Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Avast! Web Shield has blocked a harmful webpage or file


  • This topic is locked This topic is locked
18 replies to this topic

#1 aVeryConfusedMan

aVeryConfusedMan

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 08 May 2015 - 11:39 AM

I'm sure you've seen these topics before...

I need some help about the constant popups avast has given me FOR EXAMPLE

 

Avast Web Shield has blocked a harmful webpage or file.

Object:  htp://filesonlinehere.com/sync/?rmbs=...

Infection:  URL:Mal

Process:  C:\Program Files (x86)\...\chrome.exe

 

 

If there is anything I need to provide, please elaborate and I will be grateful to supply it



BC AdBot (Login to Remove)

 


m

#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,228 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:28 AM

Posted 13 May 2015 - 08:24 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download Malwarebytes' Anti-Malware from Here

Double-click mbam-setup-2.X.X.XXXX.exe to install the application (X's are the current version number).
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once MBAM opens, when it says Your databases are out of date, click the Fix Now button.
  • Click the Settings tab at the top, and then in the left column, select Detections and Protections, and if not already checked place a checkmark in the selection box for Scan for rootkits.
  • Click the Scan tab at the top of the program window, select Threat Scan and click the Scan Now button.
  • If you receive a message that updates are available, click the Update Now button (the update will be downloaded, installed, and the scan will start).
  • The scan may take some time to finish,so please be patient.
  • If potential threats are detected, ensure that Quarantine is selected as the Action for all the listed items, and click the Apply Actions button.
  • While still on the Scan tab, click the link for View detailed log, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log is automatically saved by MBAM and can also be viewed by clicking the History tab and then selecting Application Logs.
POST THE LOG FOR MY REVIEW.

Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.

===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
===


How is the computer running?
Wait for further instructions.

#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,228 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:28 AM

Posted 19 May 2015 - 08:49 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,228 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:28 AM

Posted 21 May 2015 - 06:53 AM

This topic has been re-opened at the request of the person who originally posted.

#5 nasdaq

nasdaq

  • Malware Response Team
  • 38,228 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:28 AM

Posted 27 May 2015 - 07:34 AM

Are you still with me?

#6 aVeryConfusedMan

aVeryConfusedMan
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 28 May 2015 - 01:15 PM

Very sorry nasdaq, was caught up in something the past few days.



#7 aVeryConfusedMan

aVeryConfusedMan
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 28 May 2015 - 02:53 PM

MBAM Log -

 

Malwarebytes Anti-Malware

www.malwarebytes.org
 
Scan Date 28052015
Scan Time 191611
Logfile mbam_log.txt
Administrator Yes
 
Version 2.01.6.1022
Malware Database v2015.05.28.06
Rootkit Database v2015.05.24.01
License Free
Malware Protection Disabled
Malicious Website Protection Disabled
Self-protection Disabled
 
OS Windows 8.1
CPU x64
File System NTFS
User Gears123451
 
Scan Type Threat Scan
Result Completed
Objects Scanned 631523
Time Elapsed 1 hr, 5 min, 24 sec
 
Memory Enabled
Startup Enabled
Filesystem Enabled
Archives Enabled
Rootkits Enabled
Heuristics Enabled
PUP Enabled
PUM Enabled
 
Processes 0
(No malicious items detected)
 
Modules 0
(No malicious items detected)
 
Registry Keys 7
PUP.Optional.SpeeDial.A, HKLMSOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, , [1aec5742c3c7df5768c2b6bd040143bd], 
PUP.Optional.FramedDisplay.A, HKUS-1-5-21-1543283602-3742611817-714404855-1001SOFTWAREFramed Display, , [14f23366c8c259ddf16aaacff411f30d], 
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1001SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, , [d92de9b0ee9cf83e1f0a5c171aebbb45], 
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1002SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, , [aa5cfb9efd8dbc7a2efbd69d4abb649c], 
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1003SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, , [16f0bfda8406d066b77288eb23e2be42], 
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1004SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, , [a2647b1ee1a960d61217185b92739b65], 
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1005SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, , [b254fa9f3753c5719f8a0d668c79629e], 
 
Registry Values 27
PUP.Optional.SpeeDial.A, HKLMSOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}URL, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [1aec5742c3c7df5768c2b6bd040143bd]
PUP.Optional.SpeeDial.A, HKLMSOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}TopResultURLFallback, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [1aec9801b0da5adc63c7c6ad5ca914ec]
PUP.Optional.SpeeDial.A, HKLMSOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}FaviconPath, CProgram Files (x86)Speedial1.8.29.15FavIcon.ico, , [719540596327cc6a9e8c42315ea7bf41]
PUP.Optional.SpeeDial.A, HKLMSOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, Speedial, , [cc3a45542a603cfa9496a1d233d2c53b]
PUP.Optional.SpeeDial.A, HKLMSOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}DisplayName, Speedial, , [34d24f4ac8c2072f88a23e3593724fb1]
PUP.Optional.Astromenda.C, HKLMSOFTWAREWOW6432NODEMICROSOFTINTERNET EXPLORERLOW RIGHTSELEVATIONPOLICYAppPath, CProgram Files (x86)WSE_Astromenda, , [2cdafd9cb3d767cf9b3a17ca9d66d030]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1001SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}URL, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [d92de9b0ee9cf83e1f0a5c171aebbb45]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1001SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}TopResultURLFallback, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [0ef82e6bc4c6ab8b45e4353ec93c8878]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1001SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}FaviconPath, CProgram Files (x86)Speedial1.8.29.15FavIcon.ico, , [6c9ab7e2a2e834022efb4c27ea1bf709]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1001SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, Speedial, , [7d89c0d9cbbf171f0425482b70958b75]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1001SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}DisplayName, Speedial, , [7195c9d0048691a54cdd6d066c99a957]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1002SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}URL, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [aa5cfb9efd8dbc7a2efbd69d4abb649c]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1002SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}TopResultURLFallback, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [e422badfb3d777bfea3fa9cacb3a55ab]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1002SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, Speedial, , [9670a4f5dab042f4ac7d462d02039868]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1002SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}DisplayName, Speedial, , [b650badf6d1de5510425046f5ea7936d]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1003SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}URL, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [16f0bfda8406d066b77288eb23e2be42]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1003SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}TopResultURLFallback, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [55b11c7de5a5c86eb871a9ca46bfc040]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1003SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, Speedial, , [17eff2a77d0d132381a82152fc090ef2]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1003SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}DisplayName, Speedial, , [2fd70990157555e1f1380d669273b44c]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1004SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}URL, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [a2647b1ee1a960d61217185b92739b65]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1004SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}TopResultURLFallback, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [cd39f3a6b7d3d85e74b51b581aeb7090]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1004SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, Speedial, , [5fa7c6d3880271c52702dc979c691ce4]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1004SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}DisplayName, Speedial, , [30d66f2a09815ed89198d2a1f0155ba5]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1005SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}URL, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [b254fa9f3753c5719f8a0d668c79629e]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1005SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}TopResultURLFallback, httpspeedial.comresults.phpf=4&q={searchTerms}&a=spd_secureddownload_14_22_ch&cd=2XzuyEtN2Y1L1Qzu0E0CtC0AyDzytD0E0FtAzyzyyEtAtCyBtN0D0Tzu0SzzyBzztN1L2XzutBtFtBtDtFtCzytFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0B0DtC0FtB0F0AtGyBzzyByDtGzzyDtDyDtGzz0F0AzytGtAtA0EyByDtAtCzzyDyCyE0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAyByByEyEyByBtAtG0C0ByBzytG0ByEzy0AtGzztA0A0EtGyCyCyDtB0D0EzztCyB0C0DtB2Q&cr=1669045894&ir=, , [35d17b1eec9e72c4f732fb78976e639d]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1005SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}, Speedial, , [b65056438bffb086a485b3c0b74e926e]
PUP.Optional.SpeeDial.A, HKUS-1-5-21-1543283602-3742611817-714404855-1005SOFTWAREMICROSOFTINTERNET EXPLORERSEARCHSCOPES{59F6007A-2E6B-4162-8758-F9BFA359B79F}DisplayName, Speedial, , [4eb83c5d1575f244c564314245c057a9]
 
