This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Is my browser infected? [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

 

My firefox-browser is behaving weird. The symptoms are that there are big areas that are not updated when going to a site, so that parts of the page are staying black, which is of course quite useless. I believe that the problem showed up after surfing some porn-sites, which probably makes sense. I guess that I have picked up some malware that gives the symptoms.

 

I have scanned with malwarebytes antimalware and spyhunter, but the fixes from these programes did not fix the problem.

 

It would be very nice if somebody here will take a look at my logs and see if there are any signs of infections.

 

Thanks in advance.

 

Here comes my logs:

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-10-18 22:44:17
—————————–
22:44:17.100    OS Version: Windows x64 6.1.7601 Service Pack 1
22:44:17.101    Number of processors: 4 586 0x100
22:44:17.103    ComputerName: CLIMAX  UserName: kim
22:44:20.551    Initialize success
22:44:20.556    VM: initialized successfully
22:44:20.558    VM: Amd CPU supported virtualized 
22:44:30.908    AVAST engine defs: 16101801
22:44:34.537    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:44:34.540    Disk 0 Vendor:   Size: 0MB BusType: 0
22:44:34.695    Disk 0 MBR read successfully
22:44:34.701    Disk 0 MBR scan
22:44:34.711    Disk 0 Windows 7 default MBR code
22:44:34.717    Disk 0 MBR hidden
22:44:34.727    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        20480 MB offset 2048
22:44:34.743    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS          100 MB offset 41945088
22:44:34.764    Disk 0 Partition 3 80 (A) 07    HPFS/NTFS NTFS       933287 MB offset 42149888
22:44:34.770    Disk 0 default boot code
22:44:34.877    Disk 0 scanning C:\Windows\system32\drivers
22:44:46.833    Service scanning
22:45:31.567    Modules scanning
22:45:31.580    Disk 0 trace - called modules:
22:45:31.612    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 
22:45:31.624    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007512060]
22:45:31.636    3 CLASSPNP.SYS[fffff880018d343f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8006e5d680]
22:45:34.069    AVAST engine scan C:\Windows
22:45:39.049    AVAST engine scan C:\Windows\system32
22:49:41.751    AVAST engine scan C:\Windows\system32\drivers
22:50:01.110    AVAST engine scan C:\Users\kim
22:53:11.928    Disk 0 MBR has been saved successfully to "C:\Users\kim\Desktop\MBR.dat"
22:53:11.930    The log file has been saved successfully to "C:\Users\kim\Desktop\aswMBR.txt"
 
 
————————————————————————————————————————————————-
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-10-2016
Ran by [removed] (administrator) on CLIMAX (18-10-2016 22:55:35)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Totem Entertainment) C:\Users\kim\AppData\Local\vghd\bin\vghd.exe
(-) C:\Users\kim\AppData\Local\Temp\Rar$EXa0.759\Clock64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Totem Entertainment) C:\Users\kim\AppData\Local\vghd\bin\VirtuaGirl_Downloader.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Enigma Software Group USA, LLC.) C:\Users\kim\Desktop\SpyHunter 4.21.10.4585 Portable by wood\SpyHunter4.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\kim\Downloads\aswMBR.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2723624 2011-03-27] (Synaptics Incorporated)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9083840 2016-10-13] (AVAST Software)
HKLM-x32\…\Run: [NBAgent] => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-07-05] (Nero AG)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25366584 2016-10-10] (Dropbox, Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-05-20] (Oracle Corporation)
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-09] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
Startup: C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopVideoPlayer.lnk [2016-01-03]
ShortcutTarget: DesktopVideoPlayer.lnk -> C:\Users\kim\AppData\Local\vghd\bin\vghd.exe (Totem Entertainment)
Startup: C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\T-Clock Redux x64.lnk [2015-10-22]
ShortcutTarget: T-Clock Redux x64.lnk -> C:\Users\kim\AppData\Local\Temp\Rar$EXa0.759\Clock64.exe (-)
BootExecute: autocheck autochk * sh4native Sh4RemovalaswBoot.exe /M:1548b752e4 /wow /dir:"C:\Program Files\AVAST Software\Avast"
GroupPolicyScripts-x32: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Tcpip\..\Interfaces\{0E9831BD-FDDA-4B9E-96AB-769326E184D3}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{7F88158D-DB3F-4AEC-9E48-C474DD4F8A2D}: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{CCFCB4C6-21DD-4CAC-B585-8E975B127E6D}: [DhcpNameServer] 10.127.127.11 [removed] [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ie_sp_
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> DefaultScope {8D6016E3-A1A4-4A80-ADC8-4D55BCDD0E7B} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {8D6016E3-A1A4-4A80-ADC8-4D55BCDD0E7B} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ie_ds_&tag;=bds-p17-serp-us-ie-20&query;={searchTerms}
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-07-10] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-09-09] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-07-10] (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-09-09] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-28] (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} -  No File
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
 
FireFox:
========
FF DefaultProfile: n3ibsi3h.default
FF ProfilePath: C:\Users\kim\AppData\Roaming\Mozilla\Firefox\Profiles\n3ibsi3h.default [2016-10-18]
FF NewTab: Mozilla\Firefox\Profiles\n3ibsi3h.default -> hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ff_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ff_nt_
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Yahoo!
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Amazon
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Yahoo!
FF Homepage: Mozilla\Firefox\Profiles\n3ibsi3h.default -> about:home
FF Extension: (Greasemonkey) - C:\Users\kim\AppData\Roaming\Mozilla\Firefox\Profiles\n3ibsi3h.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2016-08-23]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-09]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-09]
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn => not found
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn => not found
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-12] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-07-10] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-10] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-08-25] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
CHR StartupUrls: Default -> "hxxps://dk.search.yahoo.com/?type=435371&fr;=yo-yhp-ch","hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://www.amazon.com/websearch/?ie=UTF8__PARAM__&query;={searchTerms}
CHR DefaultSearchKeyword: Default -> amazon
CHR Profile: C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default [2016-10-18]
CHR Extension: (Google Docs) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-25]
CHR Extension: (Google Drive) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-22]
CHR Extension: (YouTube) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-22]
CHR Extension: (Google Search) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-22]
CHR Extension: (Avast SafePrice) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-09-27]
CHR Extension: (Google Docs Offline) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-27]
CHR Extension: (Avast Online Security) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-09-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-27]
CHR Extension: (Gmail) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-25]
CHR Extension: (Chrome Media Router) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-28]
CHR HKU\S-1-5-21-344082389-2557018971-2821403297-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [ooebgdicanjhnamfmdlmlbcnkgehkkmf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-344082389-2557018971-2821403297-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\Extensions\Chrome.crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-09] (AVAST Software)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-27] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [38000 2016-10-10] (Dropbox, Inc.)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [216576 2016-08-18] () [File not signed]
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-08-02] (Acer Incorporated)
R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-09-09] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-09-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-09-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-09-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-09-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-09-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
S3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20110519.002\BHDrvx64.sys [1143416 2011-05-13] (Symantec Corporation)
S3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1300000.080\ccSetx64.sys [165512 2011-05-23] (Symantec Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20110519.031\IDSVia64.sys [488056 2011-05-13] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110519.002\ENG64.SYS [117880 2011-05-19] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110519.002\EX64.SYS [2011768 2011-05-19] (Symantec Corporation)
S3 SRTSP; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSP64.SYS [721528 2011-05-21] (Symantec Corporation)
S3 SRTSPX; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSPX64.SYS [37496 2011-05-21] (Symantec Corporation)
S3 SymDS; C:\Windows\system32\drivers\NISx64\1300000.080\SYMDS64.SYS [451192 2011-05-16] (Symantec Corporation)
S3 SymEFA; C:\Windows\system32\drivers\NISx64\1300000.080\SYMEFA64.SYS [1083512 2011-05-16] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-10-24] (Symantec Corporation)
S3 SymIRON; C:\Windows\system32\drivers\NISx64\1300000.080\Ironx64.SYS [189560 2011-05-16] (Symantec Corporation)
S3 SymNetS; C:\Windows\system32\drivers\NISx64\1300000.080\SYMNETS.SYS [396408 2011-05-09] (Symantec Corporation)
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2010-08-31] (Jungo)
S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
U3 aswMBR; \??\C:\Users\kim\AppData\Local\Temp\aswMBR.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-18 22:55 - 2016-10-18 22:56 - 00027414 _____ C:\Users\kim\Downloads\FRST.txt
2016-10-18 22:54 - 2016-10-18 22:55 - 00000000 ____D C:\FRST
2016-10-18 22:53 - 2016-10-18 22:53 - 00001984 _____ C:\Users\kim\Desktop\aswMBR.txt
2016-10-18 22:53 - 2016-10-18 22:53 - 00000512 _____ C:\Users\kim\Desktop\MBR.dat
2016-10-18 22:52 - 2016-10-18 22:52 - 02407424 _____ (Farbar) C:\Users\kim\Downloads\FRST64.exe
2016-10-18 22:44 - 2016-10-18 22:44 - 05198336 _____ (AVAST Software) C:\Users\kim\Downloads\aswMBR.exe
2016-10-18 12:47 - 2016-10-18 12:47 - 00000022 _____ C:\Windows\S.dirmngr
2016-10-15 15:39 - 2016-10-15 15:39 - 00000767 _____ C:\Users\kim\Documents\TomsArchives.txt
2016-10-12 19:40 - 2016-10-12 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-10-12 11:19 - 2016-10-12 11:19 - 03160922 _____ C:\Users\kim\Downloads\1.wmv
2016-10-12 11:19 - 2016-10-12 11:19 - 03160922 _____ C:\Users\kim\Downloads\1 (1).wmv
2016-10-11 13:58 - 2016-10-11 13:58 - 00155464 _____ C:\Users\kim\Downloads\KOFRITUDLDPRET-2015-11-02 14.57.25.223.pdf
2016-10-11 13:57 - 2016-10-11 13:57 - 00154892 _____ C:\Users\kim\Downloads\MASKO_NEDS_UDL 418686 2016-05-02 08.58.25.405.pdf
2016-10-11 13:57 - 2016-10-11 13:57 - 00154892 _____ C:\Users\kim\Downloads\MASKO_NEDS_UDL 418686 2016-05-02 08.58.25.405 (1).pdf
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00038000 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2016-09-30 17:20 - 2016-09-30 17:20 - 00660552 _____ C:\Users\kim\Downloads\Pictures of Patterns.pdf
2016-09-28 10:40 - 2016-09-28 10:40 - 03514887 _____ C:\Users\kim\Downloads\sn004.wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 03514887 _____ C:\Users\kim\Downloads\sn004 (1).wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 02674173 _____ C:\Users\kim\Downloads\sn008.wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 02674173 _____ C:\Users\kim\Downloads\sn008 (1).wmv
2016-09-27 23:04 - 2016-09-27 23:04 - 00002148 _____ C:\Users\Public\Desktop\Google Earth.lnk
2016-09-27 23:04 - 2016-09-27 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2016-09-27 10:50 - 2016-09-27 10:50 - 05198336 _____ (AVAST Software) C:\Users\kim\Desktop\aswMBR.exe
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-09-27 09:49 - 2016-09-27 09:49 - 13170912 _____ (Microsoft Corporation) C:\Users\kim\Downloads\Silverlight_x64.exe
2016-09-27 09:46 - 2016-09-27 09:46 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-27 09:44 - 2016-09-27 09:44 - 00243584 _____ C:\Users\kim\Downloads\Firefox Setup Stub 49.0.1.exe
2016-09-25 13:33 - 2016-09-25 13:34 - 00000000 ____D C:\Users\kim\AppData\Roaming\.kde
2016-09-25 13:33 - 2016-09-25 13:33 - 00000000 ____D C:\Users\kim\AppData\Local\GNU
2016-09-25 13:33 - 2016-09-25 13:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gpg4win
2016-09-25 13:32 - 2016-09-27 09:53 - 00000000 ____D C:\Users\kim\AppData\Roaming\gnupg
2016-09-25 13:32 - 2016-09-25 13:32 - 00000000 ____D C:\ProgramData\GNU
2016-09-25 13:32 - 2016-09-25 13:32 - 00000000 ____D C:\Program Files (x86)\GNU
2016-09-25 13:31 - 2016-09-25 13:31 - 25629112 _____ (g10 Code GmbH) C:\Users\kim\Downloads\gpg4win-2.3.3.exe
2016-09-25 13:14 - 2016-09-25 13:14 - 15865898 _____ C:\Users\kim\Downloads\PGPDesktop.zip
2016-09-25 13:00 - 2016-09-25 13:00 - 00000000 ____D C:\Users\kim\AppData\Local\PGP Corporation
2016-09-25 12:54 - 2016-09-25 12:54 - 00000000 ____D C:\Users\kim\AppData\Roaming\PGP Corporation
2016-09-25 12:47 - 2016-09-25 13:16 - 00123066 _____ C:\Windows\SysWOW64\PGPlspRollback.reg
2016-09-24 03:56 - 2016-09-27 09:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-19 13:23 - 2016-09-20 11:05 - 00000600 _____ C:\Users\kim\AppData\Roaming\winscp.rnd
2016-09-19 13:19 - 2016-09-19 13:19 - 00001077 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2016-09-19 13:19 - 2016-09-19 13:19 - 00001065 _____ C:\Users\Public\Desktop\WinSCP.lnk
2016-09-19 13:19 - 2016-09-19 13:19 - 00000000 ____D C:\Program Files (x86)\WinSCP
2016-09-19 13:18 - 2016-09-19 13:19 - 09028128 _____ (Martin Prikryl ) C:\Users\kim\Downloads\WinSCP-5.9.2-Setup.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-18 13:38 - 2016-03-08 18:17 - 00000000 ____D C:\Users\kim\Desktop\SpyHunter 4.21.10.4585 Portable by wood
2016-10-18 12:57 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-10-18 12:57 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-10-18 12:50 - 2015-08-27 21:36 - 00000000 ___RD C:\Users\kim\Dropbox
2016-10-18 12:47 - 2016-04-28 21:47 - 00000000 ____D C:\Program Files (x86)\Amazon
2016-10-18 12:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-10-18 12:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-10-18 12:37 - 2015-08-27 21:32 - 00000982 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2016-10-18 12:32 - 2015-01-04 14:30 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-10-18 12:15 - 2014-12-12 16:43 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-10-18 12:02 - 2015-02-23 16:41 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-18 09:30 - 2015-01-04 14:30 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-10-18 09:30 - 2015-01-04 14:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-10-18 09:30 - 2015-01-04 14:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-18 01:38 - 2016-06-14 14:32 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-10-18 01:38 - 2014-12-09 12:40 - 00000000 ____D C:\Users\kim\AppData\Roaming\Skype
2016-10-18 01:38 - 2011-10-24 07:11 - 00000000 ____D C:\ProgramData\Skype
2016-10-18 01:30 - 2015-08-27 21:32 - 00000978 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2016-10-18 01:30 - 2015-02-23 16:41 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-17 10:13 - 2014-12-04 22:27 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-10-14 13:32 - 2014-12-10 13:07 - 03343270 _____ C:\Users\kim\Documents\Multi Product_Simulation.cs2
2016-10-13 20:08 - 2014-12-04 22:27 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-12 19:40 - 2015-08-27 21:32 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-10-12 09:16 - 2014-12-12 16:43 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-10-12 09:16 - 2014-12-09 01:04 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-10-12 09:16 - 2011-10-24 07:51 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-12 09:16 - 2011-10-24 07:51 - 00000000 ____D C:\Windows\system32\Macromed
2016-10-12 09:15 - 2011-10-24 07:51 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-10-06 10:36 - 2014-12-10 13:07 - 03340738 _____ C:\Users\kim\Documents\Multi Product_Simulation.bs2
2016-10-04 00:04 - 2015-05-11 22:44 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-10-04 00:04 - 2015-05-11 22:44 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-09-30 20:37 - 2015-08-27 21:31 - 00000000 ____D C:\Users\kim\AppData\Local\Dropbox
2016-09-27 23:04 - 2015-02-23 16:40 - 00000000 ____D C:\Program Files (x86)\Google
2016-09-27 10:53 - 2015-01-14 16:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-27 09:46 - 2014-12-06 00:44 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-25 13:25 - 2016-07-27 07:10 - 00003886 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1469596212
2016-09-25 13:24 - 2009-07-14 07:13 - 00876042 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-25 13:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-09-25 13:04 - 2014-12-04 21:48 - 00000000 ____D C:\Users\kim
2016-09-22 20:08 - 2014-12-04 22:27 - 00513632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
 
