Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan horse msil9 AQGQ


  • This topic is locked This topic is locked
3 replies to this topic

#1 lehameli

lehameli

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:28 PM

Posted 03 December 2015 - 08:54 AM

Hello,

 

My friend have joined a teamspeak server today and it asked him to download (ts3_sound_plugin.exe), which he downloaded but didn't open, so i have ran a scan with Malwarebytes and AVG Free, and the file was a virus (Trojan horse msil9 AQGQ). I have removed the trojan but just to be safe im posting and attaching FRST logs.

 

-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:01-12-2015

Ran by User (administrator) on USER-PC (03-12-2015 17:39:49)
Running from D:\Downloads
Loaded Profiles: User (Available Profiles: User)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(BitTorrent Inc.) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BitTorrent Inc.) C:\Users\User\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(BitTorrent Inc.) C:\Users\User\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
(Curse, Inc) C:\Users\User\AppData\Roaming\Curse Client\Bin\Curse.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\User\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7156296 2013-03-05] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2685072 2015-05-01] (NVIDIA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [13318424 2015-03-12] (Logitech Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [590144 2015-04-22] (Razer Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\Run: [uTorrent] => C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-12-03] (BitTorrent Inc.)
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\Run: [Advanced SystemCare 8] => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe [2428704 2015-01-20] (IObit)
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {60319aa3-5b63-11e3-abc4-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {60319b3f-5b63-11e3-abc4-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {a828ed44-8cd9-11e4-bc20-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {d9cf11c9-2219-11e3-ab54-806e6f6e6963} - D:\autorun.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {e4e235eb-e7df-11e3-abbe-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2015-12-03]
ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2015-12-03]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2015-12-03]
ShortcutTarget: Curse.lnk -> C:\Users\User\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{07630D4D-6ABE-4C8A-8942-421BA286C39E}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://uae.msn.com/?rd=1&ucc=AE&dcc=AE&opt=0&ocid=iehp
SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1421853438&from=zbd1&uid=corsairxforcexgs_13347907000098730069&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000 -> {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = hxxp://www.v9.com/web?type=ds&ts=1421853438&from=zbd1&uid=corsairxforcexgs_13347907000098730069&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000 -> {AE41E78F-0D9A-4F8E-ACAB-7EB9E34993DD} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10511
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-02-13] (IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-10-13] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-10-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-13] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-13] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-10-13] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2014-10-17] (IObit)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-13] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-13] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-13] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-09-17] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-10-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-10-16] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll [2008-04-28] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll [2008-04-28] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2008-04-28] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2008-04-28] (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1886107439-1478614267-3997763490-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-08-08] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2008-04-28] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll [2008-04-28] (RealNetworks, Inc.)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\pdf.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll => No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (AdBlock) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-24]
CHR Extension: (Skype Click to Call) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-10-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
CHR Extension: (AdBlock Pro) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-11-05]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdvancedSystemCareService8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [815392 2014-11-04] (IObit)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [927232 2012-10-29] ()
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2797752 2015-10-13] (Microsoft Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-05-01] (NVIDIA Corporation)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [344864 2015-01-27] (IObit)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-30] (IObit)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1884304 2015-05-01] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22997648 2015-05-01] (NVIDIA Corporation)
S3 Origin Client Service; D:\Origin\OriginClientService.exe [2078216 2015-10-02] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-03-31] ()
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] ()
S2 RealPlayer Cloud Service; C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [1141848 2015-02-16] (RealNetworks, Inc.)
R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-21] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [302000 2015-10-08] (AVG Technologies CZ, s.r.o.)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [496400 2013-02-27] (Intel Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
S4 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2014-11-10] (IObit)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-11-18] (REALiX™)
S3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2008-10-16] (Logitech Inc.)
S3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-05-01] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2014-11-10] (IObit.com)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [28416 2008-04-16] (Research In Motion Limited)
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-12-30] (Razer Inc)
R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.)
S3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [35496 2014-12-30] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-02-05] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2015-03-03] (Razer, Inc.)
R3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [32792 2015-07-01] (SteelSeries ApS)
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2014-11-10] (IObit.com)
R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [21504 2008-12-26] (Avnex)
S3 9nlALiZMy; \??\C:\Windows\system32\drivers\9nlALiZMy.sys [X]
S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-03 17:38 - 2015-12-03 17:39 - 00000000 ____D C:\FRST
2015-12-03 17:33 - 2015-12-03 17:33 - 00000000 ___HD C:\OneDriveTemp
2015-12-03 17:33 - 2015-12-03 17:33 - 00000000 ____D C:\Users\User\AppData\LocalLow\uTorrent
2015-12-03 17:27 - 2015-12-03 17:27 - 00000000 ____D C:\Users\User\AppData\Roaming\AVG
2015-12-03 17:26 - 2015-12-03 17:26 - 00000000 ___HD C:\$AVG
2015-12-03 17:26 - 2015-12-03 17:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-12-03 17:26 - 2015-12-03 17:26 - 00000000 ____D C:\Program Files\Common Files\AV
2015-12-03 17:25 - 2015-12-03 17:33 - 00000898 _____ C:\Users\Public\Desktop\AVG.lnk
2015-12-03 17:25 - 2015-12-03 17:27 - 00000000 ____D C:\Users\User\AppData\Local\Avg
2015-12-03 17:25 - 2015-12-03 17:27 - 00000000 ____D C:\ProgramData\MFAData
2015-12-03 17:25 - 2015-12-03 17:26 - 00000000 ____D C:\ProgramData\Avg
2015-12-03 17:25 - 2015-12-03 17:26 - 00000000 ____D C:\Program Files (x86)\AVG
2015-12-03 17:25 - 2015-12-03 17:25 - 00000000 ____D C:\Users\User\AppData\Local\MFAData
2015-12-03 17:25 - 2015-12-03 17:25 - 00000000 ____D C:\Users\User\AppData\Local\AvgSetupLog
2015-12-03 17:25 - 2015-12-03 17:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2015-12-03 17:18 - 2015-12-03 17:18 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client
2015-11-30 23:52 - 2015-12-01 04:50 - 00000050 _____ C:\Users\User\Desktop\New Text Document (2).txt
2015-11-18 19:13 - 2015-12-03 17:36 - 00003238 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler
2015-11-18 19:13 - 2015-12-03 17:36 - 00002870 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (User)
2015-11-18 19:13 - 2015-12-03 17:33 - 00002150 _____ C:\Users\Public\Desktop\Driver Booster 3.lnk
2015-11-18 19:13 - 2015-11-18 19:13 - 00026528 _____ (REALiX™) C:\Windows\SysWOW64\Drivers\HWiNFO64A.SYS
2015-11-18 19:13 - 2015-11-18 19:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 3
2015-11-12 16:07 - 2015-11-03 21:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-11 22:21 - 2015-11-04 02:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-11-11 22:21 - 2015-11-04 01:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-11-11 22:21 - 2015-10-31 03:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-11 22:21 - 2015-10-31 03:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-11 22:21 - 2015-10-31 03:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 22:21 - 2015-10-31 03:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-11 22:21 - 2015-10-31 03:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-11 22:21 - 2015-10-31 03:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-11-11 22:21 - 2015-10-31 03:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-11-11 22:21 - 2015-10-31 03:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-11 22:21 - 2015-10-31 03:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-11-11 22:21 - 2015-10-31 03:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-11 22:21 - 2015-10-31 03:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-11-11 22:21 - 2015-10-31 03:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-11 22:21 - 2015-10-31 03:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-11 22:21 - 2015-10-31 03:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-11-11 22:21 - 2015-10-31 03:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-11 22:21 - 2015-10-31 03:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-11 22:21 - 2015-10-31 03:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-11-11 22:21 - 2015-10-31 03:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 22:21 - 2015-10-31 03:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-11 22:21 - 2015-10-31 02:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-11-11 22:21 - 2015-10-31 02:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 22:21 - 2015-10-31 02:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-11-11 22:21 - 2015-10-31 02:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-11-11 22:21 - 2015-10-31 02:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-11 22:21 - 2015-10-31 02:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-11-11 22:21 - 2015-10-31 02:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-11 22:21 - 2015-10-31 02:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-11-11 22:21 - 2015-10-31 02:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-11-11 22:21 - 2015-10-31 02:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-11-11 22:21 - 2015-10-31 02:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-11-11 22:21 - 2015-10-31 02:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-11-11 22:21 - 2015-10-31 02:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-11-11 22:21 - 2015-10-31 02:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-11-11 22:21 - 2015-10-31 02:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-11-11 22:21 - 2015-10-31 02:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-11-11 22:21 - 2015-10-31 02:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-11-11 22:21 - 2015-10-31 02:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-11-11 22:21 - 2015-10-31 02:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-11-11 22:21 - 2015-10-31 02:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-11-11 22:21 - 2015-10-31 02:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-11-11 22:21 - 2015-10-31 02:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-11 22:21 - 2015-10-31 02:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-11 22:21 - 2015-10-31 02:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-11-11 22:21 - 2015-10-31 02:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-11-11 22:21 - 2015-10-31 02:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-11-11 22:21 - 2015-10-31 02:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-11 22:21 - 2015-10-31 02:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-11-11 22:21 - 2015-10-31 02:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-11-11 22:21 - 2015-10-31 02:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-11-11 22:21 - 2015-10-31 02:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-11 22:21 - 2015-10-31 02:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-11-11 22:21 - 2015-10-31 02:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-11-11 22:21 - 2015-10-31 02:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-11-11 22:21 - 2015-10-31 02:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-11-11 22:21 - 2015-10-31 02:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-11-11 22:21 - 2015-10-31 02:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-11-11 22:21 - 2015-10-31 02:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-11-11 