Registry Data 0
(No malicious items detected)
 
Folders 13
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186, , [13f335640288171f899e1460f31220e0], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf, , [13f335640288171f899e1460f31220e0], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197, , [d1353f5a58323ff70d1a6014ca3bbd43], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah, , [d1353f5a58323ff70d1a6014ca3bbd43], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186, , [ea1c84158bffdf5707209fd5877eb050], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf, , [ea1c84158bffdf5707209fd5877eb050], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197, , [db2b54453b4f0c2a8f980d679372d62a], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah, , [db2b54453b4f0c2a8f980d679372d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186, , [0600b2e704869e98ff28a5cf33d2d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf, , [0600b2e704869e98ff28a5cf33d2d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197, , [cf37148594f684b2f235e58f897cbd43], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah, , [cf37148594f684b2f235e58f897cbd43], 
PUP.Optional.FramedDisplay.A, CUsersMedtechAppDataLocalTempFramed Display, , [3dc9c4d5a1e9b77ffbf765780003a55b], 
 
Files 31
PUP.Optional.MyPCBackup.SID.A, CUsersMedtechAppDataLocalTempair3A34.exe, , [74926d2c4545b680033752172ed822de], 
PUP.Optional.BrowseFox, CUsersMedtechAppDataLocalTempis113516901780455229_stpwebget_setup.exe, , [010515845b2fc86e6ff34a17719107f9], 
PUP.Optional.MyPCBackup.SID.A, CUsersMedtechAppDataLocalTempis1242154493222114163_stpaff_setup.exe, , [d82e4e4b147677bf02385019b45254ac], 
PUP.Optional.MyPCBackup.SID.A, CUsersMedtechAppDataLocalTempis38652623227A527C5_stpaff_setup.exe, , [73935e3b0585ce68201a3534d72f6d93], 
PUP.Optional.Installcore, CUsersMedtechDownloadsFileOpenerSetup.exe, , [4cba87120a803ff76d152e3b4fb79f61], 
PUP.Optional.AZLyrics.A, CUsersGears123451AppDataLocalGoogleChromeUser DataDefaultLocal Storagehttp_www.azlyrics.com_0.localstorage, , [b74f574267230b2be7a6d0267192f30d], 
PUP.Optional.AZLyrics.A, CUsersGears123451AppDataLocalGoogleChromeUser DataDefaultLocal Storagehttp_www.azlyrics.com_0.localstorage-journal, , [9274e7b2187262d4305dc531a55e6799], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186lsdb.js, , [13f335640288171f899e1460f31220e0], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186background.html, , [13f335640288171f899e1460f31220e0], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186content.js, , [13f335640288171f899e1460f31220e0], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186manifest.json, , [13f335640288171f899e1460f31220e0], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197lsdb.js, , [d1353f5a58323ff70d1a6014ca3bbd43], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197background.html, , [d1353f5a58323ff70d1a6014ca3bbd43], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197content.js, , [d1353f5a58323ff70d1a6014ca3bbd43], 
PUP.Optional.MultiPlug.A, CUsersconorAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197manifest.json, , [d1353f5a58323ff70d1a6014ca3bbd43], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186lsdb.js, , [ea1c84158bffdf5707209fd5877eb050], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186background.html, , [ea1c84158bffdf5707209fd5877eb050], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186content.js, , [ea1c84158bffdf5707209fd5877eb050], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186manifest.json, , [ea1c84158bffdf5707209fd5877eb050], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197lsdb.js, , [db2b54453b4f0c2a8f980d679372d62a], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197background.html, , [db2b54453b4f0c2a8f980d679372d62a], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197content.js, , [db2b54453b4f0c2a8f980d679372d62a], 
PUP.Optional.MultiPlug.A, CUsersLaurenAppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197manifest.json, , [db2b54453b4f0c2a8f980d679372d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186lsdb.js, , [0600b2e704869e98ff28a5cf33d2d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186background.html, , [0600b2e704869e98ff28a5cf33d2d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186content.js, , [0600b2e704869e98ff28a5cf33d2d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionsfemhaoibopdmjanecjeeookdamkdfjaf186manifest.json, , [0600b2e704869e98ff28a5cf33d2d62a], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197lsdb.js, , [cf37148594f684b2f235e58f897cbd43], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197background.html, , [cf37148594f684b2f235e58f897cbd43], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197content.js, , [cf37148594f684b2f235e58f897cbd43], 
PUP.Optional.MultiPlug.A, CUsersSophi_000AppDataLocalGoogleChromeUser DataDefaultExtensionskfimphpokifbjgmjflanmfeppcjimgah197manifest.json, , [cf37148594f684b2f235e58f897cbd43], 
 
Physical Sectors 0
(No malicious items detected)
 
 
(end)

 

AdwCleaner Log -

 

