My firefox-browser is behaving weird. The symptoms are that there are big areas that are not updated when going to a site, so that parts of the page are staying black, which is of course quite useless. I believe that the problem showed up after surfing some porn-sites, which probably makes sense. I guess that I have picked up some malware that gives the symptoms.
I have scanned with malwarebytes antimalware and spyhunter, but the fixes from these programes did not fix the problem.
It would be very nice if somebody here will take a look at my logs and see if there are any signs of infections.
Thanks in advance.
22:44:34.537 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:44:34.727 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 20480 MB offset 2048
22:44:34.743 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 100 MB offset 41945088
22:44:34.764 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 933287 MB offset 42149888
22:45:31.612 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
22:45:31.636 3 CLASSPNP.SYS[fffff880018d343f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8006e5d680]
22:53:11.928 Disk 0 MBR has been saved successfully to "C:\Users\kim\Desktop\MBR.dat"
22:53:11.930 The log file has been saved successfully to "C:\Users\kim\Desktop\aswMBR.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-10-2016
Ran by [removed] (administrator) on CLIMAX (18-10-2016 22:55:35)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Totem Entertainment) C:\Users\kim\AppData\Local\vghd\bin\vghd.exe
(-) C:\Users\kim\AppData\Local\Temp\Rar$EXa0.759\Clock64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Totem Entertainment) C:\Users\kim\AppData\Local\vghd\bin\VirtuaGirl_Downloader.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Enigma Software Group USA, LLC.) C:\Users\kim\Desktop\SpyHunter 4.21.10.4585 Portable by wood\SpyHunter4.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\kim\Downloads\aswMBR.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2723624 2011-03-27] (Synaptics Incorporated)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2011-03-28] (Realtek Semiconductor)
HKLM\…\Run: [Power Management] => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9083840 2016-10-13] (AVAST Software)
HKLM-x32\…\Run: [NBAgent] => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-07-05] (Nero AG)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [25366584 2016-10-10] (Dropbox, Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-05-20] (Oracle Corporation)
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-09] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.65536.dll [2016-10-10] (Dropbox, Inc.)
Startup: C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopVideoPlayer.lnk [2016-01-03]
ShortcutTarget: DesktopVideoPlayer.lnk -> C:\Users\kim\AppData\Local\vghd\bin\vghd.exe (Totem Entertainment)
Startup: C:\Users\kim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\T-Clock Redux x64.lnk [2015-10-22]
ShortcutTarget: T-Clock Redux x64.lnk -> C:\Users\kim\AppData\Local\Temp\Rar$EXa0.759\Clock64.exe (-)
BootExecute: autocheck autochk * sh4native Sh4RemovalaswBoot.exe /M:1548b752e4 /wow /dir:"C:\Program Files\AVAST Software\Avast"
GroupPolicyScripts-x32: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Tcpip\..\Interfaces\{0E9831BD-FDDA-4B9E-96AB-769326E184D3}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{7F88158D-DB3F-4AEC-9E48-C474DD4F8A2D}: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{CCFCB4C6-21DD-4CAC-B585-8E975B127E6D}: [DhcpNameServer] 10.127.127.11 [removed] [removed]
Internet Explorer:
==================
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://packardbell.msn.com
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ie_sp_
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=APBTDF&pc;=MAPB&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> DefaultScope {8D6016E3-A1A4-4A80-ADC8-4D55BCDD0E7B} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {8D6016E3-A1A4-4A80-ADC8-4D55BCDD0E7B} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-344082389-2557018971-2821403297-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ie_ds_&tag;=bds-p17-serp-us-ie-20&query;={searchTerms}
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-07-10] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-09-09] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-07-10] (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-09-09] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-28] (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - No File
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
FireFox:
========
FF DefaultProfile: n3ibsi3h.default
FF ProfilePath: C:\Users\kim\AppData\Roaming\Mozilla\Firefox\Profiles\n3ibsi3h.default [2016-10-18]
FF NewTab: Mozilla\Firefox\Profiles\n3ibsi3h.default -> hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ff_us_display?ie=UTF8&tagbase;=bds-p17&tbrId;=v1_abb-channel-17_e28a4d96_1201_1403_20160428_DK_ff_nt_
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Yahoo!
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Amazon
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\n3ibsi3h.default -> Yahoo!