22:21 - 2015-10-31 02:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-11 22:21 - 2015-10-31 01:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-11-11 22:21 - 2015-10-31 01:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-11-11 22:21 - 2015-10-31 01:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-11-11 22:21 - 2015-10-31 01:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-11-11 22:21 - 2015-10-20 22:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-11-11 22:21 - 2015-10-20 22:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-11-11 22:21 - 2015-10-20 22:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-11-11 22:21 - 2015-10-20 22:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-11-11 22:21 - 2015-10-20 22:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-11-11 22:21 - 2015-10-20 22:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-11-11 22:21 - 2015-10-20 22:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-11-11 22:21 - 2015-10-20 22:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-11-11 22:21 - 2015-10-20 22:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-11-11 22:21 - 2015-10-20 22:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-11-11 22:21 - 2015-10-20 22:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 22:21 - 2015-10-20 21:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-11-11 22:21 - 2015-10-20 21:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-11-11 22:21 - 2015-10-20 21:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-11-11 22:21 - 2015-10-20 21:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-11-11 22:21 - 2015-10-20 21:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-11-11 22:21 - 2015-10-20 05:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-11 22:21 - 2015-10-20 05:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-11-11 22:21 - 2015-10-20 05:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-11 22:21 - 2015-10-20 05:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-11 22:21 - 2015-10-20 05:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-11-11 22:21 - 2015-10-20 05:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-11-11 22:21 - 2015-10-20 05:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-11-11 22:21 - 2015-10-20 05:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-11-11 22:21 - 2015-10-20 05:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-11-11 22:21 - 2015-10-20 05:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-11-11 22:21 - 2015-10-20 05:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-11-11 22:21 - 2015-10-20 05:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-11-11 22:21 - 2015-10-20 05:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-11-11 22:21 - 2015-10-20 05:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-11-11 22:21 - 2015-10-20 05:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-11-11 22:21 - 2015-10-20 04:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-11-11 22:21 - 2015-10-20 04:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-11-11 22:21 - 2015-10-20 04:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-11-11 22:21 - 2015-10-20 04:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-11-11 22:21 - 2015-10-20 04:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-11-11 22:21 - 2015-10-20 04:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-11-11 22:21 - 2015-10-20 04:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-11-11 22:21 - 2015-10-20 04:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-11-11 22:21 - 2015-10-20 04:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-11-11 22:21 - 2015-10-20 04:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-11-11 22:21 - 2015-10-20 04:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-11-11 22:21 - 2015-10-20 04:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-11-11 22:21 - 2015-10-20 04:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 04:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 03:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-11-11 22:21 - 2015-10-20 03:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-11-11 22:21 - 2015-10-20 03:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-11-11 22:21 - 2015-10-20 03:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-11-11 22:21 - 2015-10-20 03:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-11-11 22:21 - 2015-10-20 03:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 03:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 03:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 22:21 - 2015-10-20 03:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 22:21 - 2015-09-23 17:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-11-11 22:21 - 2015-09-23 17:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2015-11-11 22:21 - 2015-09-23 17:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2015-11-11 22:20 - 2015-10-29 21:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-11-11 22:20 - 2015-10-29 21:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-11-11 22:20 - 2015-10-29 21:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-11-11 22:20 - 2015-10-29 21:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-11-11 22:20 - 2015-10-29 21:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-11-11 22:20 - 2015-10-29 21:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-11-11 22:20 - 2015-10-29 21:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-11-11 22:20 - 2015-10-13 20:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-11 22:20 - 2015-10-13 20:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-11 22:20 - 2015-10-13 08:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-11 22:20 - 2015-10-01 22:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-11-11 22:20 - 2015-10-01 22:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-11-11 22:20 - 2015-10-01 21:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-11-06 15:50 - 2015-11-06 15:50 - 00184240 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys
2015-11-06 15:49 - 2015-11-06 15:49 - 00313776 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2015-11-06 15:49 - 2015-11-06 15:49 - 00256432 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-12-03 17:39 - 2009-07-14 09:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-03 17:39 - 2009-07-14 07:20 - 00000000 ____D C:\Windows\inf
2015-12-03 17:38 - 2013-10-18 11:59 - 00000000 ____D C:\Users\User\AppData\Roaming\uTorrent
2015-12-03 17:38 - 2009-07-14 07:20 - 00000000 ____D C:\Windows
2015-12-03 17:33 - 2015-10-15 21:30 - 00001167 _____ C:\Users\User\Desktop\Voice Changer 7.0 .lnk
2015-12-03 17:33 - 2015-08-07 21:32 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2015-12-03 17:33 - 2015-03-31 16:47 - 00000793 _____ C:\Users\Public\Desktop\Battlefield Hardline.lnk
2015-12-03 17:33 - 2015-03-31 13:38 - 00000637 _____ C:\Users\Public\Desktop\Origin.lnk
2015-12-03 17:33 - 2015-03-06 08:16 - 00001747 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-12-03 17:33 - 2015-02-20 12:44 - 00001100 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-03 17:33 - 2015-02-13 01:57 - 00002163 _____ C:\Users\Public\Desktop\Advanced SystemCare 8.lnk
2015-12-03 17:33 - 2015-01-01 21:39 - 00002631 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time 3.2.lnk
2015-12-03 17:33 - 2015-01-01 21:39 - 00002625 _____ C:\Users\Public\Desktop\Popcorn Time 3.2.lnk
2015-12-03 17:33 - 2014-10-04 21:50 - 00000807 _____ C:\Users\User\Desktop\Steam - Shortcut.lnk
2015-12-03 17:33 - 2014-09-17 18:46 - 00002154 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-12-03 17:33 - 2014-09-17 18:46 - 00000000 ___RD C:\Users\User\OneDrive
2015-12-03 17:33 - 2014-09-03 18:11 - 00002659 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk
2015-12-03 17:33 - 2014-07-30 14:18 - 00000960 _____ C:\Users\Public\Desktop\FIFA 14.lnk
2015-12-03 17:33 - 2014-07-09 03:33 - 00001187 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk
2015-12-03 17:33 - 2014-06-30 03:28 - 00001213 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-12-03 17:33 - 2014-06-30 03:28 - 00001183 _____ C:\Users\Public\Desktop\GOM Player.lnk
2015-12-03 17:33 - 2014-06-13 19:28 - 00001034 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk
2015-12-03 17:33 - 2014-06-13 19:28 - 00001028 _____ C:\Users\User\Desktop\Curse.lnk
2015-12-03 17:33 - 2014-06-13 19:28 - 00000000 ____D C:\Users\User\AppData\Roaming\Curse Client
2015-12-03 17:33 - 2014-06-07 22:01 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-03 17:33 - 2014-05-26 15:30 - 00001182 _____ C:\Users\User\Desktop\Play Super Mario Bros..lnk
2015-12-03 17:33 - 2014-04-19 22:15 - 00001138 _____ C:\Users\Public\Desktop\Diablo III.lnk
2015-12-03 17:33 - 2014-04-18 22:34 - 00001205 _____ C:\Users\User\Desktop\Uplay.lnk
2015-12-03 17:33 - 2014-03-22 22:04 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live ID.lnk
2015-12-03 17:33 - 2014-03-19 19:29 - 00002691 _____ C:\Users\Public\Desktop\Skype.lnk
2015-12-03 17:33 - 2014-03-01 21:15 - 00001748 _____ C:\Users\User\Desktop\WildStar.lnk
2015-12-03 17:33 - 2014-02-28 00:36 - 00001144 _____ C:\Users\Public\Desktop\Battle.net.lnk
2015-12-03 17:33 - 2013-12-14 20:07 - 00001154 _____ C:\Users\Public\Desktop\Movavi Video Converter 14.lnk
2015-12-03 17:33 - 2013-12-14 19:58 - 00001035 _____ C:\Users\Public\Desktop\Avidemux 2.6 (32-bit).lnk
2015-12-03 17:33 - 2013-10-13 23:39 - 00001160 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-12-03 17:33 - 2013-10-03 03:47 - 00001078 _____ C:\Users\Public\Desktop\BattlePing.lnk
2015-12-03 17:33 - 2013-09-27 17:58 - 00001607 _____ C:\Users\Public\Desktop\Play League of Legends.lnk
2015-12-03 17:33 - 2013-09-21 23:43 - 00000917 _____ C:\Users\User\Desktop\Ventrilo.lnk
2015-12-03 17:33 - 2013-09-21 03:31 - 00001376 _____ C:\Users\User\Desktop\FFXIV.lnk
2015-12-03 17:33 - 2013-09-21 03:00 - 00001011 _____ C:\Users\User\Desktop\FixMyLag.lnk
2015-12-03 17:33 - 2013-09-21 01:43 - 00001375 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2015-12-03 17:33 - 2013-09-21 01:40 - 00002177 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-03 17:33 - 2013-09-21 01:40 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-03 17:33 - 2013-09-20 21:40 - 00000000 ____D C:\ProgramData\NVIDIA
2015-12-03 17:33 - 2013-09-20 21:17 - 00001007 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-12-03 17:33 - 2013-09-20 12:16 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-12-03 17:33 - 2013-09-20 12:16 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-12-03 17:33 - 2009-07-14 09:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-12-03 17:33 - 2009-07-14 09:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-03 17:33 - 2009-07-14 09:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2015-12-03 17:33 - 2009-07-14 08:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-12-03 17:33 - 2009-07-14 08:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2015-12-03 17:33 - 2009-07-14 08:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2015-12-03 17:33 - 2009-07-14 08:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2015-12-03 17:33 - 2009-07-14 08:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2015-12-03 17:33 - 2009-07-14 08:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2015-12-03 17:32 - 2015-09-19 00:16 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-12-03 17:29 - 2013-10-13 23:39 - 00000000 ____D C:\Users\User\AppData\Roaming\TS3Client
2015-12-03 17:29 - 2013-09-21 02:40 - 00001945 _____ C:\Windows\epplauncher.mif
2015-12-03 17:26 - 2013-10-16 04:22 - 00000000 ____D C:\Users\User\AppData\Roaming\TuneUp Software
2015-12-03 17:25 - 2015-02-20 12:44 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-03 17:22 - 2015-02-20 12:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-03 17:22 - 2015-02-20 12:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-03 17:19 - 2009-07-14 08:45 - 00032096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-03 17:19 - 2009-07-14 08:45 - 00032096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-03 17:14 - 2014-07-09 08:17 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-03 15:49 - 2013-09-21 01:40 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-03 02:05 - 2014-04-26 23:40 - 00000000 ____D C:\Users\User\AppData\Local\TSVNCache
2015-12-02 15:49 - 2013-09-20 13:15 - 00000000 ____D C:\Windows\Panther
2015-11-30 00:03 - 2015-02-13 01:57 - 00000000 ____D C:\ProgramData\ProductData
2015-11-28 18:26 - 2009-07-14 09:08 - 00032536 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-11-27 20:34 - 2015-07-29 21:16 - 00000206 _____ C:\Users\User\Desktop\steam account.txt
2015-11-25 12:16 - 2014-09-17 18:42 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-11-25 12:16 - 2014-09-17 18:40 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-11-22 20:46 - 2009-07-14 07:20 - 00000000 ____D C:\Windows\system32\NDF
2015-11-19 22:10 - 2015-10-30 13:42 - 00000000 ___HD C:\$WINDOWS.~BT
2015-11-18 19:13 - 2015-02-13 01:55 - 00000000 ____D C:\Users\User\AppData\Roaming\IObit
2015-11-18 19:13 - 2015-02-13 01:54 - 00000000 ____D C:\ProgramData\IObit
2015-11-18 19:12 - 2015-02-13 01:54 - 00000000 ____D C:\Program Files (x86)\IObit
2015-11-18 19:11 - 2014-09-10 14:14 - 00506880 ___SH C:\Users\User\Desktop\Thumbs.db
2015-11-13 00:39 - 2013-10-13 23:39 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2015-11-12 18:56 - 2009-07-14 08:45 - 00327496 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-12 03:47 - 2009-07-14 07:20 - 00000000 ____D C:\Windows\rescache
2015-11-12 03:07 - 2014-08-30 14:15 - 00000000 ____D C:\Windows\system32\MRT
2015-11-12 03:04 - 2014-08-30 14:15 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-11-12 03:00 - 2013-09-21 01:42 - 00774592 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-11-12 03:00 - 2011-04-12 12:28 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 01:14 - 2014-07-09 08:17 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-11-11 01:14 - 2014-07-09 08:17 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-11 01:14 - 2014-07-09 08:17 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
 
