Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Gameharbor Malware Help


  • This topic is locked This topic is locked
8 replies to this topic

#1 tngvu

tngvu

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:15 PM

Posted 14 September 2014 - 10:31 PM

Hi, just got infected with this; whenever i startup my computer a chrome link to gameharbor.org always appears. Here's my FRST.txt:

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Tony (administrator) on TONY-PC on 14-09-2014 23:24:30
Running from C:\Users\Tony\Desktop\FRST
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\schtasks.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTsysTray8.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
() C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
() C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Razer Inc.) C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\Smc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwucli.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506136 2013-12-06] (Realtek Semiconductor)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters).
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403288 2014-08-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-25] (Intel Corporation)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [1047536 2013-11-12] (MSI)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DeathAdder] => C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe [311296 2009-12-15] ()
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKU\.DEFAULT\...\Run: [Bitdefender Wallet Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe"
HKU\.DEFAULT\...\Run: [Bitdefender Wallet] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard
HKU\.DEFAULT\...\Run: [Bitdefender Wallet Application Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe"
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1939136 2014-08-28] (Valve Corporation)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2014-06-05] (TomTom)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [CMD] => cmd.exe /c start http://extendedunlimited.org && exit <===== ATTENTION
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\MountPoints2: F - F:\setup.exe
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\MountPoints2: G - G:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{A003678C-C125-49A0-90D0-99AE485F6F92}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RCRN_Autoupdater.exe.lnk
ShortcutTarget: RCRN_Autoupdater.exe.lnk -> C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\RCRN\Autoupdater\RCRN_Autoupdater.exe (Damiano La Maida)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x641BE5812651CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Symantec Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\bin\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 192.168.1.1
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\IPSFF
FF Extension: Symantec Vulnerability Protection - C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\IPSFF [2014-04-07]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-04-18]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR DefaultSearchKeyword: Default -> B68510555A207E5346066EA590FE8B2879E05AFB06618820F6EE2A5249BE32F7
CHR DefaultSearchURL: Default -> 0A3FD8A142D5BC82F0DAAADF2B1D942A9DE42CF7E5FAD788D65DE4E3D12015F2
CHR Profile: C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-05]
CHR Extension: (Google Drive) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-05]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-22]
CHR Extension: (YouTube) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-05]
CHR Extension: (Slinky Elegant) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2014-04-05]
CHR Extension: (Google Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-05]
CHR Extension: (AdBlock) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-05]
CHR Extension: (Google Wallet) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-05]
CHR Extension: (Gmail) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-05]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2014-09-01] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-01] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-08-08] (LogMeIn, Inc.)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161776 2013-09-09] (MSI)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720792 2014-08-08] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18973144 2014-08-08] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed]
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-09-11] (Qualcomm Atheros) [File not signed]
R2 SepMasterService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe [143928 2012-11-03] (Symantec Corporation)
R3 SmcService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\Smc.exe [2294112 2012-11-03] (Symantec Corporation)
S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\snac64.exe [334288 2012-11-03] (Symantec Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
R1 BHDrvx64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20140801.011\BHDrvx64.sys [1530160 2014-05-09] (Symantec Corporation)
R1 ccSettings_{3771A34D-2132-48EA-A486-D62ECDF9D553}; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\ccSetx64.sys [168096 2012-11-03] (Symantec Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-05-14] (Disc Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-09] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-09-09] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\IPSDefs\20140912.011\IDSvia64.sys [525016 2014-05-12] (Symantec Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-08-01] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-08-01] ()
R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-01] ()
S3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [20464 2013-11-11] (Windows ® Win 7 DDK provider)
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-08-01] ()
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 NAVENG; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20140913.021\ENG64.SYS [129752 2014-08-21] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20140913.021\EX64.SYS [2137304 2014-08-21] (Symantec Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20440 2014-08-08] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R1 SRTSP; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SRTSP64.SYS [776352 2012-11-03] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SRTSPX64.SYS [37496 2012-11-03] (Symantec Corporation)
S3 SyDvCtrl; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\SyDvCtrl64.sys [34352 2012-11-03] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SYMDS64.SYS [493216 2012-11-03] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SYMEFA64.SYS [1133216 2012-11-03] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-04-07] (Symantec Corporation)
R1 SymIRON; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\Ironx64.SYS [224416 2012-11-03] (Symantec Corporation)
R1 SYMNETS; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SYMNETS.SYS [432800 2012-11-03] (Symantec Corporation)
R1 SysPlant; C:\Windows\System32\Drivers\SysPlant.sys [154904 2014-04-07] (Symantec Corporation)
R1 Teefer2; C:\Windows\System32\DRIVERS\Teefer.sys [95616 2012-11-03] (Symantec Corporation)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed]
S4 avgntflt; system32\DRIVERS\avgntflt.sys [X]
R4 avkmgr; system32\DRIVERS\avkmgr.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-14 23:22 - 2014-09-14 23:22 - 00000000 _____ () C:\ProgramData\rebootpending.txt
2014-09-14 23:14 - 2014-09-14 23:14 - 00000151 _____ () C:\Users\Tony\Downloads\fixlist.txt
2014-09-14 23:12 - 2014-09-14 23:24 - 00000000 ____D () C:\Users\Tony\Desktop\FRST
2014-09-14 23:07 - 2014-09-14 23:07 - 00033347 _____ () C:\Users\Tony\Downloads\Addition.txt
2014-09-14 22:55 - 2014-09-14 23:24 - 00000000 ____D () C:\FRST
2014-09-13 15:00 - 2014-09-14 23:21 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-13 15:00 - 2014-09-13 15:00 - 04050840 _____ (Avira Operations GmbH & Co. KG) C:\Users\Tony\Downloads\avira_en_av___dlc.exe
2014-09-13 14:35 - 2014-09-13 14:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 14:34 - 2014-09-13 14:34 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 14:02 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-13 14:01 - 2014-09-13 14:25 - 00000000 ____D () C:\AdwCleaner
2014-09-13 13:49 - 2014-09-13 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iPod
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-09-12 13:49 - 2014-09-12 13:49 - 00003082 _____ () C:\Windows\System32\Tasks\{62D6B2F3-431C-4E60-8404-F847D480F7E3}
2014-09-11 02:56 - 2014-08-19 14:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 02:56 - 2014-08-19 13:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 02:56 - 2014-08-18 19:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 02:56 - 2014-08-18 18:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 02:56 - 2014-08-18 18:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 02:56 - 2014-08-18 18:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 02:56 - 2014-08-18 18:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 02:56 - 2014-08-18 18:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 02:56 - 2014-08-18 18:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 02:56 - 2014-08-18 18:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 02:56 - 2014-08-18 18:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 02:56 - 2014-08-18 18:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 02:56 - 2014-08-18 18:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 02:56 - 2014-08-18 18:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 02:56 - 2014-08-18 18:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 02:56 - 2014-08-18 18:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 02:56 - 2014-08-18 18:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 02:56 - 2014-08-18 18:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 02:56 - 2014-08-18 18:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 02:56 - 2014-08-18 17:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 02:56 - 2014-08-18 17:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 02:56 - 2014-08-18 17:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 02:56 - 2014-08-18 17:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 02:56 - 2014-08-18 17:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 02:56 - 2014-08-18 17:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 02:56 - 2014-08-18 17:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 02:56 - 2014-08-18 17:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 02:56 - 2014-08-18 17:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 02:56 - 2014-08-18 17:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 02:56 - 2014-08-18 17:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 02:56 - 2014-08-18 17:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 02:56 - 2014-08-18 17:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 02:56 - 2014-08-18 17:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 02:56 - 2014-08-18 17:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 02:56 - 2014-08-18 17:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 02:56 - 2014-08-18 17:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 02:56 - 2014-08-18 17:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 02:56 - 2014-08-18 17:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 02:56 - 2014-08-18 17:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 02:56 - 2014-08-18 17:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 02:56 - 2014-08-18 17:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 02:56 - 2014-08-18 17:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 02:56 - 2014-08-18 17:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 02:56 - 2014-08-18 17:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 02:56 - 2014-08-18 17:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 02:56 - 2014-08-18 17:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 02:56 - 2014-08-18 17:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 02:56 - 2014-08-18 17:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 02:56 - 2014-08-18 17:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 02:56 - 2014-08-18 17:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 02:56 - 2014-08-18 17:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 02:56 - 2014-08-18 16:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 02:56 - 2014-08-18 16:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 02:56 - 2014-08-18 16:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 02:56 - 2014-08-18 16:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 02:56 - 2014-08-18 16:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 02:51 - 2014-06-26 22:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 02:51 - 2014-06-26 21:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-10 18:12 - 2014-09-04 22:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-10 18:12 - 2014-09-04 22:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-10 18:12 - 2014-08-01 07:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-10 18:12 - 2014-08-01 07:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-10 18:12 - 2014-07-06 22:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-10 18:12 - 2014-07-06 22:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-10 18:12 - 2014-07-06 21:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-10 18:12 - 2014-07-06 21:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-10 18:12 - 2014-07-06 21:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-10 18:12 - 2014-06-23 23:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-10 18:12 - 2014-06-23 22:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-07 23:36 - 2014-09-07 23:36 - 00000000 ____D () C:\Users\Tony\Downloads\The.Sims.4.Crack.v3.And.Update.1