# AdwCleaner v4.202 - Logfile created 28/05/2015 at 20:30:16

# Updated 23/04/2015 by Xplode
# Database : 2015-05-25.3 [Server]
# Operating system : Windows 8.1  (x64)
# Username : Gears123451 - HAL
# Running from : C:\Users\Gears123451\Downloads\adwcleaner_4.202.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Found : C:\prefs.js
Folder Found : C:\Program Files (x86)\KingSoft
Folder Found : C:\ProgramData\KingSoft
Folder Found : C:\Users\Gears123451\AppData\Local\KingSoft
Folder Found : C:\Users\Gears123451\AppData\Roaming\KingSoft
Folder Found : C:\Users\Lauren\AppData\Roaming\KingSoft
Folder Found : C:\Users\Medtech\AppData\Local\KingSoft
Folder Found : C:\Users\Medtech\AppData\Roaming\KingSoft
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Data Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyEnable] - 1
Data Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
Data Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:50764;hxxps=127.0.0.1:50764
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B853E835-9F24-4F4B-B55C-E554D15CCCD2}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{F8A4FC32-DDA3-4DD9-8C62-49F778FF630B}
Key Found : HKLM\SOFTWARE\Classes\uus3url-pl
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{09CFDB88-F9F0-40BA-885E-F47A957D12E6}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{2B1B440F-A9DB-46E3-ADCF-AA6E08143FB8}
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Itibiti.exe]
Value Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [DefaultConnectionSettings]
Value Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [SavedLegacySettings]
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17416
 
 
-\\ Google Chrome v43.0.2357.81
 
[C:\Users\Sophi_000\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
[C:\Users\Sophi_000\AppData\Local\Google\Chrome\User Data\Default\Web data] - Found [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
 
*************************
 
AdwCleaner[R0].txt - [24030 bytes] - [12/09/2014 21:25:36]
AdwCleaner[R10].txt - [2479 bytes] - [28/05/2015 20:30:16]
AdwCleaner[R1].txt - [4660 bytes] - [18/10/2014 13:26:22]
AdwCleaner[R2].txt - [351 bytes] - [23/10/2014 16:53:44]
AdwCleaner[R3].txt - [5119 bytes] - [23/10/2014 16:57:50]
AdwCleaner[R4].txt - [351 bytes] - [26/10/2014 10:19:31]
AdwCleaner[R5].txt - [1309 bytes] - [26/10/2014 10:20:46]
AdwCleaner[R6].txt - [6185 bytes] - [19/12/2014 18:20:51]
AdwCleaner[R7].txt - [22238 bytes] - [25/04/2015 21:13:54]
AdwCleaner[R8].txt - [2762 bytes] - [08/05/2015 17:32:25]
AdwCleaner[R9].txt - [2821 bytes] - [08/05/2015 17:41:19]
AdwCleaner[S0].txt - [22536 bytes] - [12/09/2014 21:29:24]
AdwCleaner[S1].txt - [342 bytes] - [18/10/2014 13:29:37]
AdwCleaner[S2].txt - [4778 bytes] - [23/10/2014 17:03:06]
AdwCleaner[S3].txt - [1368 bytes] - [26/10/2014 10:24:10]
AdwCleaner[S4].txt - [6260 bytes] - [19/12/2014 18:32:18]
AdwCleaner[S5].txt - [8524 bytes] - [25/04/2015 21:18:41]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R10].txt - [3423 bytes] ##########
 

 

Attached Files



#8 aVeryConfusedMan

aVeryConfusedMan
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 28 May 2015 - 02:59 PM

FRST Log - 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-05-2015 01

Ran by Gears123451 (administrator) on HAL on 28-05-2015 20:56:36
Running from C:\Users\Gears123451\Downloads
Loaded Profiles: Gears123451 (Available Profiles: Medtech & Gears123451 & conor & Lauren & GreyHarlequin)
Platform: Windows 8.1 (X64) OS Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Kinect Drivers\Service\KinectManagementService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(http://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\PAC207\Monitor.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Spotify Ltd) C:\Users\Gears123451\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Sony Computer Entertainment Inc.) C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe
() C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Sony Computer Entertainment Inc.) C:\Program Files (x86)\Sony\Content Manager Assistant\CMAWatcher.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(http://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Lionhead Studios Ltd) C:\Program Files (x86)\Lionhead Studios\Black & White 2\white.exe
(Macrovision Europe Ltd.) C:\Users\Gears123451\AppData\Local\Temp\~e5.0001
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [PAC207_Monitor] => C:\WINDOWS\PixArt\PAC207\Monitor.exe [323584 2007-12-10] (PixArt Imaging Incorporation)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [MessengerPlusForSkypeService] => "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe"
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [BambooCore] => C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [NPSStartup] => [X]
HKLM-x32\...\Run: [ArcSoft MediaImpression Monitor] => C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe [73728 2010-11-12] (ArcSoft, Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-18] (AVAST Software)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-01-30] (Raptr, Inc)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-03-30] (LogMeIn Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-04-14] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2888384 2015-05-15] (Valve Corporation)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Spotify Web Helper] => C:\Users\Gears123451\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2022968 2015-05-23] (Spotify Ltd)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Desura] => C:\Program Files (x86)\Desura\desura.exe [2529096 2013-06-08] (Desura Pty Ltd)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7767832 2014-10-01] (SUPERAntiSpyware)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3632472 2015-04-10] (Electronic Arts)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Facebook Update] => C:\Users\Medtech\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-02-09] (Facebook Inc.)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Medtech\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [SkyDrive] => "C:\Users\Medtech\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Speech Recognition] => C:\WINDOWS\Speech\Common\sapisvr.exe [44032 2014-10-29] (Microsoft Corporation)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Driver Manager] => C:\Program Files (x86)\Driver Manager\Driver Manager\DriverManager.exe /applicationMode:systemTray /showWelcome:false
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31346784 2015-02-26] (Skype Technologies S.A.)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [AutoStartNPSAgent] => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe [39712 2014-08-28] (Overwolf LTD)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [hsscp.EXE] => C:\Users\Gears123451\AppData\Roaming\Hotspot Shield\bin\hsscp.EXE -nonadmin
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [GoogleChromeAutoLaunch_F630B1F2C577464E577AA27542FD2826] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-05-22] (Google Inc.)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Spotify] => C:\Users\Gears123451\AppData\Roaming\Spotify\Spotify.exe [7298616 2015-05-23] (Spotify Ltd)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [7457336 2015-05-28] (GOG.com)
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\MountPoints2: {5a6fdbfe-9c4d-11e3-804b-50465d0864f8} - "E:\MI.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Content Manager Assistant for PlayStation®.lnk [2014-09-28]
ShortcutTarget: Content Manager Assistant for PlayStation®.lnk -> C:\Program Files (x86)\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
Startup: C:\Users\conor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-01-23]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Gears123451\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2013-09-05]
ShortcutTarget: Dropbox.lnk -> C:\Users\Gears123451\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Lauren\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-10-03]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Medtech\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-07-01]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Sophi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-09-04]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2014-10-18] (AVAST Software)
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:50764;https=127.0.0.1:50764
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1543283602-3742611817-714404855-1002 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-10-18] (AVAST Software)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-10-18] (AVAST Software)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-12-25] (Wacom)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-12-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-28] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @virtway.com/viviwo -> C:\Program Files (x86)\Virtway\ViViWo Browser Client\npviviwoFirefoxPlugin.dll [2013-08-02] (VirtWay)
FF Plugin-x32: @vizzed.com/VizzedRGR -> C:\Program Files (x86)\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll [2013-01-11] (Vizzed.com)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2012-12-25] (Wacom)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2012-12-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1543283602-3742611817-714404855-1002: @onlive.com/OnLiveGameClientDetector,version=1.0.0 -> C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll [2014-12-17] (OnLive)
FF Plugin HKU\S-1-5-21-1543283602-3742611817-714404855-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Gears123451\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-01-26] (Unity Technologies ApS)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-18]
 