==================== Files in the root of some directories =======
 
2014-10-20 23:10 - 2014-11-05 14:23 - 0000004 _____ () C:\Users\User\AppData\Roaming\appdataFr2.bin
2013-10-03 03:47 - 2013-10-03 03:47 - 0000038 ___SH () C:\Users\User\AppData\Local\1754111884ee9ab5277ca00.95260103
2015-04-08 17:20 - 2015-04-08 17:20 - 0003584 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-01 22:45 - 2015-01-01 22:45 - 0628496 _____ (CMI Limited) C:\Users\User\AppData\Local\nsb91D8.tmp
2015-01-26 04:05 - 2015-01-26 04:05 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nso3047.tmp
2015-01-16 19:51 - 2015-01-16 19:51 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nsu5DCB.tmp
2015-01-27 16:27 - 2015-01-27 16:27 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nsv28C.tmp
2015-01-22 19:47 - 2015-01-22 19:47 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nsxE801.tmp
2014-07-07 06:03 - 2014-07-09 07:28 - 0000600 _____ () C:\Users\User\AppData\Local\PUTTY.RND
2013-10-03 23:15 - 2015-02-20 12:43 - 0007624 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-11-30 02:01
 
==================== End of FRST.txt ============================
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:01-12-2015
Ran by User (2015-12-03 17:40:05)
Running from D:\Downloads
Windows 7 Professional Service Pack 1 (X64) (2013-09-20 17:17:20)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1886107439-1478614267-3997763490-500 - Administrator - Disabled)
Guest (S-1-5-21-1886107439-1478614267-3997763490-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1886107439-1478614267-3997763490-1005 - Limited - Enabled)
User (S-1-5-21-1886107439-1478614267-3997763490-1000 - Administrator - Enabled) => C:\Users\User
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
7-Zip 4.65 (HKLM-x32\...\7-Zip) (Version:  - )
AC3Filter 2.5b (HKLM-x32\...\AC3Filter_is1) (Version: 2.5b - Alexander Vigovsky)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Advanced SystemCare 8 (HKLM-x32\...\Advanced SystemCare 8_is1) (Version: 8.1.0 - IObit)
Apple Application Support (32-bit) (HKLM-x32\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ApptoU (HKLM-x32\...\{01B91C29-337A-1FFD-7CFC-473451D2F861}) (Version:  - ApptoU) <==== ATTENTION
ARK: Survival Evolved (HKLM-x32\...\Steam App 346110) (Version:  - Studio Wildcard)
AV Voice Changer Software 7.0 (HKLM-x32\...\AV Voice Changer Software 7.0) (Version: 7.0.62 - AVSOFT Corp.)
AVG (HKLM\...\AvgZen) (Version: 1.22.1.40089 - AVG Technologies)
AVG (Version: 16.12.7294 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4477 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.12.7294 - AVG Technologies)
AVG Zen (Version: 1.22.1 - AVG Technologies) Hidden
Avidemux 2.6 (32-bit) (HKLM-x32\...\Avidemux 2.6) (Version: 2.6.7.8981 - )
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.3.2.3825 - Electronic Arts)
Battlefield™ Hardline (HKLM-x32\...\{CB4AC3DA-8CC1-4516-86DA-4078B57DB229}) (Version: 1.0.0.1 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB)
BattlePing 1.3.2.6 (HKLM-x32\...\BattlePing) (Version: 1.3.2.6 - BattlePing)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version:  - Infinity Ward)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version:  - Infinity Ward)
Counter-Strike (HKLM-x32\...\Steam App 10) (Version:  - Valve)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
DARK SOULS™ II (HKLM-x32\...\Steam App 236430) (Version:  - FromSoftware, Inc)
Demonbuddy (HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\{48170409-8a29-4ede-8eba-3f0e181862b6}) (Version: 1.0.1819.357 - Bossland GmbH)
Demonbuddy (x32 Version: 1.0.1819.357 - Bossland GmbH) Hidden
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Driver Booster 3.0 (HKLM-x32\...\Driver Booster_is1) (Version: 3.0 - IObit)
Evolve (HKLM-x32\...\Steam App 273350) (Version:  - Turtle Rock Studios)
FIFA 14 (HKLM-x32\...\{AA7A2800-1E75-4240-855B-03AFF8E5171E}) (Version: 1.0.0.7 - Electronic Arts)
FixMyLag (HKLM-x32\...\FixMyLag) (Version:  - )
FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.67.5221 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version:  - Rockstar North)
H1Z1 (HKLM-x32\...\Steam App 295110) (Version:  - Daybreak Games)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel® Network Connections 18.1.59.0 (HKLM\...\PROSetDX) (Version: 18.1.59.0 - Intel)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
IObit Malware Fighter 3 (HKLM-x32\...\IObit Malware Fighter_is1) (Version: 3.0 - IObit)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.2.6.2 - IObit)
iTunes (HKLM\...\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version:  - Squad)
Killer is Dead (HKLM-x32\...\Steam App 261110) (Version:  - KADOKAWA GAMES / GRASSHOPPER MANUFACTURE)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Logitech Gaming Software 8.58 (HKLM\...\Logitech Gaming Software) (Version: 8.58.183 - Logitech Inc.)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 15.0.4771.1004 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\OneDriveSetup.exe) (Version: 17.3.6201.1019 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Middle-earth: Shadow of Mordor (HKLM-x32\...\Steam App 241930) (Version:  - Monolith Productions, Inc.)
Movavi Video Converter 14 (HKLM-x32\...\Movavi Video Converter 14) (Version: 14.0.0 - Movavi)
Mumble 1.2.4 (HKLM-x32\...\{E0955568-4353-4C85-8988-285A8C0F5E87}) (Version: 1.2.4 - Thorvald Natvig)
NETGEAR WNDA4100 (x32 Version: 1.2.0.2 - NETGEAR) Hidden
NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 344.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.48 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.3.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.3.22 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.48 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4771.1004 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4771.1004 - Microsoft Corporation) Hidden
Oracle VM VirtualBox 4.3.24 (HKLM\...\{15E093DF-951E-46CB-B3EC-E1287E7A2319}) (Version: 4.3.24 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.11.2855 - Electronic Arts, Inc.)
Popcorn Time 3.2 (HKLM-x32\...\{DB38DEFC-4E95-49A8-8AEF-E8ED60398444}) (Version: 3.2.1 - Popcorn Time Free)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.994 - Even Balance, Inc.)
Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.66 - Razer Inc)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.25502 - Razer Inc.)
Real Alternative 1.8.0 (HKLM-x32\...\RealAlt_is1) (Version: 1.8.0 - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6853 - Realtek Semiconductor Corp.)
RISK Factions (HKLM-x32\...\Steam App 47800) (Version:  - Stainless Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.6.0 - SAMSUNG Electronics Co., Ltd.)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.3.22 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.10 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.10.101 - Skype Technologies S.A.)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SteelSeries Engine 3.4.4.1 (HKLM\...\SteelSeries Engine 3) (Version: 3.4.4.1 - SteelSeries ApS)
Stranded Deep (HKLM-x32\...\Steam App 313120) (Version:  - Beam Team Games)
Super Mario Bros. (HKLM-x32\...\Super Mario Bros._is1) (Version:  - DotNes)
Super Street Fighter IV: Arcade Edition (HKLM-x32\...\Steam App 45760) (Version:  - Capcom)
Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.2 - IObit)
Surgeon Simulator 2013 (HKLM-x32\...\Steam App 233720) (Version:  - Bossa Studios)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
The Forest (HKLM-x32\...\Steam App 242760) (Version:  - Endnight Games Ltd)
The Walking Dead: Season Two (HKLM-x32\...\Steam App 261030) (Version:  - Telltale Games)
The Wolf Among Us (HKLM-x32\...\Steam App 250320) (Version:  - Telltale Games)
TortoiseSVN 1.8.6.25419 (64 bit) (HKLM\...\{0DD7C466-163D-4901-AD4B-E78EEFD7FE01}) (Version: 1.8.25419 - TortoiseSVN)
TrackMania United (HKLM-x32\...\Steam App 7200) (Version:  - Nadeo)
Trials Fusion - Closed Beta (HKLM-x32\...\Steam App 284480) (Version:  - RedLynx)
Trials Fusion (HKLM-x32\...\Steam App 245490) (Version:  - RedLynx, in collaboration with  Ubisoft Shanghai, Ubisoft Kiev)
Unity Web Player (HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\UnityWebPlayer) (Version: 4.5.3f3 - Unity Technologies ApS)
Unturned (HKLM-x32\...\Steam App 304930) (Version:  - Nelson Sexton)
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden
Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WildStar (HKLM-x32\...\WildStar) (Version: 1.0.0.6525 - NCSOFT)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR 5.30 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.1 - win.rar GmbH)
World of Warcraft Classic (HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\{D55ED80F-FAFD-40E1-99FC-89AF8614A9B5}_is1) (Version: 1.12.1.5875 - Blizzard Entertainment)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\User\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)
 