2014-09-07 23:33 - 2014-09-07 23:33 - 00030423 _____ () C:\Users\Tony\Downloads\The Sims 4-SG.torrent
2014-09-07 18:13 - 2014-09-07 18:14 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-09-07 18:05 - 2014-09-07 18:05 - 00003116 _____ () C:\Windows\System32\Tasks\Origin
2014-09-07 14:46 - 2014-09-07 18:05 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Origin
2014-09-07 14:46 - 2014-09-07 14:53 - 00000000 ____D () C:\Users\Tony\AppData\Local\Origin
2014-09-07 14:43 - 2014-09-09 02:12 - 00000000 ____D () C:\ProgramData\Origin
2014-09-07 14:43 - 2014-09-08 21:55 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-09-07 14:43 - 2014-09-07 15:18 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-09-07 14:30 - 2014-09-07 14:30 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Tony\Downloads\OriginThinSetup.exe
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-04 21:02 - 2014-09-04 21:02 - 00000000 ____D () C:\Users\Tony\Documents\Diablo III
2014-09-04 19:46 - 2014-09-04 22:38 - 00000000 ____D () C:\Users\Tony\AppData\Local\Battle.net
2014-09-04 19:46 - 2014-09-04 19:47 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Battle.net
2014-09-04 19:46 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Blizzard Entertainment
2014-09-04 19:45 - 2014-09-04 19:46 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-09-04 19:43 - 2014-09-04 19:44 - 00000000 ____D () C:\ProgramData\Battle.net
2014-09-04 19:43 - 2014-09-04 19:43 - 02907552 _____ (Blizzard Entertainment) C:\Users\Tony\Downloads\Battle.net-Setup-enUS.exe
2014-09-04 01:54 - 2014-09-04 01:54 - 00000000 ____D () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna
2014-09-04 01:53 - 2014-09-04 01:54 - 03404214 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU114-Shaine-f.sims3pack
2014-09-04 01:48 - 2014-09-04 01:48 - 07330801 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna.zip
2014-09-04 01:45 - 2014-09-04 01:45 - 02944438 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU076-Guajira-f.sims3pack
2014-09-04 01:29 - 2014-09-04 01:29 - 00000000 ____D () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p
2014-09-04 01:28 - 2014-09-04 01:29 - 06242186 _____ () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p.rar
2014-09-04 01:26 - 2014-09-04 01:26 - 00000000 ____D () C:\Users\Tony\Downloads\FrameworkSetup
2014-09-04 01:15 - 2014-09-04 01:15 - 10283978 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340976_ESkin-nATURALTAN.7z
2014-09-04 01:15 - 2014-09-04 01:15 - 09702294 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340975_ESkin-NaturalLight.7z
2014-09-04 01:05 - 2014-09-04 01:05 - 20335134 _____ () C:\Users\Tony\Downloads\Nina Dobrev.Sims3Pack
2014-09-03 23:58 - 2014-09-03 23:58 - 00011372 _____ () C:\Users\Tony\Downloads\Gas Electric.xlsx
2014-09-02 23:49 - 2014-09-03 23:17 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Program Files (x86)\MusicBee
2014-09-02 23:48 - 2014-09-02 23:48 - 15485907 _____ () C:\Users\Tony\Downloads\MusicBeeSetup_2_4.zip
2014-09-02 00:28 - 2014-09-02 00:29 - 00000000 ____D () C:\Users\Tony\Downloads\co@08_i44_escape-chernarus-i44_v1-8.chernarus
2014-09-02 00:01 - 2014-09-02 00:24 - 00000000 ____D () C:\Users\Tony\AppData\Local\SIX Networks
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\SIX Networks
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Local\IsolatedStorage
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\ProgramData\SIX Networks
2014-09-01 23:59 - 2014-09-01 23:59 - 15018832 _____ (SIX Networks) C:\Users\Tony\Downloads\withSIX-Play.exe
2014-09-01 18:06 - 2014-09-01 18:06 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
2014-09-01 14:24 - 2014-09-01 14:24 - 00000000 ____D () C:\Users\Tony\Downloads\co08_EscapeChernarus_v180
2014-09-01 13:43 - 2014-09-02 00:35 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2 OA
2014-09-01 13:43 - 2014-09-01 13:43 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio
2014-09-01 13:41 - 2014-09-02 00:18 - 00000000 ____D () C:\Users\Tony\Documents\ArmA 2
2014-09-01 13:41 - 2014-09-01 13:43 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:10 - 2014-09-01 13:10 - 00000000 ____D () C:\Users\Tony\AppData\Local\DayZCommander
2014-09-01 13:09 - 2014-09-01 13:09 - 02932736 _____ () C:\Users\Tony\Downloads\Dotjosh.DayZCommander.Installer.msi
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\Program Files (x86)\Dotjosh Studios
2014-08-31 22:31 - 2014-07-02 13:44 - 00609240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-08-31 22:29 - 2014-07-02 16:48 - 31512520 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 24196896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 22994208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 17555104 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 15294296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 13922752 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 13835208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 12866008 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-08-31 22:29 - 2014-07-02 16:48 - 11283344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 11222048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 04247000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 03989960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 01890080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434052.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 01539928 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434052.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00944928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00907096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00903624 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00869152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00846832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00502232 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00418760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00391640 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00354016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00348120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00166568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00146480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-08-29 12:27 - 2014-09-13 14:47 - 00002896 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-08-29 01:43 - 2014-08-29 01:43 - 00000000 ____D () C:\Users\Tony\Documents\Telltale Games
2014-08-27 23:50 - 2014-08-22 22:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 23:50 - 2014-08-22 21:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 23:50 - 2014-08-22 20:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-24 17:47 - 2014-08-24 17:47 - 00000000 ____D () C:\Users\Tony\Downloads\Additional Armor Decos-411-
2014-08-24 17:44 - 2014-08-24 17:46 - 00000000 ____D () C:\Users\Tony\Downloads\ModPatcher Package for UPK edits-411-1-4
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\UPKUtils v 4_0-448-4-0
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\PatcherGUI v 4_0-448-4-0
2014-08-18 15:18 - 2014-05-14 12:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-18 15:18 - 2014-05-14 12:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-18 15:18 - 2014-05-14 12:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-18 15:18 - 2014-05-14 12:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-18 15:18 - 2014-05-14 12:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-18 15:18 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-18 15:18 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-18 15:18 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-18 15:18 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-16 02:33 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-16 02:33 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-16 02:33 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-16 02:33 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-16 02:33 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-16 02:33 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-16 02:33 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-16 02:33 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-15 13:37 - 2014-07-15 23:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-15 13:37 - 2014-07-15 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-15 13:37 - 2014-06-03 06:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-15 13:36 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-15 13:36 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-15 13:36 - 2014-06-24 22:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-15 13:36 - 2014-06-24 21:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-15 13:36 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-15 13:36 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-15 13:36 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-15 13:36 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-15 13:36 - 2014-06-03 05:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-15 13:36 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-15 13:36 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-14 23:24 - 2014-09-14 23:12 - 00000000 ____D () C:\Users\Tony\Desktop\FRST
2014-09-14 23:24 - 2014-09-14 22:55 - 00000000 ____D () C:\FRST
2014-09-14 23:22 - 2014-09-14 23:22 - 00000000 _____ () C:\ProgramData\rebootpending.txt
2014-09-14 23:21 - 2014-09-13 15:00 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-14 23:21 - 2014-04-06 15:56 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-14 23:18 - 2014-06-26 16:22 - 00000000 ____D () C:\Users\Tony\AppData\Local\LogMeIn Hamachi
2014-09-14 23:17 - 2014-04-05 19:34 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Skype
2014-09-14 23:17 - 2014-04-05 19:32 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-14 23:17 - 2009-07-14 00:51 - 00136445 _____ () C:\Windows\setupact.log
2014-09-14 23:16 - 2014-04-08 22:13 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job
2014-09-14 23:16 - 2014-04-06 14:09 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-09-14 23:16 - 2014-04-05 19:25 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-14 23:16 - 2010-11-20 23:47 - 00525152 _____ () C:\Windows\PFRO.log
2014-09-14 23:16 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-14 23:15 - 2014-04-05 06:40 - 01291821 _____ () C:\Windows\WindowsUpdate.log
2014-09-14 23:14 - 2014-09-14 23:14 - 00000151 _____ () C:\Users\Tony\Downloads\fixlist.txt
2014-09-14 23:08 - 2009-07-14 00:45 - 00028528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-14 23:08 - 2009-07-14 00:45 - 00028528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-14 23:07 - 2014-09-14 23:07 - 00033347 _____ () C:\Users\Tony\Downloads\Addition.txt
2014-09-14 22:51 - 2014-04-21 21:50 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-14 21:59 - 2014-04-05 19:32 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-14 18:21 - 2014-04-06 14:15 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\uTorrent
2014-09-13 19:40 - 2014-04-07 17:51 - 00000000 ____D () C:\ProgramData\Symantec
2014-09-13 15:00 - 2014-09-13 15:00 - 04050840 _____ (Avira Operations GmbH & Co. KG) C:\Users\Tony\Downloads\avira_en_av___dlc.exe
