-27] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-21] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-06] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-03-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-21] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-06] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-06] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-06] (Google Inc.)
DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll No File
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-13] ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-03-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-03-27] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\\npsitesafety.dll [No File]
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-04] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.3 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll [No File]
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll [2013-05-30] (ESN Social Software AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-10] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-09-07] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-06-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Tomton98\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Tomton98\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-09-07] (Pando Networks)
FF Plugin HKU\S-1-5-21-1821522787-3724074743-2321965764-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-04-12] (Ubisoft)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-14]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid;=GOB1&co;=AU&userid;=498b7376-d3a1-3183-ef1e-84d17cd84b02&searchtype;=hp&installDate;=04/11/2013","hxxp://www.google.com/ig/redirectdomain?brand=ASUT&bmod;=ASUT"
CHR Profile: C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Docs Offline) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-01]
CHR Extension: (Avast Online Security) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-09]
CHR Extension: (Skype) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-05-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Gmail) - C:\Users\Tomton98\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-21]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-07-21] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-07-21] (Avast Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [802688 2015-01-22] ()
R2 CxUtilSvc; C:\Program Files\Conexant\SA3\CxUtilSvc.exe [109184 2011-10-12] (Conexant Systems, Inc.)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [174624 2015-01-17] (EasyAntiCheat Ltd)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2016-04-05] (LogMeIn, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-09] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2120712 2016-06-01] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-02-28] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-09] (Intel® Corporation)
S2 Hamachi2Svc; no ImagePath
S3 WinHttpAutoProxySvc; winhttp.dll [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [36096 2013-05-22] (Advanced Micro Devices, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-07-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-07-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-07-21] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150160 2015-07-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-07-21] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-07-21] (AVAST Software)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-21] (Avast Software)
S3 ZTEusbwwan; C:\Windows\System32\DRIVERS\ZTEusbwwan.sys [235520 2010-06-10] (ZTE Incorporated)
U3 aswMBR; \??\C:\Users\Tomton98\AppData\Local\Temp\aswMBR.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-06-28 07:06 - 2016-06-28 07:07 - 00026953 _____ C:\Users\Tomton98\Desktop\FRST.txt
2016-06-28 07:06 - 2016-06-28 07:06 - 00000000 ____D C:\FRST
2016-06-28 07:04 - 2016-06-28 06:59 - 05198336 _____ (AVAST Software) C:\Users\Tomton98\Desktop\aswMBR.exe
2016-06-28 07:04 - 2016-06-28 06:58 - 02389504 _____ (Farbar) C:\Users\Tomton98\Desktop\FRST64.exe
2016-06-27 23:24 - 2016-06-27 23:24 - 00000000 ____D C:\Users\Tomton98\Documents\Add-in Express