Chrome: 
=======
CHR Profile: C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-06]
CHR Extension: (Portal: Aperture Laboratories) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\adjpjlnifhodbcbcpelokdgbgfkmlihm [2014-10-06]
CHR Extension: (Theme Creator) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2014-12-19]
CHR Extension: (Google Docs) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-06]
CHR Extension: (Google Drive) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-06]
CHR Extension: (YouTube) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-06]
CHR Extension: (Google Search) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-06]
CHR Extension: (Google Sheets) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-06]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2014-10-06]
CHR Extension: (AdBlock) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-04-25]
CHR Extension: (Avast Online Security) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-06]
CHR Extension: (TweetDeck by Twitter) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2014-10-06]
CHR Extension: (Disconnect) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2014-10-06]
CHR Extension: (Command & Conquer Tiberium Alliances) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe [2014-10-06]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-27]
CHR Extension: (Google Wallet) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-06]
CHR Extension: (Gmail) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-06]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-18]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-18] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [441216 2015-05-08] ()
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe [56648 2015-03-08] (Google Inc.)
R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3645432 2014-07-18] (devolo AG)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-05] (Microsoft Corporation)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [182304 2014-11-17] (EasyAntiCheat Ltd)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1751096 2015-05-28] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6516280 2015-05-28] (GOG.com)
S4 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2015-02-24] ()
S4 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [558376 2015-02-24] ()
R2 KinectManagement; C:\Program Files\Microsoft Kinect Drivers\Service\KinectManagementService.exe [98816 2012-09-18] (Microsoft Corporation) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-03-30] (LogMeIn, Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-10] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [998176 2014-08-28] (Overwolf LTD)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [75136 2014-08-03] ()
R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [189248 2014-08-03] ()
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-06-09] (VIA Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S4 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [627992 2013-12-17] (Wacom Technology, Corp.)
S2 MsgPlusService; "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ArcCD; No ImagePath
U1 ArcRec; No ImagePath
S4 ArcUdfs; No ImagePath
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-18] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-18] ()
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek                                            )
R3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-03-30] (LogMeIn Inc.)
S3 hitmanpro37; C:\windows\system32\drivers\hitmanpro37.sys [32512 2013-09-04] ()
R1 HssDRV6; C:\Windows\system32\DRIVERS\hssdrv6.sys [44744 2014-06-26] (AnchorFree Inc.)
S3 IFCoEMP; C:\Windows\System32\drivers\ifM60x64.sys [387344 2012-04-20] (Intel® Corporation)
S3 IFCoEVB; C:\Windows\System32\drivers\ifP60X64.sys [77584 2012-04-20] (Intel® Corporation)
R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2012-11-20] (Highresolution Enterprises [www.highrez.co.uk])
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [136408 2015-05-28] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MsgPlusDriver; C:\Windows\system32\DRIVERS\MsgPlusDriver.sys [125392 2013-05-07] (Yune Software)
R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2014-07-18] (CACE Technologies)
S3 PAC207; C:\Windows\system32\DRIVERS\PFC027.SYS [686592 2008-02-13] (PixArt Imaging Inc.)
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation                           )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [15712 2013-03-13] ()
R3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.)
S2 vcs; C:\Program Files (x86)\Common Files\Avnex\vcs64.sys [4096 2014-01-24] () [File not signed]
R3 VCSVADHWSer; C:\Windows\system32\DRIVERS\vcsvad.sys [21504 2008-12-26] (Avnex)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 WinRing0_1_2_0; C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [14544 2012-08-01] (OpenLibSys.org)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
U0 yrat; C:\Windows\System32\drivers\tlwbnc.sys [79064 2015-05-28] (Malwarebytes Corporation)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-28 20:56 - 2015-05-28 20:57 - 00032620 _____ () C:\Users\Gears123451\Downloads\FRST.txt
2015-05-28 20:56 - 2015-05-28 20:56 - 00000000 ____D () C:\Users\Gears123451\Downloads\FRST-OlderVersion
2015-05-28 20:26 - 2015-05-28 20:26 - 00079064 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\tlwbnc.sys
2015-05-28 16:48 - 2015-05-28 16:50 - 00000000 ____D () C:\Users\Gears123451\Documents\Black & White 2
2015-05-28 12:32 - 2015-05-28 12:34 - 00000000 ____D () C:\Users\Sophi_000\Documents\Black & White 2
2015-05-28 12:31 - 2015-05-28 12:31 - 00001930 _____ () C:\Users\Public\Desktop\Black & White 2.lnk
2015-05-28 12:22 - 2015-05-28 12:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Black & White 2
2015-05-28 12:21 - 2015-05-28 12:21 - 00000000 ____D () C:\Program Files (x86)\Lionhead Studios
2015-05-24 19:13 - 2015-05-23 16:22 - 00002222 _____ () C:\Users\Gears123451\Desktop\Black & White.lnk
2015-05-23 16:21 - 2015-05-23 16:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lionhead Studios Ltd
2015-05-23 16:21 - 2015-05-23 16:21 - 00000000 ____D () C:\Program Files (x86)\Lionhead Studios Ltd
2015-05-20 18:01 - 2015-05-20 18:01 - 00021270 _____ () C:\Users\Sophi_000\Documents\Jason's CV.odt
2015-05-13 13:24 - 2015-04-30 21:35 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 13:24 - 2015-04-30 21:35 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 12:12 - 2015-05-13 12:12 - 00031358 _____ () C:\Users\Medtech\Downloads\PayPal Website Payment Details - PayPal lenovo.html
2015-05-13 12:12 - 2015-05-13 12:12 - 00000000 ____D () C:\Users\Medtech\Downloads\PayPal Website Payment Details - PayPal lenovo_files
2015-05-13 12:10 - 2015-05-13 12:10 - 00336073 _____ () C:\Users\Medtech\Downloads\PayPal_ Activity lenovo.html
2015-05-13 12:10 - 2015-05-13 12:10 - 00000000 ____D () C:\Users\Medtech\Downloads\PayPal_ Activity lenovo_files
2015-05-13 12:00 - 2015-05-13 12:00 - 00035206 _____ () C:\Users\Medtech\Downloads\PayPal Website Payment Details - PayPal z2.html
2015-05-13 12:00 - 2015-05-13 12:00 - 00000000 ____D () C:\Users\Medtech\Downloads\PayPal Website Payment Details - PayPal z2_files
2015-05-13 11:49 - 2015-05-13 12:00 - 00000000 ____D () C:\Users\Medtech\Downloads\PayPal Website Payment Details - PayPal_files
2015-05-13 11:49 - 2015-05-13 11:49 - 00030144 _____ () C:\Users\Medtech\Downloads\PayPal Website Payment Details - PayPal.html