==================== Files in the root of some directories =======
 
2016-09-19 13:23 - 2016-09-20 11:05 - 0000600 _____ () C:\Users\kim\AppData\Roaming\winscp.rnd
2014-12-13 15:57 - 2014-12-13 15:57 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-03-07 12:01 - 2016-03-07 12:01 - 0000099 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2016-03-06 14:27 - 2016-03-06 14:27 - 0000101 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
 
Files to move or delete:
====================
C:\Windows\SysWOW64\ntshrui.dll
 
 
Some files in TEMP:
====================
C:\Users\kim\AppData\Local\Temp\DefaultPack.EXE
C:\Users\kim\AppData\Local\Temp\{06113559-5494-4558-8210-BF2CB4CB8AFC}-49.0.2623.112_49.0.2623.110_chrome_updater.exe
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-10-18 04:26
 
==================== End of FRST.txt ============================

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-10-2016
Ran by [removed] (18-10-2016 22:56:40)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-04 19:48:37)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-344082389-2557018971-2821403297-500 - Administrator - Disabled)
Guest (S-1-5-21-344082389-2557018971-2821403297-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-344082389-2557018971-2821403297-1006 - Limited - Enabled)
kim (S-1-5-21-344082389-2557018971-2821403297-1000 - Administrator - Enabled) => C:\Users\kim
temp (S-1-5-21-344082389-2557018971-2821403297-1008 - Administrator - Enabled) => C:\Users\temp
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\uTorrent) (Version: 3.4.8.42576 - BitTorrent Inc.)
ACDSee Free (HKLM-x32\…\ACDSee Free) (Version: 1.1.21 - ACD Systems International Inc.)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
Amazon 1Button App (x32 Version: 2.3.4 - Amazon) Hidden <==== ATTENTION
AMD Catalyst Install Manager (HKLM\…\{995841E6-A7D8-2742-606C-98E350507317}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
AMD System Monitor (HKLM-x32\…\{C1C82DC9-1547-4038-8F0A-C069F0B7F2ED}) (Version: 1.0.5 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Apple-programunderstøttelse (32 bit) (HKLM-x32\…\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)
Apple-programunderstøttelse (64 bit) (HKLM\…\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
AVRStudio4 (HKLM-x32\…\{D5D88F8F-FDA4-4CF4-9F3E-3F40118C2120}) (Version: 4.18.684 - Atmel)
AVRStudio4 (x32 Version: 4.18.684 - Atmel) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 15.0.3.1 - Broadcom Corporation)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.4.1 - Broadcom Corporation)
CCleaner (HKLM\…\CCleaner) (Version: 5.00 - Piriform)
CodeBlocks (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\CodeBlocks) (Version: 16.01 - The Code::Blocks Team)
Crystal Reports for Visual Studio (x32 Version: 12.51.0.240 - SAP) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DB Browser for SQLite (HKLM-x32\…\SqliteBrowser3) (Version: 3.5.1 - oldsch00l)
Debut Video Capture Software (HKLM-x32\…\Debut) (Version: 2.03 - NCH Software)
Dotfuscator Software Services - Community Edition (HKLM-x32\…\{41B31ABE-5A6E-498A-8F28-3BA3B8779A41}) (Version: 5.0.2300.0 - PreEmptive Solutions)
Dropbox (HKLM-x32\…\Dropbox) (Version: 12.4.22 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
ETX Capital MT4 (HKLM-x32\…\ETX Capital MT4) (Version: 4.00 - MetaQuotes Software Corp.)
FastStone Image Viewer 5.3 (HKLM-x32\…\FastStone Image Viewer) (Version: 5.3 - FastStone Soft)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 53.0.2785.143 - Google Inc.)
Google Earth (HKLM-x32\…\{2C44ABB9-8621-4EF5-AF34-0886DCDA7C21}) (Version: 7.1.7.2600 - Google)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
gpedt.msc 1.0 (HKLM-x32\…\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version:  - Richard)
Gpg4win (2.3.3) (HKLM-x32\…\GPG4Win) (Version: 2.3.3 - The Gpg4win Project)
HP Deskjet 3050A J611 series Basic Device Software (HKLM\…\{1B77E249-B8D5-4E5E-8848-693ACEF84E6D}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
iTunes (HKLM\…\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.)
Java 8 Update 91 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.15 - Oracle Corporation)
Java 8 Update 91 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.7 - Packard Bell)
LærSelv Blindskrift (HKLM-x32\…\{C5B9C677-4BE8-11D3-8B01-0008C7797B27}) (Version: 2.08 - Keyboard Technologies Ltd.)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\…\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\…\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\…\{1803A630-3C38-4D2B-9B9A-0CB37243539C}) (Version: 2.0.50217.0 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\…\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50709.0 - Microsoft Corporation)
Microsoft Silverlight 3 SDK (HKLM-x32\…\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40818.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2008 (64-bit) (HKLM\…\Microsoft SQL Server 10 Release) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 Browser (HKLM-x32\…\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Native Client (HKLM\…\{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Data-Tier Application Framework (HKLM-x32\…\{0DDCEC37-369C-484B-B16D-B4413FD42FB9}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Data-Tier Application Project (HKLM-x32\…\{E5AE9031-79A5-4627-9641-BEFA82819B08}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\…\{4E968D9C-21A7-4915-B698-F7AEB913541D}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (x64) (HKLM\…\{DA67488A-2689-4F10-B90F-D2F6977509D6}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Transact-SQL Language Service (HKLM-x32\…\{78C3657E-742C-40B1-9F53-E5A921D40F17}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\…\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM-x32\…\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\…\{2A2F3AE8-246A-4252-BB26-1BEB45627074}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\…\{4A8CE6D7-4D52-43B9-970B-03FC75FAD667}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\…\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft Sync Framework Runtime v1.0 SP1 (x64) (HKLM\…\{8438EC02-B8A9-462D-AC72-1B521349C001}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework SDK v1.0 SP1 (HKLM-x32\…\{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework Services v1.0 SP1 (x64) (HKLM\…\{034106B5-54B7-467F-B477-5B7DBB492624}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) (HKLM\…\{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}) (Version: 2.0.3010.0 - Microsoft Corporation)
Microsoft Team Foundation Server 2010 Object Model - ENU (HKLM\…\Microsoft Team Foundation Server 2010 Object Model - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\…\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Designtime - 10.0.30319 (HKLM\…\{F5079164-1DB9-3BDA-853B-F78AF67CE071}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Runtime - 10.0.30319 (HKLM\…\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.30319 (HKLM-x32\…\{6A86554B-8928-30E4-A53C-D7337689134D}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual F# 2.0 Runtime (HKLM-x32\…\{729A3000-BC8A-3B74-BA5D-5068FE12D70C}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\…\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Professional - ENU (HKLM-x32\…\Microsoft Visual Studio 2010 Professional - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\…\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio Macro Tools (HKLM-x32\…\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 49.0.1 (x86 da) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 da)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1 - Mozilla)
Mozilla Thunderbird 38.0.1 (x86 da) (HKLM-x32\…\Mozilla Thunderbird 38.0.1 (x86 da)) (Version: 38.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyStars! 32Bit v2.7 (HKLM-x32\…\MyStars!32Bitv2.7) (Version:  - )
Navigational Algorithms (HKLM-x32\…\{2C13EAF9-FC13-4AA3-B0CF-88B9DE08914A}) (Version: 20.14.1 - Navigational Algorithms)
Nero BackItUp 10 (HKLM-x32\…\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.8.11000.8.100 - Nero AG)
Nero DiscSpeed 10 (HKLM-x32\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{68AFA3A7-9265-4ABD-994A-ACA413E3715C}) (Version: 10.6.10300 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\…\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.6.10500.3.100 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10900.31.0 - Nero AG)
NinjaTrader 8 (HKLM-x32\…\{04A902BC-76E2-4671-A389-68367F527E38}) (Version: 8.0.0.9 - NinjaTrader, LLC)
Norton Internet Security (HKLM-x32\…\NIS) (Version: 19.0.0.128 - Symantec Corporation)
OpenCPN 4.0.0 (HKLM-x32\…\OpenCPN 4.0.0) (Version: 4.0.0 - opencpn.org)
OpenOffice 4.1.2 (HKLM-x32\…\{7D5D1802-795F-451B-9BF8-831E853A43C9}) (Version: 4.12.9782 - Apache Software Foundation)
Packard Bell Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Packard Bell)
Packard Bell Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Packard Bell)
Packard Bell ScreenSaver (HKLM-x32\…\Packard Bell Screensaver) (Version: 1.1.0915.2011 - Packard Bell )
Packard Bell Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Packard Bell)
PL-2303 USB-to-Serial (HKLM-x32\…\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.12.0 - Prolific Technology INC)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pokemon GO Live Map (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\pokemon) (Version: 0.2.1 - Mike Christopher)
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Radarplot 1.5.0 (HKLM-x32\…\Radarplot_is1) (Version:  - brainaid GbR)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6343 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
SaxoTrader 2 (HKLM-x32\…\{024D66E9-D50C-44A7-92B4-2DFDDD95D228}) (Version: 2.147.67.0 - Saxo Bank)
ScanMaster-ELM 2.1.104.771 (HKLM\…\ScanMaster-ELM_is1) (Version: 2.1.104.771 - WGSoft.de)
Service Pack 1 for SQL Server 2008 (KB968369) (64-bit) (HKLM\…\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation)
Skype™ 7.29 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.101 - Skype Technologies S.A.)
Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.2.17.5 - Synaptics Incorporated)
TeslaMap57 (HKLM-x32\…\ST6UNST #1) (Version:  - )
VectorVest 7 (HKLM-x32\…\{93057e39-ceeb-4f3b-8a79-223512e8cb5b}) (Version: 1.16.175.0 - VectorVest, Inc.)
Video Web Camera (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Video Web Camera (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
VirtuaGirl version 1.2.0.84 (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\VirtuaGirl_is1) (Version: 1.2.0.84 - Totem Entertainment)
Visual Studio 2010 Prerequisites - English (HKLM\…\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.30319 - Microsoft Corporation)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
Web Deployment Tool (HKLM\…\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation)
Winamp (HKLM-x32\…\Winamp) (Version: 5.65  - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinAVR 20100110 (remove only) (HKLM-x32\…\WinAVR-20100110) (Version: 20100110 - )
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinSCP 5.9.2 (HKLM-x32\…\winscp3_is1) (Version: 5.9.2 - Martin Prikryl)
WXTide32 (HKLM-x32\…\WXTide32) (Version:  - )
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {050BCFD9-D994-46F2-B649-44A0247AC7AB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {3029EFFF-D258-48AF-B5EF-E0015A479459} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