2016-06-27 22:51 - 2016-06-27 22:49 - 01610816 _____ (Malwarebytes) C:\Users\Tomton98\Desktop\JRT (1).exe
2016-06-27 22:39 - 2016-06-27 22:39 - 00000000 ____D C:\Qoobox
2016-06-27 22:38 - 2016-06-27 22:38 - 00000000 ____D C:\Windows\erdnt
2016-06-27 22:38 - 2016-06-27 22:34 - 05659224 ____R (Swearware) C:\Users\Tomton98\Desktop\ComboFix.exe
2016-06-27 20:30 - 2016-06-27 21:40 - 00000000 ____D C:\Windows\pss
2016-06-27 17:30 - 2016-06-27 17:30 - 00283344 _____ C:\Windows\Minidump\062716-21481-01.dmp
2016-06-27 16:20 - 2016-06-27 17:26 - 00000271 _____ C:\WirelessDiagLog.csv
2016-06-24 15:29 - 2016-06-24 15:30 - 00000000 ____D C:\Users\Tomton98\Desktop\bomb 23.06.2016
2016-06-02 17:30 - 2016-06-02 17:30 - 00010312 ____N C:\bootsqm.dat
2016-05-31 15:54 - 2016-06-01 16:51 - 00003034 _____ C:\Windows\System32\Tasks\EVGAPrecision
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-06-28 05:45 - 2009-07-14 14:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-06-28 05:45 - 2009-07-14 14:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-06-28 05:41 - 2014-12-19 00:22 - 00000000 ____D C:\Users\Tomton98\AppData\Local\LogMeIn Hamachi
2016-06-28 05:36 - 2012-05-16 19:52 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2016-06-28 05:36 - 2012-05-16 19:52 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2016-06-28 05:36 - 2012-05-16 19:42 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2016-06-28 04:07 - 2013-04-15 10:42 - 00000000 ____D C:\Program Files\WinRAR
2016-06-27 23:26 - 2013-11-04 19:48 - 00000000 ____D C:\Program Files\HitmanPro
2016-06-27 23:21 - 2012-12-19 21:10 - 00000000 ____D C:\Users\Tomton98\AppData\Roaming\uTorrent
2016-06-27 22:37 - 2009-07-14 15:13 - 00782288 _____ C:\Windows\system32\PerfStringBackup.INI
2016-06-27 22:37 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\inf
2016-06-27 22:20 - 2012-12-17 20:35 - 00000000 ____D C:\Program Files (x86)\Origin
2016-06-27 19:46 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-06-27 19:46 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\system32\Dism
2016-06-27 17:30 - 2013-04-14 10:51 - 655389053 _____ C:\Windows\MEMORY.DMP
2016-06-27 17:30 - 2013-04-14 10:51 - 00000000 ____D C:\Windows\Minidump
2016-06-27 16:29 - 2013-10-06 14:34 - 00000000 ____D C:\Users\Tomton98\AppData\Local\ElevatedDiagnostics
2016-06-27 16:26 - 2013-02-22 14:30 - 00943320 _____ C:\Windows\ntbtlog.txt
2016-06-24 15:29 - 2015-04-15 21:34 - 00000000 ____D C:\Users\Tomton98\AppData\Local\Windows Live
2016-06-24 15:28 - 2015-08-26 20:37 - 00000000 ____D C:\Users\Tomton98\AppData\Roaming\vlc
2016-06-22 19:00 - 2012-05-16 19:46 - 00000000 ____D C:\ProgramData\Temp
2016-06-03 08:43 - 2012-12-10 14:29 - 00000000 ____D C:\Users\Tomton98\AppData\Local\Nero
2016-06-01 22:58 - 2012-05-16 19:13 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-06-01 22:31 - 2014-01-12 21:26 - 00000940 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA.job
2016-06-01 22:31 - 2014-01-12 21:26 - 00000918 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core.job
2016-06-01 22:27 - 2012-12-12 06:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-06-01 16:50 - 2012-12-11 14:29 - 00000000 ____D C:\Program Files (x86)\Steam
2016-06-01 16:48 - 2016-05-18 18:12 - 00000000 ____D C:\Users\Tomton98\AppData\LocalLow\uTorrent
2016-06-01 16:47 - 2012-12-12 06:37 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-01 16:46 - 2009-07-14 15:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-31 15:12 - 2014-03-10 19:46 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
==================== Files in the root of some directories =======
2013-03-10 13:59 - 2015-03-26 20:43 - 0009728 _____ () C:\Users\Tomton98\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-03-17 15:11 - 2013-03-17 15:11 - 0004096 ____H () C:\Users\Tomton98\AppData\Local\keyfile3.drm
2013-03-17 15:50 - 2015-01-22 23:22 - 0007601 _____ () C:\Users\Tomton98\AppData\Local\resmon.resmoncfg
2015-09-18 13:38 - 2015-09-18 13:38 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{265DA060-8805-4A19-A71F-E4B342EA3713}
2016-01-15 11:51 - 2016-01-15 11:53 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{AE64DE04-EC8A-4EF3-A4BA-4AED777EE961}