2014-09-13 14:47 - 2014-08-29 12:27 - 00002896 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-09-13 14:45 - 2014-07-04 13:04 - 00000000 ____D () C:\Program Files (x86)\Metro Last Light
2014-09-13 14:35 - 2014-09-13 14:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 14:34 - 2014-09-13 14:34 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 14:25 - 2014-09-13 14:01 - 00000000 ____D () C:\AdwCleaner
2014-09-13 13:49 - 2014-09-13 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iPod
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-09-12 13:49 - 2014-09-12 13:49 - 00003082 _____ () C:\Windows\System32\Tasks\{62D6B2F3-431C-4E60-8404-F847D480F7E3}
2014-09-11 18:43 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-09-11 02:55 - 2014-04-11 22:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 02:55 - 2014-04-05 07:11 - 00774592 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 02:55 - 2009-07-14 01:13 - 00774592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-11 02:52 - 2014-04-11 22:30 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-11 02:51 - 2014-05-07 22:02 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-09 17:51 - 2014-04-21 21:50 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-09 17:51 - 2014-04-06 14:04 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-09 17:51 - 2014-04-06 14:04 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-09 14:18 - 2014-04-05 20:07 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\vlc
2014-09-09 02:12 - 2014-09-07 14:43 - 00000000 ____D () C:\ProgramData\Origin
2014-09-08 22:00 - 2014-04-20 19:40 - 00000000 ____D () C:\Users\Tony\AppData\Local\CrashDumps
2014-09-08 21:55 - 2014-09-07 14:43 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-09-08 02:49 - 2014-04-05 20:07 - 00000000 ____D () C:\Program Files\PeerBlock
2014-09-07 23:36 - 2014-09-07 23:36 - 00000000 ____D () C:\Users\Tony\Downloads\The.Sims.4.Crack.v3.And.Update.1
2014-09-07 23:33 - 2014-09-07 23:33 - 00030423 _____ () C:\Users\Tony\Downloads\The Sims 4-SG.torrent
2014-09-07 19:10 - 2014-04-05 06:40 - 00000000 ____D () C:\Users\Tony
2014-09-07 18:14 - 2014-09-07 18:13 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-09-07 18:12 - 2014-05-14 16:56 - 00000000 ____D () C:\Users\Tony\Documents\Electronic Arts
2014-09-07 18:05 - 2014-09-07 18:05 - 00003116 _____ () C:\Windows\System32\Tasks\Origin
2014-09-07 18:05 - 2014-09-07 14:46 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Origin
2014-09-07 15:18 - 2014-09-07 14:43 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-09-07 14:53 - 2014-09-07 14:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Origin
2014-09-07 14:30 - 2014-09-07 14:30 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Tony\Downloads\OriginThinSetup.exe
2014-09-07 14:24 - 2014-08-09 23:52 - 00000000 ____D () C:\Program Files (x86)\Batman Arkham Origins
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-04 22:38 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Battle.net
2014-09-04 22:10 - 2014-09-10 18:12 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-04 22:05 - 2014-09-10 18:12 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-04 21:02 - 2014-09-04 21:02 - 00000000 ____D () C:\Users\Tony\Documents\Diablo III
2014-09-04 19:47 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Battle.net
2014-09-04 19:46 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Blizzard Entertainment
2014-09-04 19:46 - 2014-09-04 19:45 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-09-04 19:44 - 2014-09-04 19:43 - 00000000 ____D () C:\ProgramData\Battle.net
2014-09-04 19:43 - 2014-09-04 19:43 - 02907552 _____ (Blizzard Entertainment) C:\Users\Tony\Downloads\Battle.net-Setup-enUS.exe
2014-09-04 01:54 - 2014-09-04 01:54 - 00000000 ____D () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna
2014-09-04 01:54 - 2014-09-04 01:53 - 03404214 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU114-Shaine-f.sims3pack
2014-09-04 01:48 - 2014-09-04 01:48 - 07330801 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna.zip
2014-09-04 01:45 - 2014-09-04 01:45 - 02944438 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU076-Guajira-f.sims3pack
2014-09-04 01:29 - 2014-09-04 01:29 - 00000000 ____D () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p
2014-09-04 01:29 - 2014-09-04 01:28 - 06242186 _____ () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p.rar
2014-09-04 01:26 - 2014-09-04 01:26 - 00000000 ____D () C:\Users\Tony\Downloads\FrameworkSetup
2014-09-04 01:15 - 2014-09-04 01:15 - 10283978 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340976_ESkin-nATURALTAN.7z
2014-09-04 01:15 - 2014-09-04 01:15 - 09702294 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340975_ESkin-NaturalLight.7z
2014-09-04 01:05 - 2014-09-04 01:05 - 20335134 _____ () C:\Users\Tony\Downloads\Nina Dobrev.Sims3Pack
2014-09-03 23:58 - 2014-09-03 23:58 - 00011372 _____ () C:\Users\Tony\Downloads\Gas Electric.xlsx
2014-09-03 23:17 - 2014-09-02 23:49 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Program Files (x86)\MusicBee
2014-09-02 23:48 - 2014-09-02 23:48 - 15485907 _____ () C:\Users\Tony\Downloads\MusicBeeSetup_2_4.zip
2014-09-02 00:35 - 2014-09-01 13:43 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2 OA
2014-09-02 00:29 - 2014-09-02 00:28 - 00000000 ____D () C:\Users\Tony\Downloads\co@08_i44_escape-chernarus-i44_v1-8.chernarus
2014-09-02 00:24 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Local\SIX Networks
2014-09-02 00:18 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\Documents\ArmA 2
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\SIX Networks
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Local\IsolatedStorage
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\ProgramData\SIX Networks
2014-09-02 00:00 - 2014-07-25 18:55 - 00000000 ____D () C:\Users\Tony\AppData\Local\Downloaded Installations
2014-09-01 23:59 - 2014-09-01 23:59 - 15018832 _____ (SIX Networks) C:\Users\Tony\Downloads\withSIX-Play.exe
2014-09-01 18:06 - 2014-09-01 18:06 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
2014-09-01 14:24 - 2014-09-01 14:24 - 00000000 ____D () C:\Users\Tony\Downloads\co08_EscapeChernarus_v180
2014-09-01 13:43 - 2014-09-01 13:43 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio
2014-09-01 13:43 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:43 - 2014-04-05 19:26 - 00277923 _____ () C:\Windows\DirectX.log
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:10 - 2014-09-01 13:10 - 00000000 ____D () C:\Users\Tony\AppData\Local\DayZCommander
2014-09-01 13:09 - 2014-09-01 13:09 - 02932736 _____ () C:\Users\Tony\Downloads\Dotjosh.DayZCommander.Installer.msi
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\Program Files (x86)\Dotjosh Studios
2014-08-31 22:31 - 2014-07-04 01:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-08-31 22:31 - 2014-04-05 19:25 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-08-31 22:30 - 2014-04-05 19:24 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-08-29 01:43 - 2014-08-29 01:43 - 00000000 ____D () C:\Users\Tony\Documents\Telltale Games
2014-08-28 10:25 - 2009-07-14 00:45 - 00409576 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-24 17:47 - 2014-08-24 17:47 - 00000000 ____D () C:\Users\Tony\Downloads\Additional Armor Decos-411-
2014-08-24 17:46 - 2014-08-24 17:44 - 00000000 ____D () C:\Users\Tony\Downloads\ModPatcher Package for UPK edits-411-1-4
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\UPKUtils v 4_0-448-4-0
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\PatcherGUI v 4_0-448-4-0
2014-08-22 22:07 - 2014-08-27 23:50 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-22 21:45 - 2014-08-27 23:50 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-22 20:59 - 2014-08-27 23:50 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 15:23 - 2014-04-07 18:06 - 00000000 ____D () C:\Users\Tony\Documents\My Games
2014-08-19 14:05 - 2014-09-11 02:56 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-19 13:39 - 2014-09-11 02:56 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-18 19:01 - 2014-09-11 02:56 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-18 18:44 - 2014-04-05 07:09 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-18 18:29 - 2014-09-11 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-18 18:29 - 2014-09-11 02:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-18 18:26 - 2014-09-11 02:56 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-18 18:20 - 2014-09-11 02:56 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-18 18:19 - 2014-09-11 02:56 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-18 18:15 - 2014-09-11 02:56 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-18 18:15 - 2014-09-11 02:56 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-18 18:14 - 2014-09-11 02:56 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-18 18:14 - 2014-09-11 02:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-18 18:08 - 2014-09-11 02:56 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-18 18:08 - 2014-09-11 02:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-18 18:08 - 2014-09-11 02:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-18 18:05 - 2014-09-11 02:56 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-18 18:03 - 2014-09-11 02:56 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-18 18:03 - 2014-09-11 02:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-18 18:03 - 2014-09-11 02:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-18 17:57 - 2014-09-11 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-18 17:56 - 2014-09-11 02:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-18 17:51 - 2014-09-11 02:56 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-18 17:46 - 2014-09-11 02:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-18 17:45 - 2014-09-11 02:56 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-18 17:45 - 2014-09-11 02:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-18 17:44 - 2014-09-11 02:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-18 17:44 - 2014-09-11 02:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-18 17:42 - 2014-09-11 02:56 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-18 17:40 - 2014-09-11 02:56 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-18 17:39 - 2014-09-11 02:56 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-18 17:39 - 2014-09-11 02:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-18 17:39 - 2014-09-11 02:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-18 17:38 - 2014-09-11 02:56 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-18 17:37 - 2014-09-11 02:56 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-18 17:36 - 2014-09-11 02:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-18 17:35 - 2014-09-11 02:56 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-18 17:27 - 2014-09-11 02:56 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-18 17:25 - 2014-09-11 02:56 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-18 17:25 - 2014-09-11 02:56 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-18 17:23 - 2014-09-11 02:56 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-18 17:23 - 2014-09-11 02:56 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-18 17:22 - 2014-09-11 02:56 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-18 17:19 - 2014-09-11 02:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-18 17:17 - 2014-09-11 02:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-18 17:17 - 2014-09-11 02:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-18 17:16 - 2014-09-11 02:56 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-18 17:15 - 2014-09-11 02:56 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-18 17:15 - 2014-09-11 02:56 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-18 17:13 - 2009-07-14 01:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-18 17:09 - 2014-09-11 02:56 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-18 17:08 - 2014-09-11 02:56 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-18 17:07 - 2014-09-11 02:56 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-18 16:55 - 2014-09-11 02:56 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-18 16:46 - 2014-09-11 02:56 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-18 16:38 - 2014-09-11 02:56 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-18 16:38 - 2014-09-11 02:56 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-18 16:36 - 2014-09-11 02:56 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-18 15:51 - 2014-04-05 19:34 - 00000000 ____D () C:\ProgramData\Skype
2014-08-16 14:06 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
 
