Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Random Redirects in Firefox


  • This topic is locked This topic is locked
12 replies to this topic

#1 DocWhoops

DocWhoops

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:09 PM

Posted 07 December 2015 - 06:58 AM

Don't know where I picked up a bug, but it randomly redirects every 25th click or so to sites like PCKeeper and feedbackexplorer. FWIW, I just switched to Windows 10 last week and the problems started a few days ago. 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
Ran by Jerome (administrator) on HAL (07-12-2015 05:48:04)
Running from C:\Users\Jerome\Downloads
Loaded Profiles: Jerome (Available Profiles: Jerome)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchService.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(CobianSoft, Luis Cobian) C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
() C:\Program Files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Netflix, Inc.) C:\Program Files\WindowsApps\4DF9E0F8.Netflix_5.1.4.0_x64__mcm4njqhnhss8\Netflix.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-03] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [XFastUSB] => C:\Program Files (x86)\XFastUSB\XFastUsb.exe [6226624 2014-01-08] (FNet Co., Ltd.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-09] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\Run: [f.lux] => C:\Users\Jerome\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\Run: [Spotify Web Helper] => C:\Users\Jerome\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-25] (Spotify Ltd)
HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935904 2015-12-01] (SUPERAntiSpyware)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2015-12-05]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

AutoConfigURL: [S-1-5-21-2043291374-1636051585-76882383-1001] => hxxp://unstopp.me/wpad.dat?48fa910322d9e2f600780c747899f7da2167093
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{aecd5d7d-e394-4fb8-a1e0-a76985412d5b}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_44&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0Ezz0BtC0DtDyDyD0FzztN0D0Tzu0StCtAzyyDtN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StCyDzy0BtB0CtD0AtGyE0BtCyDtGtAzz0E0EtGyCtAzztDtGzy0E0EyCyBtB0A0AtAyCzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAzzzy0C0EyDyD0CtGtBtBtA0CtGyEtA0E0BtGzztCyE0DtGzyyE0E0CyCtCtBtDzz0Fzyzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D740488204%26a%3Dwbf_gmmedply_15_44%26os%3DWindows%2B8.1&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_44&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0Ezz0BtC0DtDyDyD0FzztN0D0Tzu0StCtAzyyDtN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StCyDzy0BtB0CtD0AtGyE0BtCyDtGtAzz0E0EtGyCtAzztDtGzy0E0EyCyBtB0A0AtAyCzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAzzzy0C0EyDyD0CtGtBtBtA0CtGyEtA0E0BtGzztCyE0DtGzyyE0E0CyCtCtBtDzz0Fzyzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D740488204%26a%3Dwbf_gmmedply_15_44%26os%3DWindows%2B8.1&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2043291374-1636051585-76882383-1001 -> DefaultScope {cf34d395-9ff1-49a0-98a5-8db1636431b1} URL =
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-11-19] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-19] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-19] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-19] (Oracle Corporation)
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2013-04-16] (Belarc, Inc.)

FireFox:
========
FF ProfilePath: C:\Users\Jerome\AppData\Roaming\Mozilla\Firefox\Profiles\w21wc83s.default-1449296613565
FF DefaultSearchEngine.US: Google
FF Homepage: hxxps://start.me/p/Z9Bq6m/startpage-us
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-12-04] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-12-04] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-19] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-27] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-27] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-01] (Google Inc.)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2011-04-20] (Wacom, Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.0.0.1 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-30] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2043291374-1636051585-76882383-1001: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-30] (Wacom)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Extension: Thumbnail Zoom Plus - C:\Users\Jerome\AppData\Roaming\Mozilla\Firefox\Profiles\w21wc83s.default-1449296613565\extensions\thumbnailZoom@dadler.github.com.xpi [2015-12-05]
FF Extension: Reddit Enhancement Suite - C:\Users\Jerome\AppData\Roaming\Mozilla\Firefox\Profiles\w21wc83s.default-1449296613565\Extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi [2015-12-05]
FF Extension: start.me - C:\Users\Jerome\AppData\Roaming\Mozilla\Firefox\Profiles\w21wc83s.default-1449296613565\Extensions\yourls@yourls.com.xpi [2015-12-05]
FF Extension: Adblock Plus - C:\Users\Jerome\AppData\Roaming\Mozilla\Firefox\Profiles\w21wc83s.default-1449296613565\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-05]