2015-05-13 09:44 - 2015-04-21 18:14 - 24971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-05-13 09:44 - 2015-04-21 17:50 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-05-13 09:44 - 2015-04-21 17:50 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-05-13 09:44 - 2015-04-21 17:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-05-13 09:44 - 2015-04-21 17:37 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-05-13 09:44 - 2015-04-21 17:35 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-05-13 09:44 - 2015-04-21 17:31 - 06025728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-05-13 09:44 - 2015-04-21 17:24 - 19691008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-05-13 09:44 - 2015-04-21 17:13 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2015-05-13 09:44 - 2015-04-21 17:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-05-13 09:44 - 2015-04-21 17:09 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-05-13 09:44 - 2015-04-21 17:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-05-13 09:44 - 2015-04-21 17:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-05-13 09:44 - 2015-04-21 17:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-05-13 09:44 - 2015-04-21 17:04 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-05-13 09:44 - 2015-04-21 16:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-05-13 09:44 - 2015-04-21 16:58 - 00664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-05-13 09:44 - 2015-04-21 16:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-05-13 09:44 - 2015-04-21 16:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-05-13 09:44 - 2015-04-21 16:49 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-05-13 09:44 - 2015-04-21 16:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-05-13 09:44 - 2015-04-21 16:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-05-13 09:44 - 2015-04-21 16:40 - 14401536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-05-13 09:44 - 2015-04-21 16:38 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-05-13 09:44 - 2015-04-21 16:37 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-05-13 09:44 - 2015-04-21 16:36 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-05-13 09:44 - 2015-04-21 16:32 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-05-13 09:44 - 2015-04-21 16:31 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-05-13 09:44 - 2015-04-21 16:28 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-05-13 09:44 - 2015-04-21 16:27 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-05-13 09:44 - 2015-04-21 16:26 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-05-13 09:44 - 2015-04-21 16:26 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-05-13 09:44 - 2015-04-21 16:25 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-05-13 09:44 - 2015-04-21 16:17 - 12828672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-05-13 09:44 - 2015-04-21 16:15 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-05-13 09:44 - 2015-04-21 16:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-05-13 09:44 - 2015-04-21 16:02 - 01882112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-05-13 09:44 - 2015-04-21 15:58 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-05-13 09:44 - 2015-04-21 15:56 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-05-13 09:43 - 2015-05-01 00:05 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-05-13 09:43 - 2015-04-30 23:48 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-05-13 09:43 - 2015-04-24 22:32 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-05-13 09:43 - 2015-04-13 23:48 - 04180480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-05-13 09:43 - 2015-04-10 02:00 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-05-13 09:43 - 2015-04-10 01:50 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-05-13 09:43 - 2015-04-10 01:34 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-05-13 09:43 - 2015-04-10 01:26 - 01560576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-05-13 09:43 - 2015-04-10 01:11 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-05-13 09:43 - 2015-04-08 23:55 - 00410128 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-05-13 09:43 - 2015-04-03 01:35 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2015-05-13 09:43 - 2015-04-03 01:14 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2015-05-13 09:43 - 2015-04-01 23:22 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2015-05-13 09:43 - 2015-04-01 23:20 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2015-05-13 09:43 - 2015-04-01 04:45 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2015-05-13 09:43 - 2015-04-01 03:31 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2015-05-13 09:43 - 2015-03-20 02:56 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-05-13 09:43 - 2015-03-17 18:26 - 00467776 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-05-13 09:43 - 2015-03-13 03:02 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2015-05-13 09:43 - 2015-03-13 02:11 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-05-13 09:43 - 2015-03-13 01:39 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-05-13 09:43 - 2015-03-09 03:02 - 00057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-05-13 09:43 - 2015-03-06 03:47 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2015-05-13 09:43 - 2015-03-05 00:09 - 01429504 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-05-13 09:43 - 2015-03-04 02:32 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2015-05-13 09:43 - 2015-03-04 02:12 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-13 09:43 - 2015-01-30 01:53 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-05-13 09:43 - 2014-11-14 07:58 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsDatabase.dll
2015-05-13 09:42 - 2015-03-30 06:47 - 00561928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-05-13 09:42 - 2015-03-27 04:27 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-05-13 09:42 - 2015-03-27 03:50 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-05-13 09:42 - 2015-03-27 03:48 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-05-13 09:42 - 2015-03-13 05:03 - 00239424 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-05-13 09:42 - 2015-03-13 05:03 - 00154432 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2015-05-13 09:42 - 2015-03-13 01:29 - 00410017 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-05-13 09:42 - 2015-03-11 02:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-05-13 09:42 - 2015-03-11 02:09 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe
2015-05-13 09:42 - 2015-03-06 04:08 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2015-05-13 09:42 - 2015-03-06 03:43 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2015-05-13 09:42 - 2015-02-18 00:19 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2015-05-11 18:53 - 2015-05-11 18:53 - 00001074 _____ () C:\Users\Public\Desktop\GOG Galaxy.lnk
2015-05-11 18:53 - 2015-05-11 18:53 - 00000000 ____D () C:\ProgramData\GOG.com
2015-05-11 18:52 - 2015-05-11 18:52 - 62539536 _____ (GOG.com ) C:\Users\Gears123451\Downloads\setup_galaxy_1.0.0.871.exe
2015-05-10 19:56 - 2015-04-21 15:00 - 00890880 _____ (Microsoft) C:\Users\Gears123451\Desktop\Matchmaking Server Picker.exe
2015-05-10 19:55 - 2015-05-10 19:55 - 00432104 _____ () C:\Users\Gears123451\Downloads\matchmaking_server_picker2_6.zip
2015-05-08 17:56 - 2015-05-08 17:59 - 00000000 ____D () C:\Users\Gears123451\Documents\Arma 3
2015-05-08 17:56 - 2015-05-08 17:59 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\Arma 3
2015-05-08 17:56 - 2015-05-08 17:56 - 00000000 ____D () C:\ProgramData\Bohemia Interactive
2015-05-08 17:54 - 2015-05-08 17:59 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\Arma 3 Launcher
2015-05-08 17:54 - 2015-05-08 17:54 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\Bohemia_Interactive
2015-05-08 17:30 - 2015-05-28 20:56 - 00000000 ____D () C:\FRST
2015-05-08 17:29 - 2015-05-28 20:56 - 02108928 _____ (Farbar) C:\Users\Gears123451\Downloads\FRST64.exe
2015-05-04 22:13 - 2015-05-04 22:13 - 00000000 ____D () C:\Users\Medtech\AppData\Local\CrashDumps
2015-05-03 19:10 - 2015-05-03 19:18 - 00000000 ____D () C:\Users\Lauren\Downloads\trash
2015-05-03 18:00 - 2015-05-03 22:31 - 00000000 ____D () C:\Users\Lauren\Downloads\PIXELS
2015-05-02 09:59 - 2015-05-02 09:59 - 00001207 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2015-05-02 09:59 - 2015-05-02 09:59 - 00001195 _____ () C:\Users\Public\Desktop\paint.net.lnk
2015-05-02 09:57 - 2015-05-02 09:58 - 00009728 _____ (Evan Wallace) C:\Users\Gears123451\Downloads\Add-Remove Watermark.dll
2015-05-02 09:55 - 2015-05-02 09:55 - 06528454 _____ () C:\Users\Gears123451\Downloads\paint.net.4.0.5.install.zip
2015-05-01 21:30 - 2015-05-01 21:30 - 00000000 ____D () C:\Users\Gears123451\AppData\Roaming\java
2015-05-01 09:40 - 2015-05-22 11:41 - 00000000 ____D () C:\Users\Sophi_000\AppData\Local\CrashDumps
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-28 20:51 - 2014-10-18 13:44 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-05-28 20:49 - 2013-01-12 20:38 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-28 20:46 - 2015-01-09 17:42 - 00000420 _____ () C:\WINDOWS\Tasks\WpsNotifyTask_Gears123451.job
2015-05-28 20:39 - 2015-01-09 17:42 - 00000420 _____ () C:\WINDOWS\Tasks\WpsUpdateTask_Gears123451.job
2015-05-28 20:39 - 2012-12-28 18:03 - 00000914 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-28 20:33 - 2014-09-12 21:15 - 00000000 ____D () C:\AdwCleaner