2015-01-28 21:09 - 2015-01-28 21:09 - 0000000 _____ () C:\Users\Tomton98\AppData\Local\{FB802408-E561-4C5E-B4A9-40E3C118C883}
Some files in TEMP:
====================
C:\Users\GUEST DAWW\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Tomton98\AppData\Local\Temp\13-4_mobility_win7_win8_64_dd_ccc_whql.exe
C:\Users\Tomton98\AppData\Local\Temp\3zhnejvq.dll
C:\Users\Tomton98\AppData\Local\Temp\api1qhxy.dll
C:\Users\Tomton98\AppData\Local\Temp\BackupSetup.exe
C:\Users\Tomton98\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprsuzwx.dll
C:\Users\Tomton98\AppData\Local\Temp\ev1fr3pf.dll
C:\Users\Tomton98\AppData\Local\Temp\gcapi_dll.dll
C:\Users\Tomton98\AppData\Local\Temp\HitmanPro.exe
C:\Users\Tomton98\AppData\Local\Temp\j75cknpg.dll
C:\Users\Tomton98\AppData\Local\Temp\nsaD8F6.exe
C:\Users\Tomton98\AppData\Local\Temp\nseCF43.exe
C:\Users\Tomton98\AppData\Local\Temp\nsgAB14.exe
C:\Users\Tomton98\AppData\Local\Temp\nsgD1C3.exe
C:\Users\Tomton98\AppData\Local\Temp\nsjCA44.exe
C:\Users\Tomton98\AppData\Local\Temp\nslA3E0.exe
C:\Users\Tomton98\AppData\Local\Temp\nso2532.exe
C:\Users\Tomton98\AppData\Local\Temp\nszD677.exe
C:\Users\Tomton98\AppData\Local\Temp\RegClean8.exe
C:\Users\Tomton98\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Tomton98\AppData\Local\Temp\sonarinst.exe
C:\Users\Tomton98\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Tomton98\AppData\Local\Temp\utt5AD6.tmp.exe
C:\Users\Tomton98\AppData\Local\Temp\uttE421.tmp.exe
C:\Users\Tomton98\AppData\Local\Temp\wtyqn_ke.dll
C:\Users\Tomton98\AppData\Local\Temp\_is7BEE.exe
C:\Users\Tomton98\AppData\Local\Temp\_n0nuc2j.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD.
LastRegBack: 2016-05-28 01:15
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-06-2016 02
Ran by [removed] (2016-06-28 07:07:24)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-12-10 04:13:49)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1821522787-3724074743-2321965764-500 - Administrator - Disabled)
Guest (S-1-5-21-1821522787-3724074743-2321965764-501 - Limited - Disabled)
GUEST DAWW (S-1-5-21-1821522787-3724074743-2321965764-1003 - Limited - Enabled) => C:\Users\GUEST DAWW
HomeGroupUser$ (S-1-5-21-1821522787-3724074743-2321965764-1002 - Limited - Enabled)
Tomton98 (S-1-5-21-1821522787-3724074743-2321965764-1001 - Administrator - Enabled) => C:\Users\Tomton98
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Addon Sync 2009 (HKLM-x32\…\{4E3AA543-09D7-401E-9DF2-2591D24C7C49}) (Version: 1.0.67 - YomaTools)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Adobe Reader X (10.1.15) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.15 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
AMD Catalyst Install Manager (HKLM\…\{3CB2E87A-33CC-8E5A-2D3F-E9ACDE622704}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{A50679D9-6CBD-4FCD-BACB-62EF3894F6F3}) (Version: 4.0.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{1F72FDD5-A069-45B4-928F-D0F16492DC69}) (Version: 4.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Arma 2 (HKLM-x32\…\Steam App 33910) (Version: - Bohemia Interactive)
ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\…\ARMA 2 Operation Arrowhead) (Version: - )
ArmA 2 Uninstall (HKLM-x32\…\ArmA 2) (Version: - )
Arma 2: Operation Arrowhead (HKLM-x32\…\Steam App 33930) (Version: - Bohemia Interactive)
Arma 3 Alpha (HKLM-x32\…\Steam App 107410) (Version: - Bohemia Interactive)
Arma 3 Alpha Lite (HKLM-x32\…\Steam App 228800) (Version: - Bohemia Interactive)
Arma: Cold War Assault (HKLM-x32\…\Steam App 65790) (Version: - Bohemia Interactive)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 10.3.2223 - AVAST Software)
Battlefield 3™ (HKLM-x32\…\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.5.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\…\Battlelog Web Plugins) (Version: 2.1.7 - EA Digital Illusions CE AB)
BattlEye for OA Uninstall (HKLM-x32\…\BattlEye for OA) (Version: - )
BattlEye Uninstall (HKLM-x32\…\BattlEye for A2) (Version: - )
BioShock (HKLM-x32\…\{E280923D-C5D9-4728-8C79-AC9A0DC75875}) (Version: 2.5.0000 - 2K Games)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon MP550 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series) (Version: - )