FF Homepage: Mozilla\Firefox\Profiles\n3ibsi3h.default -> about:home
FF Extension: (Greasemonkey) - C:\Users\kim\AppData\Roaming\Mozilla\Firefox\Profiles\n3ibsi3h.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2016-08-23]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-09]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-09]
FF HKLM-x32\…\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn => not found
FF HKLM-x32\…\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn => not found
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-12] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-07-10] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-10] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-08-25] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-28] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
CHR StartupUrls: Default -> "hxxps://dk.search.yahoo.com/?type=435371&fr;=yo-yhp-ch","hxxp://www.google.com/"
CHR DefaultSearchURL: Default -> hxxps://www.amazon.com/websearch/?ie=UTF8__PARAM__&query;={searchTerms}
CHR DefaultSearchKeyword: Default -> amazon
CHR Profile: C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default [2016-10-18]
CHR Extension: (Google Docs) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-25]
CHR Extension: (Google Drive) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-22]
CHR Extension: (YouTube) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-22]
CHR Extension: (Google Search) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-22]
CHR Extension: (Avast SafePrice) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-09-27]
CHR Extension: (Google Docs Offline) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-27]
CHR Extension: (Avast Online Security) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-09-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-09-27]
CHR Extension: (Gmail) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-25]
CHR Extension: (Chrome Media Router) - C:\Users\kim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-28]
CHR HKU\S-1-5-21-344082389-2557018971-2821403297-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [ooebgdicanjhnamfmdlmlbcnkgehkkmf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-344082389-2557018971-2821403297-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
CHR HKLM-x32\…\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\Extensions\Chrome.crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-09-09] (AVAST Software)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-27] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [38000 2016-10-10] (Dropbox, Inc.)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [216576 2016-08-18] () [File not signed]
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-08-02] (Acer Incorporated)
R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-09-09] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-09-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-09-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-09-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-09-09] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-22] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-09-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
S3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20110519.002\BHDrvx64.sys [1143416 2011-05-13] (Symantec Corporation)
S3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1300000.080\ccSetx64.sys [165512 2011-05-23] (Symantec Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20110519.031\IDSVia64.sys [488056 2011-05-13] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110519.002\ENG64.SYS [117880 2011-05-19] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20110519.002\EX64.SYS [2011768 2011-05-19] (Symantec Corporation)
S3 SRTSP; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSP64.SYS [721528 2011-05-21] (Symantec Corporation)
S3 SRTSPX; C:\Windows\system32\drivers\NISx64\1300000.080\SRTSPX64.SYS [37496 2011-05-21] (Symantec Corporation)
S3 SymDS; C:\Windows\system32\drivers\NISx64\1300000.080\SYMDS64.SYS [451192 2011-05-16] (Symantec Corporation)
S3 SymEFA; C:\Windows\system32\drivers\NISx64\1300000.080\SYMEFA64.SYS [1083512 2011-05-16] (Symantec Corporation)
S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2011-10-24] (Symantec Corporation)
S3 SymIRON; C:\Windows\system32\drivers\NISx64\1300000.080\Ironx64.SYS [189560 2011-05-16] (Symantec Corporation)
S3 SymNetS; C:\Windows\system32\drivers\NISx64\1300000.080\SYMNETS.SYS [396408 2011-05-09] (Symantec Corporation)
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2010-08-31] (Jungo)
S3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [X]
S3 dbx; system32\DRIVERS\dbx.sys [X]
U3 aswMBR; \??\C:\Users\kim\AppData\Local\Temp\aswMBR.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-18 22:55 - 2016-10-18 22:56 - 00027414 _____ C:\Users\kim\Downloads\FRST.txt
2016-10-18 22:54 - 2016-10-18 22:55 - 00000000 ____D C:\FRST
2016-10-18 22:53 - 2016-10-18 22:53 - 00001984 _____ C:\Users\kim\Desktop\aswMBR.txt
2016-10-18 22:53 - 2016-10-18 22:53 - 00000512 _____ C:\Users\kim\Desktop\MBR.dat
2016-10-18 22:52 - 2016-10-18 22:52 - 02407424 _____ (Farbar) C:\Users\kim\Downloads\FRST64.exe
2016-10-18 22:44 - 2016-10-18 22:44 - 05198336 _____ (AVAST Software) C:\Users\kim\Downloads\aswMBR.exe
2016-10-18 12:47 - 2016-10-18 12:47 - 00000022 _____ C:\Windows\S.dirmngr
2016-10-15 15:39 - 2016-10-15 15:39 - 00000767 _____ C:\Users\kim\Documents\TomsArchives.txt
