Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Chrome default search set to 'firstputnik.ru' and enforced by administrator


  • This topic is locked This topic is locked
4 replies to this topic

#1 Scoontaque

Scoontaque

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 25 January 2016 - 04:52 PM

After foolishly downloading and installing a file I thought was a game patch my computer got a virus. Malwarebytes caught most of it and cleaned it, but not before it was able to do a few nasty things to my system. After running multiple anti-malware and virus programs everything was cleaned up, except for this strange issue where my default chrome browser is set to 'firstputnik.ru', is being enforced by the administrator, and will not let me change or delete it even though I am admin. So far I have run many cleanup programs, erased and reinstalled chrome and all of its registry constituents, as well as done a manual search of my hard drive and registry for anything associated with 'firstputnik.ru'. Sadly, nothing has worked so far.

 

I am running Windows 10 64-bit.

 

Here are my logs:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:25-01-2016
Ran by Scott (administrator) on SCOTT-PC (25-01-2016 15:38:14)
Running from C:\Users\Scott\Downloads
Loaded Profiles: Scott (Available Profiles: Scott & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
() C:\Program Files\ASUS\Rotation Desktop for G Series\AsusUacSvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(gputemp.com) C:\Program Files (x86)\GPU Temp\GPUTemp.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.4669\Agent.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.6526\Battle.net.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.22.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Users\Scott\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2869008 2012-01-26] (Synaptics Incorporated)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [373248 2012-03-28] (Alcor Micro Corp.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5301880 2012-11-30] (VIA)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-02-18] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 1999-12-31] (Intel Corporation)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322176 2012-02-16] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-02] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-20] (CyberLink)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [102568 2012-02-06] (ASUS)
HKLM-x32\...\Run: [ASUS Screen Saver Protector] => C:\Windows\AsScrPro.exe
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-24] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5301880 2012-11-30] (VIA)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-09] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\...\Run: [f.lux] => C:\Users\Scott\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\...\Run: [OpenHardwareMonitor] => C:\Program Files (x86)\GPU Temp\GPUTemp.exe [1032192 2011-10-01] (gputemp.com)
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [7744568 2015-10-27] (GOG.com)
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATII4E.EXE [283232 2015-10-23] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8590760 2015-12-08] (Piriform Ltd)
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\...\Policies\Explorer: [] 
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Scott\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64\FileSyncShell64.dll [2015-12-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Scott\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64\FileSyncShell64.dll [2015-12-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Scott\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64\FileSyncShell64.dll [2015-12-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Scott\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\FileSyncShell.dll [2015-12-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Scott\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\FileSyncShell.dll [2015-12-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Scott\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\FileSyncShell.dll [2015-12-22] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Scott\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2015-12-22] ()
Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2014-10-10] ()
Startup: C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-12-27]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy-x32: Restriction - Chrome <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.122.23.22 208.122.23.23
Tcpip\..\Interfaces\{277bb56b-96e9-45ad-a4ac-eb8b5dafd70a}: [DhcpNameServer] 208.122.23.22 208.122.23.23
 
Internet Explorer:
==================
HKU\S-1-5-21-2954811343-1049523406-335798761-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
URLSearchHook: [S-1-5-21-2954811343-1049523406-335798761-1001] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2954811343-1049523406-335798761-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-06-09] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-06-09] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-06-09] (Microsoft Corporation)
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [2009-01-26] (Safer Networking Limited)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-29] (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-12-29] (Atheros Commnucations)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-06-09] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-29] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
 