==================== Restore Points =========================
 
22-11-2015 23:55:20 Windows Update
27-11-2015 22:11:09 Windows Update
01-12-2015 15:55:52 Windows Update
03-12-2015 17:26:14 Installed AVG 2016
03-12-2015 17:26:20 Installed AVG
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 06:34 - 2009-06-11 01:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {14F3E66F-8C4B-487D-ABB3-3F23895E41D4} - System32\Tasks\ASC8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 8\Monitor.exe [2015-01-23] (IObit)
Task: {2A077B5D-AA94-4202-B182-C88A9A77A9C7} - System32\Tasks\{F6D72313-DE2F-4759-835A-AF7931604B35} => pcalua.exe -a C:\ProgramData\aadsy\oT8zQq4LPiMYwN.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {35D2DD2E-F8B8-4E9F-AD23-AE4FD0564CD1} - System32\Tasks\{E93D536F-12D4-4762-B6E8-806DA1CBA0D8} => Chrome.exe hxxp://ui.skype.com/ui/0/7.1.0.105/en/abandoninstall?page=tsProgressBar
Task: {3A17718D-2E0D-4090-92A7-A376847537A8} - System32\Tasks\{67312D4E-3080-436A-9ED4-2975B6A3183F} => pcalua.exe -a C:\ProgramData\DiIgiCooUpon\BTGrqf5PzHc1yJ.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {42AB975F-2692-49AE-8432-DCABDFE2BA61} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {45BE3EEB-8897-41D7-BAA2-9585D484AF8A} - System32\Tasks\Driver Booster SkipUAC (User) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-10-08] (IObit)
Task: {4C9D0095-21BE-4126-81C8-621EF7135B4C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {535019A9-A3CD-4330-A71F-594278FA5A2C} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-09-24] (IObit)
Task: {551991D8-66D9-40D0-A077-9EA7EB067846} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {553E2649-34D8-472F-8F59-BDF413AF7406} - System32\Tasks\{49228912-8A08-46F4-A53A-D5809B008A91} => C:\Users\User\Desktop\FFXIVAPP.Client.exe [2014-01-12] (ZAMNetworkLLC)
Task: {59ACD382-97B0-4974-AE99-38E4EF40A619} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)
Task: {5C19288D-581A-4028-AC41-19BE7A3C2FA1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)
Task: {71169C6B-3A58-4D40-B20C-19161B4A9830} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)
Task: {718BC62D-3008-4F74-A7F8-7064A4132D41} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {9178B5F1-4FFC-4716-9975-75325C3CBC4C} - System32\Tasks\{B377CF71-52A2-47DA-AAB6-F1DCFCB04146} => Chrome.exe hxxp://ui.skype.com/ui/0/7.1.0.105/en/abandoninstall?page=tsProgressBar
Task: {9BCFD8C6-5367-45C6-B61D-74E6C2039C59} - System32\Tasks\{BC192FD4-E7AF-4CA5-9CAF-6BB6465C7211} => Chrome.exe hxxp://ui.skype.com/ui/0/7.5.85.101/en/abandoninstall?page=tsProgressBar
Task: {A14E7A28-F315-45A7-B206-AC7835B29157} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1886107439-1478614267-3997763490-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {A2766981-445D-440D-89FF-01056316BBF8} - System32\Tasks\Microsoft\Windows\Setup\xtgt\refreshxtgtconfig => C:\Windows\system32\XTgt\XTgtMgr.exe [2015-10-05] (Microsoft Corporation)
Task: {A949D7E1-52A6-4899-94F4-C99CE5DCF259} - System32\Tasks\{EC304146-4322-4BC4-8720-46A91C3146FB} => pcalua.exe -a C:\ProgramData\FindBestDEal\6hw6qBlbP69g3C.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {BC7572E7-977D-4981-AE1B-3CDE5D87D2DE} - System32\Tasks\Uninstaller_SkipUac_User => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-01-20] (IObit)
Task: {C0D22B04-E5E2-4688-9599-17D5CE4279F9} - System32\Tasks\ASC8_SkipUac_User => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASC.exe [2015-02-05] (IObit)
Task: {C3A6CA76-0619-4B94-90B3-58AD5B5E8DBD} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1886107439-1478614267-3997763490-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
Task: {CED83A16-BA82-4E5B-ADC2-D5BF083FF801} - System32\Tasks\{4EB49FDF-4E7E-4C6C-9817-76E5DD58E209} => pcalua.exe -a C:\ProgramData\tuakesave\cUBVwaxrKeVTTj.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {DE9786AF-8BF9-4C1F-B383-2A066B92E7FA} - System32\Tasks\{8CB3CEDD-5080-4A96-B517-FA0E2D53BD33} => C:\Users\User\Desktop\FFXIVAPP.Client.exe [2014-01-12] (ZAMNetworkLLC)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-09-20 21:40 - 2014-10-16 18:11 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-09-20 21:34 - 2012-10-29 11:48 - 00927232 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
2014-09-17 18:40 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2013-11-02 21:47 - 2015-03-31 16:47 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-02-05 04:24 - 2015-02-05 04:25 - 00187072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2015-10-28 11:51 - 2015-09-01 20:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-04-12 14:48 - 2014-04-12 14:48 - 00076016 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
2014-04-12 14:48 - 2014-04-12 14:48 - 00088816 _____ () C:\Program Files\TortoiseSVN\bin\libsasl.dll
2014-09-18 11:23 - 2014-09-18 11:23 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2015-03-12 22:23 - 2015-03-12 22:23 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-09-18 11:23 - 2014-09-18 11:23 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2015-03-12 22:23 - 2015-03-12 22:23 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2014-01-25 12:42 - 2015-05-01 20:52 - 00721552 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll
2014-01-25 12:42 - 2015-05-01 20:52 - 00854160 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll
2015-03-14 09:49 - 2015-03-14 09:49 - 00291840 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
2015-02-13 01:56 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\sqlite3.dll
2015-02-13 01:57 - 2015-01-09 18:46 - 00517408 _____ () C:\Program Files (x86)\IObit\IObit Malware Fighter\sqlite3.dll
2013-09-20 21:34 - 2015-12-03 17:33 - 00031232 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.01\PEbiosinterface32.dll
2013-09-20 21:34 - 2012-05-07 20:04 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.01\ATKEX.dll
2015-02-13 01:57 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madExcept_.bpl
2015-02-13 01:57 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madBasic_.bpl
2015-02-13 01:57 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\madDisAsm_.bpl
2015-05-13 20:07 - 2015-05-01 20:52 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-02-13 01:56 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 8\webres.dll
2015-02-02 11:52 - 2015-02-02 11:52 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
2015-12-03 17:25 - 2015-12-03 17:25 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2014-05-19 17:04 - 2015-11-12 22:04 - 00393608 _____ () C:\Users\User\AppData\Roaming\Curse Client\Bin\opus.dll
2014-05-19 17:05 - 2015-06-24 20:15 - 00443272 _____ () C:\Users\User\AppData\Roaming\Curse Client\Bin\WebRTC_CSharpWrapper.dll
2014-04-12 13:45 - 2014-04-12 13:45 - 00065776 _____ () C:\Program Files\TortoiseSVN\bin\TortoiseStub32.dll
2015-11-11 22:51 - 2015-11-07 08:36 - 01532744 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
2015-11-11 22:51 - 2015-11-07 08:36 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll
2015-05-14 14:11 - 2014-11-26 06:12 - 40622592 _____ () C:\Users\User\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll
2015-05-14 14:11 - 2014-11-26 06:12 - 00911360 _____ () C:\Users\User\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll
2015-05-14 14:11 - 2014-11-26 06:12 - 00134144 _____ () C:\Users\User\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll
2015-02-13 01:57 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2015-02-13 01:57 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2015-02-13 01:57 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\.DEFAULT\...\freerealms.com -> freerealms.com
IE trusted site: HKU\.DEFAULT\...\soe.com -> soe.com
IE trusted site: HKU\.DEFAULT\...\sony.com -> sony.com
IE trusted site: HKU\S-1-5-19\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-19\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-19\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-19\...\sony.com -> sony.com
IE trusted site: HKU\S-1-5-20\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-20\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-20\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-20\...\sony.com -> sony.com
IE trusted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\sony.com -> sony.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\100sexlinks.com -> 100sexlinks.com
 