2016-10-12 19:40 - 2016-10-12 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-10-12 11:19 - 2016-10-12 11:19 - 03160922 _____ C:\Users\kim\Downloads\1.wmv
2016-10-12 11:19 - 2016-10-12 11:19 - 03160922 _____ C:\Users\kim\Downloads\1 (1).wmv
2016-10-11 13:58 - 2016-10-11 13:58 - 00155464 _____ C:\Users\kim\Downloads\KOFRITUDLDPRET-2015-11-02 14.57.25.223.pdf
2016-10-11 13:57 - 2016-10-11 13:57 - 00154892 _____ C:\Users\kim\Downloads\MASKO_NEDS_UDL 418686 2016-05-02 08.58.25.405.pdf
2016-10-11 13:57 - 2016-10-11 13:57 - 00154892 _____ C:\Users\kim\Downloads\MASKO_NEDS_UDL 418686 2016-05-02 08.58.25.405 (1).pdf
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00074352 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2016-10-10 20:30 - 2016-10-10 20:30 - 00038000 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2016-09-30 17:20 - 2016-09-30 17:20 - 00660552 _____ C:\Users\kim\Downloads\Pictures of Patterns.pdf
2016-09-28 10:40 - 2016-09-28 10:40 - 03514887 _____ C:\Users\kim\Downloads\sn004.wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 03514887 _____ C:\Users\kim\Downloads\sn004 (1).wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 02674173 _____ C:\Users\kim\Downloads\sn008.wmv
2016-09-28 10:40 - 2016-09-28 10:40 - 02674173 _____ C:\Users\kim\Downloads\sn008 (1).wmv
2016-09-27 23:04 - 2016-09-27 23:04 - 00002148 _____ C:\Users\Public\Desktop\Google Earth.lnk
2016-09-27 23:04 - 2016-09-27 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2016-09-27 10:50 - 2016-09-27 10:50 - 05198336 _____ (AVAST Software) C:\Users\kim\Desktop\aswMBR.exe
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-09-27 09:50 - 2016-09-27 09:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-09-27 09:49 - 2016-09-27 09:49 - 13170912 _____ (Microsoft Corporation) C:\Users\kim\Downloads\Silverlight_x64.exe
2016-09-27 09:46 - 2016-09-27 09:46 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-27 09:44 - 2016-09-27 09:44 - 00243584 _____ C:\Users\kim\Downloads\Firefox Setup Stub 49.0.1.exe
2016-09-25 13:33 - 2016-09-25 13:34 - 00000000 ____D C:\Users\kim\AppData\Roaming\.kde
2016-09-25 13:33 - 2016-09-25 13:33 - 00000000 ____D C:\Users\kim\AppData\Local\GNU
2016-09-25 13:33 - 2016-09-25 13:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gpg4win
2016-09-25 13:32 - 2016-09-27 09:53 - 00000000 ____D C:\Users\kim\AppData\Roaming\gnupg
2016-09-25 13:32 - 2016-09-25 13:32 - 00000000 ____D C:\ProgramData\GNU
2016-09-25 13:32 - 2016-09-25 13:32 - 00000000 ____D C:\Program Files (x86)\GNU
2016-09-25 13:31 - 2016-09-25 13:31 - 25629112 _____ (g10 Code GmbH) C:\Users\kim\Downloads\gpg4win-2.3.3.exe
2016-09-25 13:14 - 2016-09-25 13:14 - 15865898 _____ C:\Users\kim\Downloads\PGPDesktop.zip
2016-09-25 13:00 - 2016-09-25 13:00 - 00000000 ____D C:\Users\kim\AppData\Local\PGP Corporation
2016-09-25 12:54 - 2016-09-25 12:54 - 00000000 ____D C:\Users\kim\AppData\Roaming\PGP Corporation
2016-09-25 12:47 - 2016-09-25 13:16 - 00123066 _____ C:\Windows\SysWOW64\PGPlspRollback.reg
2016-09-24 03:56 - 2016-09-27 09:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-19 13:23 - 2016-09-20 11:05 - 00000600 _____ C:\Users\kim\AppData\Roaming\winscp.rnd
2016-09-19 13:19 - 2016-09-19 13:19 - 00001077 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2016-09-19 13:19 - 2016-09-19 13:19 - 00001065 _____ C:\Users\Public\Desktop\WinSCP.lnk
2016-09-19 13:19 - 2016-09-19 13:19 - 00000000 ____D C:\Program Files (x86)\WinSCP
2016-09-19 13:18 - 2016-09-19 13:19 - 09028128 _____ (Martin Prikryl ) C:\Users\kim\Downloads\WinSCP-5.9.2-Setup.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-18 13:38 - 2016-03-08 18:17 - 00000000 ____D C:\Users\kim\Desktop\SpyHunter 4.21.10.4585 Portable by wood
2016-10-18 12:57 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-10-18 12:57 - 2009-07-14 06:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-10-18 12:50 - 2015-08-27 21:36 - 00000000 ___RD C:\Users\kim\Dropbox
2016-10-18 12:47 - 2016-04-28 21:47 - 00000000 ____D C:\Program Files (x86)\Amazon
2016-10-18 12:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-10-18 12:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-10-18 12:37 - 2015-08-27 21:32 - 00000982 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2016-10-18 12:32 - 2015-01-04 14:30 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-10-18 12:15 - 2014-12-12 16:43 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-10-18 12:02 - 2015-02-23 16:41 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-18 09:30 - 2015-01-04 14:30 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-10-18 09:30 - 2015-01-04 14:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-10-18 09:30 - 2015-01-04 14:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-18 01:38 - 2016-06-14 14:32 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-10-18 01:38 - 2014-12-09 12:40 - 00000000 ____D C:\Users\kim\AppData\Roaming\Skype
2016-10-18 01:38 - 2011-10-24 07:11 - 00000000 ____D C:\ProgramData\Skype
2016-10-18 01:30 - 2015-08-27 21:32 - 00000978 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2016-10-18 01:30 - 2015-02-23 16:41 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-17 10:13 - 2014-12-04 22:27 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-10-14 13:32 - 2014-12-10 13:07 - 03343270 _____ C:\Users\kim\Documents\Multi Product_Simulation.cs2