FireFox:
========
FF ProfilePath: C:\Users\Scott\AppData\Roaming\Mozilla\Firefox\Profiles\lvrd2p8b.default-1443134488440
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2014-12-03] (EA Digital Illusions CE AB)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-14] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll [No File]
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2014-12-03] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [1999-12-31] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [1999-12-31] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-02-17] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-04-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-27] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2954811343-1049523406-335798761-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Scott\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [No File]
FF Plugin HKU\S-1-5-21-2954811343-1049523406-335798761-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Scott\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-01-18] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2954811343-1049523406-335798761-1001: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll [2013-01-03] (The Happy Cloud)
FF Plugin HKU\S-1-5-21-2954811343-1049523406-335798761-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-12-17] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-03-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-03-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-03-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-03-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-03-10] (Apple Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-12]
CHR Extension: (Google Docs) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-12]
CHR Extension: (Google Drive) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-12]
CHR Extension: (YouTube) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-12]
CHR Extension: (Google Search) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-12]
CHR Extension: (Avira Browser Safety) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-01-19]
CHR Extension: (Google Docs Offline) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-12]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2016-01-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-12]
CHR Extension: (Gmail) - C:\Users\Scott\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-12]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-02-16] (ASUS)
R2 AsusUacSvc; C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe [113840 2011-03-27] () [File not signed]
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2753720 2015-07-01] (Microsoft Corporation)
R2 FanChkService; C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe [45696 2012-01-20] (ASUSTek Computer Inc.)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1616440 2015-10-27] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7184440 2015-12-13] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-08] (NVIDIA Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 1999-12-31] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 1999-12-31] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [45056 2006-12-14] (Sony Corporation) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-08] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-08] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-08] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2015-12-17] (Electronic Arts)
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [57344 2006-12-14] () [File not signed]
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S3 SonicStage Back-End Service; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SsBeSvc.exe [112184 2007-02-05] (Sony Corporation)
S3 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [69632 2006-12-14] (Sony Corporation) [File not signed]
S3 SSScsiSV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SSScsiSV.exe [75320 2007-02-05] (Sony Corporation)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S4 IDriverT; "C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [17152 2012-02-29] (ASUSTek Computer Inc.)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4325544 2015-07-31] (Qualcomm Atheros Communications, Inc.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-12-27] ()
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-08] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-10] (NVIDIA Corporation)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
S3 SynasUSB; C:\Windows\System32\drivers\SynUSB64.sys [31248 2006-11-16] (SIA Syncrosoft)
S3 VClone; C:\Windows\System32\DRIVERS\VClone.sys [36352 2011-01-15] (Elaborate Bytes AG) [File not signed]
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R3 WinRing0_1_2_0; C:\Users\Scott\AppData\Local\Temp\tmpE2E7.tmp [14544 2016-01-21] (OpenLibSys.org)
R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
U3 idsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-01-25 15:38 - 2016-01-25 15:39 - 00030552 _____ C:\Users\Scott\Downloads\FRST.txt
2016-01-25 15:37 - 2016-01-25 15:38 - 00000000 ____D C:\FRST
2016-01-25 15:37 - 2016-01-25 15:37 - 02370560 _____ (Farbar) C:\Users\Scott\Downloads\FRST64.exe
2016-01-24 17:09 - 2016-01-25 00:17 - 00009817 _____ C:\Users\Scott\Desktop\D3 Items Guide.xlsx
2016-01-24 17:09 - 2016-01-24 17:09 - 00000165 ____H C:\Users\Scott\Desktop\~$D3 Items Guide.xlsx
2016-01-21 15:27 - 2016-01-21 15:28 - 01505280 _____ C:\Users\Scott\Downloads\AdwCleaner.exe
2016-01-20 23:26 - 2016-01-20 23:26 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2016-01-20 23:26 - 2016-01-20 23:26 - 00000000 ____D C:\Program Files\GIMP 2
2016-01-20 23:13 - 2016-01-20 23:13 - 00448633 _____ C:\Users\Scott\Downloads\master_of_break.zip
2016-01-20 22:59 - 2016-01-20 23:25 - 96819488 _____ (The GIMP Team ) C:\Users\Scott\Downloads\gimp-2.8.16-setup.exe
2016-01-20 22:56 - 2016-01-20 22:56 - 01209554 _____ C:\Users\Scott\Downloads\Block-Breaker-Assets-V-4.zip
2016-01-20 22:25 - 2016-01-20 22:25 - 00000230 _____ C:\Users\Scott\Desktop\ESET Log.txt
2016-01-20 16:47 - 2016-01-20 16:47 - 00000000 ____D C:\Program Files (x86)\ESET
2016-01-20 16:45 - 2016-01-20 16:45 - 00000687 _____ C:\Users\Scott\Desktop\JRT.txt
2016-01-20 16:42 - 2016-01-20 16:42 - 00000744 _____ C:\Users\Scott\Desktop\AdwCleaner[S1].txt
2016-01-20 16:40 - 2016-01-21 15:30 - 00000000 ____D C:\AdwCleaner
2016-01-20 16:39 - 2016-01-20 16:39 - 00051972 _____ C:\Users\Scott\Desktop\MTB.txt
2016-01-20 14:28 - 2016-01-20 16:47 - 02870984 _____ (ESET) C:\Users\Scott\Desktop\esetsmartinstaller_enu.exe
2016-01-20 14:28 - 2016-01-20 16:42 - 01600184 _____ (Malwarebytes) C:\Users\Scott\Desktop\JRT.exe
2016-01-20 14:28 - 2016-01-20 16:39 - 01505280 _____ C:\Users\Scott\Desktop\AdwCleaner.exe
2016-01-20 14:28 - 2016-01-20 16:38 - 00891392 _____ (Farbar) C:\Users\Scott\Desktop\MiniToolBox.exe
2016-01-20 00:55 - 2016-01-20 00:55 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Subversion