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Chivalry: Medieval Warfare (HKLM-x32\…\Steam App 219640) (Version: - Torn Banner Studios)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Conexant SmartAudio HD (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.54.29.0 - Conexant)
Connect DLC 5 Toolbar for IE (HKLM-x32\…\IECT3306061) (Version: 6.17.1.25 - Connect DLC 5) <==== ATTENTION
Counter-Strike: Global Offensive (HKLM-x32\…\Steam App 730) (Version: - Valve)
Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version: - Valve)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DayZ (HKLM-x32\…\Steam App 221100) (Version: - Bohemia Interactive)
DayZ Commander (HKLM-x32\…\{BAD8395E-CE31-44AA-B9FE-A14FCD0ABE4A}) (Version: 0.9.110 - Dotjosh Studios)
Dead Space™ 3 (HKLM-x32\…\{D4329609-4102-4F8C-B83F-7FE024EEA314}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Dell Data Vault (Version: 4.3.4.0 - Dell Inc.) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.67 - Dell Inc.)
Dell DataSafe Local Backup (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.67 - Dell Inc.)
Dell DataSafe Online (HKLM-x32\…\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell)
Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell SupportAssistAgent (HKLM-x32\…\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.1.0.47 - Dell)
Dell Touchpad (HKLM\…\Elantech) (Version: 11.3.16.1 - ELAN Microelectronic Corp.)
Dell Update (HKLM-x32\…\{90437913-9D4D-4D9D-B438-B8664DF851E9}) (Version: 1.7.1007.0 - Dell Inc.)
Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
Dropbox (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
eBay (HKLM-x32\…\{A8B88634-7F90-402F-B66A-86429755F6A5}) (Version: 1.4.0 - eBay Inc.)
ESN Sonar (HKLM-x32\…\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
EVGA Precision X 4.2.1 (HKLM-x32\…\PrecisionX) (Version: 4.2.1 - EVGA Corporation)
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fallout 3 (HKLM-x32\…\Steam App 22300) (Version: - Bethesda Game Studios)
Fallout: New Vegas (HKLM-x32\…\Steam App 22380) (Version: - Obsidian Entertainment)
Far Cry 3 (HKLM-x32\…\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
Fraps (remove only) (HKLM-x32\…\Fraps) (Version: - )
Game Dev Tycoon (HKLM-x32\…\Steam App 239820) (Version: - Greenheart Games)
Garry's Mod (HKLM-x32\…\Steam App 4000) (Version: - Garry)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 50.0.2661.102 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
GoPro Studio 2.0.0 (HKLM-x32\…\GoPro Studio) (Version: 2.0.0 - WoodmanLabs Inc. d.b.a. GoPro)
Gotham City Impostors: Free To Play (HKLM-x32\…\Steam App 206210) (Version: - )
Grand Theft Auto IV (HKLM-x32\…\GFWL_{5454083B-632A-4F1D-9CED-3D1000008600}) (Version: 1.0.0000.134 - Rockstar Games Inc)
Grand Theft Auto IV (x32 Version: 1.0.0000.134 - Rockstar Games Inc) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0005.134 - Rockstar Games Inc.) Hidden
Grand Theft Auto: San Andreas (HKLM-x32\…\Steam App 12120) (Version: - Rockstar Games)
GTA San Andreas (HKLM-x32\…\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
Guns of Icarus Online (HKLM-x32\…\Steam App 209080) (Version: - Muse Games)
Heroes & Generals (HKLM-x32\…\Steam App 227940) (Version: - Reto-Moto)
Hitman: Absolution (HKLM-x32\…\Steam App 203140) (Version: - IO Interactive)
Hitman: Sniper Challenge (HKLM-x32\…\Steam App 205930) (Version: - IO Interactive)
HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
iCloud (HKLM\…\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3090 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.1.1399 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\…\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{F0932859-AA60-459E-B843-0BDECA34E2C7}) (Version: 2.0.0.0086 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel(R) WiDi (HKLM-x32\…\{7FCB8D5D-9396-4D17-8CFA-349D6D49CD32}) (Version: 3.0.13.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - )
Intel® PROSet/Wireless WiFi Software (HKLM\…\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\…\{538B98C3-773F-4F20-9C66-802D104DCBE2}) (Version: 1.23.219.2 - Intel Corporation)
iTunes (HKLM\…\{96984DE8-1DB8-425C-AC8C-3098BC696F04}) (Version: 12.3.0.44 - Apple Inc.)