2016-10-13 20:08 - 2014-12-04 22:27 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-12 19:40 - 2015-08-27 21:32 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-10-12 09:16 - 2014-12-12 16:43 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-10-12 09:16 - 2014-12-09 01:04 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-10-12 09:16 - 2011-10-24 07:51 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-12 09:16 - 2011-10-24 07:51 - 00000000 ____D C:\Windows\system32\Macromed
2016-10-12 09:15 - 2011-10-24 07:51 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-10-06 10:36 - 2014-12-10 13:07 - 03340738 _____ C:\Users\kim\Documents\Multi Product_Simulation.bs2
2016-10-04 00:04 - 2015-05-11 22:44 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-10-04 00:04 - 2015-05-11 22:44 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-09-30 20:37 - 2015-08-27 21:31 - 00000000 ____D C:\Users\kim\AppData\Local\Dropbox
2016-09-27 23:04 - 2015-02-23 16:40 - 00000000 ____D C:\Program Files (x86)\Google
2016-09-27 10:53 - 2015-01-14 16:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-09-27 09:46 - 2014-12-06 00:44 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-25 13:25 - 2016-07-27 07:10 - 00003886 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1469596212
2016-09-25 13:24 - 2009-07-14 07:13 - 00876042 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-25 13:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-09-25 13:04 - 2014-12-04 21:48 - 00000000 ____D C:\Users\kim
2016-09-22 20:08 - 2014-12-04 22:27 - 00513632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
==================== Files in the root of some directories =======
2016-09-19 13:23 - 2016-09-20 11:05 - 0000600 _____ () C:\Users\kim\AppData\Roaming\winscp.rnd
2014-12-13 15:57 - 2014-12-13 15:57 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-03-07 12:01 - 2016-03-07 12:01 - 0000099 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2016-03-06 14:27 - 2016-03-06 14:27 - 0000101 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
Files to move or delete:
====================
C:\Windows\SysWOW64\ntshrui.dll
Some files in TEMP:
====================
C:\Users\kim\AppData\Local\Temp\DefaultPack.EXE
C:\Users\kim\AppData\Local\Temp\{06113559-5494-4558-8210-BF2CB4CB8AFC}-49.0.2623.112_49.0.2623.110_chrome_updater.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-10-18 04:26
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-10-2016
Ran by [removed] (18-10-2016 22:56:40)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-12-04 19:48:37)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-344082389-2557018971-2821403297-500 - Administrator - Disabled)
Guest (S-1-5-21-344082389-2557018971-2821403297-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-344082389-2557018971-2821403297-1006 - Limited - Enabled)
kim (S-1-5-21-344082389-2557018971-2821403297-1000 - Administrator - Enabled) => C:\Users\kim
temp (S-1-5-21-344082389-2557018971-2821403297-1008 - Administrator - Enabled) => C:\Users\temp
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\uTorrent) (Version: 3.4.8.42576 - BitTorrent Inc.)
ACDSee Free (HKLM-x32\…\ACDSee Free) (Version: 1.1.21 - ACD Systems International Inc.)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
Amazon 1Button App (x32 Version: 2.3.4 - Amazon) Hidden <==== ATTENTION
AMD Catalyst Install Manager (HKLM\…\{995841E6-A7D8-2742-606C-98E350507317}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
AMD System Monitor (HKLM-x32\…\{C1C82DC9-1547-4038-8F0A-C069F0B7F2ED}) (Version: 1.0.5 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Apple-programunderstøttelse (32 bit) (HKLM-x32\…\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)
Apple-programunderstøttelse (64 bit) (HKLM\…\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
AVRStudio4 (HKLM-x32\…\{D5D88F8F-FDA4-4CF4-9F3E-3F40118C2120}) (Version: 4.18.684 - Atmel)
AVRStudio4 (x32 Version: 4.18.684 - Atmel) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\…\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 15.0.3.1 - Broadcom Corporation)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.4.1 - Broadcom Corporation)
CCleaner (HKLM\…\CCleaner) (Version: 5.00 - Piriform)
CodeBlocks (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\CodeBlocks) (Version: 16.01 - The Code::Blocks Team)
Crystal Reports for Visual Studio (x32 Version: 12.51.0.240 - SAP) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DB Browser for SQLite (HKLM-x32\…\SqliteBrowser3) (Version: 3.5.1 - oldsch00l)
Debut Video Capture Software (HKLM-x32\…\Debut) (Version: 2.03 - NCH Software)
Dotfuscator Software Services - Community Edition (HKLM-x32\…\{41B31ABE-5A6E-498A-8F28-3BA3B8779A41}) (Version: 5.0.2300.0 - PreEmptive Solutions)
Dropbox (HKLM-x32\…\Dropbox) (Version: 12.4.22 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
ETX Capital MT4 (HKLM-x32\…\ETX Capital MT4) (Version: 4.00 - MetaQuotes Software Corp.)
FastStone Image Viewer 5.3 (HKLM-x32\…\FastStone Image Viewer) (Version: 5.3 - FastStone Soft)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 53.0.2785.143 - Google Inc.)
Google Earth (HKLM-x32\…\{2C44ABB9-8621-4EF5-AF34-0886DCDA7C21}) (Version: 7.1.7.2600 - Google)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
gpedt.msc 1.0 (HKLM-x32\…\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version: - Richard)
Gpg4win (2.3.3) (HKLM-x32\…\GPG4Win) (Version: 2.3.3 - The Gpg4win Project)
HP Deskjet 3050A J611 series Basic Device Software (HKLM\…\{1B77E249-B8D5-4E5E-8848-693ACEF84E6D}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
iTunes (HKLM\…\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.)