There are 4788 more sites.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{C64A2B0B-873C-4AF3-891D-5E758E9D10DB}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{FC40D3E2-2627-4B23-A62D-0642F9671865}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{D74506DC-143D-4B7B-B92C-C6E2AE76D3B0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{3E2C3EE0-FB57-4AD9-B19B-30778A16C263}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{53F0769C-E8A9-4EBF-A1DB-51CF00A34C0C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{9AD0C1DD-D318-4C54-BEF0-FE4DE2828B53}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{AF71BD09-3C03-4EA2-999B-24E9653C6C53}] => (Allow) C:\Program Files (x86)\FixMyLag\SuperSocks5Cap.exe
FirewallRules: [{14134F53-0049-4C15-873D-85BB0BD92C8C}] => (Allow) C:\Program Files (x86)\FixMyLag\SuperSocks5Cap.exe
FirewallRules: [{E5D00B52-5564-4C6F-A39C-1727CFBEB423}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{D12D6BFF-D8DB-4270-B6F3-DBB1A6381FCA}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{9393682A-B3A5-4AB8-A396-CA1EEF68BD0D}] => (Allow) C:\Program Files\Ventrilo\Ventrilo.exe
FirewallRules: [{0B1B3265-0AC1-4331-A9B1-F27B5D9CA2A1}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{696DCD0F-092C-4604-8519-0F035B18EFA7}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E025F8DA-C52C-4094-A654-A05310F9FC76}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{B382711C-D17D-47C7-9C9E-F93100FF883C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{CDF9E395-DF92-491E-B53C-15B2EEEA38EF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B0BEFD83-BEAF-474E-B04C-1510763E706E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F8B9A587-0FAC-47E7-B064-5372C30990F4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{909FF143-7A72-4FA5-B944-B6651F884128}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{BE230AA4-D432-49A8-BF48-4A743C14C066}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{9784AD6E-7FE5-462A-8706-B9540F3947DF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [TCP Query User{1812B026-EB3D-4D15-9FEA-5D44A02FCC72}C:\users\user\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\user\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{5343AAF1-5770-4677-8C8D-4F1EA4351DBA}C:\users\user\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\user\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{807395A6-3F0E-46CF-9B44-D6DF532A21B6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{BCAF7748-1316-4DFB-B4DC-AC3DB6524A82}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{CEC3E085-3CF2-4D0D-86A1-7835FD3F57D8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{B1208B77-49D6-4BDB-B108-613ACA80AB37}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{A83CC1B7-42FB-4DDD-BE09-8D5571136046}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{D60DB436-0D40-4C61-BBFF-83A650E7F00E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{4646F466-191F-4F0B-B704-7E48503B4A31}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{C3028EA1-33CF-43F6-8B2B-AE88DEDF5377}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{2E9F8A0B-D2E3-477C-A47E-A8834B2BE12B}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{D968D31A-AE55-4B10-9B22-B65800A90B47}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{30DEA4A2-5C4C-4E05-8513-723AB5498972}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{90892712-61CA-4F10-9F77-202A408A7B81}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{96BD9510-92ED-43C6-A890-3E24299D7E76}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe
FirewallRules: [{F4D58285-008B-4AD0-AD14-2348FD78A434}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe
FirewallRules: [{FE6E3938-D466-4831-BD7E-AB6AE9275574}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe
FirewallRules: [{25E224A4-F0E6-486F-849B-0BE02D8FE363}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Half-Life\hl.exe
FirewallRules: [{98F36D6E-BF22-4ACC-8381-AA11FF4F9568}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Super Street Fighter IV - Arcade Edition\SSFIV.exe
FirewallRules: [{2796EF0E-E0A0-4F54-B08A-87499B861457}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Super Street Fighter IV - Arcade Edition\SSFIV.exe
FirewallRules: [{9DDDC8E1-9BEF-41BA-A55C-9923C9723566}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{7DFFFD6A-A109-4A5F-88D5-410FCAB8BC6A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe
FirewallRules: [{91F12988-AA91-46DA-8DBC-8E543A3F7E97}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{E93A3F33-AC6B-4380-9A5F-533EDA9ABFE2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe
FirewallRules: [{B6F6932A-96A5-439F-ABE4-CDDFF9085FD0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion - Closed Beta\datapack\trials_fusion.exe
FirewallRules: [{5C66B8F1-FC30-4ED3-A3CD-6A4837C498BC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion - Closed Beta\datapack\trials_fusion.exe
FirewallRules: [{C3052F34-BEFF-4B64-A951-FBE19D70AC9A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion - Closed Beta\datapack\trials_fusion.exe
FirewallRules: [{D29075CA-CCE4-4381-9BCE-4E50A653671F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion - Closed Beta\datapack\trials_fusion.exe
FirewallRules: [{E412ED6F-0388-44CA-A495-1AB872897F1A}] => (Allow) C:\Program Files (x86)\Diablo III\Diablo III.exe
FirewallRules: [{2ED91F1C-2AC8-4B69-88BF-A1FB6DD11088}] => (Allow) C:\Program Files (x86)\Diablo III\Diablo III.exe
FirewallRules: [{369C8CFA-189F-4E0D-ADD9-1348DED0986E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{F0311564-2CD7-4D8B-92BE-21C67CF9955D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{89A93D57-9488-4625-AAA7-6AD5E4CF07C5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TrackMania United\TmForever.exe
FirewallRules: [{D731B8B0-160D-491B-806A-026841CA0A8F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TrackMania United\TmForever.exe
FirewallRules: [{BB9B4A6E-F929-4D9F-916D-952FE363E873}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TrackMania United\TmForeverLauncher.exe
FirewallRules: [{37804442-DB23-433B-8DA0-6DF5B6D20E9D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TrackMania United\TmForeverLauncher.exe
FirewallRules: [{93BEEABA-49BA-4CD5-A7D5-2CDFA45B305B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{E1D411FA-9309-456A-A92C-CB2B3ADA51D9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{00039FE8-B7CE-4F59-ACAE-E5F291C9E342}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{8DCA0697-28DE-422E-B6E1-101104FA62DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{601CE8B9-E8C3-4893-B317-9FCEC9AEBF84}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{64B1E854-36CE-45B9-940A-40DCDBDF3664}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [TCP Query User{C6D85280-E8D0-4D4A-8138-9F1FCC097AF2}C:\program files (x86)\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe] => (Block) C:\program files (x86)\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe
FirewallRules: [UDP Query User{FE31DDC3-7409-420F-B765-010992506FA9}C:\program files (x86)\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe] => (Block) C:\program files (x86)\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe
FirewallRules: [{D5854A8E-9268-4E23-B155-C4D0E51EFFC2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 3\iw5sp.exe
FirewallRules: [{E13CADC4-07E8-4330-AB20-B5A192F4EA5B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 3\iw5sp.exe
FirewallRules: [{698CD68B-E149-49FC-B29C-D759442726FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [{EE39FC65-C998-4D6C-91B2-C5AD423F50A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [{DA8036D0-3406-4D22-9E53-3252DB04C779}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{E684261F-5CF8-49C9-BB02-848A72A431E1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{166E610D-9D89-49F7-A38A-16CE4738494D}] => (Allow) C:\Program Files (x86)\Heroes of the Storm\Support\HeroesSwitcher.exe