Files to move or delete:
====================
C:\Users\Tony\AppData\Roaming\Origin\update.vbe
 
 
Some content of TEMP:
====================
C:\Users\Tony\AppData\Local\Temp\avgnt.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-09-06 15:51
 
==================== End Of Log ============================


BC AdBot (Login to Remove)

 


#2 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:15 PM

Posted 15 September 2014 - 07:01 AM

Hi there,

please do this:


Step 1

Please download this attached Attached File  fixlist.txt   199bytes   7 downloads and save it in the same directory as FRST.
  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.


Step 2

Please download the ESET Online Scanner and save it to your Desktop.
  • Disable the realtime-protection of your antivirus and anti-malware programs because they might interfere with the scan.
  • Start esetsmartinstaller_enu.exe with administartor privileges.
  • Select the option Yes, I accept the Terms of Use and click on Start.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click on Start. The virus signature database will begin to download. This may take some time.
  • When completed the Online Scan will begin automatically.
    Note: This scan might take a long time! Please be patient.
  • When completed select Uninstall application on close if you so wish, but make sure you copy the logfile first!
  • Now click on Finish
  • A log file is created at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
    Copy and paste the content of this log file in your next reply.
Note: Do not forget to re-enable your antivirus application after running the above scan!

#3 tngvu

tngvu
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:15 PM

Posted 17 September 2014 - 10:22 AM

I've followed the steps, but the malware still appears whenever I startup my computer. I'm assuming this is from the Sims 4 torrent, which I've seen multiple people posted about on the forums. I've uninstalled the game prior to my original post. Here's the fixlog.txt:

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014
Ran by Tony at 2014-09-16 12:16:32 Run:3
Running from C:\Users\Tony\Desktop\FRST
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [CMD] => cmd.exe /c start http://extendedunlimited.org && exit <===== ATTENTION
C:\Users\Tony\AppData\Roaming\Origin\update.vbe
EmptyTemp:
*****************
 
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CMD => Value not found.
C:\Users\Tony\AppData\Roaming\Origin\update.vbe => Moved successfully.
EmptyTemp: => Removed 93.7 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====
 
Here's the log.txt:
 
 
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=534649d74a2c6940816a80d8a1ba7fdf
# engine=20181
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-09-16 09:42:27
# local_time=2014-09-16 05:42:27 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Symantec Endpoint Protection'
# compatibility_mode=3601 16777213 100 98 9724781 58040377 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776638 100 94 13431503 162447197 0 0
# scanned=443075
# found=26
# cleaned=0
# scan_time=18910
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\$WINDOWS.~BT\Sources\$oem$\$$\Setup\scripts\Windows Loader.exe"
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\$WINDOWS.~LS\Sources\$OEM$\$$\Setup\scripts\Windows Loader.exe"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\Users\Tony\Downloads\W7\Windows 7 SP1 PreActivated x86 x64 MultiBrand MultiEdition.iso"
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\Users\Tony\Downloads\W7\sourc64\$oem$\$$\Setup\scripts\Windows Loader.exe"
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\Users\Tony\Downloads\W7\sources\$oem$\$$\Setup\scripts\Windows Loader.exe"
sh=1021FF98CBA14A9A25A06E3D05127ED732766B78 ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AD trojan" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Roaming\Origin\update.vbe"
sh=1021FF98CBA14A9A25A06E3D05127ED732766B78 ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AD trojan" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Origin\update.vbe"
sh=0B4F6F14D734A816812C3E868EEBCD2F36BC13A5 ft=1 fh=e167acc115fc22fa vn="Win32/OpenCandy potentially unsafe application" ac=I fn="E:\Tony's Stuff\Old Windows\Users\TONY\APB_Reloaded_Installer.exe"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="E:\Tony's Stuff\Old Windows\Users\TONY\AppData\Local\Temp\Rar$DI78.176\Windows 7 SP1 PreActivated x86 x64 MultiBrand MultiEdition.iso"
sh=195F9BB7D46147E9BFD671500AF25E79875EE935 ft=1 fh=0b9331985462bb24 vn="Win32/OpenCandy potentially unsafe application" ac=I fn="E:\Tony's Stuff\Old Windows\Users\TONY\Downloads\DTLite4451-0236.exe"
sh=668D4DFF9647B116D0D6594909E879B8CDB400CA ft=1 fh=b173e88e8f9c4255 vn="a variant of Win32/InstallIQ.A potentially unwanted application" ac=I fn="E:\Tony's Stuff\Old Windows\Users\TONY\Downloads\FinalMediaPlayer2011Setup.exe"
sh=D70AFC85E9C6FE89C6B26856D2BAF5935390FF73 ft=1 fh=b0cf78ee6c2e5aca vn="a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application" ac=I fn="E:\Tony's Stuff\Old Windows\Users\TONY\Downloads\iLividSetupV1.exe"
sh=9B8DB062579C184EAFA1CD2178CFCBC8A14E863E ft=1 fh=47e1c385d0cc1961 vn="Win32/SoftonicDownloader.A potentially unwanted application" ac=I fn="E:\Tony's Stuff\Old Windows\Users\TONY\Downloads\SoftonicDownloader_for_directx.exe"
sh=334EF642A3903045A9E31DB70E10D3F159E91873 ft=1 fh=0be5cd77ff1989b9 vn="a variant of Win32/InstallIQ.A potentially unwanted application" ac=I fn="E:\Tony's Stuff\Old Windows\Users\TONY\Downloads\VLC_968.exe"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/HackTool.Crack.BL potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\Batman.Arkham.Origins-RELOADED\rld-baaror.iso"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/HackTool.Crack.BL potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\Call.of.Duty.Ghosts-RELOADED\rld-caofdugh.iso"
sh=C28C0CEF6F1C3A1CE673B0F4CDD73DDD5474604A ft=0 fh=0000000000000000 vn="a variant of Win32/GameHack.F potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\Mass Effect 1 - ViTALiTY 2008 + DLC's All Info-Fixes-Extras\Z-Cheats-Walkthrough-Trouble Shooting-Extras\Mass Effect Trainer +12\Mass Effect Trainer +12.rar"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/HackTool.Crack.BQ potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\Metro.Last.Light-RELOADED\rld-mtll.iso"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/HackTool.Crack.BB potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\NBA.2K14-RELOADED\rld-nba2k14.iso"
sh=144AD18DA0C3EADBEB1495FDEA01A37FCEF59CEF ft=1 fh=69fe12774fa2e3ab vn="a variant of Win32/HackTool.Crack.BQ potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\Saints.Row.IV.CRACK.ONLY-RELOADED\Crack\steam_api.dll"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Keygen.GU potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\Sims 3\The Sims 3 - Razor1911 Final MAXSPEED\The Sims 3 - Razor1911 MAXSPEED www.torentz.3xforum.ro\The Sims 3 - Razor1911 MAXSPEED www.torentz.3xforum.ro.iso"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\sr-tfoc\sr-tfoc.iso"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/HackTool.Crack.BL potentially unsafe application" ac=I fn="E:\Tony's Stuff\Tony's Stuff\A\The.Amazing.Spider-Man.2.Proper-RELOADED\rld-thamsp2.iso"
sh=60AE1097839BCBEA2CEEEEB9F7D3E933E97863EC ft=0 fh=0000000000000000 vn="a variant of Win32/InstallIQ.A potentially unwanted application" ac=I fn="E:\Tony's Stuff\TONY-PC\Backup Set 2012-01-07 153006\Backup Files 2012-01-07 153006\Backup files 106.zip"
sh=B60AE63248729F5D955988A1A1BDD1EF8A86B2D6 ft=0 fh=0000000000000000 vn="Win32/OpenCandy potentially unsafe application" ac=I fn="E:\Tony's Stuff\TONY-PC\Backup Set 2012-01-07 153006\Backup Files 2012-01-07 153006\Backup files 534.zip"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="E:\Tony's Stuff\W7\Windows 7 SP1 PreActivated x86 x64 MultiBrand MultiEdition.iso"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=534649d74a2c6940816a80d8a1ba7fdf
# engine=20190
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-09-17 05:23:43
# local_time=2014-09-17 01:23:43 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Symantec Endpoint Protection'
# compatibility_mode=3601 16777213 100 98 9752457 58068053 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776638 100 94 13459179 162474873 0 0
# scanned=199703
# found=7
# cleaned=0
# scan_time=3771
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\$WINDOWS.~BT\Sources\$oem$\$$\Setup\scripts\Windows Loader.exe"
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\$WINDOWS.~LS\Sources\$OEM$\$$\Setup\scripts\Windows Loader.exe"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\Users\Tony\Downloads\W7\Windows 7 SP1 PreActivated x86 x64 MultiBrand MultiEdition.iso"
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\Users\Tony\Downloads\W7\sourc64\$oem$\$$\Setup\scripts\Windows Loader.exe"
sh=B926AA02DCC1005A22EE87E000C788164F28EE2B ft=1 fh=7572d94ee25a7b2c vn="Win32/HackTool.WinActivator.I potentially unsafe application" ac=I fn="C:\Users\Tony\Downloads\W7\sources\$oem$\$$\Setup\scripts\Windows Loader.exe"
sh=1021FF98CBA14A9A25A06E3D05127ED732766B78 ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AD trojan" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Roaming\Origin\update.vbe"
sh=1021FF98CBA14A9A25A06E3D05127ED732766B78 ft=0 fh=0000000000000000 vn="VBS/CoinMiner.AD trojan" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Origin\update.vbe"
 