2016-01-18 19:57 - 2016-01-18 19:57 - 02351161 _____ C:\Users\Scott\Downloads\Text-101-Slides-White-Background.pdf
2016-01-18 19:56 - 2016-01-18 19:56 - 00029267 _____ C:\Users\Scott\Downloads\Prison-Word-Png.zip
2016-01-18 18:22 - 2016-01-18 18:22 - 00269527 _____ C:\Users\Scott\Downloads\Text101GDD.pdf
2016-01-18 02:10 - 2016-01-18 02:10 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2016-01-14 23:13 - 2009-06-10 14:00 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20160114-231302.backup
2016-01-14 23:07 - 2016-01-15 00:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-01-14 23:07 - 2016-01-14 23:08 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2016-01-14 23:07 - 2016-01-14 23:07 - 00001329 _____ C:\Users\Scott\Desktop\Spybot - Search & Destroy.lnk
2016-01-14 23:07 - 2016-01-14 23:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2016-01-12 22:29 - 2016-01-04 19:51 - 07477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-01-12 22:29 - 2016-01-04 19:51 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-01-12 22:29 - 2016-01-04 19:51 - 01141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-01-12 22:29 - 2016-01-04 19:50 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-12 22:29 - 2016-01-04 19:50 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-01-12 22:29 - 2016-01-04 19:50 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2016-01-12 22:29 - 2016-01-04 19:49 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-12 22:29 - 2016-01-04 19:48 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2016-01-12 22:29 - 2016-01-04 19:45 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-01-12 22:29 - 2016-01-04 19:42 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-01-12 22:29 - 2016-01-04 19:37 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-01-12 22:29 - 2016-01-04 19:37 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-01-12 22:29 - 2016-01-04 19:37 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-01-12 22:29 - 2016-01-04 19:37 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-12 22:29 - 2016-01-04 19:37 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-12 22:29 - 2016-01-04 19:37 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-01-12 22:29 - 2016-01-04 19:37 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2016-01-12 22:29 - 2016-01-04 19:36 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-01-12 22:29 - 2016-01-04 19:33 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-01-12 22:29 - 2016-01-04 19:33 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-01-12 22:29 - 2016-01-04 19:33 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-01-12 22:29 - 2016-01-04 19:33 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-01-12 22:29 - 2016-01-04 19:33 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-01-12 22:29 - 2016-01-04 19:33 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2016-01-12 22:29 - 2016-01-04 19:33 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-01-12 22:29 - 2016-01-04 19:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-01-12 22:29 - 2016-01-04 19:27 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-01-12 22:29 - 2016-01-04 19:24 - 00796352 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-01-12 22:29 - 2016-01-04 19:23 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-01-12 22:29 - 2016-01-04 19:23 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2016-01-12 22:29 - 2016-01-04 19:23 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-12 22:29 - 2016-01-04 19:21 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-01-12 22:29 - 2016-01-04 19:17 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2016-01-12 22:29 - 2016-01-04 19:16 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
2016-01-12 22:29 - 2016-01-04 18:59 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-01-12 22:29 - 2016-01-04 18:57 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-12 22:29 - 2016-01-04 18:57 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-01-12 22:29 - 2016-01-04 18:57 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
2016-01-12 22:29 - 2016-01-04 18:56 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2016-01-12 22:29 - 2016-01-04 18:54 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
2016-01-12 22:29 - 2016-01-04 18:54 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-01-12 22:29 - 2016-01-04 18:53 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2016-01-12 22:29 - 2016-01-04 18:52 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-01-12 22:29 - 2016-01-04 18:51 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-01-12 22:29 - 2016-01-04 18:51 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-12 22:29 - 2016-01-04 18:50 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-01-12 22:29 - 2016-01-04 18:50 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-01-12 22:29 - 2016-01-04 18:50 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-01-12 22:29 - 2016-01-04 18:49 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-01-12 22:29 - 2016-01-04 18:49 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-01-12 22:29 - 2016-01-04 18:49 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-12 22:29 - 2016-01-04 18:49 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-01-12 22:29 - 2016-01-04 18:49 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-01-12 22:29 - 2016-01-04 18:49 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
2016-01-12 22:29 - 2016-01-04 18:48 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-12 22:29 - 2016-01-04 18:48 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-01-12 22:29 - 2016-01-04 18:48 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
2016-01-12 22:29 - 2016-01-04 18:47 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-01-12 22:29 - 2016-01-04 18:47 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-01-12 22:29 - 2016-01-04 18:47 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2016-01-12 22:29 - 2016-01-04 18:45 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-01-12 22:29 - 2016-01-04 18:45 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-01-12 22:29 - 2016-01-04 18:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2016-01-12 22:29 - 2016-01-04 18:43 - 00953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-01-12 22:29 - 2016-01-04 18:43 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-01-12 22:29 - 2016-01-04 18:43 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-01-12 22:29 - 2016-01-04 18:43 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-01-12 22:29 - 2016-01-04 18:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-01-12 22:29 - 2016-01-04 18:41 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-01-12 22:29 - 2016-01-04 18:41 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2016-01-12 22:29 - 2016-01-04 18:41 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-01-12 22:29 - 2016-01-04 18:40 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2016-01-12 22:29 - 2016-01-04 18:40 