FirewallRules: [{F6CA4AFD-4347-4BD9-8F1A-374F9214C040}] => (Allow) C:\Program Files (x86)\Heroes of the Storm\Support\HeroesSwitcher.exe
FirewallRules: [{9DFF5CDD-796F-4A13-A1D6-892167466734}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{9B7FD890-7099-48FD-B2B1-31B639EBAAD1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{2838E3A9-322B-4B1D-A1C7-5BF07C56E77C}] => (Allow) C:\Program Files (x86)\Heroes of the Storm\Versions\Base31090\HeroesOfTheStorm.exe
FirewallRules: [{350068BB-EB64-4FA3-A43F-B7C60075618E}] => (Allow) C:\Program Files (x86)\Heroes of the Storm\Versions\Base31090\HeroesOfTheStorm.exe
FirewallRules: [{8C0C14C5-73E7-4905-BE40-5B089477C9CB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{403F77B9-ECDC-4241-931C-0D085C14EF40}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{F6B7C9D8-71DB-4B77-9886-BCBBEB431D5C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{761F6609-54A6-4986-9676-4E77DF7C9C02}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{5C5D0D0D-3EF8-474F-88FC-C930312BD53D}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{B3937BF5-7593-4485-A2AB-0821221A3AAC}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4_x86.exe
FirewallRules: [{75EABC8F-C18E-4C50-9865-042598422806}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{8168DC56-930F-4C17-9520-392C1ABACFA1}] => (Allow) C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exe
FirewallRules: [{0AC19AE9-C870-42B7-AD8B-B3483647DED7}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe
FirewallRules: [{AB7AF9E1-A3CC-4C8E-B41A-1F76118C3401}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 14\Game\fifa14.exe
FirewallRules: [{B7838ECE-65A9-4217-A8EB-67196CEAAD49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{71E5F325-BC8B-4B74-A355-CF5511762974}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{8D7A915A-13BA-452C-8EFE-A2AFAAE57499}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe
FirewallRules: [{9B930A3A-EF27-4221-A206-AF1A44FD12DF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe
FirewallRules: [{8D143EF4-78CC-4DB2-9734-0EB08DDEAA0D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{55853439-7DBF-438F-9653-C097556150E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{B2CAA0FB-416E-4677-9978-5A48C6276E74}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SecretPonchos\bin\SecretPonchosD3D11.exe
FirewallRules: [{C1CF58B8-CA65-4885-9F85-9EEBF05E2C79}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SecretPonchos\bin\SecretPonchosD3D11.exe
FirewallRules: [{6519C4A0-12CF-4809-864E-770899A301E9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{051FE32D-FB09-4388-86D3-0D6A1D3F805B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Walking Dead Season Two\TheWalkingDead2.exe
FirewallRules: [{5AF1B12F-C8AC-4C7B-B817-6686156CD093}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{6E53194B-8BCE-4084-B0BE-F39651890683}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{594FCF78-7497-4E37-833E-E474FB15BB3B}] => (Allow) C:\Users\User\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{26D6FCE3-8441-4891-8C45-3AD3D3A810EC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{6498DC9E-E80F-4CF2-AB7D-16E9973B104E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{B87F89C2-1AF4-466A-B6A1-6A731B44D245}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{8B755782-5DEF-4850-A554-F9AF7C77D145}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{69DABC5F-163B-4796-B4ED-6A9CA84241E8}] => (Allow) D:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{38BD5DFD-8CB0-4752-BFE6-1E065211F687}] => (Allow) D:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{C9C40EB8-AE0A-4B3A-8EE3-E743DB7AE838}] => (Allow) D:\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{C7D70B58-204E-4CBD-9476-77A4827F5D2E}] => (Allow) D:\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{52F0C2F9-F59D-4EDE-9C2C-C457681EFDD1}] => (Allow) D:\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{F0E90C38-665D-4579-B9A4-B885D1A7C82E}] => (Allow) D:\Steam\SteamApps\common\Trials Fusion\datapack\trials_fusion.exe
FirewallRules: [{CE52C5DF-7711-4703-9840-F09A2416623D}] => (Allow) D:\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{56429163-22BF-4D52-8BE4-C028442F8D12}] => (Allow) D:\Steam\SteamApps\common\Unturned\Unturned.exe
FirewallRules: [{BBB8EF1B-3245-418A-A17C-82E536EF96C5}] => (Allow) D:\Steam\SteamApps\common\Risk Factions\Risk Factions.exe
FirewallRules: [{4ED1F14A-08B6-4C1D-B6A1-DE04A62E8ABC}] => (Allow) D:\Steam\SteamApps\common\Risk Factions\Risk Factions.exe
FirewallRules: [TCP Query User{6BCF7874-9DD5-4A45-AED7-239E4D4F021C}D:\steam\steamapps\common\trackmania united\tmforever.exe] => (Block) D:\steam\steamapps\common\trackmania united\tmforever.exe
FirewallRules: [UDP Query User{94301418-6C8D-4FC6-9A37-37A91493D76E}D:\steam\steamapps\common\trackmania united\tmforever.exe] => (Block) D:\steam\steamapps\common\trackmania united\tmforever.exe
FirewallRules: [{786252A9-C090-433C-A44E-1875E0E02D7E}] => (Allow) D:\Steam\SteamApps\common\Super Street Fighter IV - Arcade Edition\SSFIV.exe
FirewallRules: [{B1A8768D-3E71-4029-8B51-FE98625DDBA7}] => (Allow) D:\Steam\SteamApps\common\Super Street Fighter IV - Arcade Edition\SSFIV.exe
FirewallRules: [{54177CC4-A42B-4EEB-9F22-305987AC9E92}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [{42E6AE5A-9135-4671-920E-855764740A24}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3427\Agent.exe
FirewallRules: [TCP Query User{BA78838B-76CF-49FF-BE91-2FFE64872579}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{130B2AD0-D2E9-4AB2-8C20-309106D77A65}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{7A309722-CC25-48F8-874C-3D4CF4D40082}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{6009391A-821B-4484-A9F9-DC3C51D05E46}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Block) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [{9D61ACBD-FDCB-40B7-B455-AAB4DA64A0A3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [{50BC2E8E-772B-495C-977A-3EC3F439718E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3478\Agent.exe
FirewallRules: [TCP Query User{9429A830-6D9A-464E-9B81-7D5D316CC6D9}C:\program files (x86)\popcorn time free\popcorn time 3.2\popcorn-time-app32.exe] => (Allow) C:\program files (x86)\popcorn time free\popcorn time 3.2\popcorn-time-app32.exe
FirewallRules: [UDP Query User{19B8DA0B-7F81-4F13-9BCA-4161A6FD468B}C:\program files (x86)\popcorn time free\popcorn time 3.2\popcorn-time-app32.exe] => (Allow) C:\program files (x86)\popcorn time free\popcorn time 3.2\popcorn-time-app32.exe
FirewallRules: [{1FF464E1-F5DB-419A-839B-8E592D4A9E9B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{DC28C696-A16E-4701-9E63-715ADE7C5BCD}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe
FirewallRules: [{707CDA06-A1B7-4B6C-A09B-6B623F4F5A55}] => (Allow) D:\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{135520C8-194C-45DF-826A-67E7A5B03FDD}] => (Allow) D:\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{66D6ED3A-C7EA-46DC-A8BD-803D717707EB}] => (Allow) D:\Steam\SteamApps\common\SecretPonchos\bin\SecretPonchosD3D11.exe
FirewallRules: [{E18533A5-CC9F-4285-BB2A-5358D361FB1B}] => (Allow) D:\Steam\SteamApps\common\SecretPonchos\bin\SecretPonchosD3D11.exe
FirewallRules: [{9AA3A8BD-60EF-4A0D-AA49-D39FC11CE46C}] => (Allow) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{9109AB8A-457F-49AD-AB34-322838A864EB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1B71DDE1-9E47-4F4A-A9BF-B7CC838DB7C8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{684B8FD9-F9AB-40BB-8A1B-46917D936974}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C339F51B-8322-49A1-8B7A-6BA97516B2EB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AA7F0E65-9D66-4D92-87DC-F9F9BC724D0E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{B384F4B5-9CD4-4CB6-80BB-C08C2D86845F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3689\Agent.exe