Java 8 Update 91 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.15 - Oracle Corporation)
Java 8 Update 91 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.7 - Packard Bell)
LærSelv Blindskrift (HKLM-x32\…\{C5B9C677-4BE8-11D3-8B01-0008C7797B27}) (Version: 2.08 - Keyboard Technologies Ltd.)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\…\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\…\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\…\{1803A630-3C38-4D2B-9B9A-0CB37243539C}) (Version: 2.0.50217.0 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\…\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50709.0 - Microsoft Corporation)
Microsoft Silverlight 3 SDK (HKLM-x32\…\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40818.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2008 (64-bit) (HKLM\…\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation)
Microsoft SQL Server 2008 Browser (HKLM-x32\…\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Native Client (HKLM\…\{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Data-Tier Application Framework (HKLM-x32\…\{0DDCEC37-369C-484B-B16D-B4413FD42FB9}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Data-Tier Application Project (HKLM-x32\…\{E5AE9031-79A5-4627-9641-BEFA82819B08}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\…\{4E968D9C-21A7-4915-B698-F7AEB913541D}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (x64) (HKLM\…\{DA67488A-2689-4F10-B90F-D2F6977509D6}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Transact-SQL Language Service (HKLM-x32\…\{78C3657E-742C-40B1-9F53-E5A921D40F17}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files (HKLM\…\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM-x32\…\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\…\{2A2F3AE8-246A-4252-BB26-1BEB45627074}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\…\{4A8CE6D7-4D52-43B9-970B-03FC75FAD667}) (Version: 10.50.1447.4 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\…\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.1.2531.0 - Microsoft Corporation)
Microsoft Sync Framework Runtime v1.0 SP1 (x64) (HKLM\…\{8438EC02-B8A9-462D-AC72-1B521349C001}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework SDK v1.0 SP1 (HKLM-x32\…\{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Framework Services v1.0 SP1 (x64) (HKLM\…\{034106B5-54B7-467F-B477-5B7DBB492624}) (Version: 1.0.3010.0 - Microsoft Corporation)
Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) (HKLM\…\{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}) (Version: 2.0.3010.0 - Microsoft Corporation)
Microsoft Team Foundation Server 2010 Object Model - ENU (HKLM\…\Microsoft Team Foundation Server 2010 Object Model - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\…\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 (HKLM\…\{F5079164-1DB9-3BDA-853B-F78AF67CE071}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (HKLM\…\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319 (HKLM-x32\…\{6A86554B-8928-30E4-A53C-D7337689134D}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual F# 2.0 Runtime (HKLM-x32\…\{729A3000-BC8A-3B74-BA5D-5068FE12D70C}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\…\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Professional - ENU (HKLM-x32\…\Microsoft Visual Studio 2010 Professional - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\…\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual Studio Macro Tools (HKLM-x32\…\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 49.0.1 (x86 da) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 da)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1 - Mozilla)
Mozilla Thunderbird 38.0.1 (x86 da) (HKLM-x32\…\Mozilla Thunderbird 38.0.1 (x86 da)) (Version: 38.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyStars! 32Bit v2.7 (HKLM-x32\…\MyStars!32Bitv2.7) (Version: - )
Navigational Algorithms (HKLM-x32\…\{2C13EAF9-FC13-4AA3-B0CF-88B9DE08914A}) (Version: 20.14.1 - Navigational Algorithms)
Nero BackItUp 10 (HKLM-x32\…\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.8.11000.8.100 - Nero AG)
Nero DiscSpeed 10 (HKLM-x32\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{68AFA3A7-9265-4ABD-994A-ACA413E3715C}) (Version: 10.6.10300 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\…\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.6.10500.3.100 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10900.31.0 - Nero AG)
NinjaTrader 8 (HKLM-x32\…\{04A902BC-76E2-4671-A389-68367F527E38}) (Version: 8.0.0.9 - NinjaTrader, LLC)
Norton Internet Security (HKLM-x32\…\NIS) (Version: 19.0.0.128 - Symantec Corporation)
OpenCPN 4.0.0 (HKLM-x32\…\OpenCPN 4.0.0) (Version: 4.0.0 - opencpn.org)
OpenOffice 4.1.2 (HKLM-x32\…\{7D5D1802-795F-451B-9BF8-831E853A43C9}) (Version: 4.12.9782 - Apache Software Foundation)
Packard Bell Power Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Packard Bell)
Packard Bell Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Packard Bell)
Packard Bell ScreenSaver (HKLM-x32\…\Packard Bell Screensaver) (Version: 1.1.0915.2011 - Packard Bell )
Packard Bell Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Packard Bell)
PL-2303 USB-to-Serial (HKLM-x32\…\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}) (Version: 1.12.0 - Prolific Technology INC)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pokemon GO Live Map (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\pokemon) (Version: 0.2.1 - Mike Christopher)
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Radarplot 1.5.0 (HKLM-x32\…\Radarplot_is1) (Version: - brainaid GbR)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6343 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
SaxoTrader 2 (HKLM-x32\…\{024D66E9-D50C-44A7-92B4-2DFDDD95D228}) (Version: 2.147.67.0 - Saxo Bank)
ScanMaster-ELM 2.1.104.771 (HKLM\…\ScanMaster-ELM_is1) (Version: 2.1.104.771 - WGSoft.de)
Service Pack 1 for SQL Server 2008 (KB968369) (64-bit) (HKLM\…\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation)
Skype™ 7.29 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.101 - Skype Technologies S.A.)