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2016-01-12 22:29 - 2016-01-04 18:39 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-01-12 22:29 - 2016-01-04 18:39 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-01-12 22:29 - 2016-01-04 18:39 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-01-12 22:29 - 2016-01-04 18:39 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2016-01-12 22:29 - 2016-01-04 18:38 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-01-12 22:29 - 2016-01-04 18:36 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2016-01-12 22:29 - 2016-01-04 18:36 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-01-12 22:29 - 2016-01-04 18:33 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-12 22:29 - 2016-01-04 18:30 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-01-12 22:29 - 2016-01-04 18:30 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-01-12 22:29 - 2016-01-04 18:29 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-01-12 22:29 - 2016-01-04 18:28 - 07826432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-01-12 22:29 - 2016-01-04 18:28 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-01-12 22:29 - 2016-01-04 18:28 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-01-12 22:29 - 2016-01-04 18:25 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-01-12 20:48 - 2016-01-12 20:55 - 00000000 ____D C:\Users\Scott\AppData\Roaming\MonoDevelop-Unity-4.0
2016-01-12 20:48 - 2016-01-12 20:48 - 00000000 ____D C:\Users\Scott\AppData\Local\MonoDevelop-Unity-4.0
2016-01-12 20:34 - 2016-01-12 20:34 - 00141113 _____ C:\Users\Scott\Downloads\SupportingDocument (6).PDF
2016-01-12 20:31 - 2016-01-12 20:31 - 01166482 _____ C:\Users\Scott\Downloads\SupportingDocument (5).PDF
2016-01-12 20:31 - 2016-01-12 20:31 - 00955165 _____ C:\Users\Scott\Downloads\SupportingDocument (4).PDF
2016-01-12 20:31 - 2016-01-12 20:31 - 00191333 _____ C:\Users\Scott\Downloads\SupportingDocument (3).PDF
2016-01-12 20:28 - 2016-01-12 20:28 - 00737504 _____ C:\Users\Scott\Downloads\SupportingDocument.PDF
2016-01-12 20:28 - 2016-01-12 20:28 - 00737504 _____ C:\Users\Scott\Downloads\SupportingDocument (1).PDF
2016-01-12 20:28 - 2016-01-12 20:28 - 00134816 _____ C:\Users\Scott\Downloads\SupportingDocument (2).PDF
2016-01-12 20:25 - 2016-01-19 17:43 - 00009207 _____ C:\Users\Scott\Desktop\Teacher Application Logins.xlsx
2016-01-12 20:06 - 2016-01-12 20:06 - 00029611 _____ C:\Users\Scott\Downloads\Draft of evaluation.zip
2016-01-12 20:05 - 2016-01-12 20:05 - 00301872 _____ C:\Users\Scott\Downloads\Outlook.com (2).zip
2016-01-12 19:47 - 2016-01-21 16:51 - 00000000 ____D C:\Users\Scott\Documents\New Unity Project
2016-01-12 19:43 - 2016-01-24 12:17 - 00000000 ____D C:\ProgramData\Unity
2016-01-12 19:42 - 2016-01-12 19:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity
2016-01-12 19:42 - 2016-01-12 19:42 - 00001229 _____ C:\Users\Public\Desktop\Unity.lnk
2016-01-12 19:42 - 2016-01-12 19:42 - 00000000 ____D C:\Users\Public\Documents\Unity Projects
2016-01-12 19:33 - 2016-01-12 19:43 - 00000000 ____D C:\Program Files (x86)\Unity 4.6
2016-01-12 19:20 - 2016-01-12 19:21 - 00000000 ____D C:\Users\Scott\AppData\Roaming\XamarinStudio-5.0
2016-01-12 19:20 - 2016-01-12 19:20 - 00000000 ____D C:\Users\Scott\AppData\Roaming\stetic
2016-01-12 19:20 - 2016-01-12 19:20 - 00000000 ____D C:\Users\Scott\AppData\Roaming\NuGet
2016-01-12 19:20 - 2016-01-12 19:20 - 00000000 ____D C:\Users\Scott\AppData\Local\XamarinStudio-5.0
2016-01-12 19:01 - 2016-01-12 19:01 - 00002977 _____ C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xamarin Studio.lnk
2016-01-12 19:01 - 2016-01-12 19:01 - 00000000 ____D C:\Program Files (x86)\Xamarin Studio
2016-01-12 19:01 - 2016-01-12 19:01 - 00000000 ____D C:\Program Files (x86)\MonoDevelop
2016-01-12 19:00 - 2016-01-12 19:00 - 00000000 ____D C:\Program Files (x86)\GtkSharp
2016-01-12 18:59 - 2016-01-12 19:00 - 25460736 _____ C:\Users\Scott\Downloads\gtk-sharp-2.12.30.msi
2016-01-12 18:51 - 2016-01-12 18:51 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blender
2016-01-12 18:50 - 2016-01-12 18:50 - 00000000 ____D C:\Program Files\Blender Foundation
2016-01-12 18:44 - 2016-01-12 18:49 - 83674076 _____ C:\Users\Scott\Downloads\blender-2.76b-windows64.msi
2016-01-12 18:44 - 2016-01-12 18:49 - 47878144 _____ C:\Users\Scott\Downloads\XamarinStudio-5.10.0.871-0.msi
2016-01-12 18:42 - 2016-01-12 19:33 - 1565173928 _____ (Unity Technologies ApS) C:\Users\Scott\Downloads\UnitySetup-4.6.9.exe
2016-01-12 17:56 - 2016-01-12 17:56 - 01118920 _____ (Microsoft Corporation) C:\Users\Scott\Downloads\NDP452-KB2901954-Web.exe
2016-01-12 17:14 - 2016-01-15 00:32 - 00010149 _____ C:\Users\Scott\Desktop\Goals Checklist.xlsx
2016-01-12 14:02 - 2016-01-12 19:29 - 00011873 _____ C:\Users\Scott\Desktop\BF Team Building.xlsx
2016-01-08 15:36 - 2016-01-08 16:32 - 00001137 _____ C:\Users\Scott\Desktop\nativelog.txt
2016-01-07 22:07 - 2016-01-07 22:08 - 05131688 _____ (Oculus VR, LLC) C:\Users\Scott\Downloads\OculusCompatCheck.exe
2015-12-31 13:43 - 2015-12-31 13:43 - 02164086 _____ C:\Users\Scott\Desktop\SystemInfo.nfo
2015-12-31 13:41 - 2015-12-31 13:41 - 00062652 _____ C:\Users\Scott\Desktop\DxDiag.txt
2015-12-29 13:18 - 2015-12-29 13:22 - 00000000 ____D C:\Users\Scott\Documents\Lords of the Fallen
2015-12-29 12:59 - 2015-12-29 12:59 - 00000696 _____ C:\DelFix.txt
2015-12-28 17:20 - 2015-12-28 17:20 - 00000000 ____D C:\Users\Scott\Desktop\Sword of Truth
2015-12-28 01:00 - 2016-01-11 00:08 - 00000000 ____D C:\Users\Scott\Documents\The Witcher 3
2015-12-27 21:40 - 2015-12-27 22:10 - 00000000 ____D C:\ProgramData\HitmanPro
2015-12-27 21:40 - 2015-12-27 21:40 - 00000000 ____D C:\ProgramData\Zemana AntiMalware
2015-12-27 21:40 - 2015-12-27 21:40 - 00000000 ____D C:\Program Files\Zemana AntiMalware
2015-12-27 21:39 - 2015-12-27 21:39 - 00000981 _____ C:\Users\Public\Desktop\Removal Tool.lnk
2015-12-27 21:39 - 2015-12-27 21:39 - 00000000 ____D C:\Users\Scott\AppData\Roaming\9-lab
2015-12-27 21:39 - 2015-12-27 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
2015-12-27 21:39 - 2015-12-27 21:39 - 00000000 ____D C:\ProgramData\9-lab
2015-12-27 21:39 - 2015-12-27 21:39 - 00000000 ____D C:\Program Files\9-lab
2015-12-27 21:36 - 2015-12-27 21:36 - 00290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\subinacl.exe
2015-12-27 21:36 - 2015-12-27 21:36 - 00000000 ____D C:\Program Files (x86)\Adware Removal Tool by TSA
2015-12-27 21:26 - 2016-01-14 20:31 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-27 21:26 - 2015-12-27 21:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-27 21:25 - 2016-01-25 15:30 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-27 21:25 - 2016-01-24 21:30 - 00000910 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-27 21:25 - 2015-12-27 21:25 - 00003972 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-27 21:25 - 2015-12-27 21:25 - 00003740 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-27 21:24 - 2015-12-28 23:29 - 00000000 ____D C:\Users\Scott\AppData\Local\Google
2015-12-27 20:55 - 2015-12-27 20:55 - 00000000 _____ C:\autoexec.bat