Java 7 Update 51 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java 7 Update 9 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
L.A. Noire (HKLM-x32\…\Steam App 110800) (Version: - Team Bondi)
League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead 2 (HKLM-x32\…\Steam App 550) (Version: - Valve)
LogMeIn Hamachi (HKLM-x32\…\LogMeIn Hamachi) (Version: 2.2.0.420 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.420 - LogMeIn, Inc.) Hidden
lucky leap 1.0.0 (HKLM\…\lucky leap) (Version: 1.0.0 - luckyleap)
Max Payne 3 (HKLM-x32\…\{1AA94747-3BF6-4237-9E1A-7B3067738FE1}) (Version: 1.0.0.0 - Rockstar Games)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\…\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\…\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.0.162.0 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\…\{91110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\…\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\…\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\…\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Oblivion (HKLM-x32\…\{35CB6715-41F8-4F99-8881-6FC75BF054B0}) (Version: 1.00.0000 - Bethesda Softworks)
Origin (HKLM-x32\…\Origin) (Version: 9.1.3.2637 - Electronic Arts, Inc.)
Pando Media Booster (HKLM-x32\…\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PAYDAY 2 (HKLM-x32\…\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
PAYDAY: The Heist (HKLM-x32\…\Steam App 24240) (Version: - Overkill)
PlanetSide 2 (HKLM-x32\…\Steam App 218230) (Version: - Sony Online Entertainment)
Product Support 1.74.b1377 (HKLM-x32\…\SP_963508d2) (Version: - ) <==== ATTENTION
PunkBuster Services (HKLM-x32\…\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.14.010 - Dell Inc.)
QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39019 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 5.2.0 (HKLM-x32\…\RTSS) (Version: 5.2.0 - Unwinder)
Rockstar Games Social Club (HKLM-x32\…\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\…\Steam App 2700) (Version: - Frontier)
RuneScape Launcher 1.2.2 (HKLM-x32\…\{A85FCCBE-31AB-4312-A5A9-165FF3B0BF90}) (Version: 1.2.2 - Jagex Ltd)
Rust (HKLM-x32\…\Steam App 252490) (Version: - Facepunch Studios)
Search Protect by conduit (HKLM-x32\…\SearchProtect) (Version: 1.7.0.72 - Conduit) <==== ATTENTION
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Sid Meier's Civilization V (HKLM-x32\…\Steam App 8930) (Version: - 2K Games, Inc.)
SimCity™ (HKLM-x32\…\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Six Updater (HKLM-x32\…\{2D8CED57-CCDB-4D86-9087-3BBCAE8F8F22}) (Version: 2.09.7016 - Six Projects)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.21 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.)