FirewallRules: [{E0CEAB6C-F661-4087-98F4-04D25A0AC5E4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3689\Agent.exe
FirewallRules: [TCP Query User{E42B0F1F-7F69-4405-BB62-6CFB7D67AFAA}D:\steam\steamapps\common\half-life\hl.exe] => (Block) D:\steam\steamapps\common\half-life\hl.exe
FirewallRules: [UDP Query User{2480B8B0-15D7-4EF8-B2E8-3D1B84A19070}D:\steam\steamapps\common\half-life\hl.exe] => (Block) D:\steam\steamapps\common\half-life\hl.exe
FirewallRules: [{6B176138-5217-4760-8CD6-541B832A902A}] => (Allow) D:\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{B9E39CEB-9EBB-4FD7-A643-C9335709A38F}] => (Allow) D:\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{9E28A992-225D-4875-AA24-82B3F8D3F5B4}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{BCCDE5FD-EEF6-493A-8985-40E6512865BF}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{250C8099-308B-4A7F-91A1-A2597F5E85B2}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{04BB379A-33EC-4517-B3F7-95EE85481040}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{AEDD5115-3963-424E-A488-58A448BADC62}] => (Allow) D:\Program Files (x86)\Origin Games\BFH\bfh.exe
FirewallRules: [{E7E0FE2E-2B6E-4568-961A-D2220AB13AB4}] => (Allow) D:\Program Files (x86)\Origin Games\BFH\bfh.exe
FirewallRules: [{5903DEF7-CA8C-4873-9882-084A6E9B58EF}] => (Allow) D:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{3450EE9D-C730-4E02-BBCA-51972C1E9B43}] => (Allow) D:\Steam\SteamApps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{B4A41F4E-D21B-4639-9170-0A585936FF10}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{C7340A9A-FEC7-4885-8C10-16443A9805B7}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [{2D509305-B2B2-47CC-AB24-89C843669477}] => (Allow) D:\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{4087D07A-E1A9-4F0D-B7B7-5B0D3244EEC0}] => (Allow) D:\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{44C3F884-1836-434C-A4D5-FA29A393656B}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{DDB6B157-21DD-4D7B-9C4B-77F5308EE18C}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{60752EDC-F21C-45B2-A320-C958B31BE6E7}] => (Allow) D:\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{C0DD35EE-8108-403F-BF40-FAFC2BDA33BD}] => (Allow) D:\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{D63277A4-F0C4-4C12-A772-B0025C36BAB9}] => (Allow) D:\Steam\SteamApps\common\EvolveGame\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{22B2386F-8A98-43ED-9BFF-05441C93305E}] => (Allow) D:\Steam\SteamApps\common\EvolveGame\Bin64_SteamRetail\Evolve.exe
FirewallRules: [TCP Query User{63A787F2-8F10-4C84-8959-6BC19445B634}C:\program files (x86)\heroes of the storm\versions\base32253\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base32253\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{5A93B2BD-7090-4924-BB25-0BFAE461EF1D}C:\program files (x86)\heroes of the storm\versions\base32253\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base32253\heroesofthestorm_x64.exe
FirewallRules: [TCP Query User{AC08C2AC-590C-484A-B06F-03B26BA1D8BA}C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{0196A8F6-BC48-400D-B6CE-484441AE913E}C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe
FirewallRules: [{00CFC036-7E57-4C20-9485-1A78B6A44D3A}] => (Allow) D:\Steam\SteamApps\common\The Wolf Among Us\TheWolfAmongUs.exe
FirewallRules: [{6768A4B3-A915-412F-9429-9265174A5251}] => (Allow) D:\Steam\SteamApps\common\The Wolf Among Us\TheWolfAmongUs.exe
FirewallRules: [{3396E34D-0F58-46D5-8F37-F0D65C6C3C39}] => (Allow) D:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{5F1B5CD3-25AF-43C5-B5E4-4639E590E22C}] => (Allow) D:\Steam\SteamApps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{6805F672-CAB8-489E-A4EB-568E237E3D09}] => (Allow) D:\Steam\SteamApps\common\Stranded Deep\Stranded_Deep_x64.exe
FirewallRules: [{6680053A-DFF6-4085-859B-904E9B3DD9AF}] => (Allow) D:\Steam\SteamApps\common\Stranded Deep\Stranded_Deep_x64.exe
FirewallRules: [{F4AFA706-220F-4939-B64D-51D96C764FC9}] => (Allow) D:\Steam\SteamApps\common\H1Z1\LaunchPad.exe
FirewallRules: [{ED1077CD-BDC6-4CAD-9A0C-2387FD4B7383}] => (Allow) D:\Steam\SteamApps\common\H1Z1\LaunchPad.exe
FirewallRules: [TCP Query User{A5CC2FEA-FF07-4E46-B576-C7D6A52E3079}D:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) D:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [UDP Query User{9647CDCE-6473-43D4-93C5-AA660D7C5B1B}D:\steam\steamapps\common\h1z1\h1z1.exe] => (Allow) D:\steam\steamapps\common\h1z1\h1z1.exe
FirewallRules: [TCP Query User{226E2351-E15B-4B1B-9C8A-BEB326287F9A}D:\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe] => (Allow) D:\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe
FirewallRules: [UDP Query User{0CF21345-F24D-4546-8EB5-40731F8184DB}D:\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe] => (Allow) D:\steam\steamapps\common\killerisdead\binaries\win32\kidgame.exe
FirewallRules: [{9C2A15E2-6DA9-4093-AE7E-C6ECBFF00E9B}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D8D2B471-0040-48F7-9CA8-F2FC2B58145B}] => (Allow) C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{77F20654-087F-4652-BE93-C419F9AF3C0C}] => (Allow) D:\Steam\SteamApps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [{C07D9F12-5464-4EA0-9B63-06BADDCD882B}] => (Allow) D:\Steam\SteamApps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [TCP Query User{57E83AFC-3AA5-4196-AE3A-3BBAF9C6E153}C:\users\user\appdata\roaming\utorrent\updates\3.4.4_40911.exe] => (Block) C:\users\user\appdata\roaming\utorrent\updates\3.4.4_40911.exe
FirewallRules: [UDP Query User{0C2950FA-5B7D-443F-9D3D-78EA48F434CA}C:\users\user\appdata\roaming\utorrent\updates\3.4.4_40911.exe] => (Block) C:\users\user\appdata\roaming\utorrent\updates\3.4.4_40911.exe
FirewallRules: [TCP Query User{2BF23991-83C1-493B-9069-477295E8898E}C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe] => (Block) C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe
FirewallRules: [UDP Query User{02CFA522-29BD-4602-8675-DC076751E627}C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe] => (Block) C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe
FirewallRules: [TCP Query User{EFDF0FE9-5351-40D6-A3F9-B521263A5CA5}C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe] => (Block) C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe
FirewallRules: [UDP Query User{A13B496A-EA56-4071-8279-FBCA56E1B080}C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe] => (Block) C:\users\user\appdata\roaming\utorrent\updates\3.4.5_41202.exe
FirewallRules: [{346E5E33-31F8-483D-8A3D-4BDBAC6392C9}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{2D32C1F2-322A-4FC4-AA4A-2EA03EAEBAA6}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{0A27FE4B-4D21-4364-8712-8246E9520B40}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{104D11CC-6A7E-46CC-B15D-4FCA0ADBF62C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{24BF9732-5C00-4ABD-9C9F-02A18E09131E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{81BC5D2B-C5ED-46DD-9350-61A5E5BF26F6}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{8161904C-6D22-4819-B607-5E38936DA7B1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{4BF526F3-FEA7-407A-B732-85DF29125C19}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{E4593233-2D10-43A4-8A25-011F3DBE0BE0}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{B2A189F0-E56B-453F-8F2A-EDBD12DCCA0D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{DA9397DC-A7C6-49D4-8099-00C8BEEF50A2}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/03/2015 05:34:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/03/2015 05:32:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (12/03/2015 05:32:25 PM) (Source: AdvancedSystemCareService8) (EventID: 0) (User: )
Description: The handle is invalid
 