2015-12-27 20:54 - 2015-12-27 20:54 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-12-27 20:53 - 2015-12-27 20:53 - 03286400 _____ (Enigma Software Group USA, LLC.) C:\Users\Scott\Downloads\SpyHunter-Installer.exe
2015-12-27 20:42 - 2016-01-25 13:09 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{89A4369E-E093-4C35-BD6C-0972A6A2AEFD}
2015-12-27 20:42 - 2015-12-27 21:25 - 00000000 ____D C:\Users\Scott\AppData\Local\Deployment
2015-12-27 20:41 - 2015-12-27 20:41 - 00303408 _____ C:\Users\Scott\Desktop\bookmarks_12_27_15.html
2015-12-27 20:13 - 2015-12-27 20:14 - 00221832 _____ C:\Users\Scott\Desktop\Regbackup.reg
2015-12-27 20:11 - 2015-12-31 13:32 - 00000000 ____D C:\Program Files (x86)\jv16 PowerTools X
2015-12-27 20:11 - 2015-12-27 20:11 - 00001939 _____ C:\Users\Scott\Desktop\jv16 PowerTools X.lnk
2015-12-27 20:11 - 2015-12-27 20:11 - 00000020 ___SH C:\Users\Scott\AppData\Roaming\System413_DataDB.ind
2015-12-27 20:11 - 2015-12-27 20:11 - 00000020 ___SH C:\Users\Scott\AppData\Roaming\Sys11965 DataCollection.dat
2015-12-27 20:10 - 2015-12-27 20:10 - 00002856 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-12-27 20:10 - 2015-12-27 20:10 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-12-27 20:09 - 2015-12-27 20:10 - 00000000 ____D C:\Program Files\CCleaner
2015-12-27 20:09 - 2015-12-27 20:09 - 09049408 _____ C:\Users\Scott\Downloads\jv16pt_setup.exe
2015-12-27 20:08 - 2015-12-27 20:09 - 06808384 _____ (Piriform Ltd) C:\Users\Scott\Downloads\ccsetup513pro.exe
2015-12-27 20:05 - 2016-01-02 23:56 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Enigma Software Group
2015-12-27 20:05 - 2016-01-02 23:56 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-12-27 20:05 - 2015-12-27 20:05 - 00001129 _____ C:\Users\Scott\Desktop\RegHunter.lnk
2015-12-27 20:05 - 2015-12-27 20:05 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegHunter
2015-12-27 19:39 - 2015-12-27 19:39 - 00002040 _____ C:\Users\Scott\Desktop\Update Checker.lnk
2015-12-27 19:39 - 2015-12-27 19:39 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2015-12-27 19:38 - 2015-12-27 19:38 - 00000000 ____D C:\ProgramData\Sophos
2015-12-27 19:37 - 2015-12-27 19:37 - 00002775 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2015-12-27 19:37 - 2015-12-27 19:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-12-27 19:37 - 2015-12-27 19:37 - 00000000 ____D C:\Program Files (x86)\Sophos
2015-12-27 17:49 - 2015-12-27 19:09 - 00001167 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-27 17:46 - 2015-12-27 19:07 - 00000258 __RSH C:\ProgramData\ntuser.pol
2015-12-27 17:45 - 2015-12-27 17:46 - 00000000 ____D C:\Users\Scott\Downloads\Torrentex
2015-12-26 18:25 - 2015-12-27 19:09 - 00001275 _____ C:\Users\Public\Desktop\HD VDeck.lnk
2015-12-26 18:25 - 2015-12-26 18:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VIA
2015-12-26 18:19 - 2015-12-26 18:24 - 00003304 _____ C:\WINDOWS\System32\Tasks\ASUS Patch for VIA Audio
2015-12-26 18:19 - 2012-11-07 17:55 - 00160448 _____ (ASUSTek Computer INC.) C:\WINDOWS\system32\AsPatchViaAudio.exe
2015-12-26 18:19 - 2012-11-01 17:14 - 00000216 _____ C:\WINDOWS\system32\AsPatchViaAudio.ini
2015-12-26 17:52 - 2015-12-26 18:09 - 162182226 _____ C:\Users\Scott\Downloads\Audio_VIA_Win8_VER60101400.zip
2015-12-26 15:34 - 2015-12-26 18:23 - 00000000 ____D C:\Users\Scott\Desktop\Audio Drivers
2015-12-26 15:15 - 2015-12-26 15:20 - 298292467 _____ C:\Users\Scott\Downloads\20765058_37b807c269de32572daf33fb6bab50395ce6f382.cab
2015-12-26 15:13 - 2015-12-26 15:13 - 02449376 _____ (Megaify Software ) C:\Users\Scott\Downloads\DriverToolkitInstaller.exe
2015-12-26 15:10 - 2015-12-26 15:11 - 05950176 _____ (NVIDIA Corporation) C:\Users\Scott\Downloads\hdaudio_1.00.00.59_xp_vista_win7.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-01-25 15:38 - 2015-10-29 23:28 - 00000000 ____D C:\Windows
2016-01-25 15:37 - 2013-08-19 15:27 - 00000000 ____D C:\Users\Scott\AppData\Local\Battle.net
2016-01-25 13:58 - 2012-08-05 16:46 - 00000000 ____D C:\Users\Scott\AppData\Local\CrashDumps
2016-01-25 13:09 - 2015-12-22 05:38 - 01008216 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-25 13:09 - 2015-10-30 00:21 - 00000000 ____D C:\WINDOWS\INF
2016-01-25 13:07 - 2015-10-30 00:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-01-25 01:41 - 2012-10-31 17:11 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Mumble
2016-01-24 12:23 - 2015-12-22 06:26 - 00000000 ____D C:\Windows.old
2016-01-24 12:14 - 2015-10-30 00:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-01-23 20:19 - 2013-08-19 15:27 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-01-22 00:08 - 2014-11-01 18:28 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-01-21 15:33 - 2015-12-22 05:39 - 00000000 ____D C:\Users\Scott
2016-01-21 15:31 - 2015-12-22 10:08 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-21 15:31 - 2015-12-22 05:35 - 00000000 ____D C:\ProgramData\NVIDIA
2016-01-21 15:31 - 2015-10-29 23:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-01-21 15:30 - 2015-10-30 00:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-01-21 15:30 - 2009-07-13 20:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-01-21 11:45 - 2014-10-16 12:23 - 00000000 ____D C:\Program Files (x86)\Heroes of the Storm
2016-01-20 22:58 - 2012-10-01 12:20 - 00000000 ____D C:\Users\Scott\.thumbnails
2016-01-20 21:02 - 2015-10-24 22:21 - 00000000 ____D C:\Users\Scott\Desktop\Official Files
2016-01-18 21:29 - 2015-08-20 15:02 - 00000000 ____D C:\Users\Scott\Desktop\Resumes
2016-01-18 02:10 - 2015-12-22 05:39 - 00000000 ____D C:\Users\DefaultAppPool
2016-01-14 22:57 - 2013-08-15 00:55 - 00000000 ____D C:\ProgramData\Origin
2016-01-14 19:37 - 2012-11-04 03:41 - 00000000 ____D C:\Program Files (x86)\Diablo III
2016-01-13 10:32 - 2014-04-01 11:44 - 00000000 ____D C:\Users\Scott\AppData\Local\Unity
2016-01-13 10:32 - 2013-03-14 09:12 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-13 10:32 - 2013-03-14 09:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-13 10:31 - 2015-10-30 00:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-01-12 23:51 - 2015-09-12 13:11 - 00414505 ____H C:\Users\Scott\Desktop\~WRL1792.tmp
2016-01-12 23:49 - 2015-09-12 13:11 - 00415161 ____H C:\Users\Scott\Desktop\~WRL2701.tmp
2016-01-12 23:32 - 2015-09-12 13:11 - 00414390 ____H C:\Users\Scott\Desktop\~WRL0950.tmp
2016-01-12 23:27 - 2015-09-12 13:11 - 00414032 ____H C:\Users\Scott\Desktop\~WRL2306.tmp
2016-01-12 23:24 - 2015-09-12 13:11 - 00413503 ____H C:\Users\Scott\Desktop\~WRL3222.tmp
2016-01-12 23:01 - 2015-09-12 13:11 - 00420755 ____H C:\Users\Scott\Desktop\~WRL4021.tmp
2016-01-12 22:55 - 2012-08-06 17:06 - 00000000 ____D C:\ProgramData\Microsoft Help
2016-01-12 22:54 - 2013-03-14 09:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-12 22:53 - 2015-10-30 00:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-01-12 22:53 - 2015-09-12 13:11 - 00420513 ____H C:\Users\Scott\Desktop\~WRL0609.tmp