Sleeping Dogs™ (HKLM-x32\…\Steam App 202170) (Version: - United Front Games)
Spore (HKLM-x32\…\Steam App 17390) (Version: - Maxis™)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Surgeon Simulator 2013 (HKLM-x32\…\Steam App 233720) (Version: - Bossa Studios)
SyncUP (HKLM-x32\…\{D92C9CCE-E5F0-4125-977A-0590F3225B74}) (Version: 10.2.16100 - Nero AG)
SyncUP (x32 Version: 1.12.12400.17.102 - Nero AG) Hidden
Team Fortress 2 (HKLM-x32\…\Steam App 440) (Version: - Valve)
TeamSpeak 3 Client (HKLM-x32\…\TeamSpeak 3 Client) (Version: 3.0.12 - TeamSpeak Systems GmbH)
The Elder Scrolls III: Morrowind (HKLM-x32\…\Steam App 22320) (Version: - Bethesda Game Studios®)
The Elder Scrolls V: Skyrim (HKLM-x32\…\Steam App 72850) (Version: - Bethesda Game Studios)
The Sims 2: Ultimate Collection (HKLM-x32\…\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts)
The Sims™ 3 (HKLM-x32\…\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts)
The Sims™ 3 70s, 80s, & 90s Stuff (HKLM-x32\…\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts)
The Sims™ 3 Ambitions (HKLM-x32\…\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
The Sims™ 3 Diesel Stuff (HKLM-x32\…\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts)
The Sims™ 3 Fast Lane Stuff (HKLM-x32\…\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts)
The Sims™ 3 Generations (HKLM-x32\…\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts)
The Sims™ 3 High-End Loft Stuff (HKLM-x32\…\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
The Sims™ 3 Island Paradise (HKLM-x32\…\{DB21639E-FE55-432C-BCA2-0C5249E3F79E}) (Version: 19.0.101 - Electronic Arts)
The Sims™ 3 Late Night (HKLM-x32\…\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts)
The Sims™ 3 Master Suite Stuff (HKLM-x32\…\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts)
The Sims™ 3 Outdoor Living Stuff (HKLM-x32\…\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts)
The Sims™ 3 Pets (HKLM-x32\…\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
The Sims™ 3 Seasons (HKLM-x32\…\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
The Sims™ 3 Showtime (HKLM-x32\…\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts)
The Sims™ 3 Supernatural (HKLM-x32\…\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
The Sims™ 3 Town Life Stuff (HKLM-x32\…\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts)
The Sims™ 3 University Life (HKLM-x32\…\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts)
The Sims™ 3 World Adventures (HKLM-x32\…\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
Thief (HKLM-x32\…\Steam App 239160) (Version: - Eidos-Montréal)
Tropico 4 Gold (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\Tropico 4 Gold) (Version: 1.05 - Kalypso Media)
Tropico 5 (HKLM-x32\…\Steam App 245620) (Version: - Haemimont Games)
Unity Web Player (HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\UnityWebPlayer) (Version: 5.0.1f1 - Unity Technologies ApS)
Uplay (HKLM-x32\…\Uplay) (Version: 2.0 - Ubisoft)
VIO Player version 1.0.1 (HKLM-x32\…\{C8A17598-7F89-41EA-9876-0F89DA0B24F1}_is1) (Version: 1.0.1 - VIO)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Warframe (HKLM-x32\…\Steam App 230410) (Version: - Digital Extremes)
Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices (03/07/2012 ) (HKLM\…\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012 - GoPro)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Movie Maker 2.6 (HKLM-x32\…\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Tomton98\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {04986720-95AF-4AE5-A028-FBAD214FF3E4} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-06-11] (Dell Inc.)