 



#4 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:15 PM

Posted 17 September 2014 - 01:39 PM

Start FRST with administator privileges.
  • Press the Scan button.
  • When finished, FRST will produce a log (FRST.txt) in the same directory the tool was run from.
    Please copy and paste this log in your next reply.


#5 tngvu

tngvu
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:15 PM

Posted 17 September 2014 - 02:52 PM

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Tony (administrator) on TONY-PC on 17-09-2014 15:51:07
Running from C:\Users\Tony\Desktop\FRST
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\Smc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTsysTray8.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
() C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
() C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
(Razer Inc.) C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506136 2013-12-06] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403288 2014-08-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-25] (Intel Corporation)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [1047536 2013-11-12] (MSI)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [DeathAdder] => C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe [311296 2009-12-15] ()
HKU\.DEFAULT\...\Run: [Bitdefender Wallet Agent] => "C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe"
HKU\.DEFAULT\...\Run: [Bitdefender Wallet] => "C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe" --hidden --nowizard
HKU\.DEFAULT\...\Run: [Bitdefender Wallet Application Agent] => "C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe"
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1939136 2014-08-28] (Valve Corporation)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2014-06-05] (TomTom)
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [CMD] => cmd.exe /c start http://extendedunlimited.org && exit <===== ATTENTION
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\MountPoints2: F - F:\setup.exe
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\MountPoints2: G - G:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{A003678C-C125-49A0-90D0-99AE485F6F92}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RCRN_Autoupdater.exe.lnk
ShortcutTarget: RCRN_Autoupdater.exe.lnk -> C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\RCRN\Autoupdater\RCRN_Autoupdater.exe (Damiano La Maida)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x641BE5812651CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Symantec Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\bin\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 4.2.2.1
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\IPSFF
FF Extension: Symantec Vulnerability Protection - C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\IPSFF [2014-04-07]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-04-18]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR DefaultSearchKeyword: Default -> B68510555A207E5346066EA590FE8B2879E05AFB06618820F6EE2A5249BE32F7
CHR DefaultSearchURL: Default -> 0A3FD8A142D5BC82F0DAAADF2B1D942A9DE42CF7E5FAD788D65DE4E3D12015F2
CHR Profile: C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-05]
CHR Extension: (Google Drive) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-05]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-22]
CHR Extension: (YouTube) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-05]
CHR Extension: (Slinky Elegant) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2014-04-05]
CHR Extension: (Google Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-05]
CHR Extension: (AdBlock) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-05]
CHR Extension: (Google Wallet) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-05]
CHR Extension: (Gmail) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-05]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2014-09-01] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-01] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-08-08] (LogMeIn, Inc.)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161776 2013-09-09] (MSI)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720792 2014-08-08] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18973144 2014-08-08] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed]
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-09-11] (Qualcomm Atheros) [File not signed]
R2 SepMasterService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin\ccSvcHst.exe [143928 2012-11-03] (Symantec Corporation)
R3 SmcService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\Smc.exe [2294112 2012-11-03] (Symantec Corporation)
S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\snac64.exe [334288 2012-11-03] (Symantec Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.)
R1 BHDrvx64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\BASHDefs\20140913.012\BHDrvx64.sys [1530160 2014-05-09] (Symantec Corporation)
R1 ccSettings_{3771A34D-2132-48EA-A486-D62ECDF9D553}; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\ccSetx64.sys [168096 2012-11-03] (Symantec Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-05-14] (Disc Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-09] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-09-09] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\IPSDefs\20140915.011\IDSvia64.sys [525016 2014-05-12] (Symantec Corporation)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-08-01] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-08-01] ()
R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-01] ()
S3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [20464 2013-11-11] (Windows ® Win 7 DDK provider)
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-08-01] ()
R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 NAVENG; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20140916.006\ENG64.SYS [129752 2014-08-21] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Data\Definitions\VirusDefs\20140916.006\EX64.SYS [2137304 2014-08-21] (Symantec Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20440 2014-08-08] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R1 SRTSP; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SRTSP64.SYS [776352 2012-11-03] (Symantec Corporation)
R1 SRTSPX; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SRTSPX64.SYS [37496 2012-11-03] (Symantec Corporation)
S3 SyDvCtrl; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.2015.2015.105\Bin64\SyDvCtrl64.sys [34352 2012-11-03] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SYMDS64.SYS [493216 2012-11-03] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SYMEFA64.SYS [1133216 2012-11-03] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-04-07] (Symantec Corporation)
R1 SymIRON; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\Ironx64.SYS [224416 2012-11-03] (Symantec Corporation)
R1 SYMNETS; C:\Windows\System32\Drivers\SEP\0C0107DF\07DF.105\x64\SYMNETS.SYS [432800 2012-11-03] (Symantec Corporation)
R1 SysPlant; C:\Windows\System32\Drivers\SysPlant.sys [154904 2014-04-07] (Symantec Corporation)
R1 Teefer2; C:\Windows\System32\DRIVERS\Teefer.sys [95616 2012-11-03] (Symantec Corporation)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-16 12:47 - 2014-09-16 13:02 - 00000000 ____D () C:\Users\Tony\Documents\Outlook Files
2014-09-16 12:23 - 2014-09-16 12:23 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-09-16 12:22 - 2014-09-16 12:22 - 02347384 _____ (ESET) C:\Users\Tony\Desktop\esetsmartinstaller_enu.exe
2014-09-14 23:34 - 2014-09-14 23:44 - 00000000 ____D () C:\Windows\pss
2014-09-14 23:12 - 2014-09-17 15:51 - 00000000 ____D () C:\Users\Tony\Desktop\FRST
2014-09-14 23:07 - 2014-09-14 23:07 - 00033347 _____ () C:\Users\Tony\Downloads\Addition.txt
2014-09-14 22:55 - 2014-09-17 15:51 - 00000000 ____D () C:\FRST
2014-09-13 15:00 - 2014-09-13 15:00 - 04050840 _____ (Avira Operations GmbH & Co. KG) C:\Users\Tony\Downloads\avira_en_av___dlc.exe
2014-09-13 14:35 - 2014-09-13 14:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 14:34 - 2014-09-13 14:34 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 14:02 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-13 14:01 - 2014-09-13 14:25 - 00000000 ____D () C:\AdwCleaner
2014-09-13 13:49 - 2014-09-13 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iPod
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-09-12 13:49 - 2014-09-12 13:49 - 00003082 _____ () C:\Windows\System32\Tasks\{62D6B2F3-431C-4E60-8404-F847D480F7E3}
2014-09-11 02:56 - 2014-08-19 14:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 02:56 - 2014-08-19 13:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 02:56 - 2014-08-18 19:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 02:56 - 2014-08-18 18:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 02:56 - 2014-08-18 18:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 02:56 - 2014-08-18 18:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 02:56 - 2014-08-18 18:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 02:56 - 2014-08-18 18:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 02:56 - 2014-08-18 18:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 02:56 - 2014-08-18 18:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 02:56 - 2014-08-18 18:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 02:56 - 2014-08-18 18:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 02:56 - 2014-08-18 18:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 02:56 - 2014-08-18 18:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 02:56 - 2014-08-18 18:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 02:56 - 2014-08-18 18:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 02:56 - 2014-08-18 18:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 02:56 - 2014-08-18 18:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 02:56 - 2014-08-18 18:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 02:56 - 2014-08-18 17:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 02:56 - 2014-08-18 17:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 02:56 - 2014-08-18 17:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 02:56 - 2014-08-18 17:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 02:56 - 2014-08-18 17:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 02:56 - 2014-08-18 17:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 02:56 - 2014-08-18 17:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 02:56 - 2014-08-18 17:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 02:56 - 2014-08-18 17:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 02:56 - 2014-08-18 17:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 02:56 - 2014-08-18 17:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 02:56 - 2014-08-18 17:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 02:56 - 2014-08-18 17:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 02:56 - 2014-08-18 17:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 02:56 - 2014-08-18 17:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 02:56 - 2014-08-18 17:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 02:56 - 2014-08-18 17:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 02:56 - 2014-08-18 17:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 02:56 - 2014-08-18 17:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 02:56 - 2014-08-18 17:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 02:56 - 2014-08-18 17:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 02:56 - 2014-08-18 17:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 02:56 - 2014-08-18 17:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 02:56 - 2014-08-18 17:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 02:56 - 2014-08-18 17:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 02:56 - 2014-08-18 17:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 02:56 - 2014-08-18 17:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 02:56 - 2014-08-18 17:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 02:56 - 2014-08-18 17:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 02:56 - 2014-08-18 17:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 02:56 - 2014-08-18 17:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 02:56 - 2014-08-18 17:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 02:56 - 2014-08-18 16:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 02:56 - 2014-08-18 16:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 02:56 - 2014-08-18 16:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 02:56 - 2014-08-18 16:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 02:56 - 2014-08-18 16:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 02:51 - 2014-06-26 22:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 02:51 - 2014-06-26 21:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-10 18:12 - 2014-09-04 22:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-10 18:12 - 2014-09-04 22:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-10 18:12 - 2014-08-01 07:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-10 18:12 - 2014-08-01 07:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-10 18:12 - 2014-07-06 22:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-10 18:12 - 2014-07-06 22:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-10 18:12 - 2014-07-06 21:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-10 18:12 - 2014-07-06 21:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-10 18:12 - 2014-07-06 21:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-10 18:12 - 2014-06-23 23:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-10 18:12 - 2014-06-23 22:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-07 23:36 - 2014-09-07 23:36 - 00000000 ____D () C:\Users\Tony\Downloads\The.Sims.4.Crack.v3.And.Update.1