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-02]
CHR Extension: (Google Docs) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-02]
CHR Extension: (Google Drive) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-02]
CHR Extension: (YouTube) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-02]
CHR Extension: (Google Search) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-02]
CHR Extension: (Google Sheets) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-02]
CHR Extension: (Google Docs Offline) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-02]
CHR Extension: (Gmail) - C:\Users\Jerome\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-02]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
R2 ASRockIOMon; C:\Program Files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe [454656 2013-05-28] () [File not signed]
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-01-08] (BitRaider, LLC)
R2 cbVSCService11; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [67584 2013-03-07] (CobianSoft, Luis Cobian) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-03] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-03] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-03] (NVIDIA Corporation)
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AsrDrv101; C:\Windows\SysWOW64\Drivers\AsrDrv101.sys [22280 2014-01-08] (ASRock Incorporation)
S3 AsrHidFilter; C:\Windows\system32\DRIVERS\AsrHidFilter.sys [20232 2013-09-09] (ASRock Inc.)
R0 AsrRamDisk; C:\Windows\System32\drivers\AsrRamDisk.sys [40200 2013-05-09] (ASRock Inc.)
S3 AsrSetupDrv; C:\WINDOWS\SysWOW64\Drivers\AsrSetupDrv.sys [22352 2015-12-05] (RW-Everything)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [75056 2013-02-13] (Qualcomm Atheros, Inc.)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2014-01-08] (BitRaider)
R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2015-11-28] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-01-08] (FNet Co., Ltd.)
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [23936 2014-02-03] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] ()
R3 Ke2200; C:\Windows\System32\drivers\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-07-10] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-03] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46768 2015-05-18] (NVIDIA Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-07 05:48 - 2015-12-07 05:48 - 00017226 _____ C:\Users\Jerome\Downloads\FRST.txt
2015-12-07 05:47 - 2015-12-07 05:48 - 00000000 ____D C:\FRST
2015-12-07 05:47 - 2015-12-07 05:47 - 02369024 _____ (Farbar) C:\Users\Jerome\Downloads\FRST64.exe
2015-12-06 02:23 - 2015-12-06 02:23 - 01736704 _____ C:\Users\Jerome\Downloads\adwcleaner_5.023.exe
2015-12-05 02:17 - 2015-12-05 02:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cobian Backup 11
2015-12-05 02:17 - 2015-12-05 02:17 - 00000000 ____D C:\Program Files (x86)\Cobian Backup 11
2015-12-05 02:14 - 2015-12-05 02:14 - 19709440 _____ (Luis Cobian, CobianSoft) C:\Users\Jerome\Downloads\cbSetup.exe
2015-12-05 00:23 - 2015-12-05 00:23 - 00000000 ____D C:\Users\Jerome\Desktop\Old Firefox Data
2015-12-05 00:19 - 2015-12-05 00:19 - 00002930 _____ C:\Users\Jerome\Desktop\Rkill.txt
2015-12-05 00:18 - 2015-12-05 00:18 - 02032072 _____ (Bleeping Computer, LLC) C:\Users\Jerome\Downloads\iExplore.exe
2015-12-05 00:17 - 2015-12-05 00:18 - 00257792 _____ C:\TDSSKiller.3.1.0.7_05.12.2015_00.17.46_log.txt
2015-12-05 00:15 - 2015-12-05 00:16 - 00257058 _____ C:\TDSSKiller.3.1.0.7_05.12.2015_00.15.25_log.txt
2015-12-05 00:15 - 2015-12-05 00:15 - 04398264 _____ (Kaspersky Lab ZAO) C:\Users\Jerome\Downloads\tdsskiller.exe
2015-12-05 00:11 - 2015-12-05 00:12 - 275925990 _____ C:\Users\Jerome\Downloads\Killer_network_w10.zip
2015-12-05 00:08 - 2015-12-05 00:08 - 00000000 ___HD C:\OneDriveTemp
2015-12-05 00:07 - 2015-12-05 00:07 - 00002799 _____ C:\Users\Public\Desktop\Killer Network Manager.lnk
2015-12-05 00:07 - 2015-12-05 00:07 - 00000000 ____D C:\ProgramData\Qualcomm
2015-12-05 00:07 - 2015-12-05 00:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Qualcomm Atheros
2015-12-05 00:07 - 2015-12-05 00:07 - 00000000 ____D C:\Program Files\Qualcomm Atheros
2015-12-05 00:04 - 2015-12-05 00:04 - 00022352 _____ (RW-Everything) C:\WINDOWS\SysWOW64\Drivers\AsrSetupDrv.sys
2015-12-05 00:04 - 2015-12-05 00:04 - 00000000 ____D C:\Users\Jerome\Downloads\Setup
2015-12-04 22:42 - 2015-12-07 02:00 - 00000520 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task e4cf6373-4472-4af4-90bd-799002eada42.job
2015-12-04 22:42 - 2015-12-06 06:42 - 00000520 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task afda71bf-c67f-4457-b989-c657dc2b58d4.job
2015-12-04 22:42 - 2015-12-04 22:42 - 00003738 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task e4cf6373-4472-4af4-90bd-799002eada42
2015-12-04 22:42 - 2015-12-04 22:42 - 00003656 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task afda71bf-c67f-4457-b989-c657dc2b58d4
2015-12-04 22:41 - 2015-12-04 22:41 - 24081704 _____ (SUPERAntiSpyware) C:\Users\Jerome\Downloads\SUPERAntiSpyware.exe
2015-12-04 22:41 - 2015-12-04 22:41 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-12-04 22:41 - 2015-12-04 22:41 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\SUPERAntiSpyware.com
2015-12-04 22:41 - 2015-12-04 22:41 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-12-04 22:41 - 2015-12-04 22:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-12-04 22:41 - 2015-12-04 22:41 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-12-04 03:09 - 2015-12-04 07:24 - 00001956 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2015-12-04 03:09 - 2015-12-04 03:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2015-12-04 03:09 - 2015-12-04 03:09 - 00000000 ____D C:\Program Files\HitmanPro
2015-12-04 03:07 - 2015-12-04 03:08 - 11337112 _____ (SurfRight B.V.) C:\Users\Jerome\Downloads\HitmanPro_x64.exe
2015-12-04 03:06 - 2015-12-06 02:26 - 00000556 _____ C:\Users\Jerome\Desktop\JRT.txt
2015-12-04 03:05 - 2015-12-04 03:05 - 01599336 _____ (Malwarebytes) C:\Users\Jerome\Downloads\JRT.exe
2015-12-04 01:23 - 2015-12-04 01:23 - 01736704 _____ C:\Users\Jerome\Downloads\AdwCleaner.exe
2015-12-03 01:55 - 2015-12-03 01:55 - 136558360 _____ (Microsoft Corporation) C:\Users\Jerome\Downloads\msert.exe
2015-12-03 01:20 - 2015-11-22 04:47 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-12-03 01:20 - 2015-11-22 04:47 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 01:20 - 2015-11-22 04:41 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-12-03 01:20 - 2015-11-22 04:41 - 01284960 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-12-03 01:20 - 2015-11-22 04:41 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-12-03 01:20 - 2015-11-22 04:35 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-12-03 01:20 - 2015-11-22 04:34 - 00975200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-12-03 01:20 - 2015-11-22 04:34 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2015-12-03 01:20 - 2015-11-22 04:33 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2015-12-03 01:20 - 2015-11-22 04:33 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-03 01:20 - 2015-11-22 04:33 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-03 01:20 - 2015-11-22 04:30 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-12-03 01:20 - 2015-11-22 04:30 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-12-03 01:20 - 2015-11-22 04:26 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-12-03 01:20 - 2015-11-22 04:25 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2015-12-03 01:20 - 2015-11-22 04:24 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2015-12-03 01:20 - 2015-11-22 04:20 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-12-03 01:20 - 2015-11-22 04:19 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-12-03 01:20 - 2015-11-22 04:14 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2015-12-03 01:20 - 2015-11-22 04:00 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2015-12-03 01:20 - 2015-11-22 04:00 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2015-12-03 01:20 - 2015-11-22 03:57 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2015-12-03 01:20 - 2015-11-22 03:57 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-03 01:20 - 2015-11-22 03:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-03 01:20 - 2015-11-22 03:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-03 01:20 - 2015-11-22 03:57 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-03 01:20 - 2015-11-22 03:56 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-12-03 01:20 - 2015-11-22 03:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-03 01:20 - 2015-11-22 03:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2015-12-03 01:20 - 2015-11-22 03:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-03 01:20 - 2015-11-22 03:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2015-12-03 01:20 - 2015-11-22 03:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-03 01:20 - 2015-11-22 03:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-03 01:20 - 2015-11-22 03:55 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2015-12-03 01:20 - 2015-11-22 03:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2015-12-03 01:20 - 2015-11-22 03:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-03 01:20 - 2015-11-22 03:52 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-12-03 01:20 - 2015-11-22 03:52 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2015-12-03 01:20 - 2015-11-22 03:52 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-03 01:20 - 2015-11-22 03:52 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2015-12-03 01:20 - 2015-11-22 03:52 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-03 01:20 - 2015-11-22 03:51 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-12-03 01:20 - 2015-11-22 03:51 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-03 01:20 - 2015-11-22 03:51 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2015-12-03 01:20 - 2015-11-22 03:51 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2015-12-03 01:20 - 2015-11-22 03:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2015-12-03 01:20 - 2015-11-22 03:50 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2015-12-03 01:20 - 2015-11-22 03:49 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2015-12-03 01:20 - 2015-11-22 03:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2015-12-03 01:20 - 2015-11-22 03:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2015-12-03 01:20 - 2015-11-22 03:49 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2015-12-03 01:20 - 2015-11-22 03:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2015-12-03 01:20 - 2015-11-22 03:47 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2015-12-03 01:20 - 2015-11-22 03:46 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-12-03 01:20 - 2015-11-22 03:46 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2015-12-03 01:20 - 2015-11-22 03:45 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-12-03 01:20 - 2015-11-22 03:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2015-12-03 01:20 - 2015-11-22 03:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2015-12-03 01:20 - 2015-11-22 03:44 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2015-12-03 01:20 - 2015-11-22 03:44 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-12-03 01:20 - 2015-11-22 03:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2015-12-03 01:20 - 2015-11-22 03:43 - 24604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-12-03 01:20 - 2015-11-22 03:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-12-03 01:20 - 2015-11-22 03:43 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-12-03 01:20 - 2015-11-22 03:43 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-12-03 01:20 - 2015-11-22 03:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-12-03 01:20 - 2015-11-22 03:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2015-12-03 01:20 - 2015-11-22 03:42 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-12-03 01:20 - 2015-11-22 03:42 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-12-03 01:20 - 2015-11-22 03:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-12-03 01:20 - 2015-11-22 03:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-12-03 01:20 - 2015-11-22 03:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