2015-05-28 20:33 - 2013-12-15 22:08 - 01689209 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-28 20:26 - 2013-11-14 13:29 - 00000000 ____D () C:\WINDOWS\ShellNew
2015-05-28 20:24 - 2014-12-16 21:40 - 00357888 ___SH () C:\Users\Gears123451\Documents\Thumbs.db
2015-05-28 20:12 - 2013-11-14 13:45 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-28 20:09 - 2013-08-22 15:46 - 00455332 _____ () C:\WINDOWS\setupact.log
2015-05-28 20:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-28 19:54 - 2013-02-09 14:49 - 00000944 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1543283602-3742611817-714404855-1001UA.job
2015-05-28 19:23 - 2013-05-26 11:05 - 00000000 ____D () C:\Users\Gears123451\AppData\Roaming\Spotify
2015-05-28 19:23 - 2013-05-26 11:05 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\Spotify
2015-05-28 19:16 - 2014-09-13 21:22 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-28 18:25 - 2012-12-28 19:12 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-28 16:52 - 2012-12-26 11:35 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1543283602-3742611817-714404855-1002
2015-05-28 16:48 - 2013-01-03 09:56 - 00000000 ____D () C:\ProgramData\Origin
2015-05-28 16:47 - 2014-08-02 10:10 - 00000472 _____ () C:\WINDOWS\Tasks\RegCure Pro Startup.job
2015-05-28 16:47 - 2014-05-10 10:48 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\TSVNCache
2015-05-28 16:47 - 2012-12-28 18:03 - 00000910 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-28 16:46 - 2014-05-30 16:23 - 00000000 ____D () C:\Users\Sophi_000\AppData\Local\TSVNCache
2015-05-28 13:54 - 2013-02-09 14:49 - 00000922 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1543283602-3742611817-714404855-1001Core.job
2015-05-28 13:02 - 2014-10-02 11:01 - 00000000 ____D () C:\Users\Sophi_000\AppData\Roaming\Spotify
2015-05-28 12:36 - 2013-01-01 21:23 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1543283602-3742611817-714404855-1005
2015-05-28 12:21 - 2012-12-25 11:51 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-28 12:21 - 2012-09-28 11:26 - 00179910 _____ () C:\WINDOWS\DirectX.log
2015-05-28 12:14 - 2014-04-04 22:49 - 00000000 ____D () C:\Users\Sophi_000\AppData\Roaming\Raptr
2015-05-28 12:13 - 2014-10-02 11:01 - 00000000 ____D () C:\Users\Sophi_000\AppData\Local\Spotify
2015-05-28 12:13 - 2014-08-14 18:44 - 00000000 ____D () C:\Users\Sophi_000\AppData\Local\Overwolf
2015-05-28 11:02 - 2013-01-02 14:40 - 00000000 ____D () C:\Users\Gears123451\AppData\Roaming\TS3Client
2015-05-27 15:44 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-05-27 09:36 - 2015-04-08 21:52 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\CrashDumps
2015-05-26 16:45 - 2014-02-01 20:34 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{ED3E2D24-546B-424D-BAB9-F6328C961A67}
2015-05-26 13:56 - 2013-01-03 09:57 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2015-05-26 08:40 - 2014-10-06 20:52 - 00002210 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-26 08:19 - 2014-08-14 18:44 - 00000000 ____D () C:\Users\Sophi_000\AppData\Roaming\Skype
2015-05-25 21:28 - 2015-01-16 19:12 - 00093696 ___SH () C:\Users\Gears123451\Desktop\Thumbs.db
2015-05-25 16:19 - 2013-12-15 21:40 - 00000000 ____D () C:\Users\Medtech
2015-05-25 14:49 - 2014-12-20 13:26 - 00371712 ___SH () C:\Users\Gears123451\Downloads\Thumbs.db
2015-05-24 13:12 - 2012-12-29 11:13 - 00000000 ____D () C:\Users\Gears123451\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-05-24 09:31 - 2013-01-01 21:17 - 00000000 ____D () C:\Users\Sophi_000\AppData\Local\VirtualStore
2015-05-24 09:16 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-24 09:15 - 2013-11-14 05:34 - 00170028 _____ () C:\WINDOWS\PFRO.log
2015-05-23 17:11 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-05-23 17:06 - 2015-04-04 15:15 - 00000000 ___SD () C:\WINDOWS\SysWOW64\GWX
2015-05-23 17:06 - 2015-04-04 15:15 - 00000000 ___SD () C:\WINDOWS\system32\GWX
2015-05-21 18:54 - 2013-05-26 18:34 - 00000000 ____D () C:\Users\Gears123451\AppData\Roaming\vlc
2015-05-21 11:25 - 2014-05-11 07:13 - 00000000 ____D () C:\Users\Medtech\AppData\Local\TSVNCache
2015-05-21 09:23 - 2012-12-25 09:59 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1543283602-3742611817-714404855-1001
2015-05-21 09:19 - 2014-06-18 20:14 - 00000000 ____D () C:\Users\Medtech\AppData\Local\Overwolf
2015-05-21 09:19 - 2013-08-18 06:47 - 00004647 _____ () C:\autoupdate.log
2015-05-21 09:19 - 2013-08-09 20:11 - 00000000 ____D () C:\Users\Medtech\AppData\Local\Akamai
2015-05-21 09:17 - 2014-09-11 10:57 - 00000000 ___RD () C:\Users\Medtech\OneDrive
2015-05-19 12:37 - 2013-01-17 15:09 - 00025334 _____ () C:\WINDOWS\SysWOW64\Crystal Fireplace.log
2015-05-19 08:04 - 2014-06-05 18:35 - 00000000 ____D () C:\Users\Lauren\AppData\Local\TSVNCache
2015-05-19 07:46 - 2014-04-02 17:06 - 00000000 ____D () C:\Users\Lauren\AppData\Roaming\Spotify
2015-05-19 07:45 - 2012-12-26 18:39 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1543283602-3742611817-714404855-1004
2015-05-19 07:41 - 2014-04-02 17:06 - 00000000 ____D () C:\Users\Lauren\AppData\Local\Spotify
2015-05-19 06:07 - 2014-05-20 16:01 - 00000000 ____D () C:\Users\conor\AppData\Local\TSVNCache
2015-05-19 06:02 - 2012-12-26 11:39 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1543283602-3742611817-714404855-1003
2015-05-19 06:00 - 2014-08-03 13:14 - 00000000 ____D () C:\Users\conor\AppData\Local\Overwolf
2015-05-19 05:59 - 2014-07-09 14:35 - 00000000 ___DO () C:\Users\conor\SkyDrive
2015-05-19 05:58 - 2014-02-23 15:27 - 00000000 ____D () C:\Users\conor\AppData\Roaming\Raptr
2015-05-16 16:34 - 2012-12-28 18:03 - 00003886 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-16 16:34 - 2012-12-28 18:03 - 00003650 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-15 20:25 - 2014-12-16 21:40 - 00385024 ___SH () C:\Users\Gears123451\Thumbs.db
2015-05-14 13:44 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-05-13 15:35 - 2014-03-01 20:00 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-13 15:35 - 2014-03-01 20:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-05-13 15:35 - 2013-08-22 15:44 - 00364920 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-05-13 15:25 - 2013-08-22 14:25 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-13 15:24 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-05-13 15:24 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers
2015-05-13 13:22 - 2013-08-14 13:17 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-13 12:33 - 2012-12-28 19:28 - 140425016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-13 12:27 - 2014-03-01 20:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-13 12:23 - 2013-11-14 13:29 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-13 12:11 - 2015-01-20 09:44 - 01648128 ___SH () C:\Users\Medtech\Downloads\Thumbs.db
2015-05-13 11:55 - 2014-02-22 07:08 - 00003914 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{460270ED-BCBE-48FE-9E33-9B20A06A2194}
2015-05-13 11:41 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-05-12 19:22 - 2014-05-08 14:22 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-11 19:29 - 2013-01-03 10:59 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\LogMeIn Hamachi
2015-05-11 19:26 - 2014-09-13 21:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-11 18:53 - 2014-10-22 20:29 - 00000000 ____D () C:\Program Files (x86)\GalaxyClient
2015-05-11 18:53 - 2014-10-22 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2015-05-10 19:57 - 2013-06-10 17:37 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-05-10 19:56 - 2014-09-13 21:22 - 00001121 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-10 19:56 - 2014-09-13 21:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-10 14:56 - 2015-04-18 10:25 - 00099328 ___SH () C:\Users\Sophi_000\Downloads\Thumbs.db
2015-05-08 17:52 - 2013-04-04 20:09 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-07 19:29 - 2013-11-26 21:47 - 00000000 ____D () C:\Users\Gears123451\Documents\RPGVXAce
2015-05-05 21:00 - 2013-12-15 21:40 - 00000000 ____D () C:\Users\Sophi_000
2015-05-05 18:59 - 2015-03-12 19:15 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-05-05 18:59 - 2015-03-12 19:15 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-05-03 19:49 - 2015-01-16 17:33 - 01475584 ___SH () C:\Users\Lauren\Downloads\Thumbs.db
2015-05-02 10:01 - 2013-01-05 11:23 - 00000000 ____D () C:\Users\Gears123451\AppData\Local\Paint.NET
2015-05-02 09:59 - 2013-01-05 11:20 - 00000000 ____D () C:\Program Files\Paint.NET
2015-05-01 21:34 - 2012-12-31 18:20 - 00000000 ____D () C:\Users\Gears123451\AppData\Roaming\.minecraft
 