2014-09-07 23:33 - 2014-09-07 23:33 - 00030423 _____ () C:\Users\Tony\Downloads\The Sims 4-SG.torrent
2014-09-07 18:13 - 2014-09-07 18:14 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-09-07 18:05 - 2014-09-07 18:05 - 00003116 _____ () C:\Windows\System32\Tasks\Origin
2014-09-07 14:46 - 2014-09-16 12:16 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Origin
2014-09-07 14:46 - 2014-09-07 14:53 - 00000000 ____D () C:\Users\Tony\AppData\Local\Origin
2014-09-07 14:43 - 2014-09-09 02:12 - 00000000 ____D () C:\ProgramData\Origin
2014-09-07 14:43 - 2014-09-08 21:55 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-09-07 14:43 - 2014-09-07 15:18 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-09-07 14:30 - 2014-09-07 14:30 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Tony\Downloads\OriginThinSetup.exe
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-04 21:02 - 2014-09-04 21:02 - 00000000 ____D () C:\Users\Tony\Documents\Diablo III
2014-09-04 19:46 - 2014-09-04 22:38 - 00000000 ____D () C:\Users\Tony\AppData\Local\Battle.net
2014-09-04 19:46 - 2014-09-04 19:47 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Battle.net
2014-09-04 19:46 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Blizzard Entertainment
2014-09-04 19:45 - 2014-09-04 19:46 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-09-04 19:43 - 2014-09-04 19:44 - 00000000 ____D () C:\ProgramData\Battle.net
2014-09-04 19:43 - 2014-09-04 19:43 - 02907552 _____ (Blizzard Entertainment) C:\Users\Tony\Downloads\Battle.net-Setup-enUS.exe
2014-09-04 01:54 - 2014-09-04 01:54 - 00000000 ____D () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna
2014-09-04 01:53 - 2014-09-04 01:54 - 03404214 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU114-Shaine-f.sims3pack
2014-09-04 01:48 - 2014-09-04 01:48 - 07330801 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna.zip
2014-09-04 01:45 - 2014-09-04 01:45 - 02944438 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU076-Guajira-f.sims3pack
2014-09-04 01:29 - 2014-09-04 01:29 - 00000000 ____D () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p
2014-09-04 01:28 - 2014-09-04 01:29 - 06242186 _____ () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p.rar
2014-09-04 01:26 - 2014-09-04 01:26 - 00000000 ____D () C:\Users\Tony\Downloads\FrameworkSetup
2014-09-04 01:15 - 2014-09-04 01:15 - 10283978 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340976_ESkin-nATURALTAN.7z
2014-09-04 01:15 - 2014-09-04 01:15 - 09702294 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340975_ESkin-NaturalLight.7z
2014-09-04 01:05 - 2014-09-04 01:05 - 20335134 _____ () C:\Users\Tony\Downloads\Nina Dobrev.Sims3Pack
2014-09-03 23:58 - 2014-09-03 23:58 - 00011372 _____ () C:\Users\Tony\Downloads\Gas Electric.xlsx
2014-09-02 23:49 - 2014-09-03 23:17 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Program Files (x86)\MusicBee
2014-09-02 23:48 - 2014-09-02 23:48 - 15485907 _____ () C:\Users\Tony\Downloads\MusicBeeSetup_2_4.zip
2014-09-02 00:28 - 2014-09-02 00:29 - 00000000 ____D () C:\Users\Tony\Downloads\co@08_i44_escape-chernarus-i44_v1-8.chernarus
2014-09-02 00:01 - 2014-09-02 00:24 - 00000000 ____D () C:\Users\Tony\AppData\Local\SIX Networks
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\SIX Networks
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Local\IsolatedStorage
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\ProgramData\SIX Networks
2014-09-01 23:59 - 2014-09-01 23:59 - 15018832 _____ (SIX Networks) C:\Users\Tony\Downloads\withSIX-Play.exe
2014-09-01 18:06 - 2014-09-01 18:06 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
2014-09-01 14:24 - 2014-09-01 14:24 - 00000000 ____D () C:\Users\Tony\Downloads\co08_EscapeChernarus_v180
2014-09-01 13:43 - 2014-09-02 00:35 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2 OA
2014-09-01 13:43 - 2014-09-01 13:43 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio
2014-09-01 13:41 - 2014-09-02 00:18 - 00000000 ____D () C:\Users\Tony\Documents\ArmA 2
2014-09-01 13:41 - 2014-09-01 13:43 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:10 - 2014-09-01 13:10 - 00000000 ____D () C:\Users\Tony\AppData\Local\DayZCommander
2014-09-01 13:09 - 2014-09-01 13:09 - 02932736 _____ () C:\Users\Tony\Downloads\Dotjosh.DayZCommander.Installer.msi
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\Program Files (x86)\Dotjosh Studios
2014-08-31 22:31 - 2014-07-02 13:44 - 00609240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-08-31 22:29 - 2014-07-02 16:48 - 31512520 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 24196896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 22994208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 17555104 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 15294296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 13922752 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 13835208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 12866008 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-08-31 22:29 - 2014-07-02 16:48 - 11283344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 11222048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 04247000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 03989960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 01890080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434052.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 01539928 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434052.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00944928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00907096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00903624 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00869152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00846832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00502232 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00418760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00391640 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00354016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00348120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00166568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-08-31 22:29 - 2014-07-02 16:48 - 00146480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-08-29 12:27 - 2014-09-13 14:47 - 00002896 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-08-29 01:43 - 2014-08-29 01:43 - 00000000 ____D () C:\Users\Tony\Documents\Telltale Games
2014-08-27 23:50 - 2014-08-22 22:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 23:50 - 2014-08-22 21:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 23:50 - 2014-08-22 20:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-24 17:47 - 2014-08-24 17:47 - 00000000 ____D () C:\Users\Tony\Downloads\Additional Armor Decos-411-
2014-08-24 17:44 - 2014-08-24 17:46 - 00000000 ____D () C:\Users\Tony\Downloads\ModPatcher Package for UPK edits-411-1-4
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\UPKUtils v 4_0-448-4-0
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\PatcherGUI v 4_0-448-4-0
2014-08-18 15:18 - 2014-05-14 12:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-18 15:18 - 2014-05-14 12:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-18 15:18 - 2014-05-14 12:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-18 15:18 - 2014-05-14 12:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-18 15:18 - 2014-05-14 12:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-18 15:18 - 2014-05-14 12:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-18 15:18 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-18 15:18 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-18 15:18 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-18 15:18 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-17 15:51 - 2014-09-14 23:12 - 00000000 ____D () C:\Users\Tony\Desktop\FRST
2014-09-17 15:51 - 2014-09-14 22:55 - 00000000 ____D () C:\FRST
2014-09-17 15:51 - 2014-04-21 21:50 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-17 15:45 - 2014-04-05 19:34 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Skype
2014-09-17 14:59 - 2014-04-05 19:32 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-17 14:47 - 2014-04-08 22:13 - 00000266 _____ () C:\Windows\Tasks\AutoKMS.job
2014-09-17 09:59 - 2014-04-05 19:32 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-17 09:46 - 2009-07-14 00:45 - 00028528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-17 09:46 - 2009-07-14 00:45 - 00028528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-17 09:41 - 2014-04-05 06:40 - 01433473 _____ () C:\Windows\WindowsUpdate.log
2014-09-16 20:06 - 2014-04-07 17:51 - 00000000 ____D () C:\ProgramData\Symantec
2014-09-16 18:33 - 2014-04-06 14:09 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-09-16 18:31 - 2014-06-26 16:22 - 00000000 ____D () C:\Users\Tony\AppData\Local\LogMeIn Hamachi
2014-09-16 18:29 - 2014-04-05 19:25 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-16 18:29 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-16 18:29 - 2009-07-14 00:51 - 00143871 _____ () C:\Windows\setupact.log
2014-09-16 18:28 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-16 15:17 - 2014-04-05 20:07 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\vlc
2014-09-16 13:02 - 2014-09-16 12:47 - 00000000 ____D () C:\Users\Tony\Documents\Outlook Files
2014-09-16 12:23 - 2014-09-16 12:23 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-09-16 12:22 - 2014-09-16 12:22 - 02347384 _____ (ESET) C:\Users\Tony\Desktop\esetsmartinstaller_enu.exe
2014-09-16 12:18 - 2010-11-20 23:47 - 00550258 _____ () C:\Windows\PFRO.log
2014-09-16 12:16 - 2014-09-07 14:46 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Origin
2014-09-14 23:44 - 2014-09-14 23:34 - 00000000 ____D () C:\Windows\pss
2014-09-14 23:21 - 2014-04-06 15:56 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-14 23:07 - 2014-09-14 23:07 - 00033347 _____ () C:\Users\Tony\Downloads\Addition.txt
2014-09-14 18:21 - 2014-04-06 14:15 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\uTorrent
2014-09-13 15:00 - 2014-09-13 15:00 - 04050840 _____ (Avira Operations GmbH & Co. KG) C:\Users\Tony\Downloads\avira_en_av___dlc.exe
2014-09-13 14:47 - 2014-08-29 12:27 - 00002896 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-09-13 14:45 - 2014-07-04 13:04 - 00000000 ____D () C:\Program Files (x86)\Metro Last Light
2014-09-13 14:35 - 2014-09-13 14:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 14:34 - 2014-09-13 14:34 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Tony\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 14:25 - 2014-09-13 14:01 - 00000000 ____D () C:\AdwCleaner
2014-09-13 13:49 - 2014-09-13 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iTunes
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files\iPod