2015-12-03 01:20 - 2015-11-22 03:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2015-12-03 01:20 - 2015-11-22 03:42 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2015-12-03 01:20 - 2015-11-22 03:41 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-12-03 01:20 - 2015-11-22 03:41 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2015-12-03 01:20 - 2015-11-22 03:41 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-12-03 01:20 - 2015-11-22 03:40 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-12-03 01:20 - 2015-11-22 03:40 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-12-03 01:20 - 2015-11-22 03:40 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-12-03 01:20 - 2015-11-22 03:40 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2015-12-03 01:20 - 2015-11-22 03:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-12-03 01:20 - 2015-11-22 03:39 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2015-12-03 01:20 - 2015-11-22 03:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2015-12-03 01:20 - 2015-11-22 03:38 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-12-03 01:20 - 2015-11-22 03:38 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-12-03 01:20 - 2015-11-22 03:38 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-12-03 01:20 - 2015-11-22 03:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2015-12-03 01:20 - 2015-11-22 03:38 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2015-12-03 01:20 - 2015-11-22 03:37 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2015-12-03 01:20 - 2015-11-22 03:37 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-03 01:20 - 2015-11-22 03:37 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-12-03 01:20 - 2015-11-22 03:36 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-03 01:20 - 2015-11-22 03:34 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2015-12-03 01:20 - 2015-11-22 03:34 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2015-12-03 01:20 - 2015-11-22 03:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-03 01:20 - 2015-11-22 03:34 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-12-03 01:20 - 2015-11-22 03:34 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-03 01:20 - 2015-11-22 03:34 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-03 01:20 - 2015-11-22 03:33 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-12-03 01:20 - 2015-11-22 03:33 - 13380608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-12-03 01:20 - 2015-11-22 03:33 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-03 01:20 - 2015-11-22 03:33 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2015-12-03 01:20 - 2015-11-22 03:32 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-12-03 01:20 - 2015-11-22 03:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2015-12-03 01:20 - 2015-11-22 03:32 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-12-03 01:20 - 2015-11-22 03:31 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-12-03 01:20 - 2015-11-22 03:31 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-12-03 01:20 - 2015-11-22 03:31 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-12-03 01:20 - 2015-11-22 03:30 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-12-03 01:20 - 2015-11-22 03:30 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-03 01:20 - 2015-11-22 03:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-12-03 01:20 - 2015-11-22 03:28 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2015-12-03 01:20 - 2015-11-22 03:27 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-03 01:20 - 2015-11-22 03:27 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-12-03 01:20 - 2015-11-22 03:27 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2015-12-03 01:20 - 2015-11-22 03:27 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-12-03 01:20 - 2015-11-22 03:27 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2015-12-03 01:20 - 2015-11-22 03:27 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-12-03 01:20 - 2015-11-22 03:26 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-12-03 01:20 - 2015-11-22 03:26 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-12-03 01:20 - 2015-11-22 03:26 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2015-12-03 01:20 - 2015-11-22 03:26 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-12-03 01:20 - 2015-11-22 03:25 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-12-03 01:20 - 2015-11-22 03:25 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-12-03 01:20 - 2015-11-22 03:25 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-12-03 01:20 - 2015-11-22 03:24 - 12124672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-12-03 01:20 - 2015-11-22 03:24 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-12-03 01:20 - 2015-11-22 03:24 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-03 01:20 - 2015-11-22 03:24 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-12-03 01:20 - 2015-11-22 03:24 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2015-12-03 01:20 - 2015-11-22 03:24 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2015-12-03 01:20 - 2015-11-22 03:23 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-12-03 01:20 - 2015-11-22 03:20 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2015-12-03 01:20 - 2015-11-22 03:19 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-12-03 01:20 - 2015-11-22 03:18 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-12-03 01:20 - 2015-11-22 03:18 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-12-03 01:20 - 2015-11-22 03:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2015-12-03 01:20 - 2015-11-22 03:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-12-03 01:20 - 2015-11-22 03:17 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-12-03 01:20 - 2015-11-22 03:16 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2015-12-03 01:20 - 2015-11-22 03:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-12-02 23:01 - 2015-12-02 23:06 - 00000000 ____D C:\Users\Jerome\AppData\Local\Chromium
2015-12-02 22:59 - 2015-12-02 23:00 - 04628328 _____ (New Monte Inc) C:\Users\Jerome\Downloads\Inside_Out_2015_HDRip_XviD_AC3-EVO_downloader.exe
2015-12-02 18:38 - 2015-12-02 18:38 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Trimble Connect for SketchUp
2015-12-02 18:32 - 2015-12-02 19:14 - 00000000 ____D C:\Users\Jerome\Documents\sketchup
2015-12-02 17:07 - 2015-12-04 07:24 - 00002229 _____ C:\Users\Public\Desktop\Style Builder 2016.lnk
2015-12-02 17:07 - 2015-12-04 07:24 - 00002143 _____ C:\Users\Public\Desktop\LayOut 2016.lnk
2015-12-02 17:07 - 2015-12-04 07:24 - 00002054 _____ C:\Users\Public\Desktop\SketchUp 2016.lnk
2015-12-02 17:07 - 2015-12-02 17:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2016
2015-12-02 17:07 - 2015-12-02 17:07 - 00000000 ____D C:\Program Files\SketchUp
2015-12-02 16:50 - 2015-12-02 16:51 - 127073600 _____ (Trimble Navigation Limited) C:\Users\Jerome\Downloads\SketchUpMake-en-x64.exe
2015-11-30 11:53 - 2015-11-30 11:53 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-11-29 01:00 - 2015-11-28 23:34 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-29 00:59 - 2015-11-29 00:59 - 00000000 ____D C:\Windows.old
2015-11-29 00:58 - 2015-11-29 00:58 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-29 00:58 - 2015-11-29 00:58 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-29 00:58 - 2015-11-29 00:58 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-29 00:58 - 2015-11-29 00:58 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-11-29 00:58 - 2015-11-29 00:58 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-11-29 00:58 - 2015-11-29 00:58 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-29 00:58 - 2015-11-29 00:58 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-11-29 00:58 - 2015-11-29 00:58 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2015-11-29 00:58 - 2015-11-29 00:58 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-11-29 00:58 - 2015-11-29 00:58 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-11-29 00:58 - 2015-11-29 00:58 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2015-11-29 00:58 - 2015-11-29 00:58 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2015-11-29 00:53 - 2015-11-29 00:53 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-11-29 00:53 - 2015-11-29 00:53 - 00000000 ____D C:\Program Files\MSBuild
2015-11-29 00:53 - 2015-11-29 00:53 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-11-29 00:53 - 2015-11-29 00:53 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-11-29 00:53 - 2015-10-23 19:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-11-29 00:53 - 2015-10-23 19:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-29 00:53 - 2015-10-23 19:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-11-29 00:53 - 2015-10-23 19:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-11-29 00:53 - 2015-10-23 19:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-11-29 00:53 - 2015-10-23 19:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-28 23:48 - 2015-12-04 07:24 - 00002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-28 23:48 - 2015-12-04 07:24 - 00002118 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-11-28 23:48 - 2015-11-28 23:48 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-11-28 23:36 - 2015-12-06 02:25 - 00000000 ___RD C:\Users\Jerome\OneDrive
2015-11-28 23:36 - 2015-12-04 07:24 - 00002335 _____ C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-11-28 23:36 - 2015-11-28 23:43 - 00000000 ____D C:\Users\Jerome\AppData\Local\MicrosoftEdge
2015-11-28 23:36 - 2015-11-28 23:36 - 00000000 ____D C:\Users\Jerome\AppData\Local\ActiveSync
2015-11-28 23:36 - 2015-11-28 23:36 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-11-28 23:35 - 2015-11-28 23:35 - 00000000 ____D C:\Users\Jerome\AppData\Local\Publishers
2015-11-28 23:34 - 2015-12-02 23:15 - 00000000 __RHD C:\Users\Public\AccountPictures
2015-11-28 23:34 - 2015-11-28 23:34 - 00000020 ___SH C:\Users\Jerome\ntuser.ini
2015-11-28 23:34 - 2015-11-28 23:34 - 00000000 ____D C:\Users\Jerome\AppData\Local\TileDataLayer
2015-11-28 23:34 - 2015-11-28 23:34 - 00000000 ____D C:\Users\Jerome\AppData\Local\Comms
2015-11-28 23:10 - 2015-11-28 23:10 - 00000000 ____D C:\ProgramData\USOShared
2015-11-28 23:09 - 2015-11-28 23:09 - 00000000 _SHDL C:\Users\Default\My Documents
2015-11-28 23:09 - 2015-11-28 23:09 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2015-11-28 23:09 - 2015-11-28 23:09 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2015-11-28 23:09 - 2015-11-28 23:09 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2015-11-28 23:09 - 2015-11-28 23:09 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2015-11-28 23:09 - 2015-11-28 23:09 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2015-11-28 23:09 - 2015-11-28 23:09 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2015-11-28 23:08 - 2015-12-06 02:30 - 00881036 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-28 23:08 - 2015-12-06 02:24 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-28 23:08 - 2015-11-28 23:08 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-11-28 23:05 - 2015-12-04 07:24 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-11-28 23:04 - 2015-11-28 23:36 - 00000000 ____D C:\Users\Jerome
2015-11-28 23:04 - 2015-11-28 23:04 - 00000000 _SHDL C:\Users\Jerome\My Documents
2015-11-28 23:04 - 2015-11-28 23:04 - 00000000 _SHDL C:\Users\Jerome\Documents\My Videos
2015-11-28 23:04 - 2015-11-28 23:04 - 00000000 _SHDL C:\Users\Jerome\Documents\My Pictures
2015-11-28 23:04 - 2015-11-28 23:04 - 00000000 _SHDL C:\Users\Jerome\Documents\My Music
2015-11-28 23:04 - 2015-11-28 23:04 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2015-11-28 23:01 - 2015-12-06 02:24 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-28 23:01 - 2015-11-28 23:04 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-28 23:01 - 2015-11-28 23:04 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-11-28 23:01 - 2015-11-28 23:04 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-11-28 23:01 - 2015-11-28 23:01 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-11-28 23:01 - 2015-11-28 23:01 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2015-11-28 23:01 - 2015-11-28 23:01 - 00000000 ____D C:\Program Files\Realtek
2015-11-28 23:01 - 2015-11-28 23:01 - 00000000 ____D C:\Program Files\Canon
2015-11-28 23:01 - 2015-10-30 01:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-11-28 23:01 - 2015-08-06 18:24 - 06873904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-11-28 23:01 - 2015-08-06 18:24 - 03492984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-11-28 23:01 - 2015-08-06 18:24 - 02558768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-11-28 23:01 - 2015-08-06 18:24 - 00937592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-11-28 23:01 - 2015-08-06 18:24 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-11-28 23:01 - 2015-08-06 18:24 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-11-28 23:01 - 2015-08-03 04:04 - 05133709 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-11-28 23:00 - 2015-11-28 23:05 - 00252320 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-28 22:38 - 2015-11-28 23:09 - 00009528 _____ C:\WINDOWS\diagwrn.xml
2015-11-28 22:38 - 2015-11-28 23:09 - 00009528 _____ C:\WINDOWS\diagerr.xml
2015-11-19 03:28 - 2015-11-19 03:28 - 00110176 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2015-11-19 03:27 - 2015-11-19 03:27 - 57017440 _____ (Oracle Corporation) C:\Users\Jerome\Downloads\jre-8u66-windows-x64.exe
2015-11-19 03:27 - 2015-11-19 03:27 - 00000000 ____D C:\Program Files\Java
2015-11-19 03:17 - 2015-11-28 23:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-19 03:17 - 2015-11-19 03:17 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-11-19 03:17 - 2015-11-19 03:17 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-19 03:16 - 2015-11-19 03:16 - 00584288 _____ (Oracle Corporation) C:\Users\Jerome\Downloads\jxpiinstall(1).exe
2015-11-19 03:14 - 2015-11-19 03:28 - 00000000 ____D C:\Users\Jerome\.oracle_jre_usage
2015-11-19 03:14 - 2015-11-19 03:14 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Sun
2015-11-19 03:13 - 2015-11-19 03:13 - 00584288 _____ (Oracle Corporation) C:\Users\Jerome\Downloads\jxpiinstall.exe
2015-11-17 01:59 - 2015-11-17 01:59 - 00001068 _____ C:\Users\Jerome\Modules.cfg
2015-11-17 01:56 - 2015-11-17 01:56 - 00014475 _____ C:\Users\Jerome\main.cfg
2015-11-17 01:46 - 2015-11-17 01:46 - 00421007 _____ C:\Users\Jerome\Downloads\IguanaTinkerTweaks-1.7.10-2.1.5.jar
2015-11-16 23:37 - 2015-11-16 23:37 - 00000079 _____ C:\Users\Jerome\server.properties
2015-11-07 22:56 - 2015-11-07 22:56 - 00001986 _____ C:\Users\Jerome\AppData\Local\recently-used.xbel