Error: (12/03/2015 05:13:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/03/2015 00:49:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/03/2015 02:07:29 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/02/2015 03:50:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (12/01/2015 03:56:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (11/30/2015 09:08:21 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program rads_user_kernel.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 20e4
 
Start Time: 01d12b91b11262b0
 
Termination Time: 2
 
Application Path: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
 
Report Id: f2a51fa7-9784-11e5-aa2a-74d02bc992c2
 
Error: (11/30/2015 04:13:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (12/03/2015 05:33:39 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer BURFMEDIASERVER
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{07630D4D-6ABE-4C8A-8942-421BA286C39E}.
The master browser is stopping or an election is being forced.
 
Error: (12/03/2015 05:33:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Cloud Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/03/2015 05:32:10 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
 
Error: (12/03/2015 05:11:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Cloud Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/03/2015 00:47:46 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Cloud Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/03/2015 02:05:46 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Cloud Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/02/2015 07:58:22 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.200.
The computer with the IP address 192.168.1.244 did not allow the name to be claimed by
this computer.
 
Error: (12/02/2015 03:50:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240055: Upgrade to Windows 10 Pro, version 1511, 10586.
 
Error: (12/02/2015 03:48:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Cloud Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (12/01/2015 03:54:30 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The RealPlayer Cloud Service service terminated unexpectedly.  It has done this 1 time(s).
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-4770K CPU @ 3.50GHz
Percentage of memory in use: 29%
Total physical RAM: 16321.67 MB
Available physical RAM: 11489.33 MB
Total Virtual: 32641.54 MB
Available Virtual: 28094.43 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:223.47 GB) (Free:59.95 GB) NTFS
Drive d: () (Fixed) (Total:1863.01 GB) (Free:1268.11 GB) NTFS
Drive e: (LGPS_301_Multi) (CDROM) (Total:0.1 GB) (Free:0 GB) CDFS
Drive f: (ZAYED) (Removable) (Total:7.45 GB) (Free:5.76 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 6E09C8A6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 6E09C8BD)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (Size: 7.5 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
 
 

Attached Files



BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:28 AM

Posted 07 December 2015 - 12:50 PM

Greetings lehameli and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Please consider and do this.

===================================================

P2P Warning

--------------------

Going over your logs I noticed that you have µTorrent installed. It is pretty much certain that if you continue to use P2P programs, you will get infected again.
  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove the program, you can do so via Start > Control Panel > Add/Remove Programs.

If you are still leaning toward using this program, please take a look at this information about Ransomware which can be delivered via P2P file transfers. The newest variation of Ransomware can make it impossible to recover the files this malicious software encrypts. In other words, you will probably lose most if not all of your valuable information, including pictures. In addition it has recently been reported that P2P downloads may be tracked resulting in your IP address being monitored by copyright authorities. .

If you wish to keep it, please do not use it until we are completely done and your machine is determined to be clean and updated.

===================================================

Uninstalling a Program using Add/Remove Program

--------------------

I recommend the uninstalling of the below listed program(s).
  • Press windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type appwiz.cpl and press Enter
  • A list of installed programs will be displayed
  • Uninstall the following by clicking on the program(s) below (and any other similar names) and selecting Remove or Uninstall

ApptoU


===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {60319aa3-5b63-11e3-abc4-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {60319b3f-5b63-11e3-abc4-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {a828ed44-8cd9-11e4-bc20-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {d9cf11c9-2219-11e3-ab54-806e6f6e6963} - D:\autorun.exe
HKU\S-1-5-21-1886107439-1478614267-3997763490-1000\...\MountPoints2: {e4e235eb-e7df-11e3-abbe-74d02bc992c2} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\start.exe
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL = 
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\pdf.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll => No File
S3 9nlALiZMy; \??\C:\Windows\system32\drivers\9nlALiZMy.sys [X]
S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X]
2015-01-01 22:45 - 2015-01-01 22:45 - 0628496 _____ (CMI Limited) C:\Users\User\AppData\Local\nsb91D8.tmp
2015-01-26 04:05 - 2015-01-26 04:05 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nso3047.tmp
2015-01-16 19:51 - 2015-01-16 19:51 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nsu5DCB.tmp
2015-01-27 16:27 - 2015-01-27 16:27 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nsv28C.tmp
2015-01-22 19:47 - 2015-01-22 19:47 - 0613057 _____ (CMI Limited) C:\Users\User\AppData\Local\nsxE801.tmp
Task: {2A077B5D-AA94-4202-B182-C88A9A77A9C7} - System32\Tasks\{F6D72313-DE2F-4759-835A-AF7931604B35} => pcalua.exe -a C:\ProgramData\aadsy\oT8zQq4LPiMYwN.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {3A17718D-2E0D-4090-92A7-A376847537A8} - System32\Tasks\{67312D4E-3080-436A-9ED4-2975B6A3183F} => pcalua.exe -a C:\ProgramData\DiIgiCooUpon\BTGrqf5PzHc1yJ.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {718BC62D-3008-4F74-A7F8-7064A4132D41} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {A949D7E1-52A6-4899-94F4-C99CE5DCF259} - System32\Tasks\{EC304146-4322-4BC4-8720-46A91C3146FB} => pcalua.exe -a C:\ProgramData\FindBestDEal\6hw6qBlbP69g3C.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {CED83A16-BA82-4E5B-ADC2-D5BF083FF801} - System32\Tasks\{4EB49FDF-4E7E-4C6C-9817-76E5DD58E209} => pcalua.exe -a C:\ProgramData\tuakesave\cUBVwaxrKeVTTj.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
C:\ProgramData\aadsy
C:\ProgramData\DiIgiCooUpon
C:\Program Files (x86)\MyPC Backup
C:\ProgramData\FindBestDEal
C:\ProgramData\tuakesave
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

AdwCleaner by Xplode - Delete Adware

-------------------
  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browser
  • Double click on AdwCleaner.exe, click Run, then select I agree if it appears
  • Click Scan
  • Once the scan has completed youi will see Pending. Please check elements you don't want to remove above the progress bar
  • Click on Clean
  • Confirm the cleaning and rebooting of your computer by clicking OK
  • Your computer will be rebooted automatically. A text file will open after the restart
  • Copy and paste the contents in your reply
  • You can also find the logfile at C:\AdwCleaner\AdwCleaner.txt
===================================================

Junkware Removal Tool

-------------------
  • Please download Junkware Removal Tool and save it to your desktop.
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Right-mouse click JRT.exe and select Run as administrator (Windows XP double click the icon)
  • Please allow the program time to run
  • Once completed a Notepad document will open on your desktop
  • Copy and paste the contents in your reply
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Did the program uninstall successfully?
  • Fixlog
  • Adwcleaner report
  • Junkware report
  • System Summary Information
  • Update on computer performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:28 AM

Posted 10 December 2015 - 10:30 AM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:28 AM

Posted 12 December 2015 - 04:06 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users