==================== Files in the root of some directories =======
 
2014-10-11 11:01 - 2014-10-21 15:34 - 0000004 _____ () C:\Users\Gears123451\AppData\Roaming\appdataFr2.bin
2014-09-14 19:01 - 2014-09-14 19:15 - 0000125 _____ () C:\Users\Gears123451\AppData\Roaming\burnaware.ini
2014-09-14 19:15 - 2014-09-14 19:15 - 0000031 _____ () C:\Users\Gears123451\AppData\Local\burnaware.ini
2015-02-27 20:35 - 2015-02-27 20:35 - 0002743 _____ () C:\Users\Gears123451\AppData\Local\recently-used.xbel
2014-10-21 15:32 - 2014-10-21 15:32 - 0761485 _____ () C:\ProgramData\ChromeTabExtension.crx
2013-10-19 13:22 - 2013-08-20 13:22 - 0000032 ____R () C:\ProgramData\hash.dat
2014-12-20 20:26 - 2014-12-20 20:26 - 0000040 _____ () C:\ProgramData\ra3.ini
2014-09-12 13:30 - 2014-09-12 13:31 - 2465301 _____ () C:\ProgramData\Setup_EZ_YouTube_Video_Downloader_v1.2.4.exe
2014-10-21 15:32 - 2014-10-21 15:32 - 1525193 _____ () C:\ProgramData\yvd_firefox_se.exe
 
Files to move or delete:
====================
C:\ProgramData\hash.dat
C:\ProgramData\Setup_EZ_YouTube_Video_Downloader_v1.2.4.exe
C:\ProgramData\yvd_firefox_se.exe
 