2016-01-12 22:52 - 2013-07-12 03:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-01-12 22:44 - 2012-07-27 17:00 - 143671360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-01-12 19:52 - 2015-07-31 09:47 - 00000000 ____D C:\Users\Scott\AppData\Local\Packages
2016-01-12 19:47 - 2014-04-01 11:45 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Unity
2016-01-12 19:43 - 2012-08-06 12:51 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Apple Computer
2016-01-12 19:43 - 2012-08-06 12:51 - 00000000 ____D C:\Users\Scott\AppData\Local\Apple Computer
2016-01-12 19:20 - 2014-08-13 04:03 - 00000000 ____D C:\Users\Scott\.android
2016-01-12 18:00 - 2012-09-27 08:41 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Skype
2016-01-12 14:55 - 2013-03-20 23:57 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2016-01-11 16:56 - 2015-09-12 13:11 - 00418615 ____H C:\Users\Scott\Desktop\~WRL1462.tmp
2016-01-11 16:53 - 2015-09-12 13:11 - 00410347 ____H C:\Users\Scott\Desktop\~WRL2731.tmp
2016-01-11 16:48 - 2015-09-12 13:11 - 00410112 ____H C:\Users\Scott\Desktop\~WRL3028.tmp
2016-01-11 16:45 - 2015-09-12 13:11 - 00417991 ____H C:\Users\Scott\Desktop\~WRL2079.tmp
2016-01-11 16:43 - 2015-09-12 13:11 - 00409772 ____H C:\Users\Scott\Desktop\~WRL3387.tmp
2016-01-11 16:42 - 2015-09-12 13:11 - 00417848 ____H C:\Users\Scott\Desktop\~WRL4037.tmp
2016-01-11 15:10 - 2015-09-12 13:11 - 00404904 ____H C:\Users\Scott\Desktop\~WRL2214.tmp
2016-01-11 15:03 - 2015-09-12 13:11 - 00404513 ____H C:\Users\Scott\Desktop\~WRL0004.tmp
2016-01-10 18:19 - 2012-08-02 17:08 - 00000000 ____D C:\Users\Scott\AppData\Roaming\SoftGrid Client
2016-01-08 17:51 - 2015-12-17 02:28 - 00000992 _____ C:\Users\Public\Desktop\STAR WARS Battlefront.lnk
2016-01-02 18:40 - 2015-10-30 00:26 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-01-02 18:40 - 2015-10-30 00:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-31 16:21 - 2015-08-22 21:25 - 00000000 ____D C:\Users\Scott\Desktop\PS4 Controller
2015-12-31 13:38 - 2014-12-16 16:20 - 00000000 ____D C:\Users\Scott\AppData\Roaming\vlc
2015-12-31 13:31 - 2015-12-22 05:31 - 00340176 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-29 13:28 - 2015-07-07 01:24 - 00001000 _____ C:\Users\Public\Desktop\Dragon Age Inquisition.lnk
2015-12-28 17:20 - 2012-08-19 02:04 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Azureus
2015-12-28 17:18 - 2012-08-19 02:05 - 00000000 ____D C:\Users\Scott\Documents\Vuze Downloads
2015-12-27 22:42 - 2013-11-25 17:09 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdateInstaller
2015-12-27 22:42 - 2013-10-06 11:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.3
2015-12-27 22:42 - 2013-10-06 11:54 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.3
2015-12-27 22:42 - 2012-08-22 10:45 - 00000000 ____D C:\Program Files (x86)\To the Moon
2015-12-27 22:42 - 2012-08-04 02:15 - 00000000 ____D C:\Users\Scott\AppData\Local\Adobe
2015-12-27 21:48 - 2015-12-25 23:26 - 00001276 _____ C:\Users\Scott\Desktop\Uplay.lnk
2015-12-27 21:26 - 2012-02-18 00:37 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-27 21:23 - 2015-04-23 11:17 - 00000000 ____D C:\Users\Scott\AppData\OICE_15_974FA576_32C1D314_1D4
2015-12-27 21:23 - 2015-04-18 18:08 - 00000000 ____D C:\Users\Scott\AppData\OICE_15_974FA576_32C1D314_115D
2015-12-27 20:20 - 2015-12-22 06:29 - 00000000 ___DC C:\WINDOWS\Panther
2015-12-27 20:20 - 2015-12-03 00:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft Beta
2015-12-27 20:20 - 2015-10-24 18:15 - 00000000 ____D C:\Users\Scott\Desktop\USB Stick Files
2015-12-27 20:20 - 2015-07-17 01:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II - Legacy of the Void Beta
2015-12-27 20:20 - 2014-10-17 18:39 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVE
2015-12-27 20:20 - 2014-05-02 10:17 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PicPick
2015-12-27 20:01 - 2013-11-18 00:55 - 00000000 ____D C:\ProgramData\Package Cache
2015-12-27 20:01 - 2012-07-27 16:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
2015-12-27 20:01 - 2012-07-27 16:52 - 00000000 ____D C:\Program Files (x86)\CyberLink
2015-12-27 20:01 - 2012-07-27 16:39 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-12-27 20:00 - 2012-10-19 09:36 - 00000000 ____D C:\ProgramData\Avira
2015-12-27 19:58 - 2015-07-31 09:56 - 00000000 ___RD C:\Users\Scott\OneDrive
2015-12-27 19:09 - 2015-12-22 23:07 - 00001446 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2015-12-27 19:09 - 2015-12-22 05:50 - 00001495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-12-27 19:09 - 2015-10-28 11:00 - 00001114 _____ C:\Users\Public\Desktop\Warcraft III.lnk
2015-12-27 19:09 - 2015-10-27 17:05 - 00001159 _____ C:\Users\Public\Desktop\Overwatch.lnk
2015-12-27 19:09 - 2015-10-23 22:00 - 00001901 _____ C:\Users\Public\Desktop\Vuze.lnk
2015-12-27 19:09 - 2015-10-06 13:35 - 00001026 _____ C:\Users\Public\Desktop\Minecraft.lnk
2015-12-27 19:09 - 2014-10-29 09:28 - 00001774 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOG_1_22.lnk
2015-12-27 19:09 - 2014-09-04 09:25 - 00001230 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-12-27 19:09 - 2013-11-12 16:29 - 00002557 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
2015-12-27 19:09 - 2012-08-19 02:04 - 00001919 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
2015-12-27 19:09 - 2012-08-06 12:49 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-27 19:09 - 2012-02-18 00:43 - 00001376 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
2015-12-27 19:09 - 2012-02-18 00:43 - 00001307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
2015-12-27 19:09 - 2012-02-18 00:42 - 00001460 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-12-27 19:09 - 2012-02-18 00:41 - 00002488 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-12-27 19:09 - 2012-02-18 00:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-12-27 19:08 - 2015-12-15 14:28 - 00001258 _____ C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Origin.lnk
2015-12-27 19:08 - 2015-09-07 14:31 - 00001124 _____ C:\Users\Scott\Desktop\Notepad++.lnk
2015-12-27 19:08 - 2015-07-31 09:56 - 00002405 _____ C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-12-27 19:08 - 2015-07-29 22:53 - 00001318 _____ C:\Users\Scott\Desktop\First Novel - Shortcut.lnk
2015-12-27 19:08 - 2012-11-21 09:32 - 00002519 _____ C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2.lnk
2015-12-27 19:04 - 2012-08-16 20:24 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-12-27 19:04 - 2009-07-13 22:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-12-27 17:49 - 2014-11-01 18:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-27 17:49 - 2014-11-01 18:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-27 14:55 - 2015-12-25 00:56 - 00000234 _____ C:\Users\Scott\Desktop\Assassin's Creed Syndicate.url
2015-12-26 18:30 - 2013-08-15 00:56 - 00000000 ____D C:\Users\Scott\AppData\Roaming\Origin
2015-12-26 17:02 - 2015-10-30 00:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-12-26 14:17 - 2015-01-23 10:55 - 00000000 ____D C:\Users\Scott\AppData\Local\ElevatedDiagnostics
2015-12-26 00:38 - 2015-12-25 00:56 - 00000000 ____D C:\Users\Scott\Assassin's Creed Syndicate
 