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-07 05:47 - 2015-10-30 00:28 - 00000000 ____D C:\Windows
2015-12-07 05:37 - 2014-01-08 03:23 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-07 04:50 - 2015-05-25 22:51 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-07 00:43 - 2014-01-31 11:15 - 00004142 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BA8CC4C1-355F-4D78-BCA8-868CFBE2712E}
2015-12-06 02:30 - 2015-10-30 01:21 - 00000000 ____D C:\WINDOWS\INF
2015-12-06 02:27 - 2014-04-21 23:35 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-06 02:24 - 2015-10-30 00:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-12-06 02:24 - 2014-11-14 23:49 - 00000000 ____D C:\AdwCleaner
2015-12-06 02:24 - 2014-01-08 03:50 - 00003028 _____ C:\WINDOWS\System32\Tasks\HDMISwitch
2015-12-06 02:24 - 2014-01-08 03:23 - 00000910 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-05 23:09 - 2015-10-30 01:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-05 01:53 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-05 00:07 - 2014-01-08 03:30 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-12-05 00:07 - 2014-01-08 03:29 - 00000000 _____ C:\Users\Jerome\AppData\Local\Driver_LOM_8161Present.flag
2015-12-05 00:06 - 2014-01-08 03:50 - 00000000 ____D C:\Program Files (x86)\Intel
2015-12-05 00:02 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-12-04 11:40 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\rescache
2015-12-04 07:24 - 2015-04-05 23:28 - 00000991 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk
2015-12-04 07:24 - 2015-03-10 12:56 - 00001387 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2015-12-04 07:24 - 2015-01-03 23:51 - 00000957 _____ C:\Users\Public\Desktop\pyfa.lnk
2015-12-04 07:24 - 2014-10-15 08:08 - 00000992 _____ C:\Users\Public\Desktop\Configure ReClock.lnk
2015-12-04 07:24 - 2014-07-30 00:20 - 00000641 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartDraw CI.lnk
2015-12-04 07:24 - 2014-07-19 05:55 - 00002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
2015-12-04 07:24 - 2014-07-19 05:55 - 00002130 _____ C:\Users\Public\Desktop\Belarc Advisor.lnk
2015-12-04 07:24 - 2014-07-16 16:24 - 00002082 _____ C:\Users\Public\Desktop\Canon MF Toolbox 4.9.lnk
2015-12-04 07:24 - 2014-06-04 15:00 - 00001031 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape.lnk
2015-12-04 07:24 - 2014-06-04 14:59 - 00001013 _____ C:\Users\Public\Desktop\Inkscape.lnk
2015-12-04 07:24 - 2014-05-29 21:24 - 00001195 _____ C:\Users\Public\Desktop\GOM Player.lnk
2015-12-04 07:24 - 2014-05-13 16:06 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-12-04 07:24 - 2014-05-13 16:06 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-12-04 07:24 - 2014-04-21 23:35 - 00001165 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-04 07:24 - 2014-03-21 02:43 - 00000940 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2015-12-04 07:24 - 2014-03-13 00:04 - 00001824 _____ C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-12-04 07:24 - 2014-03-03 18:29 - 00000940 _____ C:\Users\Public\Desktop\EPSON Scan.lnk
2015-12-04 07:24 - 2014-02-22 23:46 - 00002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-04 07:24 - 2014-01-11 20:51 - 00000942 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-12-04 07:24 - 2014-01-11 17:16 - 00001017 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2015-12-04 07:24 - 2014-01-08 05:10 - 00002045 _____ C:\Users\Public\Desktop\Action!.lnk
2015-12-04 07:24 - 2014-01-08 04:33 - 00000985 _____ C:\Users\Public\Desktop\Origin.lnk
2015-12-04 07:24 - 2014-01-08 03:59 - 00001102 _____ C:\Users\Public\Desktop\ASRock SmartConnect.lnk
2015-12-04 07:24 - 2014-01-08 03:59 - 00001078 _____ C:\Users\Public\Desktop\ASRock RapidStart.lnk
2015-12-04 07:24 - 2014-01-08 03:58 - 00001891 _____ C:\Users\Public\Desktop\XFast USB.LNK
2015-12-04 07:24 - 2014-01-08 03:50 - 00001323 _____ C:\Users\Public\Desktop\F-Stream Tuning.lnk
2015-12-04 07:24 - 2014-01-08 03:43 - 00000969 _____ C:\Users\Public\Desktop\Steam.lnk
2015-12-04 07:24 - 2014-01-08 03:23 - 00002254 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-04 07:23 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\Globalization
2015-12-04 07:23 - 2015-05-07 01:54 - 00000840 _____ C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2015-12-04 07:23 - 2015-04-05 23:28 - 00000991 _____ C:\Users\Jerome\Desktop\Pidgin.lnk
2015-12-04 07:23 - 2015-01-12 16:47 - 00001092 _____ C:\Users\Jerome\Desktop\EveRefinery.exe - Shortcut.lnk
2015-12-04 07:23 - 2014-12-21 01:42 - 00001026 _____ C:\Users\Jerome\Desktop\Mumble.lnk
2015-12-04 07:23 - 2014-11-25 19:56 - 00001138 _____ C:\Users\Jerome\Desktop\EVE-Central.com Contribtastic.lnk
2015-12-04 07:23 - 2014-11-22 01:17 - 00001907 _____ C:\Users\Jerome\Desktop\EVE.lnk
2015-12-04 07:23 - 2014-04-27 21:48 - 00001300 _____ C:\Users\Jerome\Desktop\Dogeminer.bat - Shortcut.lnk
2015-12-04 07:23 - 2014-03-13 00:04 - 00001818 _____ C:\Users\Jerome\Desktop\Spotify.lnk
2015-12-04 07:23 - 2014-02-10 19:55 - 00001760 _____ C:\Users\Jerome\Desktop\WildStar.lnk
2015-12-04 07:23 - 2014-02-02 00:40 - 00001225 _____ C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-12-04 07:23 - 2014-01-29 20:15 - 00001117 _____ C:\Users\Jerome\Desktop\FTB - Shortcut.lnk
2015-12-04 07:23 - 2014-01-10 23:27 - 00001217 _____ C:\Users\Jerome\Desktop\Uplay.lnk
2015-12-04 07:23 - 2014-01-08 03:28 - 00001098 _____ C:\Users\Jerome\Desktop\MSI Afterburner.lnk
2015-12-04 07:23 - 2014-01-08 03:21 - 00001168 _____ C:\Users\Jerome\Desktop\MSI GamingApp.lnk
2015-12-04 02:11 - 2014-01-10 02:09 - 00000000 ____D C:\Users\Jerome\AppData\Local\Adobe
2015-12-04 01:27 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-12-04 01:11 - 2015-10-30 01:24 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-02 23:05 - 2014-04-21 23:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-02 23:05 - 2014-04-21 23:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-02 23:02 - 2013-08-22 07:25 - 00000194 _____ C:\WINDOWS\win.ini
2015-12-02 23:01 - 2015-05-25 22:51 - 00003816 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-12-02 17:07 - 2014-11-12 17:13 - 00000000 ____D C:\ProgramData\Reprise
2015-12-02 17:07 - 2014-05-26 13:49 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\SketchUp
2015-12-02 17:07 - 2014-05-26 13:38 - 00000000 ____D C:\ProgramData\SketchUp
2015-12-02 02:40 - 2014-06-30 12:31 - 00000000 ____D C:\Users\Jerome\AppData\Local\ftblauncher
2015-12-01 22:32 - 2014-01-08 03:23 - 00003972 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-01 22:32 - 2014-01-08 03:23 - 00003740 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-11-29 23:45 - 2014-01-08 03:14 - 00000000 ____D C:\Users\Jerome\AppData\Local\Packages
2015-11-29 03:43 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\appcompat
2015-11-29 01:00 - 2015-10-30 01:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-11-29 00:59 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-29 00:59 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\Provisioning
2015-11-29 00:59 - 2015-10-30 00:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-11-29 00:59 - 2015-10-30 00:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-11-28 23:51 - 2015-10-30 01:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2015-11-28 23:48 - 2014-12-24 10:17 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-11-28 23:48 - 2014-01-10 02:10 - 00000000 ____D C:\ProgramData\Adobe
2015-11-28 23:36 - 2014-01-08 05:35 - 00032320 _____ (FNet Co., Ltd.) C:\WINDOWS\system32\Drivers\FNETTBOH_305.SYS
2015-11-28 23:34 - 2015-10-30 01:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-11-28 23:34 - 2015-10-30 01:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-11-28 23:34 - 2015-10-30 01:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-11-28 23:34 - 2015-10-30 01:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-11-28 23:10 - 2015-10-30 01:24 - 00000000 ____D C:\ProgramData\USOPrivate
2015-11-28 23:09 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-11-28 23:09 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\Registration
2015-11-28 23:09 - 2015-10-30 00:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-28 23:08 - 2015-10-30 01:24 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-28 23:08 - 2015-05-07 01:23 - 00002098 _____ C:\WINDOWS\System32\Tasks\{34887F4A-60F0-41BD-8AB9-E7F015957B12}
2015-11-28 23:08 - 2014-11-14 23:46 - 00002100 _____ C:\WINDOWS\System32\Tasks\{45C4881F-B7A8-467E-963C-CD5784C82615}
2015-11-28 23:08 - 2014-07-19 05:44 - 00002210 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe
2015-11-28 23:08 - 2014-07-19 05:44 - 00002184 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe
2015-11-28 23:08 - 2014-07-19 05:44 - 00002182 _____ C:\WINDOWS\System32\Tasks\Microsoft_Hardware_Launch_itype_exe
2015-11-28 23:08 - 2014-07-19 05:44 - 00002168 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2015-11-28 23:08 - 2014-07-19 05:44 - 00002166 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2015-11-28 23:08 - 2014-01-08 03:31 - 00879220 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-11-28 23:08 - 2014-01-08 03:19 - 00002808 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2043291374-1636051585-76882383-1001
2015-11-28 23:05 - 2015-10-28 12:44 - 00000000 ____D C:\WINDOWS\SysWOW64\Codecs
2015-11-28 23:05 - 2015-10-28 12:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player - Codec Pack
2015-11-28 23:05 - 2015-08-29 23:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-11-28 23:05 - 2015-06-10 15:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BOSS
2015-11-28 23:05 - 2015-03-10 12:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-28 23:05 - 2015-03-03 20:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOOT
2015-11-28 23:05 - 2015-01-03 23:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyfa
2015-11-28 23:05 - 2014-11-25 19:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EVE-Central.com
2015-11-28 23:05 - 2014-11-22 01:17 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVE
2015-11-28 23:05 - 2014-10-15 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReClock
2015-11-28 23:05 - 2014-10-15 08:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
2015-11-28 23:05 - 2014-09-28 21:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2015-11-28 23:05 - 2014-07-19 05:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
2015-11-28 23:05 - 2014-07-16 16:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon D560_D530
2015-11-28 23:05 - 2014-04-28 03:20 - 00000000 ____D C:\Program Files\Classic Shell
2015-11-28 23:05 - 2014-04-27 20:38 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dogecoin
2015-11-28 23:05 - 2014-03-05 21:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bamboo
2015-11-28 23:05 - 2014-03-03 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Scan
2015-11-28 23:05 - 2014-02-22 23:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-11-28 23:05 - 2014-02-20 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-11-28 23:05 - 2014-02-02 00:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
2015-11-28 23:05 - 2014-01-24 00:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2015-11-28 23:05 - 2014-01-11 17:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2015-11-28 23:05 - 2014-01-11 10:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2015-11-28 23:05 - 2014-01-10 02:22 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2015-11-28 23:05 - 2014-01-08 06:26 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
2015-11-28 23:05 - 2014-01-08 05:08 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
2015-11-28 23:05 - 2014-01-08 03:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XFast USB
2015-11-28 23:05 - 2014-01-08 03:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-11-28 23:05 - 2014-01-08 03:31 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-11-28 23:05 - 2014-01-08 03:28 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2015-11-28 23:05 - 2014-01-08 03:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-28 23:05 - 2014-01-07 17:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-11-28 23:05 - 2014-01-07 16:17 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-28 23:05 - 2014-01-07 16:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-28 23:05 - 2013-08-22 07:36 - 00000000 ____D C:\Users\Default.migrated
2015-11-28 23:04 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\spool
2015-11-28 23:04 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-11-28 23:04 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2015-11-28 23:04 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\InputMethod
2015-11-28 23:04 - 2015-10-30 01:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-11-28 23:04 - 2014-12-21 01:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2015-11-28 23:04 - 2014-07-16 16:23 - 00000000 ___HD C:\WINDOWS\system32\CanonMF Uninstaller Information
2015-11-28 23:04 - 2014-07-16 16:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon
2015-11-28 23:04 - 2014-02-10 19:55 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCSOFT
2015-11-28 23:04 - 2014-01-10 23:27 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-11-28 23:04 - 2014-01-08 05:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
2015-11-28 23:04 - 2014-01-08 04:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-11-28 23:04 - 2014-01-08 03:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fatal1ty Utility
2015-11-28 23:04 - 2014-01-08 03:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
2015-11-28 23:04 - 2014-01-08 03:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-11-28 23:04 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2015-11-28 23:04 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2015-11-28 23:04 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\ADFS
2015-11-28 23:02 - 2015-10-30 00:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-11-28 23:01 - 2015-10-30 03:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2015-11-28 23:01 - 2015-10-30 01:24 - 00000000 __RSD C:\WINDOWS\Media
2015-11-28 23:01 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\Help
2015-11-28 22:38 - 2015-10-30 03:42 - 00000000 ___HD C:\$WINDOWS.~BT
2015-11-19 03:17 - 2014-01-07 14:41 - 00000000 ____D C:\ProgramData\Oracle
2015-11-17 02:09 - 2015-08-29 23:39 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\FileZilla
2015-11-17 01:29 - 2014-01-09 00:14 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\ClassicShell
2015-11-16 23:35 - 2015-08-29 23:39 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2015-11-14 04:14 - 2014-05-13 16:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-14 04:13 - 2013-08-22 09:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-11-11 01:12 - 2014-01-10 03:48 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-11 01:10 - 2014-01-10 03:48 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-07 22:56 - 2014-01-11 20:56 - 00000000 ____D C:\Users\Jerome\AppData\Local\gtk-2.0
2015-11-07 22:56 - 2014-01-11 20:52 - 00000000 ____D C:\Users\Jerome\.gimp-2.8
2015-11-07 22:22 - 2014-03-13 00:04 - 00000000 ____D C:\Users\Jerome\AppData\Local\Spotify
2015-11-07 20:35 - 2014-03-13 00:04 - 00000000 ____D C:\Users\Jerome\AppData\Roaming\Spotify