Task: {333BDBAC-4387-4C9C-844A-DD9726A2A058} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {391DCC99-3D05-466F-8738-337989CD831E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-12] (Adobe Systems Incorporated)
Task: {48092976-6C56-4609-A6C3-18F9B75BEA0C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-27] (Dropbox, Inc.)
Task: {66CF9A58-B16C-403F-9FAD-63CA0E130F95} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-27] (Dropbox, Inc.)
Task: {73E1C3BD-405E-43F0-900B-AFC75CFDE2EB} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\WSCStub.exe
Task: {7FF46A41-7994-41D6-8AC5-19FBD3703357} - System32\Tasks\SafeZone scheduled Autoupdate 1469596212 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {89BDE521-FBA4-48D7-A881-9E0F84385CBA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {8BB26800-7622-456D-B335-F623C031C5CD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-09-09] (AVAST Software)
Task: {A4E9D0DE-D927-4865-88E0-A5A4705EEC69} - System32\Tasks\{5449FCC3-D3FE-45AD-A98C-526732AD1D87} => Firefox.exe hxxp://ui.skype.com/ui/0/7.0.0.100/da/abandoninstall?source=lightinstaller&page;=tsBing
Task: {A804DE58-1C05-47EC-9FF4-7E8BD15DDCC8} - System32\Tasks\NBAgent => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2011-07-05] (Nero AG)
Task: {C2F4FC50-7A7F-42D6-A0F4-0D69DAB158E2} - System32\Tasks\{259DA613-8344-4467-BEC6-2774072E2B3F} => pcalua.exe -a C:\Users\kim\Downloads\myst3227.exe -d C:\Users\kim\Downloads
Task: {DC4CA033-9F6E-4BB7-AC09-5BCC5BCF7ACA} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-03] (AVAST Software)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\kim\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.html
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-13 06:45 - 2015-10-13 06:45 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-13 06:45 - 2015-10-13 06:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-08-18 10:27 - 2016-08-18 10:27 - 00216576 _____ () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
2016-09-09 08:07 - 2016-09-09 08:07 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-09-09 08:07 - 2016-09-09 08:07 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-10-18 20:52 - 2016-10-18 20:52 - 03121496 _____ () C:\Program Files\AVAST Software\Avast\defs\16101801\algo.dll
2016-08-18 10:14 - 2016-08-18 10:14 - 00222720 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll
2016-08-18 10:09 - 2016-08-18 10:09 - 00103424 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll
2016-08-18 10:03 - 2016-08-18 10:03 - 00050176 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll
2016-08-18 10:14 - 2016-08-18 10:14 - 00073728 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll
2016-08-18 10:17 - 2016-08-18 10:17 - 00751104 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-20.dll
2016-07-11 19:52 - 2016-07-11 19:52 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-05-13 05:15 - 2016-09-22 03:44 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2016-10-12 19:39 - 2016-09-22 03:45 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-05-13 05:15 - 2016-09-22 03:44 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2016-05-13 05:15 - 2016-09-22 03:44 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2016-05-13 05:15 - 2016-09-22 03:44 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2016-05-13 05:15 - 2016-09-22 03:45 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00021312 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2016-10-12 19:39 - 2016-09-22 03:46 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00025424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-08-07 00:43 - 2016-09-22 03:45 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2016-10-12 19:39 - 2016-09-22 03:42 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2016-10-12 19:39 - 2016-10-10 20:35 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-10-12 19:39 - 2016-10-10 20:35 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-05-13 05:15 - 2016-09-22 03:45 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 01972528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00133424 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00224056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd
2016-10-12 19:39 - 2016-09-22 03:49 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2016-10-12 19:39 - 2016-09-22 03:49 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2016-05-13 05:15 - 2016-09-22 03:46 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00168760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2016-01-03 21:06 - 2014-06-19 12:50 - 00875520 _____ () C:\Users\kim\AppData\Local\vghd\bin\platforms\qwindows.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00034304 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qdds.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00023552 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qgif.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00029184 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qicns.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00023552 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qico.dll
2016-01-03 21:06 - 2014-06-19 12:56 - 00418304 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qjp2.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00241152 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qjpeg.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00220672 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qmng.dll
2016-01-03 21:06 - 2014-06-19 12:51 - 00017408 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qsvg.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00017408 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qtga.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00309760 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qtiff.dll
2016-01-03 21:06 - 2014-06-19 12:56 - 00016896 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qwbmp.dll
2016-01-03 21:06 - 2014-06-19 12:56 - 00288256 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qwebp.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00037888 _____ () C:\Users\kim\AppData\Local\vghd\bin\bearer\qgenericbearer.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00039936 _____ () C:\Users\kim\AppData\Local\vghd\bin\bearer\qnativewifibearer.dll
2016-01-03 21:06 - 2014-08-13 13:47 - 00126464 _____ () C:\Users\kim\AppData\Local\vghd\bin\mediaservice\dsengine.dll
2016-01-03 21:06 - 2014-06-19 13:16 - 00136192 _____ () C:\Users\kim\AppData\Local\vghd\bin\mediaservice\wmfengine.dll
2016-01-03 21:06 - 2014-06-19 13:14 - 00018944 _____ () C:\Users\kim\AppData\Local\vghd\bin\sensors\qtsensors_dummy.dll
2016-01-03 21:06 - 2014-06-19 13:14 - 00027648 _____ () C:\Users\kim\AppData\Local\vghd\bin\sensors\qtsensors_generic.dll
2016-10-04 00:04 - 2016-09-25 05:47 - 01805416 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libglesv2.dll
2016-10-04 00:04 - 2016-09-25 05:47 - 00093288 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\kim\Desktop\2015-09-09 22.14.27.jpg:com.dropbox.attributes [1042]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\amazon.com -> hxxps://amazon.com
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\iitech.dk -> iitech.dk
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\onlinewebconnect.com -> onlinewebconnect.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\kim\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.127.127.11 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{52CD9EBD-1813-4B94-A0E7-E15645E19BE0}] => (Allow) LPort=2869
FirewallRules: [{16619C0A-335A-42D1-AA95-8477B20542F5}] => (Allow) LPort=1900
FirewallRules: [{D9F6762B-AE5D-4977-87DF-EE71EE0619C6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{084814EA-5468-49F8-94DA-B079D3A432A9}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{592CB469-B665-4CF1-B147-F587164B64FB}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{BE2F38B0-BFE7-4230-9636-D700B3494257}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{E91DAAFC-F189-444A-909E-5AF388EB3EE0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{CD654684-FD39-41C8-8C0B-8E5E6D700379}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{4753085C-54EC-427B-9ADC-560A3BE463EB}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{94BBDC24-5AD9-449F-BB70-B61EC9F2A82E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{C8BA2D88-9170-40A4-AC53-FE1A11162ED2}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{08F1A06F-DCDD-4A1C-BD37-9F84481B5642}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{A6A98C68-9508-4AAA-AA44-44902A2C3B6B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{30CC684D-D29D-4496-A33E-EADC8AB32697}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{29513CC2-C458-4119-91F1-19D1B4BDC921}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{63C1F76B-BA3B-43B4-AC77-F99647261763}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{3D01301F-291B-4F48-82BB-92926B0CC4B6}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{4C7A9F98-F2CC-46DB-8818-EEF8622BEB7F}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{207F0D76-3CE8-4848-B99A-9C47C93E926E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5C8041AD-D5E2-44C8-8950-52942DC49A6C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BC292713-CAC9-4A5D-BB51-FD76C7C6224C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{35CD772E-95DE-4E2D-8978-B6F1D1C424E8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A07024A0-CC21-47E2-A975-F9202451C498}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6A21CAB9-7DE9-42B0-8A79-0CC95FA27194}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EDFCD553-1BEE-47B6-A606-35133186423B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{5E89391F-F90C-47C3-A109-138D38A74F13}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [UDP Query User{4930BA5C-4EE1-46D8-8252-5ECDCA3BB583}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [TCP Query User{ACB73085-2C30-4A35-BDCB-4F00E269C87C}C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe
FirewallRules: [UDP Query User{F845ED2F-10DE-4664-BBE5-9FC9F5ED8BD7}C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe
FirewallRules: [TCP Query User{2A52002E-CA9F-4A0C-BC11-6ACAF58602ED}C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe
FirewallRules: [UDP Query User{7EC9A817-36A8-46B9-AFF9-0E85FF777100}C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe
FirewallRules: [TCP Query User{BB50121D-2167-4554-8016-F5AA53E598D1}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [UDP Query User{DF0A9A1C-A94A-4C3D-B860-DEDFA26FACF2}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [TCP Query User{7046F038-6B10-4CBA-A0C2-9D17FFFB777F}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [UDP Query User{D5381F17-2F49-4ACE-B93B-765F81A699BE}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [{FCBAD548-CD77-4349-A9BA-7E684F9C748E}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{34768908-382A-4342-AFEA-1E022CE8F3DC}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5FF4523A-790F-4512-8ADE-B7468D233EA4}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5DAE0DAE-6FD2-4848-83CA-9307485C58F6}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{FA5DB429-81AC-4D5C-8C4A-4D070238BCA7}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6744B7EF-4650-4B3B-8EFD-43E2AE3FB0F0}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{41F878FA-8B74-44EB-9F66-EAEDB1240ACC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2D3A5DDF-A964-4928-A765-68620CA509C2}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
 