2014-09-13 13:48 - 2014-09-13 13:48 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-09-12 13:49 - 2014-09-12 13:49 - 00003082 _____ () C:\Windows\System32\Tasks\{62D6B2F3-431C-4E60-8404-F847D480F7E3}
2014-09-11 18:43 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-09-11 02:55 - 2014-04-11 22:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 02:55 - 2014-04-05 07:11 - 00774592 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 02:55 - 2009-07-14 01:13 - 00774592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-11 02:52 - 2014-04-11 22:30 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-11 02:51 - 2014-05-07 22:02 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-09 17:51 - 2014-04-21 21:50 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-09 17:51 - 2014-04-06 14:04 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-09 17:51 - 2014-04-06 14:04 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-09 02:12 - 2014-09-07 14:43 - 00000000 ____D () C:\ProgramData\Origin
2014-09-08 22:00 - 2014-04-20 19:40 - 00000000 ____D () C:\Users\Tony\AppData\Local\CrashDumps
2014-09-08 21:55 - 2014-09-07 14:43 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-09-08 02:49 - 2014-04-05 20:07 - 00000000 ____D () C:\Program Files\PeerBlock
2014-09-07 23:36 - 2014-09-07 23:36 - 00000000 ____D () C:\Users\Tony\Downloads\The.Sims.4.Crack.v3.And.Update.1
2014-09-07 23:33 - 2014-09-07 23:33 - 00030423 _____ () C:\Users\Tony\Downloads\The Sims 4-SG.torrent
2014-09-07 19:10 - 2014-04-05 06:40 - 00000000 ____D () C:\Users\Tony
2014-09-07 18:14 - 2014-09-07 18:13 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-09-07 18:12 - 2014-05-14 16:56 - 00000000 ____D () C:\Users\Tony\Documents\Electronic Arts
2014-09-07 18:05 - 2014-09-07 18:05 - 00003116 _____ () C:\Windows\System32\Tasks\Origin
2014-09-07 15:18 - 2014-09-07 14:43 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-09-07 14:53 - 2014-09-07 14:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Origin
2014-09-07 14:30 - 2014-09-07 14:30 - 17088592 _____ (Electronic Arts, Inc.) C:\Users\Tony\Downloads\OriginThinSetup.exe
2014-09-07 14:24 - 2014-08-09 23:52 - 00000000 ____D () C:\Program Files (x86)\Batman Arkham Origins
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-06 13:52 - 2014-09-06 13:52 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-09-04 22:38 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Battle.net
2014-09-04 22:10 - 2014-09-10 18:12 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-04 22:05 - 2014-09-10 18:12 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-04 21:02 - 2014-09-04 21:02 - 00000000 ____D () C:\Users\Tony\Documents\Diablo III
2014-09-04 19:47 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Battle.net
2014-09-04 19:46 - 2014-09-04 19:46 - 00000000 ____D () C:\Users\Tony\AppData\Local\Blizzard Entertainment
2014-09-04 19:46 - 2014-09-04 19:45 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-09-04 19:44 - 2014-09-04 19:43 - 00000000 ____D () C:\ProgramData\Battle.net
2014-09-04 19:43 - 2014-09-04 19:43 - 02907552 _____ (Blizzard Entertainment) C:\Users\Tony\Downloads\Battle.net-Setup-enUS.exe
2014-09-04 01:54 - 2014-09-04 01:54 - 00000000 ____D () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna
2014-09-04 01:54 - 2014-09-04 01:53 - 03404214 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU114-Shaine-f.sims3pack
2014-09-04 01:48 - 2014-09-04 01:48 - 07330801 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU153-Hanna.zip
2014-09-04 01:45 - 2014-09-04 01:45 - 02944438 _____ () C:\Users\Tony\Downloads\NewSea-SIMS3-hair-YU076-Guajira-f.sims3pack
2014-09-04 01:29 - 2014-09-04 01:29 - 00000000 ____D () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p
2014-09-04 01:29 - 2014-09-04 01:28 - 06242186 _____ () C:\Users\Tony\Downloads\coolsims_s3fhair103_s3p.rar
2014-09-04 01:26 - 2014-09-04 01:26 - 00000000 ____D () C:\Users\Tony\Downloads\FrameworkSetup
2014-09-04 01:15 - 2014-09-04 01:15 - 10283978 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340976_ESkin-nATURALTAN.7z
2014-09-04 01:15 - 2014-09-04 01:15 - 09702294 _____ () C:\Users\Tony\Downloads\MTS_teru_k_1340975_ESkin-NaturalLight.7z
2014-09-04 01:05 - 2014-09-04 01:05 - 20335134 _____ () C:\Users\Tony\Downloads\Nina Dobrev.Sims3Pack
2014-09-03 23:58 - 2014-09-03 23:58 - 00011372 _____ () C:\Users\Tony\Downloads\Gas Electric.xlsx
2014-09-03 23:17 - 2014-09-02 23:49 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicBee
2014-09-02 23:49 - 2014-09-02 23:49 - 00000000 ____D () C:\Program Files (x86)\MusicBee
2014-09-02 23:48 - 2014-09-02 23:48 - 15485907 _____ () C:\Users\Tony\Downloads\MusicBeeSetup_2_4.zip
2014-09-02 00:35 - 2014-09-01 13:43 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2 OA
2014-09-02 00:29 - 2014-09-02 00:28 - 00000000 ____D () C:\Users\Tony\Downloads\co@08_i44_escape-chernarus-i44_v1-8.chernarus
2014-09-02 00:24 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Local\SIX Networks
2014-09-02 00:18 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\Documents\ArmA 2
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\SIX Networks
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\Users\Tony\AppData\Local\IsolatedStorage
2014-09-02 00:01 - 2014-09-02 00:01 - 00000000 ____D () C:\ProgramData\SIX Networks
2014-09-02 00:00 - 2014-07-25 18:55 - 00000000 ____D () C:\Users\Tony\AppData\Local\Downloaded Installations
2014-09-01 23:59 - 2014-09-01 23:59 - 15018832 _____ (SIX Networks) C:\Users\Tony\Downloads\withSIX-Play.exe
2014-09-01 18:06 - 2014-09-01 18:06 - 00000000 ____D () C:\Users\Tony\AppData\Local\Adobe
2014-09-01 14:24 - 2014-09-01 14:24 - 00000000 ____D () C:\Users\Tony\Downloads\co08_EscapeChernarus_v180
2014-09-01 13:43 - 2014-09-01 13:43 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio
2014-09-01 13:43 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:43 - 2014-04-05 19:26 - 00277923 _____ () C:\Windows\DirectX.log
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\Users\Tony\AppData\Local\ArmA 2
2014-09-01 13:41 - 2014-09-01 13:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
2014-09-01 13:10 - 2014-09-01 13:10 - 00000000 ____D () C:\Users\Tony\AppData\Local\DayZCommander
2014-09-01 13:09 - 2014-09-01 13:09 - 02932736 _____ () C:\Users\Tony\Downloads\Dotjosh.DayZCommander.Installer.msi
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios
2014-09-01 13:09 - 2014-09-01 13:09 - 00000000 ____D () C:\Program Files (x86)\Dotjosh Studios
2014-08-31 22:31 - 2014-07-04 01:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-08-31 22:31 - 2014-04-05 19:25 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-08-31 22:30 - 2014-04-05 19:24 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-08-29 01:43 - 2014-08-29 01:43 - 00000000 ____D () C:\Users\Tony\Documents\Telltale Games
2014-08-28 10:25 - 2009-07-14 00:45 - 00409576 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-24 17:47 - 2014-08-24 17:47 - 00000000 ____D () C:\Users\Tony\Downloads\Additional Armor Decos-411-
2014-08-24 17:46 - 2014-08-24 17:44 - 00000000 ____D () C:\Users\Tony\Downloads\ModPatcher Package for UPK edits-411-1-4
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\UPKUtils v 4_0-448-4-0
2014-08-24 17:42 - 2014-08-24 17:42 - 00000000 ____D () C:\Users\Tony\Downloads\PatcherGUI v 4_0-448-4-0
2014-08-22 22:07 - 2014-08-27 23:50 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-22 21:45 - 2014-08-27 23:50 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-22 20:59 - 2014-08-27 23:50 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 15:23 - 2014-04-07 18:06 - 00000000 ____D () C:\Users\Tony\Documents\My Games
2014-08-19 14:05 - 2014-09-11 02:56 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-19 13:39 - 2014-09-11 02:56 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-18 19:01 - 2014-09-11 02:56 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-18 18:44 - 2014-04-05 07:09 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-18 18:29 - 2014-09-11 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-18 18:29 - 2014-09-11 02:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-18 18:26 - 2014-09-11 02:56 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-18 18:20 - 2014-09-11 02:56 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-18 18:19 - 2014-09-11 02:56 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-18 18:15 - 2014-09-11 02:56 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-18 18:15 - 2014-09-11 02:56 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-18 18:14 - 2014-09-11 02:56 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-18 18:14 - 2014-09-11 02:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-18 18:08 - 2014-09-11 02:56 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-18 18:08 - 2014-09-11 02:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-18 18:08 - 2014-09-11 02:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-18 18:05 - 2014-09-11 02:56 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-18 18:03 - 2014-09-11 02:56 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-18 18:03 - 2014-09-11 02:56 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-18 18:03 - 2014-09-11 02:56 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-18 17:57 - 2014-09-11 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-18 17:56 - 2014-09-11 02:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-18 17:51 - 2014-09-11 02:56 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-18 17:46 - 2014-09-11 02:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-18 17:45 - 2014-09-11 02:56 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-18 17:45 - 2014-09-11 02:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-18 17:44 - 2014-09-11 02:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-18 17:44 - 2014-09-11 02:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-18 17:42 - 2014-09-11 02:56 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-18 17:40 - 2014-09-11 02:56 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-18 17:39 - 2014-09-11 02:56 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-18 17:39 - 2014-09-11 02:56 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-18 17:39 - 2014-09-11 02:56 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-18 17:38 - 2014-09-11 02:56 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-18 17:37 - 2014-09-11 02:56 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-18 17:36 - 2014-09-11 02:56 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-18 17:35 - 2014-09-11 02:56 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-18 17:27 - 2014-09-11 02:56 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-18 17:25 - 2014-09-11 02:56 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-18 17:25 - 2014-09-11 02:56 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-18 17:23 - 2014-09-11 02:56 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-18 17:23 - 2014-09-11 02:56 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-18 17:22 - 2014-09-11 02:56 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-18 17:19 - 2014-09-11 02:56 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-18 17:17 - 2014-09-11 02:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-18 17:17 - 2014-09-11 02:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-18 17:16 - 2014-09-11 02:56 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-18 17:15 - 2014-09-11 02:56 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-18 17:15 - 2014-09-11 02:56 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-18 17:13 - 2009-07-14 01:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-18 17:09 - 2014-09-11 02:56 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-18 17:08 - 2014-09-11 02:56 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-18 17:07 - 2014-09-11 02:56 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-18 16:55 - 2014-09-11 02:56 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-18 16:46 - 2014-09-11 02:56 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-18 16:38 - 2014-09-11 02:56 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-18 16:38 - 2014-09-11 02:56 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-18 16:36 - 2014-09-11 02:56 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-18 15:51 - 2014-04-05 19:34 - 00000000 ____D () C:\ProgramData\Skype
 