==================== Files in the root of some directories =======
 
2012-08-28 15:44 - 2012-08-28 15:44 - 0000048 _____ () C:\Users\Scott\AppData\Roaming\net.dacons.mil1
2012-12-05 10:25 - 2012-12-14 10:06 - 0001536 _____ () C:\Users\Scott\AppData\Roaming\Sketchpad 5 Preferences.dat
2015-12-27 20:11 - 2015-12-27 20:11 - 0000020 ___SH () C:\Users\Scott\AppData\Roaming\Sys11965 DataCollection.dat
2015-12-27 20:11 - 2015-12-27 20:11 - 0000020 ___SH () C:\Users\Scott\AppData\Roaming\System413_DataDB.ind
2012-10-19 12:55 - 2012-10-19 12:55 - 0066045 _____ () C:\Users\Scott\AppData\Local\recently-used.xbel
2015-01-01 09:56 - 2015-01-01 09:56 - 0396480 _____ (Sysinternals - www.sysinternals.com) C:\ProgramData\PsExec.exe
2012-07-27 16:53 - 2012-07-27 16:53 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2012-07-27 16:52 - 2012-07-27 16:53 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2012-07-27 16:52 - 2012-07-27 16:52 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
 
Files to move or delete:
====================
C:\ProgramData\PsExec.exe
 
 
Some files in TEMP:
====================
C:\Users\Scott\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-01-20 13:45
 
==================== End of FRST.txt ============================

Attached Files



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,543 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:03 PM

Posted 26 January 2016 - 10:20 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===


Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
 
start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

GroupPolicy-x32: Restriction - Chrome <======= ATTENTION
URLSearchHook: [S-1-5-21-2954811343-1049523406-335798761-1001] ATTENTION => Default URLSearchHook is missing
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll [No File]
FF Plugin HKU\S-1-5-21-2954811343-1049523406-335798761-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Scott\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [No File]
S4 IDriverT; "C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [X]
U3 idsvc; no ImagePath
Task: {0205FECF-761A-46A1-9036-112783928162} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {176772DD-6F75-45C5-8C29-800E852EDE2C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {28D94079-84C9-4086-AC57-24F32BC50D2E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {47F1A740-226B-4E60-8EF5-C3152FA880C6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {68C37C0E-E871-4AF8-AB0F-4CC16A955C2F} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {6B68AE9B-3685-4440-9D97-3FBA498A1879} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {725D7DA3-748B-41A5-AC36-C5089C115BC7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {854E03A4-4FC3-4915-93DD-2E8D0D1F5B47} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9098D07A-5E4A-4609-9941-5A9F80DBE09C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A6A6F229-D6A4-430C-BDA8-7143B016B4B0} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {D242677C-D140-4201-BCD9-B4CC45D07826} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the LogFile button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleanerCx.txt (x is a number).
===


Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png which is located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset browser settings" button.
 
Clear your cache and cookies
https://support.google.com/chromebook/answer/183083?hl=en
Select "From the beginning of time"

Restart Chrome.
===

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.

You can manually check your present version and update as recommended.
https://www.java.com/en/download/installed.jsp

Be careful not to install malware posing as Java update!
Important read this blog.
http://blog.trendmicro.com/trendlabs-security-intelligence/malware-poses-as-an-update-for-java-0-day-fix/

Quoted from the page.
"In light of the recent events surrounding Java, users must seriously consider their use of Java. Do they really need it? If yes, make sure that users follow the steps we recommended and get the security update directly from the official oracle website." at:
http://www.oracle.com/technetwork/java/javase/downloads/index.html

How to disable Java in your browsers
http://www.infoworld.com/t/web-browsers/how-disable-java-in-your-browsers-210882


If present remove the old version(s) of Java using the Control Panel > Programs and Features applet.
Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)

Please post the logs and let me know if the problem persists.

#3 Scoontaque

Scoontaque
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 28 January 2016 - 04:57 PM

That fixed it! I've posted the logs below for your reference.

 

Thank you so much!

 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:25-01-2016
Ran by Scott (2016-01-28 15:19:53) Run:1
Running from C:\Users\Scott\Desktop
Loaded Profiles: Scott (Available Profiles: Scott & DefaultAppPool)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
GroupPolicy-x32: Restriction - Chrome <======= ATTENTION
URLSearchHook: [S-1-5-21-2954811343-1049523406-335798761-1001] ATTENTION => Default URLSearchHook is missing
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll [No File]
FF Plugin HKU\S-1-5-21-2954811343-1049523406-335798761-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Scott\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [No File]
S4 IDriverT; "C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [X]
U3 idsvc; no ImagePath
Task: {0205FECF-761A-46A1-9036-112783928162} -
\Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {176772DD-6F75-45C5-8C29-800E852EDE2C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {28D94079-84C9-4086-AC57-24F32BC50D2E} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {47F1A740-226B-4E60-8EF5-C3152FA880C6} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {68C37C0E-E871-4AF8-AB0F-4CC16A955C2F} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {6B68AE9B-3685-4440-9D97-3FBA498A1879} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {725D7DA3-748B-41A5-AC36-C5089C115BC7} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {854E03A4-4FC3-4915-93DD-2E8D0D1F5B47} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File
<==== ATTENTION
Task: {9098D07A-5E4A-4609-9941-5A9F80DBE09C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A6A6F229-D6A4-430C-BDA8-7143B016B4B0} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {D242677C-D140-4201-BCD9-B4CC45D07826} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
C:\WINDOWS\SysWOW64\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
Could not restore Default URLSearchHook.
"HKLM\Software\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.2" => key removed successfully
"HKU\S-1-5-21-2954811343-1049523406-335798761-1001\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin" => key removed successfully
C:\Users\Scott\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll => not found.
IDriverT => service removed successfully
idsvc => service removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\Task: {0205FECF-761A-46A1-9036-112783928162} - => key not found. 
\Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{176772DD-6F75-45C5-8C29-800E852EDE2C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{176772DD-6F75-45C5-8C29-800E852EDE2C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{28D94079-84C9-4086-AC57-24F32BC50D2E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28D94079-84C9-4086-AC57-24F32BC50D2E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47F1A740-226B-4E60-8EF5-C3152FA880C6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47F1A740-226B-4E60-8EF5-C3152FA880C6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68C37C0E-E871-4AF8-AB0F-4CC16A955C2F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68C37C0E-E871-4AF8-AB0F-4CC16A955C2F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6B68AE9B-3685-4440-9D97-3FBA498A1879}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6B68AE9B-3685-4440-9D97-3FBA498A1879}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{725D7DA3-748B-41A5-AC36-C5089C115BC7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{725D7DA3-748B-41A5-AC36-C5089C115BC7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{854E03A4-4FC3-4915-93DD-2E8D0D1F5B47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{854E03A4-4FC3-4915-93DD-2E8D0D1F5B47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
<==== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9098D07A-5E4A-4609-9941-5A9F80DBE09C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9098D07A-5E4A-4609-9941-5A9F80DBE09C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A6A6F229-D6A4-430C-BDA8-7143B016B4B0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A6A6F229-D6A4-430C-BDA8-7143B016B4B0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D242677C-D140-4201-BCD9-B4CC45D07826}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D242677C-D140-4201-BCD9-B4CC45D07826}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
EmptyTemp: => 1 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 15:20:32 ====
 
 
The 2nd program (adwcleaner) found no problems.


#4 nasdaq

nasdaq

  • Malware Response Team
  • 39,543 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:03 PM

Posted 29 January 2016 - 07:43 AM

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#5 nasdaq

nasdaq

  • Malware Response Team
  • 39,543 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:03 PM

Posted 03 February 2016 - 10:15 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users