Sql Server Customer Experience Improvement Program (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.2.17.5 - Synaptics Incorporated)
TeslaMap57 (HKLM-x32\…\ST6UNST #1) (Version: - )
VectorVest 7 (HKLM-x32\…\{93057e39-ceeb-4f3b-8a79-223512e8cb5b}) (Version: 1.16.175.0 - VectorVest, Inc.)
Video Web Camera (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Video Web Camera (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
VirtuaGirl version 1.2.0.84 (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\VirtuaGirl_is1) (Version: 1.2.0.84 - Totem Entertainment)
Visual Studio 2010 Prerequisites - English (HKLM\…\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.30319 - Microsoft Corporation)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
Web Deployment Tool (HKLM\…\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation)
Winamp (HKLM-x32\…\Winamp) (Version: 5.65 - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinAVR 20100110 (remove only) (HKLM-x32\…\WinAVR-20100110) (Version: 20100110 - )
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinSCP 5.9.2 (HKLM-x32\…\winscp3_is1) (Version: 5.9.2 - Martin Prikryl)
WXTide32 (HKLM-x32\…\WXTide32) (Version: - )
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {050BCFD9-D994-46F2-B649-44A0247AC7AB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {3029EFFF-D258-48AF-B5EF-E0015A479459} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
Task: {333BDBAC-4387-4C9C-844A-DD9726A2A058} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {391DCC99-3D05-466F-8738-337989CD831E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-12] (Adobe Systems Incorporated)
Task: {48092976-6C56-4609-A6C3-18F9B75BEA0C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-27] (Dropbox, Inc.)
Task: {66CF9A58-B16C-403F-9FAD-63CA0E130F95} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-27] (Dropbox, Inc.)
Task: {73E1C3BD-405E-43F0-900B-AFC75CFDE2EB} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\19.0.0.128\WSCStub.exe
Task: {7FF46A41-7994-41D6-8AC5-19FBD3703357} - System32\Tasks\SafeZone scheduled Autoupdate 1469596212 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {89BDE521-FBA4-48D7-A881-9E0F84385CBA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-23] (Google Inc.)
Task: {8BB26800-7622-456D-B335-F623C031C5CD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-09-09] (AVAST Software)
Task: {A4E9D0DE-D927-4865-88E0-A5A4705EEC69} - System32\Tasks\{5449FCC3-D3FE-45AD-A98C-526732AD1D87} => Firefox.exe hxxp://ui.skype.com/ui/0/7.0.0.100/da/abandoninstall?source=lightinstaller&page;=tsBing
Task: {A804DE58-1C05-47EC-9FF4-7E8BD15DDCC8} - System32\Tasks\NBAgent => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2011-07-05] (Nero AG)
Task: {C2F4FC50-7A7F-42D6-A0F4-0D69DAB158E2} - System32\Tasks\{259DA613-8344-4467-BEC6-2774072E2B3F} => pcalua.exe -a C:\Users\kim\Downloads\myst3227.exe -d C:\Users\kim\Downloads
Task: {DC4CA033-9F6E-4BB7-AC09-5BCC5BCF7ACA} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-03] (AVAST Software)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\kim\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.html
==================== Loaded Modules (Whitelisted) ==============
2015-10-13 06:45 - 2015-10-13 06:45 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-13 06:45 - 2015-10-13 06:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-08-18 10:27 - 2016-08-18 10:27 - 00216576 _____ () C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
2016-09-09 08:07 - 2016-09-09 08:07 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-09-09 08:07 - 2016-09-09 08:07 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-10-18 20:52 - 2016-10-18 20:52 - 03121496 _____ () C:\Program Files\AVAST Software\Avast\defs\16101801\algo.dll
2016-08-18 10:14 - 2016-08-18 10:14 - 00222720 _____ () C:\Program Files (x86)\GNU\GnuPG\libksba-8.dll
2016-08-18 10:09 - 2016-08-18 10:09 - 00103424 _____ () C:\Program Files (x86)\GNU\GnuPG\libgpg-error-0.dll
2016-08-18 10:03 - 2016-08-18 10:03 - 00050176 _____ () C:\Program Files (x86)\GNU\GnuPG\libw32pth-0.dll
2016-08-18 10:14 - 2016-08-18 10:14 - 00073728 _____ () C:\Program Files (x86)\GNU\GnuPG\libassuan-0.dll
2016-08-18 10:17 - 2016-08-18 10:17 - 00751104 _____ () C:\Program Files (x86)\GNU\GnuPG\libgcrypt-20.dll
2016-07-11 19:52 - 2016-07-11 19:52 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-05-13 05:15 - 2016-09-22 03:44 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2016-10-12 19:39 - 2016-09-22 03:45 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-05-13 05:15 - 2016-09-22 03:44 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2016-05-13 05:15 - 2016-09-22 03:44 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2016-05-13 05:15 - 2016-09-22 03:44 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2016-05-13 05:15 - 2016-09-22 03:45 - 00123856 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00021312 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-10-12 19:39 - 2016-09-22 03:44 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2016-10-12 19:39 - 2016-09-22 03:46 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00025424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00246592 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-08-07 00:43 - 2016-09-22 03:45 - 00241104 _____ () C:\Program Files (x86)\Dropbox\Client\_jpegtran.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
2016-05-13 05:15 - 2016-09-22 03:46 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-05-13 05:15 - 2016-10-10 20:35 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2016-10-12 19:39 - 2016-09-22 03:42 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2016-10-12 19:39 - 2016-10-10 20:35 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-10-12 19:39 - 2016-10-10 20:35 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-05-13 05:15 - 2016-09-22 03:45 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 01972528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00133424 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00224056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00020288 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32._winffi_user32.pyd