==================== Restore Points =========================
 
14-08-2016 22:21:17 Scheduled Checkpoint
23-08-2016 11:49:13 Scheduled Checkpoint
29-08-2016 23:18:58 ASU_MSI_TRAN
17-09-2016 14:54:59 Scheduled Checkpoint
23-09-2016 22:29:32 ASU_MSI_TRAN
25-09-2016 12:46:17 Installed PGP Desktop
25-09-2016 13:00:53 Removed PGP Desktop
25-09-2016 13:16:03 Installed PGP Desktop
25-09-2016 13:23:48 Removed PGP Desktop
25-09-2016 13:26:55 Removed PGP Desktop
03-10-2016 00:28:23 Scheduled Checkpoint
10-10-2016 02:23:41 Scheduled Checkpoint
18-10-2016 01:35:31 ASU_MSI_TRAN
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/18/2016 12:48:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/18/2016 04:28:27 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NMDllHost.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/18/2016 04:26:48 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NeroStartSmart.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/18/2016 01:30:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/18/2016 01:28:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 37487
 
Error: (10/18/2016 01:28:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 37487
 
Error: (10/18/2016 01:28:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (10/18/2016 01:28:52 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 34991
 
Error: (10/18/2016 01:28:52 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 34991
 
Error: (10/18/2016 01:28:52 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (10/18/2016 12:47:35 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.
 
Error: (10/18/2016 12:47:35 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.
 
Error: (10/18/2016 01:30:14 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 01:29:09 on ‎18-‎10-‎2016 was unexpected.
 
Error: (10/10/2016 01:54:14 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (10/10/2016 01:54:13 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (10/10/2016 01:54:13 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (10/06/2016 10:38:32 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
 
Error: (10/06/2016 10:33:22 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
 
Error: (10/06/2016 10:28:12 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
 
Error: (10/06/2016 10:23:02 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
 
 
CodeIntegrity:
===================================
  Date: 2016-08-23 11:04:06.618
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-23 11:04:06.196
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-07-27 07:08:58.393
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-07-27 07:08:58.050
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD A6-3420M APU with Radeon™ HD Graphics
Percentage of memory in use: 35%
Total physical RAM: 7658.9 MB
Available physical RAM: 4945.98 MB
Total Virtual: 15316.01 MB
Available Virtual: 12321.42 MB
 
==================== Drives ================================
 
Drive c: (ACER) (Fixed) (Total:911.41 GB) (Free:705.57 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]
 
==================== MBR & Partition Table ==================
 
==================== End of Addition.txt ============================

:welcome:

 

Windows LIve is infected, this fix wont fix it but Windows Live is hidden from Programs and Features in the Control Panel and the fix will make it visible so that you can uninstall it, uninstall anything related to Windows Live after this quick fix

 

FIRST
Your running FRST64 from your Downloads folder, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST64, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST64 exactly where we want it to be.
 

 
Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , 
Under Encoding , click the down arrow and select UNICODE  <<<
Save it to your desktop where you have FRST/FRST64 or the fix wont work. 
 
Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
GroupPolicyScripts-x32: Restriction <======= ATTENTION
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Hi Ken,

 

Thanks for your reply! :-) - I an sorry for my late answer, but I had to go to Jutland to buy a new car which took my time!

 

I have followed you instructions, and here comes the output from FRST:

 

——————————————————————————————————-

Fix result of Farbar Recovery Scan Tool (x64) Version: 17-10-2016
Ran by [removed] (21-10-2016 02:09:42) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
GroupPolicyScripts-x32: Restriction <======= ATTENTION
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
C:\Windows\SysWOW64\GroupPolicy\Machine => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C00C2A91-6CB3-483F-80B3-2958E29468F1}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E83DC314-C926-4214-AD58-147691D6FE9F}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B63F0CE3-CCD0-490A-9A9C-E1A3B3A17137}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{77F69CA1-E53D-4D77-8BA3-FA07606CC851}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4444F27C-B1A8-464E-9486-4C37BAB39A09}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CE929F09-3853-4180-BD90-30764BFF7136}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0A4C4B29-5A9D-4910-A13C-B920D5758744}\\SystemComponent => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FBCA06D2-4642-4F33-B20A-A7AB3F0D2E69}\\SystemComponent => value removed successfully
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 16908459 B
Java, Flash, Steam htmlcache => 69837 B
Windows/system/drivers => 82096165 B
Edge => 0 B
Chrome => 235735482 B
Firefox => 376522369 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58558720 B
systemprofile32 => 98996 B
LocalService => 0 B
NetworkService => 77470 B
kim => 437374212 B
temp => 74855 B
 
RecycleBin => 176096201 B
EmptyTemp: => 1.3 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 02:11:38 ====
 
 
————————————————————————————————————-
 
Hopefully that was what you wanted… :-)
 
Best Regards
 
- Kim.

Morning Kim

 

No worries, your doing just fine.  If you havent done it already go into Programs and Features in the Control Panel and uninstall any and all instances of Windows Live.

 

Then lets run these programs and see what they find and remove, remember to download and run them from your desktop

 

 

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
 
 
[external image: MBAM221%201043_zpsdtasp5xe.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 

Hi Ken,

 

I have deleted all instances of Windows live. There were 8 of them. Next I tried to run adwcleaner, but it gave my some problems, as it seemed to hang! - I could see that it generated a huge amount of pagefaults, but it did not seem to do any progress, so I killed it and ran it again. The second time I tried to untick a folder it wanted to delete, and then it terminated just fine. Then I ran it again and accepted when it wanted to delete the folder that I didnt allow it to delete before, and this time it eventually terminated normaly, so I guess that it has done it job by now. here comes the output from both runs:

 

# AdwCleaner v6.030 - Logfile created 21/10/2016 at 19:50:42
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-10-18.1 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : kim - CLIMAX
# Running from : C:\Users\kim\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[!] Folder not deleted: C:\Users\kim\AppData\Local\vghd
 
 
***** [ Files ] *****
 
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
[-] Key deleted: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\distromatic
[-] Key deleted: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Softonic
[#] Key deleted on reboot: HKCU\Software\distromatic
[#] Key deleted on reboot: HKCU\Software\Softonic
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B6DCCCD3-520D-4485-B642-FCC136CE12C3}
[#] Key deleted on reboot: [x64] HKCU\Software\distromatic
[#] Key deleted on reboot: [x64] HKCU\Software\Softonic
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[-] Key deleted: HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
[#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: pbjikboenpfhbbejgkoklgkhjpfogcam
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [3358 Bytes] - [21/10/2016 19:50:42]
C:\AdwCleaner\AdwCleaner[S0].txt - [3440 Bytes] - [21/10/2016 19:09:54]
C:\AdwCleaner\AdwCleaner[S1].txt - [3513 Bytes] - [21/10/2016 19:29:00]
C:\AdwCleaner\AdwCleaner[S2].txt - [3586 Bytes] - [21/10/2016 19:41:15]
C:\AdwCleaner\AdwCleaner[S3].txt - [3659 Bytes] - [21/10/2016 19:44:13]
C:\AdwCleaner\AdwCleaner[S4].txt - [3732 Bytes] - [21/10/2016 19:50:11]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3796 Bytes] ##########
 
 
——————————————————————————————————————————————————————————-
 
 
# AdwCleaner v6.030 - Logfile created 21/10/2016 at 19:50:42
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-10-18.1 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : kim - CLIMAX
# Running from : C:\Users\kim\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[!] Folder not deleted: C:\Users\kim\AppData\Local\vghd
 
 
***** [ Files ] *****
 
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
[-] Key deleted: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\distromatic
[-] Key deleted: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Softonic
[#] Key deleted on reboot: HKCU\Software\distromatic
[#] Key deleted on reboot: HKCU\Software\Softonic
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B6DCCCD3-520D-4485-B642-FCC136CE12C3}
[#] Key deleted on reboot: [x64] HKCU\Software\distromatic
[#] Key deleted on reboot: [x64] HKCU\Software\Softonic
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
[-] Key deleted: HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
[#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: pbjikboenpfhbbejgkoklgkhjpfogcam
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [3358 Bytes] - [21/10/2016 19:50:42]
C:\AdwCleaner\AdwCleaner[S0].txt - [3440 Bytes] - [21/10/2016 19:09:54]
C:\AdwCleaner\AdwCleaner[S1].txt - [3513 Bytes] - [21/10/2016 19:29:00]
C:\AdwCleaner\AdwCleaner[S2].txt - [3586 Bytes] - [21/10/2016 19:41:15]
C:\AdwCleaner\AdwCleaner[S3].txt - [3659 Bytes] - [21/10/2016 19:44:13]
C:\AdwCleaner\AdwCleaner[S4].txt - [3732 Bytes] - [21/10/2016 19:50:11]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3796 Bytes] ##########
 