Task: {176B0FD7-2CC5-4890-BFAD-D3DE48A60639} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
Task: {1B2BF7FD-213C-47AB-B191-41FB869FC45A} - System32\Tasks\{486C2EC1-91DE-4997-B97C-6D8085EC3DEC} => C:\Program Files (x86)\Bohemia Interactive\ArmA 2\arma2OA.exe [2013-03-10] (Bohemia Interactive)
Task: {3364C208-BD3E-4121-93A6-E455C937C905} - System32\Tasks\{A42F91EF-79E2-4B10-BD5F-45C67B238C3F} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {355A5A19-CC60-4DCC-AD0B-412DE8A03E61} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-07-21] (AVAST Software)
Task: {3AF391DB-81EB-4999-A303-1A3D0C4350FF} - System32\Tasks\EVGAPrecision => C:\Program Files (x86)\EVGA Precision X\EVGAPrecision.exe [2013-07-18] ()
Task: {3B3090EA-B338-4F30-B800-1E6D4875B6F8} - System32\Tasks\{0F0A7E5D-A4FF-4DA9-96F8-245E48069309} => pcalua.exe -a C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe -d C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
Task: {3C304234-609D-4CA2-9778-0287B37A9EEE} - System32\Tasks\RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION
Task: {3D8A0521-5049-4199-A763-FBA0F99DCF5F} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-03-31] (AVAST Software)
Task: {3E4F8A16-6A43-46BE-BCB0-5D68F8145C79} - System32\Tasks\{C1397205-A924-40E8-BABC-90F8470FC152} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {4819DCCA-2472-49ED-B371-D6C0EBFB4556} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2012-11-02] (Microsoft Corporation)
Task: {59F44749-E201-4945-A2FA-4BDBA3150EAD} - System32\Tasks\{95A88E8F-1A35-418E-91C6-623E45497224} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {65D692E5-EFD1-4A06-8212-2D275B468BB0} - System32\Tasks\{87D6AF67-0AC9-4487-961E-48DD8279E085} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {70CC3F5D-16EC-4970-AFE7-DF50762F11D2} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2012-11-02] (Microsoft)
Task: {77B971D2-1360-49C4-802B-A0FE71AC47BD} - System32\Tasks\{510D9FCC-C247-42BB-8865-9BF9F9A12D43} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {7966649C-0BFE-446B-A3DF-2185D445791E} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-12] (Facebook Inc.)
Task: {79BA81AC-140E-434B-AEFE-B4FB00C790CC} - System32\Tasks\{2ED90E63-1EFA-4874-9880-50F55D5B05A3} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {7D24805E-9738-4F0A-805E-C40689C47FE6} - System32\Tasks\{A0898C8A-B638-4FCC-9EA3-5627E35F4A76} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {81835C2A-9E23-47CA-9EF0-58DA1B70C124} - System32\Tasks\{B03A9A69-01BD-49E9-9487-2CB6E4AFD4F5} => pcalua.exe -a C:\Users\Tomton98\AppData\Local\Temp\Temp1_EVGAPrecisionX.zip\EVGA_PrecisionX_Setup_400.exe
Task: {850EA906-00FB-4C85-B05D-51F84637CE4A} - System32\Tasks\{E833EEB4-F078-4649-8451-4A9815559007} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {9AAF1711-2139-47CC-997A-2605A90B70CF} - System32\Tasks\{D7AB502A-0F67-44E6-BB12-C678A9802368} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {A0EC30EB-237E-4CA9-8F56-3397F9943713} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
Task: {A423D2EB-59BE-4070-98D2-8D6B60762770} - System32\Tasks\{5FB514CF-A913-4AAF-B204-9F1876F7FB7E} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {A6D0945A-7130-4987-86B2-8E154C6CDA68} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {A7FBEA51-0EA2-42DF-B236-0683419DF8BC} - System32\Tasks\{14C66831-93DA-426D-A90D-0F1D42B01577} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
Task: {B3EDB281-5791-48BB-8D3A-98C489FB6922} - System32\Tasks\{F2B51C84-7766-404C-B31D-F2032079966B} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {BD44F3E9-1E58-4579-94F5-0859F523DE23} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {BFEA4E8A-6FB0-42A9-9775-69866C7C286E} - System32\Tasks\{90C8B7AA-222D-41AC-87BE-B3FD06D3D7A7} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {D512AAA6-268E-49CF-83BA-384E6CBD21F7} - System32\Tasks\{FD2F5746-23D7-4628-9C45-C811788B4A10} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {DCE663B6-40DA-4C33-8583-B566259C92E9} - System32\Tasks\{F2A17ECB-C0C2-4ECD-AAD9-33C9BDE927C2} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {E15C7EFF-31C9-4511-B17F-A3C91F641491} - System32\Tasks\{0CFB6EBC-8F8E-44EC-8AF5-2DF3AF60683C} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {E2406D5B-9A8F-4CC4-A9AD-B1DDB8F4EC2A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-05-13] (Adobe Systems Incorporated)
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: {E43463FC-5209-4F16-A5CC-FD713BA73DED} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.)