==================== Files in the root of some directories =======

2014-01-08 03:29 - 2015-12-05 00:07 - 0000000 _____ () C:\Users\Jerome\AppData\Local\Driver_LOM_8161Present.flag
2015-11-07 22:56 - 2015-11-07 22:56 - 0001986 _____ () C:\Users\Jerome\AppData\Local\recently-used.xbel
2015-11-28 23:01 - 2015-11-28 23:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-28 23:00

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by Jerome (2015-12-07 05:48:24)
Running from C:\Users\Jerome\Downloads
Windows 10 Home (X64) (2015-11-29 05:34:48)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2043291374-1636051585-76882383-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2043291374-1636051585-76882383-503 - Limited - Disabled)
Guest (S-1-5-21-2043291374-1636051585-76882383-501 - Limited - Disabled)
Jerome (S-1-5-21-2043291374-1636051585-76882383-1001 - Administrator - Enabled) => C:\Users\Jerome

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\uTorrent) (Version: 3.4.5.41202 - BitTorrent Inc.)
Action! (HKLM-x32\...\Mirillis Action!) (Version: 1.16.3 - Mirillis)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
ASRock HDMI Switch v1.0.25 (HKLM-x32\...\ASRock HDMI Switch_is1) (Version: 1.0.25 - )
ASRock Key Master v1.0.6 (HKLM-x32\...\ASRock Key Master_is1) (Version: 1.0.6 - )
ASRock RapidStart v1.0.7 (HKLM\...\ASRock RapidStart_is1) (Version: - ASRock Inc.)
ASRock SmartConnect v1.0.6 (HKLM\...\ASRock SmartConnect_is1) (Version: - ASRock Inc.)
ASRock XFast RAM v3.0.2 (HKLM\...\ASRock XFast RAM_is1) (Version: - ASRock Inc.)
Assassins Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft)
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - )
Bamboo (HKLM\...\Pen Tablet Driver) (Version: 5.2.5-5 - Wacom Technology Corp.)
BattleBlock Theater (HKLM-x32\...\Steam App 238460) (Version: - The Behemoth)
Belarc Advisor 8.4 (HKLM-x32\...\Belarc Advisor) (Version: 8.4.0.0 - Belarc Inc.)
BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version: - Irrational Games)
BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software)
BOSS (HKLM-x32\...\BOSS) (Version: 2.1.1 - BOSS Development Team)
Canon D530/D560 (HKLM\...\{50D00125-863A-47ee-BB02-9CB950BEDE16}) (Version: 4.1.0.1 - CANON INC.)
Canon MF Toolbox 4.9.1.1.mf14 (HKLM-x32\...\{6767DFEE-8909-453A-B553-C7693912B2EB}) (Version: 4.9.1.1.mf14 - CANON INC.)
Chainmail Ring Aspect Ratio Calculator (HKLM-x32\...\{AC780F67-E0C5-457A-9C39-ECB156744F67}) (Version: 1.0.0 - ADR)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
Cobian Backup 11 Gravity (HKLM-x32\...\CobBackup11) (Version: - )
Contribtastic 2.1.2 (HKLM-x32\...\Contribtastic) (Version: 2.1.2 - StackFoundry LLC)
Curse Client (HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
Darksiders (HKLM-x32\...\Steam App 50620) (Version: - Vigil Games)
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.64 - DivX, LLC)
Dogecoin (HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\Dogecoin) (Version: 1.6.0.0 - Dogecoin)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
EVE Online (remove only) (HKLM-x32\...\EVE) (Version: - CCP Games Ltd.)
f.lux (HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\Flux) (Version: - )
FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse)
F-Stream Tuning v2.0.39.1 (HKLM-x32\...\F-Stream Tuning_is1) (Version: 2.0.39.1 - )
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.71.5231 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.73 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.10.251 - SurfRight B.V.)
Inkscape 0.48.4 (HKLM-x32\...\Inkscape) (Version: 0.48.4 - )
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
Java 8 Update 66 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
LOOT (HKLM-x32\...\LOOT) (Version: 0.6.1 - LOOT Development Team)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Media Player Codec Pack 4.4.0 (HKLM-x32\...\Media Player - Codec Pack) (Version: 4.4.0 - Media Player Codec Pack)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 en-US)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD)
MSI GamingApp (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 1.0.0.3 - MSI)
Mumble 1.2.8 (HKLM-x32\...\{A9DBD31A-A09F-4C7E-86D1-3B21C59000D1}) (Version: 1.2.8 - Thorvald Natvig)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.56.1 - Black Tree Gaming)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.6 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.06 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.5.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.44 - NVIDIA Corporation)
NVIDIA Graphics Driver 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.06 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA Miracast Virtual Audio 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.06 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
OpenOffice 4.0.1 (HKLM-x32\...\{47F460DA-D1BE-4D85-8DF2-AA1F31D3445F}) (Version: 4.01.9714 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 9.3.11.2762 - Electronic Arts, Inc.)
Pidgin (HKLM-x32\...\Pidgin) (Version: 2.10.11 - )
pyfa version 1.10.0 (Scylla 1.0) (HKLM-x32\...\{3DA39096-C08D-49CD-90E0-1D177F32C8AA}_is1) (Version: 1.10.0 (Scylla 1.0) - pyfa)
Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer E220x Drivers (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\...\{FE5DFB80-6937-4154-A2C7-EF845C1301F8}) (Version: 1.0.30.1259 - Qualcomm Atheros)
Qualcomm Atheros Network Manager (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden
QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
ReClock (HKLM-x32\...\ReClock) (Version: - SlySoft, Inc.)
SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.5.44 - NVIDIA Corporation) Hidden
SketchUp 2016 (HKLM\...\{D87EE6DC-32BA-4219-AC75-0A6FD54ED058}) (Version: 16.0.19912 - Trimble Navigation Limited)
Spotify (HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\Spotify) (Version: 1.0.4.90.g0b6df40b - Spotify AB)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1210 - SUPERAntiSpyware.com)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
Uplay (HKLM-x32\...\Uplay) (Version: 4.2 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
WebTablet FB Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.0.0.1 - Wacom Technology Corp.)
WebTablet IE Plugin (HKLM-x32\...\Wacom WebTabletPlugin for IE) (Version: 1.1.0.12 - Wacom Technology Corp.)
WebTablet Netscape Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Netscape) (Version: 1.1.0.10 - Wacom Technology Corp.)
WildStar (HKLM-x32\...\WildStar) (Version: 1.0.0.6505 - NCSOFT)
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
XFastUSB (HKLM-x32\...\XFastUSB) (Version: 3.02.38 - ASRock Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2043291374-1636051585-76882383-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Jerome\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 07:25 - 2015-10-27 11:48 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {011946F0-6E6C-48E6-A97E-2060B805CABF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2BE8C9DC-1845-4AD1-9D38-EBDFF346CB10} - System32\Tasks\{34887F4A-60F0-41BD-8AB9-E7F015957B12} => pcalua.exe -a C:\Users\Jerome\Downloads\deluge-1.3.11-win32-setup.exe -d C:\Users\Jerome\Downloads
Task: {2D9524F5-840F-4341-A485-F115DA98B931} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {30742F55-427C-4102-9399-019D07C7460F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {3105FAEC-9AE3-4DB7-8592-D68D51131377} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {4CB31E23-09F5-48A2-B1D6-A049068972FB} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {5E32E457-12A9-43CF-AC8E-0D462D46BD57} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {61EC1E06-85D3-466D-A22F-3386E0BC348A} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {641CE875-950A-450C-99A4-AA02039EF3A2} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {67FF922D-AC73-4773-9315-F6883CE66A6D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {71339FA9-97A6-4D56-9576-BBB278633EFE} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {71422E84-32E7-46DA-A6DA-937DBB0F5119} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-11-11] (Microsoft Corporation)
Task: {858FD14F-EEA0-48CF-A8CE-A080A8766A87} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {880E7994-F067-4ADE-BEB6-ADD9C4722FC8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {8E608894-33BC-496E-91BD-57340769CA21} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-04] (Adobe Systems Incorporated)
Task: {919A3CE4-33AC-4F9C-97F0-326636FD374E} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {9E8842DC-F1CA-45AE-9E15-5FCC0BB3EEA6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {A38E1C3F-A67C-4F88-A2B0-42750C82A592} - System32\Tasks\{45C4881F-B7A8-467E-963C-CD5784C82615} => pcalua.exe -a "C:\Program Files (x86)\ReClock\uninstall.exe" -c /D="C:\Program Files (x86)\ReClock"
Task: {A897AA61-641A-4246-9CC2-A0C27E6C0A8F} - System32\Tasks\SUPERAntiSpyware Scheduled Task e4cf6373-4472-4af4-90bd-799002eada42 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {A9E8690F-B379-4E34-A1AD-C944A1C19A4E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {AB6F6D3C-FF79-478C-BA52-E99C27CD2D74} - \IBUpd -> No File <==== ATTENTION
Task: {C672E22D-15A8-40C4-8C5E-510CDE835EB3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {C82B444E-66C3-4D27-94EF-DEEB5BEC54E9} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {D539F20E-E4EB-47F3-8DB4-D2860A776F02} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {DDF593EE-B54A-4CD6-A6A3-157E7AC53FD8} - System32\Tasks\SUPERAntiSpyware Scheduled Task afda71bf-c67f-4457-b989-c657dc2b58d4 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {F002A929-45D7-48D7-91CD-D7A21138C107} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {F676ECDD-1C2B-435E-967D-37F38725FDDB} - System32\Tasks\HDMISwitch => C:\Program Files (x86)\ASRock Utility\HDMISwitch\Bin\HDMISwitch.exe [2013-09-04] () <==== ATTENTION
Task: {FEFD7529-61A8-415C-9D0B-D7B5A5D21830} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task afda71bf-c67f-4457-b989-c657dc2b58d4.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task e4cf6373-4472-4af4-90bd-799002eada42.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Jerome\Desktop\Dogeminer.bat - Shortcut.lnk -> C:\Users\Jerome\Desktop\cudaminer-2014-02-28\x64\Dogeminer.bat () <==== ATTENTION