 
 
After that I ran jtr as surgested, but it didnt find anything. Here is its output:
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on 21-10-2016 at 22:07:11.26
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 0 
 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21-10-2016 at 22:11:34.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
At last I ran mbam, but there was only one entry which I denyed it to delete, as it was a registry entry for Spyhunter which I actually use from time to time. Here comes the output:
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Dato: 23-10-2016
Scan Tid: 16:13
Logfil: 
Administrator: Ja
 
Version: 0.0.0.0000
Malware Database: v2016.10.23.04
Rootkit Database: v2016.09.26.02
Licens: Retssag
Malware Protection: Handicappede
Ondsindet Hjemmeside Beskyttelse: Handicappede
Selvbeskyttelse: Handicappede
 
OS: Windows 7 Service Pack 1
CPU: x64
Fil system: NTFS
Bruger: kim
 
Scan Type: Trussel Scanning
Resultater: Fuldført
Objekter Scannet: 424381
Forløbet Tid: 28 min, 8 sek
 
Hukommelse: Aktiveret
Startop: Aktiveret
Filsystem: Aktiveret
Arkiver: Aktiveret
Rootkits: Handicappede
Heuristics: Aktiveret
PUP: Aktiveret
PUM: Aktiveret
 
Processer: 0
(Ingen skadelige varer fundet)
 
Moduler: 0
(Ingen skadelige varer fundet)
 
Nøgle Register: 0
(Ingen skadelige varer fundet)
 
Værdi Register: 0
(Ingen skadelige varer fundet)
 
Data Register: 0
(Ingen skadelige varer fundet)
 
Mapper: 0
(Ingen skadelige varer fundet)
 
Filer: 0
(Ingen skadelige varer fundet)
 
Fysiske sektorer: 0
(Ingen skadelige varer fundet)
 
 
(end)
 
 
Hope this is all acceptable.
 
Thanks for your guidance! :-)
 
- Kim.

Again you did just fine.  :thumbup:

 

Open up FRST64 by Right Clicking on the icon and select RUN AS ADMINISTATOR,  when it opens make sure there is a checkmark in ADDITIONS, leave everything else as is , then click on SCAN and post both new logs please and lets see where we stand.

Hi Ken,

 

that was a fast reply! :-) - I have done as you instructed, and again here follows the output:

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-10-2016
Ran by [removed] (administrator) on CLIMAX (23-10-2016 22:45:02)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ACD Systems) C:\Program Files (x86)\ACD Systems\ACDSee Free\ACDSeeFreeInTouch2.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2723624 2011-03-27] (Synaptics Incorporated)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9083840 2016-10-13] (AVAST Software)
HKLM-x32\…\Run: [NBAgent] => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-07-05] (Nero AG)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25366584 2016-10-10] (Dropbox, Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-05-20] (Oracle Corporation)
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-09] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
Startup: C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopVideoPlayer.lnk [2016-01-03]
ShortcutTarget: DesktopVideoPlayer.lnk -> C:\Users\kim\AppData\Local\vghd\bin\vghd.exe (No File)
Startup: C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\T-Clock Redux x64.lnk [2015-10-22]
ShortcutTarget: T-Clock Redux x64.lnk -> C:\Users\kim\AppData\Local\Temp\Rar$EXa0.759\Clock64.exe (No File)
BootExecute: autocheck autochk * sh4native Sh4Removal
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Tcpip\..\Interfaces\{0E9831BD-FDDA-4B9E-96AB-769326E184D3}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{7F88158D-DB3F-4AEC-9E48-C474DD4F8A2D}: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{CCFCB4C6-21DD-4CAC-B585-8E975B127E6D}: [DhcpNameServer] 10.127.127.11 [removed] [removed]
 
Internet Explorer:
==================
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ie_sp_
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> DefaultScope {8D6016E3-A1A4-4A80-ADC8-4D55BCDD0E7B} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {8D6016E3-A1A4-4A80-ADC8-4D55BCDD0E7B} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ie_ds_&tag;=bds-p17-serp-us-ie-20&query;={searchTerms}
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-07-10] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-09-09] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-07-10] (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-09-09] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-28] (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} -  No File
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
 
FireFox:
========
FF DefaultProfile: n3ibsi3h.default
FF ProfilePath: C:\Users\kim\AppData\Roaming\Mozilla\Firefox\Profiles\n3ibsi3h.default [2016-10-22]
FF NewTab: Mozilla\Firefox\Profiles\n3ibsi3h.default -> hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ff_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ff_nt_
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Yahoo!
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Amazon
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Yahoo!
FF Homepage: Mozilla\Firefox\Profiles\n3ibsi3h.default -> about:home
FF Extension: (Greasemonkey) - C:\Users\kim\AppData\Roaming\Mozilla\Firefox\Profiles\n3ibsi3h.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2016-08-23]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-09]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-09]
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn => not found
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn => not found
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-12] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-07-10] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-10] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-08-25] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
CHR StartupUrls: Default -> "hxxps://dk.search.yahoo.com/?type=435371&fr;=yo-yhp-ch","hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://www.amazon.com/websearch/?ie=UTF8__PARAM__&query;={searchTerms}
CHR DefaultSearchKeyword: Default -> amazon
CHR Profile: C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default [2016-10-23]
CHR Extension: (Google Docs) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-25]
CHR Extension: (Google Drive) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-22]
CHR Extension: (YouTube) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-22]
CHR Extension: (Google Search) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-22]
CHR Extension: (Avast SafePrice) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-09-27]
CHR Extension: (Google Docs Offline) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-27]
CHR Extension: (Avast Online Security) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-09-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-27]
CHR Extension: (Gmail) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-25]
CHR Extension: (Chrome Media Router) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-28]
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\Extensions\Chrome.crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-09] (AVAST Software)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-27] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [38000 2016-10-10] (Dropbox, Inc.)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [216576 2016-08-18] () [File not signed]
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-08-02] (Acer Incorporated)
R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-09-09] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-09-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-09-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-09-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-09-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-09-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
S3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20110519.002\BHDrvx64.sys [1143416 2011-05-13] (Symantec Corporation)
S3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1300000.080\ccSetx64.sys [165512 2011-05-23] (Symantec Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20110519.031\IDSVia64.sys [488056 2011-05-13] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-10-23] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110519.002\ENG64.SYS [117880 2011-05-19] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110519.002\EX64.SYS [2011768 2011-05-19] (Symantec Corporation)
S3 SRTSP; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSP64.SYS [721528 2011-05-21] (Symantec Corporation)
S3 SRTSPX; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSPX64.SYS [37496 2011-05-21] (Symantec Corporation)
S3 SymDS; C:\Windows\system32\drivers\NISx64\1300000.080\SYMDS64.SYS [451192 2011-05-16] (Symantec Corporation)
S3 SymEFA; C:\Windows\system32\drivers\NISx64\1300000.080\SYMEFA64.SYS [1083512 2011-05-16] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-10-24] (Symantec Corporation)
S3 SymIRON; C:\Windows\system32\drivers\NISx64\1300000.080\Ironx64.SYS [189560 2011-05-16] (Symantec Corporation)
S3 SymNetS; C:\Windows\system32\drivers\NISx64\1300000.080\SYMNETS.SYS [396408 2011-05-09] (Symantec Corporation)
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2010-08-31] (Jungo)
S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-21 22:53 - 2016-10-21 22:53 - 22851472 _____ (Malwarebytes ) C:\Users\kim\Desktop\mbam-setup-2.2.1.1043.exe
2016-10-21 22:11 - 2016-10-21 22:11 - 00000552 _____ C:\Users\kim\Desktop\JRT.txt
2016-10-21 22:03 - 2016-10-21 22:04 - 01631928 _____ (Malwarebytes) C:\Users\kim\Desktop\JRT.exe
2016-10-21 22:02 - 2016-10-21 22:02 - 00001474 _____ C:\Users\kim\Desktop\AdwCleaner[C2].txt
2016-10-21 20:03 - 2016-10-21 20:03 - 00003919 _____ C:\Users\kim\Desktop\AdwCleaner[C0].txt
2016-10-21 19:37 - 2016-10-21 19:38 - 03910208 _____ C:\Users\kim\Downloads\AdwCleaner.exe
2016-10-21 19:07 - 2016-10-21 20:31 - 00000000 ____D C:\AdwCleaner
2016-10-21 19:04 - 2016-10-21 19:05 - 03910208 _____ C:\Users\kim\Desktop\AdwCleaner.exe
2016-10-21 02:09 - 2016-10-21 02:11 - 00003856 _____ C:\Users\kim\Desktop\Fixlog.txt
2016-10-18 23:10 - 2016-10-23 22:45 - 00026805 _____ C:\Users\kim\Desktop\FRST.txt
2016-10-18 23:10 - 2016-10-18 23:10 - 00051076 _____ C:\Users\kim\Desktop\Addition.txt
2016-10-18 22:56 - 2016-10-18 22:57 - 00051073 _____ C:\Users\kim\Downloads\Addition.txt
2016-10-18 22:55 - 2016-10-18 22:57 - 00038599 _____ C:\Users\kim\Downloads\FRST.txt
2016-10-18 22:54 - 2016-10-23 22:45 - 00000000 ____D C:\FRST
2016-10-18 22:53 - 2016-10-18 22:53 - 00001984 _____ C:\Users\kim\Desktop\aswMBR.txt
2016-10-18 22:53 - 2016-10-18 22:53 - 00000512 _____ C:\Users\kim\Desktop\MBR.dat
2016-10-18 22:52 - 2016-10-18 22:52 - 02407424 _____ (Farbar) C:\Users\kim\Desktop\FRST64.exe
2016-10-18 22:44 - 2016-10-18 22:44 - 05198336 _____ (AVAST Software) C:\Users\kim\Downloads\aswMBR.exe
2016-10-18 12:47 - 2016-10-21 20:34 - 00000022 _____ C:\Windows\S.dirmngr
2016-10-15 15:39 - 2016-10-15 15:39 - 00000767 _____ C:\Users\kim\Documents\TomsArchives.txt
2016-10-12 19:40 - 2016-10-12 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-10-12 11:19 - 2016-10-12 11:19 - 03160922 _____ C:\Users\kim\Downloads\1.wmv
2016-10-12 11:19 - 2016-10-12 11:19 - 03160922 _____ C:\Users\kim\Downloads\1 (1).wmv
2016-10-11 13:58 - 2016-10-11 13:58 - 00155464 _____ C:\Users\kim\Downloads\KOFRITUDLDPRET-2015-11-02 14.57.25.223.pdf
2016-10-11 13:57 - 2016-10-11 13:57 - 00154892 _____ C:\Users\kim\Downloads\MASKO_NEDS_UDL 418686 2016-05-02 08.58.25.405.pdf
2016-10-11 13:57 - 2016-10-11 13:57 - 00154892 _____ C:\Users\kim\Downloads\MASKO_NEDS_UDL 418686 2016-05-02 08.58.25.405 (1).pdf
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00038000 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2016-09-30 17:20 - 2016-09-30 17:20 - 00660552 _____ C:\Users\kim\Downloads\Pictures of Patterns.pdf
2016-09-28 10:40 - 2016-09-28 10:40 - 03514887 _____ C:\Users\kim\Downloads\sn004.wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 03514887 _____ C:\Users\kim\Downloads\sn004 (1).wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 02674173 _____ C:\Users\kim\Downloads\sn008.wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 02674173 _____ C:\Users\kim\Downloads\sn008 (1).wmv
2016-09-27 23:04 - 2016-09-27 23:04 - 00002148 _____ C:\Users\Public\Desktop\Google Earth.lnk
2016-09-27 23:04 - 2016-09-27 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2016-09-27 10:50 - 2016-09-27 10:50 - 05198336 _____ (AVAST Software) C:\Users\kim\Desktop\aswMBR.exe
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-09-27 09:49 - 2016-09-27 09:49 - 13170912 _____ (Microsoft Corporation) C:\Users\kim\Downloads\Silverlight_x64.exe
2016-09-27 09:46 - 2016-09-27 09:46 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-27 09:44 - 2016-09-27 09:44 - 00243584 _____ C:\Users\kim\Downloads\Firefox Setup Stub 49.0.1.exe
2016-09-25 13:33 - 2016-09-25 13:34 - 00000000 ____D C:\Users\kim\AppData\Roaming\.kde
2016-09-25 13:33 - 2016-09-25 13:33 - 00000000 ____D C:\Users\kim\AppData\Local\GNU
2016-09-25 13:33 - 2016-09-25 13:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gpg4win
2016-09-25 13:32 - 2016-09-27 09:53 - 00000000 ____D C:\Users\kim\AppData\Roaming\gnupg
2016-09-25 13:32 - 2016-09-25 13:32 - 00000000 ____D C:\ProgramData\GNU
2016-09-25 13:32 - 2016-09-25 13:32 - 00000000 ____D C:\Program Files (x86)\GNU
2016-09-25 13:31 - 2016-09-25 13:31 - 25629112 _____ (g10 Code GmbH) C:\Users\kim\Downloads\gpg4win-2.3.3.exe
2016-09-25 13:14 - 2016-09-25 13:14 - 15865898 _____ C:\Users\kim\Downloads\PGPDesktop.zip
2016-09-25 13:00 - 2016-09-25 13:00 - 00000000 ____D C:\Users\kim\AppData\Local\PGP Corporation
2016-09-25 12:54 - 2016-09-25 12:54 - 00000000 ____D C:\Users\kim\AppData\Roaming\PGP Corporation
2016-09-25 12:47 - 2016-09-25 13:16 - 00123066 _____ C:\Windows\SysWOW64\PGPlspRollback.reg
2016-09-24 03:56 - 2016-09-27 09:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-10-23 22:37 - 2015-08-27 21:32 - 00000982 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2016-10-23 22:15 - 2014-12-12 16:43 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-10-23 22:08 - 2015-01-04 14:30 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-10-23 22:02 - 2015-02-23 16:41 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-23 21:37 - 2015-08-27 21:32 - 00000978 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2016-10-23 01:02 - 2015-02-23 16:41 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-22 09:11 - 2014-12-04 22:27 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-10-21 22:55 - 2015-01-04 14:30 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-10-21 22:55 - 2015-01-04 14:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-10-21 22:55 - 2015-01-04 14:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-21 20:42 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-10-21 20:42 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-10-21 20:37 - 2015-08-27 21:36 - 00000000 ___RD C:\Users\kim\Dropbox
2016-10-21 20:34 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-10-21 19:07 - 2014-12-10 13:07 - 03336243 _____ C:\Users\kim\Documents\Multi Product_Simulation.cs2
2016-10-21 19:07 - 2014-12-09 12:40 - 00000000 ____D C:\Users\kim\AppData\Roaming\Skype
2016-10-21 18:18 - 2011-10-24 07:11 - 00000000 ____D C:\ProgramData\Skype
2016-10-21 02:11 - 2015-03-27 20:13 - 00000000 ____D C:\Users\kim\AppData\LocalLow\Temp
2016-10-21 02:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2016-10-21 01:46 - 2014-12-10 13:07 - 03343554 _____ C:\Users\kim\Documents\Multi Product_Simulation.bs2
2016-10-18 13:38 - 2016-03-08 18:17 - 00000000 ____D C:\Users\kim\Desktop\SpyHunter 4.21.10.4585 Portable by wood
2016-10-18 12:47 - 2016-04-28 21:47 - 00000000 ____D C:\Program Files (x86)\Amazon
2016-10-18 12:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-10-18 01:38 - 2016-06-14 14:32 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-10-13 20:08 - 2014-12-04 22:27 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-12 19:40 - 2015-08-27 21:32 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-10-12 09:16 - 2014-12-12 16:43 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-10-12 09:16 - 2014-12-09 01:04 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-10-12 09:16 - 2011-10-24 07:51 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-12 09:16 - 2011-10-24 07:51 - 00000000 ____D C:\Windows\system32\Macromed
2016-10-12 09:15 - 2011-10-24 07:51 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-10-04 00:04 - 2015-05-11 22:44 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-10-04 00:04 - 2015-05-11 22:44 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-09-30 20:37 - 2015-08-27 21:31 - 00000000 ____D C:\Users\kim\AppData\Local\Dropbox
2016-09-27 23:04 - 2015-02-23 16:40 - 00000000 ____D C:\Program Files (x86)\Google
2016-09-27 10:53 - 2015-01-14 16:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-27 09:46 - 2014-12-06 00:44 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-25 13:25 - 2016-07-27 07:10 - 00003886 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1469596212
2016-09-25 13:24 - 2009-07-14 07:13 - 00876042 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-25 13:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-09-25 13:04 - 2014-12-04 21:48 - 00000000 ____D C:\Users\kim
 