Task: {EE02410A-B1E4-4FCE-AFBE-893C390D110E} - System32\Tasks\{96351ECB-CB3A-434E-AA5C-299A56B11B45} => C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe [2015-05-01] ()
Task: {F2FC758A-BCC4-4648-A89C-901389A134F4} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-12] (Facebook Inc.)
Task: {F3E383DE-9DC2-4631-A292-A55A05B9AEC6} - System32\Tasks\{57529728-AB80-4AD7-B849-659206CEDFBA} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
Task: {F3FCFD1D-1C37-4ED3-9FF5-F28E03623037} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2012-11-02] (Microsoft Corporation)
Task: {F9FD37EA-00D5-4071-98DF-A64DD791F10F} - System32\Tasks\{548BC96D-8091-4868-9DF0-3D34E6D39169} => C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe [2005-04-29] ()
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001Core.job => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1821522787-3724074743-2321965764-1001UA.job => C:\Users\Tomton98\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{F6A9A4FE-91CF-496D-8EC5-F11ACD174B28}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\2\Adobe Flash.lnk -> hxxp://www.adobe.com/products/flash/about (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\1\Social Club.lnk -> hxxp://socialclub.rockstargames.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{E3EE9886-A04D-E37C-86CD-3E7EA3CF8A0B}\SupportTasks\0\Rockstar Games.lnk -> hxxp://www.rockstargames.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{7D27B567-B3A3-48B0-B97E-80B69505D3A4}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.rockstargames.com/sanandreas/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{264058BF-9E81-495C-AB14-8DCF244449B6}\SupportTasks\1\Support.lnk -> hxxp://www.bethsoft.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Local\Microsoft\Windows\GameExplorer\{264058BF-9E81-495C-AB14-8DCF244449B6}\SupportTasks\0\More Games from Microsoft.lnk -> hxxp://www.elderscrolls.com/ (No File)
Shortcut: C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.com (No File)
==================== Loaded Modules (Whitelisted) ==============
2012-12-27 12:54 - 2013-02-28 17:44 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2012-05-16 19:42 - 2012-01-27 12:49 - 02751808 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2012-05-16 19:26 - 2012-01-11 06:36 - 00159360 _____ () C:\Program Files\Conexant\SA3\MaxxAudioWrapper.dll
2012-05-16 20:45 - 2012-01-19 08:48 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-09-23 15:47 - 2015-09-23 15:47 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-09-23 15:47 - 2015-09-23 15:47 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-07-23 19:36 - 2013-07-23 19:36 - 00401408 _____ () C:\Program Files (x86)\ATI Technologies\HydraVision\HydraGrd.exe
2015-07-21 21:11 - 2015-07-21 21:11 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-07-21 21:11 - 2015-07-21 21:11 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-06-01 20:51 - 2016-06-01 20:51 - 02984152 _____ () C:\Program Files\AVAST Software\Avast\defs\16060100\algo.dll
2016-05-12 19:40 - 2016-05-12 19:40 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\5a8eeeddc97028a9f94d0518c22f4c2c\IsdiInterop.ni.dll
2012-05-16 19:28 - 2011-11-30 11:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-09-14 00:51 - 2013-09-14 00:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 00:50 - 2013-09-14 00:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
2015-07-21 21:11 - 2015-07-21 21:12 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:054203E4 [290]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\…\sony.com -> sony.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 12:34 - 2009-06-11 07:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1821522787-3724074743-2321965764-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tomton98\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
MpsSvc => Firewall Service is not running.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
ATTENTION: System Restore is disabled
25-05-2016 19:29:34 Windows Update
27-05-2016 14:28:51 Windows Update
30-05-2016 17:14:30 Windows Backup
31-05-2016 15:47:06 Windows Update
Check "winmgmt" service or repair WMI.
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Could not start eventlog service, could not read events.
'net' is not recognized as an internal or external command,
operable program or batch file.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-3612QM CPU @ 2.10GHz
Percentage of memory in use: 31%
Total physical RAM: 6046.36 MB
Available physical RAM: 4156.76 MB
Total Virtual: 12090.89 MB
Available Virtual: 9809.93 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:917.66 GB) (Free:62.49 GB) NTFS
Drive e: () (Removable) (Total:7.45 GB) (Free:6.33 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 69519867)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=13.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================