2016-10-12 19:39 - 2016-09-22 03:49 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2016-10-12 19:39 - 2016-09-22 03:49 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2016-05-13 05:15 - 2016-09-22 03:46 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2016-08-07 00:43 - 2016-10-10 20:35 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2016-10-12 19:39 - 2016-10-10 20:35 - 00168760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2016-01-03 21:06 - 2014-06-19 12:50 - 00875520 _____ () C:\Users\kim\AppData\Local\vghd\bin\platforms\qwindows.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00034304 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qdds.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00023552 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qgif.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00029184 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qicns.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00023552 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qico.dll
2016-01-03 21:06 - 2014-06-19 12:56 - 00418304 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qjp2.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00241152 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qjpeg.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00220672 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qmng.dll
2016-01-03 21:06 - 2014-06-19 12:51 - 00017408 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qsvg.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00017408 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qtga.dll
2016-01-03 21:06 - 2014-06-19 12:55 - 00309760 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qtiff.dll
2016-01-03 21:06 - 2014-06-19 12:56 - 00016896 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qwbmp.dll
2016-01-03 21:06 - 2014-06-19 12:56 - 00288256 _____ () C:\Users\kim\AppData\Local\vghd\bin\imageformats\qwebp.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00037888 _____ () C:\Users\kim\AppData\Local\vghd\bin\bearer\qgenericbearer.dll
2016-01-03 21:06 - 2014-06-19 12:49 - 00039936 _____ () C:\Users\kim\AppData\Local\vghd\bin\bearer\qnativewifibearer.dll
2016-01-03 21:06 - 2014-08-13 13:47 - 00126464 _____ () C:\Users\kim\AppData\Local\vghd\bin\mediaservice\dsengine.dll
2016-01-03 21:06 - 2014-06-19 13:16 - 00136192 _____ () C:\Users\kim\AppData\Local\vghd\bin\mediaservice\wmfengine.dll
2016-01-03 21:06 - 2014-06-19 13:14 - 00018944 _____ () C:\Users\kim\AppData\Local\vghd\bin\sensors\qtsensors_dummy.dll
2016-01-03 21:06 - 2014-06-19 13:14 - 00027648 _____ () C:\Users\kim\AppData\Local\vghd\bin\sensors\qtsensors_generic.dll
2016-10-04 00:04 - 2016-09-25 05:47 - 01805416 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libglesv2.dll
2016-10-04 00:04 - 2016-09-25 05:47 - 00093288 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.143\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\kim\Desktop\2015-09-09 22.14.27.jpg:com.dropbox.attributes [1042]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\amazon.com -> hxxps://amazon.com
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\iitech.dk -> iitech.dk
IE trusted site: HKU\S-1-5-21-344082389-2557018971-2821403297-1000\…\onlinewebconnect.com -> onlinewebconnect.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-344082389-2557018971-2821403297-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\kim\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.127.127.11 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{52CD9EBD-1813-4B94-A0E7-E15645E19BE0}] => (Allow) LPort=2869
FirewallRules: [{16619C0A-335A-42D1-AA95-8477B20542F5}] => (Allow) LPort=1900
FirewallRules: [{D9F6762B-AE5D-4977-87DF-EE71EE0619C6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{084814EA-5468-49F8-94DA-B079D3A432A9}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{592CB469-B665-4CF1-B147-F587164B64FB}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{BE2F38B0-BFE7-4230-9636-D700B3494257}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{E91DAAFC-F189-444A-909E-5AF388EB3EE0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{CD654684-FD39-41C8-8C0B-8E5E6D700379}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\DeviceSetup.exe
FirewallRules: [{4753085C-54EC-427B-9ADC-560A3BE463EB}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{94BBDC24-5AD9-449F-BB70-B61EC9F2A82E}] => (Allow) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{C8BA2D88-9170-40A4-AC53-FE1A11162ED2}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{08F1A06F-DCDD-4A1C-BD37-9F84481B5642}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{A6A98C68-9508-4AAA-AA44-44902A2C3B6B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{30CC684D-D29D-4496-A33E-EADC8AB32697}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{29513CC2-C458-4119-91F1-19D1B4BDC921}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{63C1F76B-BA3B-43B4-AC77-F99647261763}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{3D01301F-291B-4F48-82BB-92926B0CC4B6}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{4C7A9F98-F2CC-46DB-8818-EEF8622BEB7F}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{207F0D76-3CE8-4848-B99A-9C47C93E926E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5C8041AD-D5E2-44C8-8950-52942DC49A6C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{BC292713-CAC9-4A5D-BB51-FD76C7C6224C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{35CD772E-95DE-4E2D-8978-B6F1D1C424E8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A07024A0-CC21-47E2-A975-F9202451C498}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6A21CAB9-7DE9-42B0-8A79-0CC95FA27194}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EDFCD553-1BEE-47B6-A606-35133186423B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{5E89391F-F90C-47C3-A109-138D38A74F13}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [UDP Query User{4930BA5C-4EE1-46D8-8252-5ECDCA3BB583}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [TCP Query User{ACB73085-2C30-4A35-BDCB-4F00E269C87C}C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe
FirewallRules: [UDP Query User{F845ED2F-10DE-4664-BBE5-9FC9F5ED8BD7}C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin64\ninjatrader.exe
FirewallRules: [TCP Query User{2A52002E-CA9F-4A0C-BC11-6ACAF58602ED}C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe
FirewallRules: [UDP Query User{7EC9A817-36A8-46B9-AFF9-0E85FF777100}C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe] => (Allow) C:\program files (x86)\ninjatrader 8\bin\ninjatrader.exe
FirewallRules: [TCP Query User{BB50121D-2167-4554-8016-F5AA53E598D1}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [UDP Query User{DF0A9A1C-A94A-4C3D-B860-DEDFA26FACF2}C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Block) C:\users\kim\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [TCP Query User{7046F038-6B10-4CBA-A0C2-9D17FFFB777F}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [UDP Query User{D5381F17-2F49-4ACE-B93B-765F81A699BE}C:\program files\java\jre1.8.0_91\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_91\bin\java.exe
FirewallRules: [{FCBAD548-CD77-4349-A9BA-7E684F9C748E}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{34768908-382A-4342-AFEA-1E022CE8F3DC}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5FF4523A-790F-4512-8ADE-B7468D233EA4}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5DAE0DAE-6FD2-4848-83CA-9307485C58F6}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{FA5DB429-81AC-4D5C-8C4A-4D070238BCA7}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6744B7EF-4650-4B3B-8EFD-43E2AE3FB0F0}] => (Allow) C:\Users\kim\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{41F878FA-8B74-44EB-9F66-EAEDB1240ACC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{2D3A5DDF-A964-4928-A765-68620CA509C2}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
==================== Restore Points =========================
14-08-2016 22:21:17 Scheduled Checkpoint
23-08-2016 11:49:13 Scheduled Checkpoint
29-08-2016 23:18:58 ASU_MSI_TRAN
17-09-2016 14:54:59 Scheduled Checkpoint
23-09-2016 22:29:32 ASU_MSI_TRAN
25-09-2016 12:46:17 Installed PGP Desktop
25-09-2016 13:00:53 Removed PGP Desktop
25-09-2016 13:16:03 Installed PGP Desktop
25-09-2016 13:23:48 Removed PGP Desktop
25-09-2016 13:26:55 Removed PGP Desktop
03-10-2016 00:28:23 Scheduled Checkpoint
10-10-2016 02:23:41 Scheduled Checkpoint
18-10-2016 01:35:31 ASU_MSI_TRAN
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/18/2016 12:48:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (10/18/2016 04:28:27 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NMDllHost.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
Error: (10/18/2016 04:26:48 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\NeroStartSmart.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Nero\Nero 10\Nero StartSmart\Nero.NeDiscManager\Nero.NeDiscManager.MANIFEST" on line 3.
Component identity found in manifest does not match the identity of the component requested.
Reference is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.1.0.0".
Definition is Nero.NeDiscManager,processorArchitecture="x86",type="win32",version="7.3.0.0".
Please use sxstrace.exe for detailed diagnosis.
Error: (10/18/2016 01:30:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (10/18/2016 01:28:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 37487
Error: (10/18/2016 01:28:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 37487
Error: (10/18/2016 01:28:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/18/2016 01:28:52 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 34991
Error: (10/18/2016 01:28:52 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 34991
Error: (10/18/2016 01:28:52 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (10/18/2016 12:47:35 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.
Error: (10/18/2016 12:47:35 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.
Error: (10/18/2016 01:30:14 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 01:29:09 on 18-10-2016 was unexpected.
Error: (10/10/2016 01:54:14 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
Error: (10/10/2016 01:54:13 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
Error: (10/10/2016 01:54:13 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
Error: (10/06/2016 10:38:32 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
Error: (10/06/2016 10:33:22 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
Error: (10/06/2016 10:28:12 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
Error: (10/06/2016 10:23:02 AM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP :1d" could not be registered on the interface with IP address [removed].
The computer with the IP address [removed] did not allow the name to be claimed by
this computer.
CodeIntegrity:
===================================
Date: 2016-08-23 11:04:06.618
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-23 11:04:06.196
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-07-27 07:08:58.393
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-07-27 07:08:58.050
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: AMD A6-3420M APU with Radeon™ HD Graphics
Percentage of memory in use: 35%
Total physical RAM: 7658.9 MB
Available physical RAM: 4945.98 MB
Total Virtual: 15316.01 MB
Available Virtual: 12321.42 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:911.41 GB) (Free:705.57 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)]
==================== MBR & Partition Table ==================
==================== End of Addition.txt ============================