Some content of TEMP:
====================
C:\Users\Tony\AppData\Local\Temp\mysearchdial.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-09-16 00:49
 
==================== End Of Log ============================


#6 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:15 PM

Posted 17 September 2014 - 02:56 PM

Please download this attached Attached File  fixlist.txt   379bytes   1 downloads and save it in the same directory as FRST.
  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.


#7 tngvu

tngvu
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:15 PM

Posted 17 September 2014 - 03:12 PM

The malware has stopped appearing, thank you so much! 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014
Ran by Tony at 2014-09-17 16:07:09 Run:4
Running from C:\Users\Tony\Desktop\FRST
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\...\Run: [CMD] => cmd.exe /c start http://extendedunlimited.org && exit <===== ATTENTION
REG: reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v CMD /f
C:\Windows\System32\config\systemprofile\AppData\Roaming\Origin\update.vbe
C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Origin\update.vbe
Reboot:
*****************
 
HKU\S-1-5-21-3993470856-267786844-2316804574-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CMD => value deleted successfully.
 
========= reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v CMD /f =========
 
ERROR: The system was unable to find the specified registry key or value.
 
 
========= End of Reg: =========
 
C:\Windows\System32\config\systemprofile\AppData\Roaming\Origin\update.vbe => Moved successfully.
C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Origin\update.vbe => Moved successfully.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====


#8 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:15 PM

Posted 17 September 2014 - 03:41 PM

You're welcome.

My help is free for everybody.
If you want to support me fighting against malware or buy me a beer for the assistance you received, then you can consider a donation: btn_donate_SM.gif.
Thank you!

#9 aharonov

aharonov

  • Malware Response Team
  • 2,441 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:15 PM

Posted 19 September 2014 - 03:43 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users