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 01:18 - 2015-10-30 01:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2014-01-08 03:50 - 2013-05-28 19:58 - 00454656 _____ () C:\Program Files (x86)\Fatal1ty Utility\F-Stream Tuning\Bin\IOMonitorSrv.exe
2015-12-03 01:20 - 2015-11-22 04:47 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 01:20 - 2015-11-22 04:47 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-11-29 00:14 - 2015-11-29 00:15 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-10-30 01:17 - 2015-10-30 01:17 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-10-30 01:17 - 2015-10-30 01:17 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-12-03 01:20 - 2015-11-22 03:23 - 08005632 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-12-03 01:20 - 2015-11-22 03:18 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-12-03 01:20 - 2015-11-22 03:19 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-12-03 01:20 - 2015-11-22 03:21 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-10-16 04:02 - 2015-10-16 04:02 - 00043480 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2015-11-28 23:01 - 2015-08-06 18:24 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-11-29 00:14 - 2015-11-29 00:15 - 00152064 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2015-11-29 00:14 - 2015-11-29 00:15 - 18906624 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkyWrap.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Program Files\Classic Shell:Win32App_1
AlternateDataStreams: C:\Program Files\FileZilla FTP Client:Win32App_1
AlternateDataStreams: C:\Program Files\GIMP 2:Win32App_1
AlternateDataStreams: C:\Program Files\HitmanPro:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Mouse and Keyboard Center:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App_1
AlternateDataStreams: C:\Program Files\Nexus Mod Manager:Win32App_1
AlternateDataStreams: C:\Program Files\SUPERAntiSpyware:Win32App_1
AlternateDataStreams: C:\Program Files\TeamSpeak 3 Client:Win32App_1
AlternateDataStreams: C:\Program Files\WinRAR:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Inkscape:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Malware:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Mozilla Firefox:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Mumble:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\OpenOffice 4:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Origin:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\pyfa:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\ReClock:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\Logitech:Win32App_1
AlternateDataStreams: C:\ProgramData\BitRaider:Win32App_1
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2043291374-1636051585-76882383-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jerome\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2043291374-1636051585-76882383-1001\...\StartupApproved\Run: => "SearchProtection"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{F479B825-C0EB-4275-AA05-98823975514F}C:\program files\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [TCP Query User{21D59DB0-B866-4DB4-BE0C-91617009BF74}C:\program files\java\jre1.8.0_66\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_66\bin\javaw.exe
FirewallRules: [{67D391D0-6F7F-407D-BCBB-4DBD2728B1D7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D46DFBB2-46EC-4C7B-B880-74C2A801A466}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{FE7D02FB-FA08-42E1-B688-54D22A8F4336}C:\users\jerome\desktop\multicraft\multicraft\bin\multicraft.exe] => (Block) C:\users\jerome\desktop\multicraft\multicraft\bin\multicraft.exe
FirewallRules: [TCP Query User{4D7A77F7-B506-4321-93B8-59640544247A}C:\users\jerome\desktop\multicraft\multicraft\bin\multicraft.exe] => (Block) C:\users\jerome\desktop\multicraft\multicraft\bin\multicraft.exe
FirewallRules: [UDP Query User{2001CA01-F7F0-4AD9-8939-14C4A65CA954}C:\users\jerome\desktop\multicraft\nginx\nginx.exe] => (Block) C:\users\jerome\desktop\multicraft\nginx\nginx.exe
FirewallRules: [TCP Query User{3972EBCF-39E5-4989-94AC-A11AD0C193FD}C:\users\jerome\desktop\multicraft\nginx\nginx.exe] => (Block) C:\users\jerome\desktop\multicraft\nginx\nginx.exe
FirewallRules: [{B0743A93-3634-46C8-8641-6DBA8A0968AE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{75B0B043-982D-40C4-B099-DA7B37D48498}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{0DB9581E-CC10-46AC-BAED-D68DD0686646}C:\program files\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [TCP Query User{AEC0CB32-C42E-4FD5-931C-FBA6A046BC10}C:\program files\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{E015C267-9842-4B79-B4A0-F705B99771AF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{3A7A931C-0189-459D-BE94-1CE41DE8CDA5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{1E94A8CA-B21D-4786-81BE-E69F14FE9DD3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{1EEA10A4-B36A-42CB-B83F-91148E84CB5E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{F14A995E-1EAD-4DC0-ABDE-17F25B9798C0}] => (Allow) LPort=3724
FirewallRules: [{9AEEDE03-6553-4247-A4E5-2E1699A8D539}] => (Allow) LPort=26000
FirewallRules: [{7BE52469-EF36-496C-96ED-DC702AD3FBFA}] => (Allow) C:\Users\Jerome\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8EE183A9-96B7-44E3-9E5C-6039F2432A0F}] => (Allow) C:\Users\Jerome\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [UDP Query User{53839563-2DDC-45CE-94FA-4AFC2A55F5A0}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe
FirewallRules: [TCP Query User{122176C2-4192-4F03-B5BC-4DFEE3B1388A}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe
FirewallRules: [UDP Query User{3A1CD28F-925E-47D2-BEAE-DA63C370DD3A}C:\program files (x86)\ccp\eve\bin\exefile.exe] => (Allow) C:\program files (x86)\ccp\eve\bin\exefile.exe
FirewallRules: [TCP Query User{D8849A86-5FF9-4A22-B218-74E30D9D6574}C:\program files (x86)\ccp\eve\bin\exefile.exe] => (Allow) C:\program files (x86)\ccp\eve\bin\exefile.exe
FirewallRules: [{CC4AF012-22AC-4F57-B015-3F0A188EE42A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{30C571A5-AD07-40AD-87E3-FE80C6B12E22}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{9744CC06-3067-41D7-96E9-AF3DAAEC5D53}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{B39DAA8B-A36B-45A0-815B-4A52C0963B8B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{D19D93AD-D652-45A1-AB1A-6C1588B63CE3}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{06441309-0A15-4D42-8164-36A638EB7CE8}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [UDP Query User{4E8D3921-35E2-4C09-B4D6-4EA5A27685B5}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{FCEC9093-253A-4C98-BBBA-12ABA0C45AA9}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [{535D71C1-6DF5-45A4-BF89-B175746B455E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{0224DED2-E80E-4F3A-86D5-E296BB9CBA0D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [UDP Query User{26A3A4A2-57EE-4736-B716-F67E6C98B9E4}C:\program files (x86)\ccp\eve\bin\exefile.exe] => (Allow) C:\program files (x86)\ccp\eve\bin\exefile.exe
FirewallRules: [TCP Query User{9365DBB7-9D2F-4505-8C6E-F45192E0C9E0}C:\program files (x86)\ccp\eve\bin\exefile.exe] => (Allow) C:\program files (x86)\ccp\eve\bin\exefile.exe
FirewallRules: [{62D79530-81C5-4C2C-9C62-E9AEADD4549C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BattleBlock Theater\BattleBlockTheater.exe
FirewallRules: [{00A66F29-2F58-46A8-AC66-ABD84CA5FF69}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BattleBlock Theater\BattleBlockTheater.exe
FirewallRules: [UDP Query User{FD1D5E56-F62D-4391-9C79-85F3006C97B3}C:\program files (x86)\dogecoin\dogecoin-qt.exe] => (Allow) C:\program files (x86)\dogecoin\dogecoin-qt.exe
FirewallRules: [TCP Query User{224EC51F-FEF7-4BE1-9AC9-CC768F33879A}C:\program files (x86)\dogecoin\dogecoin-qt.exe] => (Allow) C:\program files (x86)\dogecoin\dogecoin-qt.exe
FirewallRules: [UDP Query User{29C1D649-6E46-46B0-9F1C-4E6AE15DF9BB}C:\users\jerome\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jerome\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{CC78BBE4-64DB-429A-B8EE-E811C7BB4BE4}C:\users\jerome\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\jerome\appdata\roaming\spotify\spotify.exe
FirewallRules: [{3B4D447D-B9B7-4CCD-BE32-F7BD256CF377}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{70762CCB-3280-4A48-A998-B9BE0A159F1C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{2D2611E3-0066-43F4-920A-291D4401A9A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{DFE52C2E-157F-45BB-89ED-ECB7C8FB2D62}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{DAE5C30C-AE42-4DFF-A0DE-09E8164FD284}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFMP.exe
FirewallRules: [{8DA8244A-8238-4BC0-8BF7-D36C2DF5433D}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{8ABA7055-CBE9-4EC7-911E-971E33E627BF}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{84BD83FB-09BE-464D-9A03-F2C87D8B515D}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{CD9417E3-7AFC-407A-8C33-D2BA595FD388}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{6862C3B5-B29A-4D20-8AF4-F7CC5450260F}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{73B2A6BD-9185-4E81-9A9C-47DF873C230E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{7EAE7E49-1F9B-424A-B1CD-7758C9EE7788}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{EB792FA9-0A7F-413A-9952-7EC342AB6A33}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [UDP Query User{0CE49039-171F-49A2-B415-5DA2E4E2C738}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{EE93F017-048D-4A7C-BB1D-D201E229CDA1}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{0272197B-1756-4C5A-B454-04DC4A4FD17E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{7A449FF7-79B7-47BF-8A4A-4849640A7D94}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\Benchmark.bat
FirewallRules: [{1812015F-A1DA-4BF0-86BA-B3C97EB894ED}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{EE945491-FA08-455F-8D0A-B1FD2C9AE956}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{AD30225F-6246-44D1-B5BE-3D76A33104CB}] => (Allow) C:\Users\Jerome\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A5DAA60B-7972-4236-AC6B-101DAC2BEBF7}] => (Allow) C:\Users\Jerome\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3881F5A8-BE80-4698-B0DA-80F7A7330E14}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{4EB6F569-5C23-45DE-A94F-E3065296393C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{99CA9419-43F3-48CA-9461-085920CBEB16}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/07/2015 02:10:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SUPERAntiSpyware.exe, version: 6.0.0.1210, time stamp: 0x565e2b05
Faulting module name: ntdll.dll, version: 10.0.10586.0, time stamp: 0x5632d193
Exception code: 0xc0000374
Fault offset: 0x00000000000edfac
Faulting process id: 0x42c
Faulting application start time: 0xSUPERAntiSpyware.exe0
Faulting application path: SUPERAntiSpyware.exe1
Faulting module path: SUPERAntiSpyware.exe2
Report Id: SUPERAntiSpyware.exe3
Faulting package full name: SUPERAntiSpyware.exe4
Faulting package-relative application ID: SUPERAntiSpyware.exe5

Error: (12/06/2015 02:25:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 42.0.0.5780, time stamp: 0x5632d0a4
Faulting module name: mozglue.dll, version: 42.0.0.5780, time stamp: 0x5632ba58
Exception code: 0x80000003
Fault offset: 0x0000ed50
Faulting process id: 0x1f14
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (12/06/2015 02:25:45 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (12/06/2015 02:24:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 42.0.0.5780, time stamp: 0x5632d0a4
Faulting module name: mozglue.dll, version: 42.0.0.5780, time stamp: 0x5632ba58
Exception code: 0x80000003
Fault offset: 0x0000ed50
Faulting process id: 0x7bc
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
Faulting package full name: plugin-container.exe4
Faulting package-relative application ID: plugin-container.exe5

Error: (12/05/2015 11:09:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (12/05/2015 03:18:03 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
Gathering Writer Data

Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {5e749031-b9f5-40e3-be7f-688999043eaf}

Error: (12/05/2015 02:24:07 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
Gathering Writer Data

Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {5e749031-b9f5-40e3-be7f-688999043eaf}

Error: (12/05/2015 02:08:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SUPERAntiSpyware.exe, version: 6.0.0.1210, time stamp: 0x565e2b05
Faulting module name: ntdll.dll, version: 10.0.10586.0, time stamp: 0x5632d193
Exception code: 0xc0000374
Fault offset: 0x00000000000edfac
Faulting process id: 0x1bf0
Faulting application start time: 0xSUPERAntiSpyware.exe0
Faulting application path: SUPERAntiSpyware.exe1
Faulting module path: SUPERAntiSpyware.exe2
Report Id: SUPERAntiSpyware.exe3
Faulting package full name: SUPERAntiSpyware.exe4
Faulting package-relative application ID: SUPERAntiSpyware.exe5

Error: (12/05/2015 12:07:15 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: InstallPrepTool.exe, version: 1.0.0.0, time stamp: 0x5203f1f0
Faulting module name: KERNELBASE.dll, version: 10.0.10586.0, time stamp: 0x5632d1de
Exception code: 0xe0434352
Fault offset: 0x0000000000071f08
Faulting process id: 0x1018
Faulting application start time: 0xInstallPrepTool.exe0
Faulting application path: InstallPrepTool.exe1
Faulting module path: InstallPrepTool.exe2
Report Id: InstallPrepTool.exe3
Faulting package full name: InstallPrepTool.exe4
Faulting package-relative application ID: InstallPrepTool.exe5

Error: (12/05/2015 12:07:15 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: InstallPrepTool.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.FormatException
at System.Text.StringBuilder.AppendFormatHelper(System.IFormatProvider, System.String, System.ParamsArray)
at System.String.FormatHelper(System.IFormatProvider, System.String, System.ParamsArray)
at System.String.Format(System.String, System.Object)
at Qualcomm.InstallUtilities.HardwareCleaner.Clean(Qualcomm.InstallUtilities.ILogger)
at Qualcomm.InstallUtilities.LOM8161Cleaner.CleanLOM8161(Qualcomm.InstallUtilities.ILogger)
at InstallPrepTool.Program.Clean()
at InstallPrepTool.Program.Main(System.String[])


System errors:
=============
Error: (12/06/2015 03:27:22 AM) (Source: volsnap) (EventID: 36) (User: )
Description: The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.