==================== Files in the root of some directories =======
 
2016-09-19 13:23 - 2016-09-20 11:05 - 0000600 _____ () C:\Users\kim\AppData\Roaming\winscp.rnd
2014-12-13 15:57 - 2014-12-13 15:57 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-03-07 12:01 - 2016-03-07 12:01 - 0000099 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2016-03-06 14:27 - 2016-03-06 14:27 - 0000101 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
 
Some files in TEMP:
====================
C:\Users\kim\AppData\Local\Temp\libeay32.dll
C:\Users\kim\AppData\Local\Temp\msvcr120.dll
C:\Users\kim\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-10-18 04:26
 
==================== End of FRST.txt ============================
 
 
————————————————————————————————————————————————
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-10-2016
Ran by [removed] (23-10-2016 22:46:00)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-04 19:48:37)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-344082389-2557018971-2821403297-500 - Administrator - Disabled)
Guest (S-1-5-21-344082389-2557018971-2821403297-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-344082389-2557018971-2821403297-1006 - Limited - Enabled)
kim (S-1-5-21-344082389-2557018971-2821403297-1000 - Administrator - Enabled) => C:\Users\kim
temp (S-1-5-21-344082389-2557018971-2821403297-1008 - Administrator - Enabled) => C:\Users\temp
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\uTorrent) (Version: 3.4.8.42576 - BitTorrent Inc.)
ACDSee Free (HKLM-x32\…\ACDSee Free) (Version: 1.1.21 - ACD Systems International Inc.)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\…\{995841E6-A7D8-2742-606C-98E350507317}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
AMD System Monitor (HKLM-x32\…\{C1C82DC9-1547-4038-8F0A-C069F0B7F2ED}) (Version: 1.0.5 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Apple-programunderstøttelse (32 bit) (HKLM-x32\…\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)
Apple-programunderstøttelse (64 bit) (HKLM\…\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
AVRStudio4 (HKLM-x32\…\{D5D88F8F-FDA4-4CF4-9F3E-3F40118C2120}) (Version: 4.18.684 - Atmel)
AVRStudio4 (x32 Version: 4.18.684 - Atmel) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 15.0.3.1 - Broadcom Corporation)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.4.1 - Broadcom Corporation)
CCleaner (HKLM\…\CCleaner) (Version: 5.00 - Piriform)
CodeBlocks (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\CodeBlocks) (Version: 16.01 - The Code::Blocks Team)
Crystal Reports for Visual Studio (x32 Version: 12.51.0.240 - SAP) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DB Browser for SQLite (HKLM-x32\…\SqliteBrowser3) (Version: 3.5.1 - oldsch00l)
Debut Video Capture Software (HKLM-x32\…\Debut) (Version: 2.03 - NCH Software)
Dotfuscator Software Services - Community Edition (HKLM-x32\…\{41B31ABE-5A6E-498A-8F28-3BA3B8779A41}) (Version: 5.0.2300.0 - PreEmptive Solutions)
Dropbox (HKLM-x32\…\Dropbox) (Version: 12.4.22 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
ETX Capital MT4 (HKLM-x32\…\ETX Capital MT4) (Version: 4.00 - MetaQuotes Software Corp.)
FastStone Image Viewer 5.3 (HKLM-x32\…\FastStone Image Viewer) (Version: 5.3 - FastStone Soft)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 53.0.2785.143 - Google Inc.)
Google Earth (HKLM-x32\…\{2C44ABB9-8621-4EF5-AF34-0886DCDA7C21}) (Version: 7.1.7.2600 - Google)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
gpedt.msc 1.0 (HKLM-x32\…\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version:  - Richard)
Gpg4win (2.3.3) (HKLM-x32\…\GPG4Win) (Version: 2.3.3 - The Gpg4win Project)
HP Deskjet 3050A J611 series Basic Device Software (HKLM\…\{1B77E249-B8D5-4E5E-8848-693ACEF84E6D}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
iTunes (HKLM\…\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.)
Java 8 Update 91 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.15 - Oracle Corporation)
Java 8 Update 91 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.7 - Packard Bell)
LærSelv Blindskrift (HKLM-x32\…\{C5B9C677-4BE8-11D3-8B01-0008C7797B27}) (Version: 2.08 - Keyboard Technologies Ltd.)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\…\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\…\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\…\{1803A630-3C38-4D2B-9B9A-0CB37243539C}) (Version: 2.0.50217.0 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\…\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50709.0 - Microsoft Corporation)
Microsoft Silverlight 3 SDK (HKLM-x32\…\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40818.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2008 (64-bit) (HKLM\…\Microsoft SQL Server 10 Release) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2008 Browser (HKLM-x32\…\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Native Client (HKLM\…\{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Data-Tier Application Framework (HKLM-x32\…\{0DDCEC37-369C-484B-B16D-B4413FD42FB9}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Data-Tier Application Project (HKLM-x32\…\{E5AE9031-79A5-4627-9641-BEFA82819B08}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\…\{4E968D9C-21A7-4915-B698-F7AEB913541D}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (x64) (HKLM\…\{DA67488A-2689-4F10-B90F-D2F6977509D6}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Transact-SQL Language Service (HKLM-x32\…\{78C3657E-742C-40B1-9F53-E5A921D40F17}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\…\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM-x32\…\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\…\{2A2F3AE8-246A-4252-BB26-1BEB45627074}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\…\{4A8CE6D7-4D52-43B9-970B-03FC75FAD667}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\…\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft Sync Framework Runtime v1.0 SP1 (x64) (HKLM\…\{8438EC02-B8A9-462D-AC72-1B521349C001}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework SDK v1.0 SP1 (HKLM-x32\…\{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework Services v1.0 SP1 (x64) (HKLM\…\{034106B5-54B7-467F-B477-5B7DBB492624}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) (HKLM\…\{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}) (Version: 2.0.3010.0 - Microsoft Corporation)
Microsoft Team Foundation Server 2010 Object Model - ENU (HKLM\…\Microsoft Team Foundation Server 2010 Object Model - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\…\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Designtime - 10.0.30319 (HKLM\…\{F5079164-1DB9-3BDA-853B-F78AF67CE071}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Runtime - 10.0.30319 (HKLM\…\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.30319 (HKLM-x32\…\{6A86554B-8928-30E4-A53C-D7337689134D}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual F# 2.0 Runtime (HKLM-x32\…\{729A3000-BC8A-3B74-BA5D-5068FE12D70C}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\…\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Professional - ENU (HKLM-x32\…\Microsoft Visual Studio 2010 Professional - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\…\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio Macro Tools (HKLM-x32\…\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 49.0.1 (x86 da) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 da)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1 - Mozilla)
Mozilla Thunderbird 38.0.1 (x86 da) (HKLM-x32\…\Mozilla Thunderbird 38.0.1 (x86 da)) (Version: 38.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyStars! 32Bit v2.7 (HKLM-x32\…\MyStars!32Bitv2.7) (Version:  - )
Navigational Algorithms (HKLM-x32\…\{2C13EAF9-FC13-4AA3-B0CF-88B9DE08914A}) (Version: 20.14.1 - Navigational Algorithms)
Nero BackItUp 10 (HKLM-x32\…\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.8.11000.8.100 - Nero AG)
Nero DiscSpeed 10 (HKLM-x32\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{68AFA3A7-9265-4ABD-994A-ACA413E3715C}) (Version: 10.6.10300 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\…\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.6.10500.3.100 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10900.31.0 - Nero AG)
NinjaTrader 8 (HKLM-x32\…\{04A902BC-76E2-4671-A389-68367F527E38}) (Version: 8.0.0.9 - NinjaTrader, LLC)
Norton Internet Security (HKLM-x32\…\NIS) (Version: 19.0.0.128 - Symantec Corporation)
OpenCPN 4.0.0 (HKLM-x32\…\OpenCPN 4.0.0) (Version: 4.0.0 - opencpn.org)
OpenOffice 4.1.2 (HKLM-x32\…\{7D5D1802-795F-451B-9BF8-831E853A43C9}) (Version: 4.12.9782 - Apache Software Foundation)
Packard Bell Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Packard Bell)
Packard Bell Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Packard Bell)
Packard Bell ScreenSaver (HKLM-x32\…\Packard Bell Screensaver) (Version: 1.1.0915.2011 - Packard Bell )
PL-2303 USB-to-Serial (HKLM-x32\…\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.12.0 - Prolific Technology INC)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pokemon GO Live Map (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\pokemon) (Version: 0.2.1 - Mike Christopher)
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Radarplot 1.5.0 (HKLM-x32\…\Radarplot_is1) (Version:  - brainaid GbR)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6343 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
SaxoTrader 2 (HKLM-x32\…\{024D66E9-D50C-44A7-92B4-2DFDDD95D228}) (Version: 2.147.67.0 - Saxo Bank)
ScanMaster-ELM 2.1.104.771 (HKLM\…\ScanMaster-ELM_is1) (Version: 2.1.104.771 - WGSoft.de)
Service Pack 1 for SQL Server 2008 (KB968369) (64-bit) (HKLM\…\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation)
Skype™ 7.29 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.)
Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.2.17.5 - Synaptics Incorporated)
TeslaMap57 (HKLM-x32\…\ST6UNST #1) (Version:  - )
VectorVest 7 (HKLM-x32\…\{93057e39-ceeb-4f3b-8a79-223512e8cb5b}) (Version: 1.16.175.0 - VectorVest, Inc.)
Video Web Camera (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Video Web Camera (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
VirtuaGirl version 1.2.0.84 (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\VirtuaGirl_is1) (Version: 1.2.0.84 - Totem Entertainment)