 
Some files in TEMP:
====================
C:\Users\conor\AppData\Local\Temp\i4jdel0.exe
C:\Users\Gears123451\AppData\Local\Temp\HssInstaller.exe
C:\Users\Gears123451\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\Gears123451\AppData\Local\Temp\qing_update.exe
C:\Users\Gears123451\AppData\Local\Temp\Quarantine.exe
C:\Users\Gears123451\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Gears123451\AppData\Local\Temp\sqlite3.dll
C:\Users\Gears123451\AppData\Local\Temp\SRLDetectionLibrary3278438039453944216.dll
C:\Users\Medtech\AppData\Local\Temp\aftvyz1q.dll
C:\Users\Medtech\AppData\Local\Temp\airA3FC.exe
C:\Users\Medtech\AppData\Local\Temp\airBD03.exe
C:\Users\Medtech\AppData\Local\Temp\airCDC.exe
C:\Users\Medtech\AppData\Local\Temp\c8ar-ujk.dll
C:\Users\Medtech\AppData\Local\Temp\dmriwunx.dll
C:\Users\Medtech\AppData\Local\Temp\GdiPlus.dll
C:\Users\Medtech\AppData\Local\Temp\GLF23AB.tmp.dll
C:\Users\Medtech\AppData\Local\Temp\GLF86C5.tmp.dll
C:\Users\Medtech\AppData\Local\Temp\h94wi_mk.dll
C:\Users\Medtech\AppData\Local\Temp\ICReinstall_kindle-for-pc_setup.exe
C:\Users\Medtech\AppData\Local\Temp\InstallerMessageBox.exe
C:\Users\Medtech\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Medtech\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\Medtech\AppData\Local\Temp\mediaimpression_2.0.24.1127.exe
C:\Users\Medtech\AppData\Local\Temp\NPSInstallerProxy.exe
C:\Users\Medtech\AppData\Local\Temp\NPSInstallerProxyMessageBoxHookDll.dll
C:\Users\Medtech\AppData\Local\Temp\oxeo5deq.dll
C:\Users\Medtech\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\Medtech\AppData\Local\Temp\q3xspe66.dll
C:\Users\Medtech\AppData\Local\Temp\Quarantine.exe
C:\Users\Medtech\AppData\Local\Temp\ReimageExpress.exe
C:\Users\Medtech\AppData\Local\Temp\ReimageExpressPackage.exe
C:\Users\Medtech\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Medtech\AppData\Local\Temp\sonarinst.exe
C:\Users\Medtech\AppData\Local\Temp\sqlite3.dll
C:\Users\Medtech\AppData\Local\Temp\sqlite3.exe
C:\Users\Medtech\AppData\Local\Temp\Update_1464.exe
C:\Users\Medtech\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Medtech\AppData\Local\Temp\vlc-2.1.2-win32.exe
C:\Users\Medtech\AppData\Local\Temp\vlc-2.1.3-win32.exe
C:\Users\Medtech\AppData\Local\Temp\vlc-2.1.5-win32.exe
C:\Users\Medtech\AppData\Local\Temp\zoivugwc.dll
C:\Users\Sophi_000\AppData\Local\Temp\80orqmf1.dll
C:\Users\Sophi_000\AppData\Local\Temp\mediaimpression_2.0.24.1127.exe
C:\Users\Sophi_000\AppData\Local\Temp\mediaimpression_2.0.24.1127_2.0.24.1216_update_all.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-26 08:30
 
==================== End of log ============================


#9 nasdaq

nasdaq

  • Malware Response Team
  • 38,228 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:28 AM

Posted 29 May 2015 - 06:52 AM

If you have set this proxy and know that it's needed leave it alone.
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled
ProxyServer: [.DEFAULT] => http=127.0.0.1:50764;https=127.0.0.1:50764


If you wish to remove it add both lines in bold to the fix below before saving the fixlist.txt file.

===

Run this tool to clean your Temporary files/Folders.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program.
  • TFC will close all open programs itself in order to run.
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted, it should not take long to finish.
  • Once it's finished, click OK to reboot.
  • If it does not reboot, reboot your system manually.
===

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.
 
start

CreateRestorePoint:
CloseProcesses:

HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
CHR Extension: (Avast Online Security) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-06]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-18]
S2 MsgPlusService; "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [X]
S3 ArcCD; No ImagePath
U1 ArcRec; No ImagePath
S4 ArcUdfs; No ImagePath
U0 yrat; C:\Windows\System32\drivers\tlwbnc.sys [79064 2015-05-28] (Malwarebytes Corporation)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
C:\Windows\System32\drivers\tlwbnc.sys

End
Save the files as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

How is the computer running now?

#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,228 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:28 AM

Posted 03 June 2015 - 08:16 AM

Are you still with me?

#11 aVeryConfusedMan

aVeryConfusedMan
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 06 June 2015 - 04:05 AM

Sorry about the unresponsiveness :P



#12 aVeryConfusedMan

aVeryConfusedMan
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 06 June 2015 - 04:30 AM

fixlog.txt

Fix result of Farbar Recovery Scan Tool (x64) Version:03-06-2015
Ran by Gears123451 at 2015-06-06 10:16:52 Run:1
Running from C:\Program Files (x86)\FRST64
Loaded Profiles: Gears123451 (Available Profiles: Medtech & Gears123451 & conor & Lauren & GreyHarlequin)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
 
CreateRestorePoint:
CloseProcesses:
 
HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe /applicationMode:systemTray /showWelcome:false
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\...\Run: [Itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
CHR Extension: (Avast Online Security) - C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-06]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-18]
S2 MsgPlusService; "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [X]
S3 ArcCD; No ImagePath
U1 ArcRec; No ImagePath
S4 ArcUdfs; No ImagePath
U0 yrat; C:\Windows\System32\drivers\tlwbnc.sys [79064 2015-05-28] (Malwarebytes Corporation)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
C:\Windows\System32\drivers\tlwbnc.sys
 
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => value removed successfully
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Driver Support => value removed successfully
HKU\S-1-5-21-1543283602-3742611817-714404855-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Itibiti.exe => value removed successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
C:\Users\Gears123451\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki => moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki" => key removed successfully
Could not move "C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx" => Scheduled to move on reboot.
MsgPlusService => Service removed successfully
ArcCD => Service removed successfully
ArcRec => Service removed successfully
ArcUdfs => Service removed successfully
yrat => Service not found.
FairplayKD => Service removed successfully
"C:\Windows\System32\drivers\tlwbnc.sys" => File/Folder not found.

Attached Files



#13 aVeryConfusedMan

aVeryConfusedMan
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 06 June 2015 - 04:32 AM

The computer is still coming up with the alert whenever chrome is opened. (In reply to your last question)



#14 nasdaq

nasdaq

  • Malware Response Team
  • 38,228 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:28 AM

Posted 06 June 2015 - 07:14 AM

Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png which is located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset browser settings" button.
 
Clear your cache and cookies
https://support.google.com/chromebook/answer/183083?hl=en

Restart Chrome.

====

Keep me posted.

#15 aVeryConfusedMan

aVeryConfusedMan
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:10:28 AM

Posted 07 June 2015 - 05:20 AM

That seems to have done it, hopefully it will stay that way, thank you if it does work!


Edited by aVeryConfusedMan, 07 June 2015 - 10:05 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users