Error: (12/06/2015 02:27:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYNETWORK SERVICES-1-5-20LocalHost (Using LRPC)UnavailableUnavailable

Error: (12/06/2015 02:27:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYNETWORK SERVICES-1-5-20LocalHost (Using LRPC)UnavailableUnavailable

Error: (12/06/2015 02:26:56 AM) (Source: DCOM) (EventID: 10016) (User: HAL)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}HALJeromeS-1-5-21-2043291374-1636051585-76882383-1001LocalHost (Using LRPC)Microsoft.WindowsStore_2015.23.23.0_x64__8wekyb3d8bbweS-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157

Error: (12/06/2015 02:25:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The TabletServicePen service terminated unexpectedly. It has done this 1 time(s).

Error: (12/06/2015 02:25:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Streamer Service service terminated unexpectedly. It has done this 1 time(s).

Error: (12/06/2015 02:25:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).

Error: (12/06/2015 02:24:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_46f6d service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (12/06/2015 02:24:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_46f6d service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (12/06/2015 02:24:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_46f6d service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.


CodeIntegrity:
===================================
Date: 2015-12-06 02:27:38.006
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-12-04 01:28:03.312
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-12-02 23:18:07.905
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-12-02 23:00:43.160
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-02 23:00:43.155
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-02 23:00:43.149
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-02 23:00:43.139
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-02 23:00:42.908
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-02 23:00:41.311
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-02 23:00:41.302
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel® Core™ i5-4670K CPU @ 3.40GHz
Percentage of memory in use: 20%
Total physical RAM: 16314.74 MB
Available physical RAM: 12926.14 MB
Total Virtual: 18746.74 MB
Available Virtual: 14940.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.1 GB) (Free:23.74 GB) NTFS
Drive e: (Elements) (Fixed) (Total:2794.52 GB) (Free:2122.85 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 6012F8DF)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Attempted reading MBR returned 0 bytes.
Could not read MBR for disk 1.

==================== End of Addition.txt ============================

Attached Files


Edited by Oh My!, 08 December 2015 - 03:05 PM.


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 08 December 2015 - 03:12 PM

Greetings DocWhoops and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Are you aware of these?

http://unstopp.me
C:\Users\Jerome\Desktop\cudaminer-2014-02-28\x64\Dogeminer.bat


Please consider and do this.

===================================================

P2P Warning

--------------------

Going over your logs I noticed that you have µTorrent installed. It is pretty much certain that if you continue to use P2P programs, you will get infected again.
  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove the program, you can do so via Start > Control Panel > Add/Remove Programs.

If you are still leaning toward using this program, please take a look at this information about Ransomware which can be delivered via P2P file transfers. The newest variation of Ransomware can make it impossible to recover the files this malicious software encrypts. In other words, you will probably lose most if not all of your valuable information, including pictures. In addition it has recently been reported that P2P downloads may be tracked resulting in your IP address being monitored by copyright authorities. .

If you wish to keep it, please do not use it until we are completely done and your machine is determined to be clean and updated.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_44&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0Ezz0BtC0DtDyDyD0FzztN0D0Tzu0StCtAzyyDtN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StCyDzy0BtB0CtD0AtGyE0BtCyDtGtAzz0E0EtGyCtAzztDtGzy0E0EyCyBtB0A0AtAyCzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAzzzy0C0EyDyD0CtGtBtBtA0CtGyEtA0E0BtGzztCyE0DtGzyyE0E0CyCtCtBtDzz0Fzyzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D740488204%26a%3Dwbf_gmmedply_15_44%26os%3DWindows%2B8.1&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_44&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0Ezz0BtC0DtDyDyD0FzztN0D0Tzu0StCtAzyyDtN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StCyDzy0BtB0CtD0AtGyE0BtCyDtGtAzz0E0EtGyCtAzztDtGzy0E0EyCyBtB0A0AtAyCzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAzzzy0C0EyDyD0CtGtBtBtA0CtGyEtA0E0BtGzztCyE0DtGzyyE0E0CyCtCtBtDzz0Fzyzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D740488204%26a%3Dwbf_gmmedply_15_44%26os%3DWindows%2B8.1&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2043291374-1636051585-76882383-1001 -> DefaultScope {cf34d395-9ff1-49a0-98a5-8db1636431b1} URL =
Task: {011946F0-6E6C-48E6-A97E-2060B805CABF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2D9524F5-840F-4341-A485-F115DA98B931} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {3105FAEC-9AE3-4DB7-8592-D68D51131377} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {4CB31E23-09F5-48A2-B1D6-A049068972FB} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {5E32E457-12A9-43CF-AC8E-0D462D46BD57} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {858FD14F-EEA0-48CF-A8CE-A080A8766A87} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {9E8842DC-F1CA-45AE-9E15-5FCC0BB3EEA6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {A9E8690F-B379-4E34-A1AD-C944A1C19A4E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {AB6F6D3C-FF79-478C-BA52-E99C27CD2D74} - \IBUpd -> No File <==== ATTENTION
Task: {C672E22D-15A8-40C4-8C5E-510CDE835EB3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {C82B444E-66C3-4D27-94EF-DEEB5BEC54E9} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {D539F20E-E4EB-47F3-8DB4-D2860A776F02} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {F676ECDD-1C2B-435E-967D-37F38725FDDB} - System32\Tasks\HDMISwitch => C:\Program Files (x86)\ASRock Utility\HDMISwitch\Bin\HDMISwitch.exe [2013-09-04] () <==== ATTENTION
Task: {FEFD7529-61A8-415C-9D0B-D7B5A5D21830} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Farbar's MiniToolBox

--------------------
  • Please download MiniToolBox, save it to your desktop
  • Please close any Firefox browsers you may have open
  • Double click the icon to launch the program
  • Make sure only the following options are checked:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries

  • Click Go and once the scan is completed a Result.txt Notepad document will open on your desktop
  • Please copy and paste the contents in your reply
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • MiniToolBox log
  • System Summary Information

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 DocWhoops

DocWhoops
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:09 PM

Posted 08 December 2015 - 08:15 PM

Thank you so much

 

I don't know what unstop.me is. Dogeminer and utorrent haven't been used in a long time, so I uninstalled both and did a little tidying up.

 

Fix result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by Jerome (2015-12-08 18:59:01) Run:1
Running from C:\Users\Jerome\Desktop
Loaded Profiles: Jerome (Available Profiles: Jerome)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_44&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0Ezz0BtC0DtDyDyD0FzztN0D0Tzu0StCtAzyyDtN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StCyDzy0BtB0CtD0AtGyE0BtCyDtGtAzz0E0EtGyCtAzztDtGzy0E0EyCyBtB0A0AtAyCzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAzzzy0C0EyDyD0CtGtBtBtA0CtGyEtA0E0BtGzztCyE0DtGzyyE0E0CyCtCtBtDzz0Fzyzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D740488204%26a%3Dwbf_gmmedply_15_44%26os%3DWindows%2B8.1&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_gmmedply_15_44&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0B0CyD0F0FyE0Ezz0BtC0DtDyDyD0FzztN0D0Tzu0StCtAzyyDtN1L2XzutAtFtCtBtFyBtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2StCyDzy0BtB0CtD0AtGyE0BtCyDtGtAzz0E0EtGyCtAzztDtGzy0E0EyCyBtB0A0AtAyCzztB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StAzzzy0C0EyDyD0CtGtBtBtA0CtGyEtA0E0BtGzztCyE0DtGzyyE0E0CyCtCtBtDzz0Fzyzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDzzzy%26cr%3D740488204%26a%3Dwbf_gmmedply_15_44%26os%3DWindows%2B8.1&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2043291374-1636051585-76882383-1001 -> DefaultScope {cf34d395-9ff1-49a0-98a5-8db1636431b1} URL =
Task: {011946F0-6E6C-48E6-A97E-2060B805CABF} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2D9524F5-840F-4341-A485-F115DA98B931} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {3105FAEC-9AE3-4DB7-8592-D68D51131377} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {4CB31E23-09F5-48A2-B1D6-A049068972FB} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {5E32E457-12A9-43CF-AC8E-0D462D46BD57} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {858FD14F-EEA0-48CF-A8CE-A080A8766A87} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {9E8842DC-F1CA-45AE-9E15-5FCC0BB3EEA6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {A9E8690F-B379-4E34-A1AD-C944A1C19A4E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {AB6F6D3C-FF79-478C-BA52-E99C27CD2D74} - \IBUpd -> No File <==== ATTENTION
Task: {C672E22D-15A8-40C4-8C5E-510CDE835EB3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {C82B444E-66C3-4D27-94EF-DEEB5BEC54E9} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {D539F20E-E4EB-47F3-8DB4-D2860A776F02} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {F676ECDD-1C2B-435E-967D-37F38725FDDB} - System32\Tasks\HDMISwitch => C:\Program Files (x86)\ASRock Utility\HDMISwitch\Bin\HDMISwitch.exe [2013-09-04] () <==== ATTENTION
Task: {FEFD7529-61A8-415C-9D0B-D7B5A5D21830} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
*****************

"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-2043291374-1636051585-76882383-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{011946F0-6E6C-48E6-A97E-2060B805CABF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{011946F0-6E6C-48E6-A97E-2060B805CABF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2D9524F5-840F-4341-A485-F115DA98B931}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D9524F5-840F-4341-A485-F115DA98B931}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3105FAEC-9AE3-4DB7-8592-D68D51131377}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3105FAEC-9AE3-4DB7-8592-D68D51131377}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4CB31E23-09F5-48A2-B1D6-A049068972FB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CB31E23-09F5-48A2-B1D6-A049068972FB}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5E32E457-12A9-43CF-AC8E-0D462D46BD57}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E32E457-12A9-43CF-AC8E-0D462D46BD57}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{858FD14F-EEA0-48CF-A8CE-A080A8766A87}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{858FD14F-EEA0-48CF-A8CE-A080A8766A87}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9E8842DC-F1CA-45AE-9E15-5FCC0BB3EEA6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E8842DC-F1CA-45AE-9E15-5FCC0BB3EEA6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9E8690F-B379-4E34-A1AD-C944A1C19A4E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9E8690F-B379-4E34-A1AD-C944A1C19A4E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AB6F6D3C-FF79-478C-BA52-E99C27CD2D74}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB6F6D3C-FF79-478C-BA52-E99C27CD2D74}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IBUpd => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C672E22D-15A8-40C4-8C5E-510CDE835EB3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C672E22D-15A8-40C4-8C5E-510CDE835EB3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C82B444E-66C3-4D27-94EF-DEEB5BEC54E9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C82B444E-66C3-4D27-94EF-DEEB5BEC54E9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D539F20E-E4EB-47F3-8DB4-D2860A776F02}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D539F20E-E4EB-47F3-8DB4-D2860A776F02}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F676ECDD-1C2B-435E-967D-37F38725FDDB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F676ECDD-1C2B-435E-967D-37F38725FDDB}" => key removed successfully
C:\WINDOWS\System32\Tasks\HDMISwitch => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDMISwitch" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FEFD7529-61A8-415C-9D0B-D7B5A5D21830}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEFD7529-61A8-415C-9D0B-D7B5A5D21830}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully

==== End of Fixlog 18:59:01 ====

MiniToolBox by Farbar  Version: 02-11-2015
Ran by Jerome (administrator) on 08-12-2015 at 19:07:08
Running from "C:\Users\Jerome\Desktop"
Microsoft Windows 10 Home  (X64)
Model: To Be Filled By O.E.M. Manufacturer: To Be Filled By O.E.M.
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================
========================= IP Configuration: ================================

Killer e2200 Gigabit Ethernet Controller (NDIS 6.30) = Ethernet (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled


popd
# End of IPv4 configuration



Windows IP Configuration

   Host Name . . . . . . . . . . . . : HAL
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : Belkin

Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : Belkin
   Description . . . . . . . . . . . : Killer e2200 Gigabit Ethernet Controller (NDIS 6.30)
   Physical Address. . . . . . . . . : BC-5F-F4-E8-B1-D0
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::30bc:5796:392f:e0ef%11(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.2.5(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Sunday, December 6, 2015 2:24:39 AM
   Lease Expires . . . . . . . . . . : Saturday, January 15, 2152 1:35:24 AM
   Default Gateway . . . . . . . . . : 192.168.2.1
   DHCP Server . . . . . . . . . . . : 192.168.2.1
   DHCPv6 IAID . . . . . . . . . . . : 314335220
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1A-5E-D2-FD-BC-5F-F4-E8-B1-D0
   DNS Servers . . . . . . . . . . . : 192.168.2.1
   NetBIOS over Tcpip. . . . . . . . : Enabled
Server:  HAL-PC
Address:  192.168.2.1

Name:    google.com
Addresses:  2607:f8b0:4009:808::200e
      216.58.216.238


Pinging google.com [216.58.216.110] with 32 bytes of data:
Reply from 216.58.216.110: bytes=32 time=18ms TTL=55
Reply from 216.58.216.110: bytes=32 time=18ms TTL=55

Ping statistics for 216.58.216.110:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 18ms, Maximum = 18ms, Average = 18ms
Server:  HAL-PC
Address:  192.168.2.1

Name:    yahoo.com
Addresses:  2001:4998:58:c02::a9
      2001:4998:44:204::a7
      2001:4998:c:a06::2:4008
      206.190.36.45
      98.138.253.109
      98.139.183.24


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=67ms TTL=48
Reply from 98.139.183.24: bytes=32 time=67ms TTL=48

Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 67ms, Maximum = 67ms, Average = 67ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 11...bc 5f f4 e8 b1 d0 ......Killer e2200 Gigabit Ethernet Controller (NDIS 6.30)
  1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.2.1      192.168.2.5     20
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.2.0    255.255.255.0         On-link       192.168.2.5    276
      192.168.2.5  255.255.255.255         On-link       192.168.2.5    276
    192.168.2.255  255.255.255.255         On-link       192.168.2.5    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       192.168.2.5    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       192.168.2.5    276
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  1    306 ::1/128                  On-link
 11    276 fe80::/64                On-link
 11    276 fe80::30bc:5796:392f:e0ef/128
                                    On-link
  1    306 ff00::/8                 On-link
 11    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656] (Microsoft Corporation)
Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
Catalog9 11 C:\WINDOWS\SysWOW64\mswsock.dll [312160] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [80896] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [31744] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [357216] (Microsoft Corporation)

**** End of log ****
 

Attached Files


Edited by Oh My!, 08 December 2015 - 08:52 PM.


#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 08 December 2015 - 08:55 PM

Thank you. Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
AutoConfigURL: [S-1-5-21-2043291374-1636051585-76882383-1001] => hxxp://unstopp.me/wpad.dat?48fa910322d9e2f600780c747899f7da2167093
AlternateDataStreams: C:\Program Files\Classic Shell:Win32App_1
AlternateDataStreams: C:\Program Files\FileZilla FTP Client:Win32App_1
AlternateDataStreams: C:\Program Files\GIMP 2:Win32App_1
AlternateDataStreams: C:\Program Files\HitmanPro:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Mouse and Keyboard Center:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App_1
AlternateDataStreams: C:\Program Files\Nexus Mod Manager:Win32App_1
AlternateDataStreams: C:\Program Files\SUPERAntiSpyware:Win32App_1
AlternateDataStreams: C:\Program Files\TeamSpeak 3 Client:Win32App_1
AlternateDataStreams: C:\Program Files\WinRAR:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Inkscape:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Malware:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Mozilla Firefox:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Mumble:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\OpenOffice 4:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Origin:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\pyfa:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\ReClock:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\Logitech:Win32App_1
AlternateDataStreams: C:\ProgramData\BitRaider:Win32App_1
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Update on computer performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 DocWhoops

DocWhoops
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:09 PM

Posted 08 December 2015 - 09:03 PM

Fix result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by Jerome (2015-12-08 20:00:39) Run:2
Running from C:\Users\Jerome\Desktop
Loaded Profiles: Jerome (Available Profiles: Jerome)
Boot Mode: Normal
==============================================

fixlist content:
*****************
AutoConfigURL: [S-1-5-21-2043291374-1636051585-76882383-1001] => hxxp://unstopp.me/wpad.dat?48fa910322d9e2f600780c747899f7da2167093
AlternateDataStreams: C:\Program Files\Classic Shell:Win32App_1
AlternateDataStreams: C:\Program Files\FileZilla FTP Client:Win32App_1
AlternateDataStreams: C:\Program Files\GIMP 2:Win32App_1
AlternateDataStreams: C:\Program Files\HitmanPro:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Mouse and Keyboard Center:Win32App_1
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App_1
AlternateDataStreams: C:\Program Files\Nexus Mod Manager:Win32App_1
AlternateDataStreams: C:\Program Files\SUPERAntiSpyware:Win32App_1
AlternateDataStreams: C:\Program Files\TeamSpeak 3 Client:Win32App_1
AlternateDataStreams: C:\Program Files\WinRAR:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Inkscape:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Malware:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Mozilla Firefox:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Mumble:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\OpenOffice 4:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\Origin:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\pyfa:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App_1
AlternateDataStreams: C:\Program Files (x86)\ReClock:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\Logitech:Win32App_1
AlternateDataStreams: C:\ProgramData\BitRaider:Win32App_1
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm
*****************

HKU\S-1-5-21-2043291374-1636051585-76882383-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value removed successfully
"C:\Program Files\Classic Shell" => ":Win32App_1" ADS not found.
C:\Program Files\FileZilla FTP Client => ":Win32App_1" ADS removed successfully.
C:\Program Files\GIMP 2 => ":Win32App_1" ADS removed successfully.
"C:\Program Files\HitmanPro" => ":Win32App_1" ADS not found.
C:\Program Files\Microsoft Mouse and Keyboard Center => ":Win32App_1" ADS removed successfully.
C:\Program Files\Microsoft Silverlight => ":Win32App_1" ADS removed successfully.
C:\Program Files\Nexus Mod Manager => ":Win32App_1" ADS removed successfully.
"C:\Program Files\SUPERAntiSpyware" => ":Win32App_1" ADS not found.
C:\Program Files\TeamSpeak 3 Client => ":Win32App_1" ADS removed successfully.
C:\Program Files\WinRAR => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Apple Software Update => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Inkscape => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Malwarebytes Anti-Malware => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Mozilla Firefox => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Mumble => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\OpenOffice 4 => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\Origin => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\pyfa => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\QuickTime => ":Win32App_1" ADS removed successfully.
C:\Program Files (x86)\ReClock => ":Win32App_1" ADS removed successfully.
C:\Program Files\Common Files\Logitech => ":Win32App_1" ADS removed successfully.
C:\ProgramData\BitRaider => ":Win32App_1" ADS removed successfully.
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`26hfm" ADS removed successfully.
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`27hfm" ADS removed successfully.

==== End of Fixlog 20:00:40 ====

 

 

 

Done. I haven't been browsing much since the first round, but it seems better already.



#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 08 December 2015 - 09:05 PM

Very good. Please do these things for me.

===================================================

ESET Online Scanner

--------------------

I'd like us to scan your machine with ESET OnlineScan This process may may take several hours, that is normal.
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click Run ESET Online Scanner.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
  • Check YES, I accept the Terms of Use.
  • Click the Start button.
  • Click Enable detection of potentially unwanted applications
  • Accept any security warnings from your browser.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Copy and paste the information in your next reply. Note: If no malware was found you will not get a log.
  • Click the Back button.
  • Check Uninstall application on close and Delete quarantined files
  • Click the Finish button.
  • Close the ESET window and reboot your computer
===================================================

screen317's Security Check

--------------------
  • Please download screen317's Security Check to your desktop
  • Double-click icon to launch the program
  • Click OK
  • Select Run Note: If you receive an error message saying UNSUPPORTED OPERATING SYSTEM! ABORTED! reboot your computer and attempt to run it again
  • Allow the program to run
  • A Notepad document will open on your desktop. Please copy and paste the contents in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • ESET log
  • Security Check log
  • How is your computer running?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 DocWhoops

DocWhoops
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:09 PM

Posted 08 December 2015 - 10:09 PM

ESET- no threats found

 

 Results of screen317's Security Check version 1.013 --- 11/28/15  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
Windows Defender   
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Java 8 Update 66  
 Adobe Flash Player     19.0.0.245  
 Mozilla Firefox (42.0)
 Google Chrome (46.0.2490.86)
 Google Chrome (47.0.2526.73)
````````Process Check: objlist.exe by Laurent````````  
 Windows Defender MSMpEng.exe
 Windows Defender MpCmdRun.exe   
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````
 

Everything's still fine!



#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 08 December 2015 - 10:32 PM

That looks great. I would like you to use the computer until tomorrow to make sure we got everything. If you don't get any redirects then we can wrap this up.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 10 December 2015 - 10:29 AM

How are things going?


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 11 December 2015 - 10:13 AM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#11 DocWhoops

DocWhoops
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:09 PM

Posted 11 December 2015 - 01:30 PM

It seems fine now, I think we got it.

Tyvm for all your help.

#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 11 December 2015 - 03:53 PM

Very good, thanks for letting me know.

Now that your computer is running well it is my great pleasure to proclaim to you the Good News!

===================================================

All Clean!

--------------

Your machine appears to be clean and you may delete any programs or logs on your computer as a result of our efforts. If we used Emsisoft Emergency Kit just delete the icon on your desktop and the C:\EEK folder. For everything else you simply delete the log files or desktop icons.

Please take the time to read below on how to secure the machine and take the necessary steps to keep it clean :thumbsup:

Lawrence Abrams, the founder of BleepingComputer.com, has developed an excellent tutorial which will provide you with the information you need to know to keep your computer secure and clean. Please take the time to read:In addition, here are some more links you might find of interest:Thank you for placing your trust in BleepingComputer. It was a pleasure serving you. OhMy_done.gif
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,145 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:02:09 PM

Posted 21 January 2016 - 10:00 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users