Visual Studio 2010 Prerequisites - English (HKLM\…\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.30319 - Microsoft Corporation)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
Web Deployment Tool (HKLM\…\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation)
Winamp (HKLM-x32\…\Winamp) (Version: 5.65  - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinAVR 20100110 (remove only) (HKLM-x32\…\WinAVR-20100110) (Version: 20100110 - )
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinSCP 5.9.2 (HKLM-x32\…\winscp3_is1) (Version: 5.9.2 - Martin Prikryl)
WXTide32 (HKLM-x32\…\WXTide32) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {050BCFD9-D994-46F2-B649-44A0247AC7AB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {3029EFFF-D258-48AF-B5EF-E0015A479459} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
Task: {333BDBAC-4387-4C9C-844A-DD9726A2A058} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {391DCC99-3D05-466F-8738-337989CD831E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-12] (Adobe Systems Incorporated)
Task: {48092976-6C56-4609-A6C3-18F9B75BEA0C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-27] (Dropbox, Inc.)
Task: {66CF9A58-B16C-403F-9FAD-63CA0E130F95} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-27] (Dropbox, Inc.)
Task: {73E1C3BD-405E-43F0-900B-AFC75CFDE2EB} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\WSCStub.exe
Task: {7FF46A41-7994-41D6-8AC5-19FBD3703357} - System32\Tasks\SafeZone scheduled Autoupdate 1469596212 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {89BDE521-FBA4-48D7-A881-9E0F84385CBA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {8BB26800-7622-456D-B335-F623C031C5CD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-09-09] (AVAST Software)
Task: {A4E9D0DE-D927-4865-88E0-A5A4705EEC69} - System32\Tasks\{5449FCC3-D3FE-45AD-A98C-526732AD1D87} => Firefox.exe hxxp://ui.skype.com/ui/0/7.0.0.100/da/abandoninstall?source=lightinstaller&page;=tsBing
Task: {A804DE58-1C05-47EC-9FF4-7E8BD15DDCC8} - System32\Tasks\NBAgent => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2011-07-05] (Nero AG)
Task: {C2F4FC50-7A7F-42D6-A0F4-0D69DAB158E2} - System32\Tasks\{259DA613-8344-4467-BEC6-2774072E2B3F} => pcalua.exe -a C:\Users\kim\Downloads\myst3227.exe -d C:\Users\kim\Downloads
Task: {DC4CA033-9F6E-4BB7-AC09-5BCC5BCF7ACA} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-03] (AVAST Software)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\kim\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.html
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-13 06:45 - 2015-10-13 06:45 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-13 06:45 - 2015-10-13 06:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-08-18 10:27 - 2016-08-18 10:27 - 00216576 _____ () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
2016-09-09 08:07 - 2016-09-09 08:07 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-10-21 18:14 - 2016-10-21 18:14 - 03121496 _____ () C:\Program Files\AVAST Software\Avast\defs\16102100\algo.dll
2016-09-09 08:07 - 2016-09-09 08:07 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-10-23 12:42 - 2016-10-23 12:42 - 03121496 _____ () C:\Program Files\AVAST Software\Avast\defs\16102300\algo.dll
2016-08-18 10:14 - 2016-08-18 10:14 - 00222720 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll
2016-08-18 10:09 - 2016-08-18 10:09 - 00103424 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll
2016-08-18 10:03 - 2016-08-18 10:03 - 00050176 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll
2016-08-18 10:14 - 2016-08-18 10:14 - 00073728 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll
2016-08-18 10:17 - 2016-08-18 10:17 - 00751104 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-20.dll
2016-07-11 19:52 - 2016-07-11 19:52 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-05-13 05:15 - 2016-09-22 03:44 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2016-10-12 19:39 - 2016-09-22 03:45 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-05-13 05:15 - 2016-09-22 03:44 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2016-05-13 05:15 - 2016-09-22 03:44 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2016-05-13 05:15 - 2016-09-22 03:44 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2016-05-13 05:15 - 2016-09-22 03:45 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00021312 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2016-10-12 19:39 - 2016-09-22 03:46 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00025424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-08-07 00:43 - 2016-09-22 03:45 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2016-10-12 19:39 - 2016-09-22 03:42 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2016-10-12 19:39 - 2016-10-10 20:35 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-10-12 19:39 - 2016-10-10 20:35 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-05-13 05:15 - 2016-09-22 03:45 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 01972528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00133424 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00224056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd
2016-10-12 19:39 - 2016-09-22 03:49 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2016-10-12 19:39 - 2016-09-22 03:49 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2016-05-13 05:15 - 2016-09-22 03:46 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00168760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2016-10-04 00:04 - 2016-09-25 05:47 - 01805416 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libglesv2.dll
2016-10-04 00:04 - 2016-09-25 05:47 - 00093288 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\kim\Desktop\2015-09-09 22.14.27.jpg:com.dropbox.attributes [1042]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\amazon.com -> hxxps://amazon.com
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\iitech.dk -> iitech.dk
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\onlinewebconnect.com -> onlinewebconnect.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 04:34 - 2016-10-21 02:10 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\kim\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.127.127.11 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{52CD9EBD-1813-4B94-A0E7-E15645E19BE0}] => (Allow) LPort=2869
FirewallRules: [{16619C0A-335A-42D1-AA95-8477B20542F5}] => (Allow) LPort=1900
FirewallRules: [{D9F6762B-AE5D-4977-87DF-EE71EE0619C6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{084814EA-5468-49F8-94DA-B079D3A432A9}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{592CB469-B665-4CF1-B147-F587164B64FB}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{BE2F38B0-BFE7-4230-9636-D700B3494257}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{E91DAAFC-F189-444A-909E-5AF388EB3EE0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{CD654684-FD39-41C8-8C0B-8E5E6D700379}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{4753085C-54EC-427B-9ADC-560A3BE463EB}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{94BBDC24-5AD9-449F-BB70-B61EC9F2A82E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{C8BA2D88-9170-40A4-AC53-FE1A11162ED2}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{08F1A06F-DCDD-4A1C-BD37-9F84481B5642}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{A6A98C68-9508-4AAA-AA44-44902A2C3B6B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{30CC684D-D29D-4496-A33E-EADC8AB32697}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{29513CC2-C458-4119-91F1-19D1B4BDC921}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{63C1F76B-BA3B-43B4-AC77-F99647261763}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{3D01301F-291B-4F48-82BB-92926B0CC4B6}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{4C7A9F98-F2CC-46DB-8818-EEF8622BEB7F}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{207F0D76-3CE8-4848-B99A-9C47C93E926E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5C8041AD-D5E2-44C8-8950-52942DC49A6C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BC292713-CAC9-4A5D-BB51-FD76C7C6224C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{35CD772E-95DE-4E2D-8978-B6F1D1C424E8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A07024A0-CC21-47E2-A975-F9202451C498}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6A21CAB9-7DE9-42B0-8A79-0CC95FA27194}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EDFCD553-1BEE-47B6-A606-35133186423B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{5E89391F-F90C-47C3-A109-138D38A74F13}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [UDP Query User{4930BA5C-4EE1-46D8-8252-5ECDCA3BB583}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [TCP Query User{ACB73085-2C30-4A35-BDCB-4F00E269C87C}C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe
FirewallRules: [UDP Query User{F845ED2F-10DE-4664-BBE5-9FC9F5ED8BD7}C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe
FirewallRules: [TCP Query User{2A52002E-CA9F-4A0C-BC11-6ACAF58602ED}C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe
FirewallRules: [UDP Query User{7EC9A817-36A8-46B9-AFF9-0E85FF777100}C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe
FirewallRules: [TCP Query User{BB50121D-2167-4554-8016-F5AA53E598D1}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [UDP Query User{DF0A9A1C-A94A-4C3D-B860-DEDFA26FACF2}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [TCP Query User{7046F038-6B10-4CBA-A0C2-9D17FFFB777F}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [UDP Query User{D5381F17-2F49-4ACE-B93B-765F81A699BE}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [{FCBAD548-CD77-4349-A9BA-7E684F9C748E}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{34768908-382A-4342-AFEA-1E022CE8F3DC}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5FF4523A-790F-4512-8ADE-B7468D233EA4}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5DAE0DAE-6FD2-4848-83CA-9307485C58F6}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{FA5DB429-81AC-4D5C-8C4A-4D070238BCA7}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6744B7EF-4650-4B3B-8EFD-43E2AE3FB0F0}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{41F878FA-8B74-44EB-9F66-EAEDB1240ACC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2D3A5DDF-A964-4928-A765-68620CA509C2}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
 
==================== Restore Points =========================
 
17-09-2016 14:54:59 Scheduled Checkpoint
23-09-2016 22:29:32 ASU_MSI_TRAN
25-09-2016 12:46:17 Installed PGP Desktop
25-09-2016 13:00:53 Removed PGP Desktop
25-09-2016 13:16:03 Installed PGP Desktop
25-09-2016 13:23:48 Removed PGP Desktop
25-09-2016 13:26:55 Removed PGP Desktop
03-10-2016 00:28:23 Scheduled Checkpoint
10-10-2016 02:23:41 Scheduled Checkpoint
18-10-2016 01:35:31 ASU_MSI_TRAN
21-10-2016 02:09:53 Restore Point Created by FRST
21-10-2016 18:15:53 ASU_MSI_TRAN
21-10-2016 18:58:53 Removed Συλλογή φωτογραφιών του Windows Live
21-10-2016 18:59:32 Removed Основные компоненты Windows Live
21-10-2016 19:00:15 Removed Почта Windows Live
21-10-2016 19:00:56 Removed Фотоальбом Windows Live
21-10-2016 19:01:39 Removed Фотогалерия на Windows Live
21-10-2016 19:02:25 Removed גלריית התמונות של Windows Live
21-10-2016 19:03:04 Removed بريد Windows Live
21-10-2016 19:03:45 Removed معرض صور Windows Live
21-10-2016 22:07:18 JRT Pre-Junkware Removal
22-10-2016 12:29:16 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/22/2016 12:32:08 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NMDllHost.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/22/2016 12:30:38 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NeroStartSmart.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/21/2016 08:34:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/21/2016 07:52:35 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/21/2016 07:32:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program AdwCleaner.exe version 6.0.3.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: ef4
 
Start Time: 01d22bc04f65471d
 
Termination Time: 16
 
Application Path: C:\Users\kim\Desktop\AdwCleaner.exe
 
Report Id: 4dd5232e-97b4-11e6-8d89-b888e34a3dab
 
Error: (10/21/2016 07:26:35 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program AdwCleaner.exe version 6.0.3.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 4bb4
 
Start Time: 01d22bbd9bc8a339
 
Termination Time: 0
 
Application Path: C:\Users\kim\Desktop\AdwCleaner.exe
 
Report Id: 745e9a91-97b3-11e6-8d89-b888e34a3dab
 
Error: (10/21/2016 03:27:00 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NMDllHost.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/21/2016 03:25:28 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NeroStartSmart.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (10/21/2016 02:14:25 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (10/21/2016 02:09:52 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {42018d01-65fe-44b1-a7d2-7b285a1ea9e3}
 
 
System errors:
=============
Error: (10/23/2016 01:25:27 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.
 
Error: (10/21/2016 08:08:12 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod-tjeneste service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/21/2016 08:08:11 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (10/21/2016 08:08:11 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (10/21/2016 08:08:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SQL Server (SQLEXPRESS) service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/21/2016 08:08:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SQL Server VSS Writer service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/21/2016 08:08:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Live Updater Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/21/2016 08:08:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The ePower Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (10/21/2016 08:08:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Dritek WMI Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 3000 milliseconds: Restart the service.
 
Error: (10/21/2016 08:08:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The DirMngr service terminated unexpectedly.  It has done this 1 time(s).
 
 
CodeIntegrity:
===================================
  Date: 2016-08-23 11:04:06.618
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-08-23 11:04:06.196
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-07-27 07:08:58.393
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-07-27 07:08:58.050
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD A6-3420M APU with Radeon™ HD Graphics
Percentage of memory in use: 43%
Total physical RAM: 7658.9 MB
Available physical RAM: 4343.22 MB
Total Virtual: 15316.01 MB
Available Virtual: 11092.02 MB
 
==================== Drives ================================
 
Drive c: (ACER) (Fixed) (Total:911.41 GB) (Free:695.98 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1D733A33)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Not Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=911.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
 
Best regards
 
- Kim.

There are just a couple of things to remove, there not earthshattering but I will be offliine until the morning.

 

uTorrent <– Heads up on this, not all but almost 99% of files and programs downloaded via File Sharing are infected. Look at your Additions log under Firewall rules, uTorrent has free access both in and out of your computer…NOt Nice

 

 

How is your system running now , any better ??

You should uninstall uTorrent and stay away from all P2P (File Sharing Programs)

 

 

Avast Free Antivirus 
Norton Internet Security
Looks like you have both of these Anti Virus Programs installed,, as per Microsoft, you should have only one AV installed, keep it updated , run  regular scans, more than one is overkill and will hamper system perfomance.
 
 
T-Clock Redux  <–Gettting mixed reviews on this one , some bad, if its something you dont use  I would uninstall it also
 
 

[external image: CKS_zpsugippntv.jpg]
Download CKScanner by askey127 from Here & save it to your Desktop.
  •  
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
 
 
 
 

Hi Ken,

 

lightning fast as usual! :-) - well, even though it is very nice to get ridge of all the nasties, I must admit that the original problem is still there. There are big 

black areas in the page when firefox presents it. To illustrate, I have taken a screenshot as an example. You will find it here:

 

http://www.ejlertsen.dk/firefox.png

 

Besides from that I have of course followed your instructions, so gone is uTorrent. Norton and T-Clock Redux was'nt really there; it was just empty links which I have now removed.

 

I also ran SKScanner and here comes the output:

 

CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
c:\majora\documents and settings\kim\dokumenter\musik\itunes\itunes media\mobile applications\crackulous-1.0.0.5.deb
c:\majora\documents and settings\kim\dokumenter\musik\itunes\itunes media\mobile applications\mazemaster-v1.0.1-icracker.ipa.zip.ipa
c:\majora\documents and settings\kim\dokumenter\musik\karaoke\(u's) the ultimate sunfly karaoke collection cdg (23 of 26)\uncle cracker - follow me.cdg
c:\majora\documents and settings\kim\skrivebord\lazarus\ipas\angry birds (v3.0.0)-darkgaminglord-[cracklords].ipa
c:\majora\documents and settings\kim\skrivebord\lazarus\ipas\angry birds space (v1.5.1 3gs rlsa lp os43)-slamdance-[cracklords].ipa
c:\majora\documents and settings\kim\skrivebord\lazarus\var\lib\dpkg\info\com.sinfuliphone.sinfulcrack.list
c:\majora\documents and settings\kim\skrivebord\lazarus\var\lib\dpkg\info\com.xsellize.cracknshare.list
c:\majora\documents and settings\kim\skrivebord\lazarus\var\lib\dpkg\info\com.xsellize.cracknshare.preinst
c:\majora\documents and settings\kim\skrivebord\lazarus\var\lib\dpkg\info\us.hackulo.crackulous.list
c:\majora\documents and settings\kim\skrivebord\lazarus\var\lib\dpkg\info\us.hackulo.crackulous.postinst
c:\users\kim\documents\elm 327 odbii-interface\scanmasterelm_2.1\keygen-scanmaster-2.1.exe
scanner sequence 3.EF.11.RKNAMZ
 —– EOF —– 

 

 
 
As far as I can see it looks pretty harmless, as everything is unix-based stuff with exception of the last one which is a program that came with a piece of diagnose hardware for my car that I once bought. It has not been executed for at least a year, so I doubt that it should be the problem.
 
Let me here what you think.
 
Best regards
 
- Kim.

Kim

 

This is your computer and I really cant tell you what to do with it , I can only advise.  It looks like you downloaded illegal software  via the torrents, besides being illegal all cracked/keygen software is infected . This forum as well as  many of the other malware removal forums do not support the use of illegal software except for there removal.  If I would have seen this when we first started I would have given you the option to uninstall any illegal stuff and if you deciede you wanted to keep it than this thread would have been closed. It would be in your best interest to uninstall this program

 

c:\users\kim\documents\elm 327 odbii-interface\scanmasterelm_2.1\keygen-scanmaster-2.1.exe

 

 

I want you to reset firefox back to defaults, to do this I need you to do this

 

https://malwaretips.com/blogs/reset-firefox-settings/

 
  • Open Firefox
  • Click on Help > Troubleshooting Information > Refresh Firefox
  •  
     
     
    restart the computer and check firefox for me now

    Hi Ken,

     

    Well, if you say it is infected it clearly has to go! - I have deleted it now, even though it feels a bit weird to delete something that I actually legally payed for. The file came on a CD as a part of the driver software for a testing device to my car. But that itself is obviously not a guarantee that it is clean! :-(

     

    I know for a fact that you are completely right! - P2P-sharing is very risky, the majority of the stuff one get this way is infected, so it is clearly best to stay away from this world.

     

    I did the resetting of Firefox, as instructed, I rebooted and tested it again. I am sorry to say that the problem is not gone, - but I do have a feeling that it is better now. There are still some updating here and there that is not done, but as far as I can tell it is clearly not as much as before, so I guess that something actually is improved… :-)

     

    Best Regards

     

    - Kim.

    Morning Kim

     

    That program was questionable since it showed up on your CKScanner log as being a keygen. 

     

     

    When you open FF, click on the Help menu and About FF, the latest version is 49.0.2  If your running an earlier version update it and see what happens. if it still doesent fix it click on Help and Restart with Add Ons disabled and again see what happens

    Hi Ken,

     

    I have updated from 49.0.1 to 49.0.2 but that changed nothing. I then did the restart with add ons disabled, and that actually did the trick! :-) :-)

    - so now it is just a question about figuring out which of the add ons are coursing trouble! - nice work!! :-)

     

    I will not change anything before I hear from you, but to give you something to go by, I have done a litte research.

     

    When I go to help -> technical information and scroll down to the paragraph concerning the add ons, I find this information:

     

    Udvidelser
    Navn                                                   Version      Aktiveret          ID
    Asynchronous Plugin Rendering     2.0             true                  [removed]
    Multi-process staged rollout            1.3             true                  [removed]
    Pocket                                                 1.0.4          true                  [removed]
    Web Compat                                      1.0             true                  [removed]
    Avast Online Security                        12.0.88      false                 [removed]
    Avast SafePrice                                  10.3.5.39   false                 [removed]
     
    It is in danish, but I believe that I bright guy like you can easily figure it out anyway.
     
    Now, when I go to "Udvidelser" (add ons) only the last two which is deactivated shows up! - I find that suspicious, but let me hear what you have to say about it…
     
    Best regards
     
    - Kim

    Ask AI

    AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

    Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI