Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Firefox seems to crash and windows defender keeps popping up


  • This topic is locked This topic is locked
9 replies to this topic

#1 guitarman77

guitarman77

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:43 PM

Posted 09 February 2016 - 11:26 PM

Please Help

 

Firefox keeps crashing with errors appearing as this : A script on this page may be busy, or it may have stopped responding. You can stop the script now, open the script in the debugger, or let the script continue. and windows defenders keep detecting Malware and removing it, firewall keeps disabling on its own.

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-02-2016
Ran by Admin (administrator) on LENOVO-PC (09-02-2016 20:18:29)
Running from C:\Users\Admin\Downloads
Loaded Profiles: UpdatusUser & Admin (Available Profiles: UpdatusUser & Admin & Administrator)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Maxthon\bin\maxthon.exe" "%1")
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Lenovo) C:\Program Files\lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
() C:\Users\Admin\AppData\Roaming\ACEStream\updater\ace_update.exe
() C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe
(Spotify Ltd) C:\Users\Admin\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
(GoPro) C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
(SAMSUNG Electornics Co., Ltd.) C:\Users\Admin\AppData\Roaming\VERIZON\UA_ar\UA.exe
() C:\Users\Public\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqgpc01.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusSGPlusBTServer64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusSmartGestureDetector64.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
() C:\Users\Admin\AppData\Local\Temp\temp\tmp797F.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3743648 2015-08-24] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [5060864 2015-06-16] (Realtek semiconductor)
HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [402344 2015-12-19] ()
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-17] (NVIDIA Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-25] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-12] (Conexant Systems, Inc.)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-14] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2014-09-26] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-09-26] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-04-28] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GoPro Studio Importer] => C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe [3218184 2015-10-02] (GoPro)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-4206410717-698191494-857776807-1001\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-29] (Microsoft Corporation)
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [AceUpdater] => C:\Users\Admin\AppData\Roaming\ACEStream\updater\ace_update.exe [27000 2015-11-10] ()
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [AceStream] => C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe [27000 2015-12-25] ()
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [Spotify Web Helper] => C:\Users\Admin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2355312 2016-02-04] (Spotify Ltd)
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [Spotify] => C:\Users\Admin\AppData\Roaming\Spotify\Spotify.exe [8449136 2016-02-04] (Spotify Ltd)
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [BluetoothManage] => rundll32.exe "%appdata%\Microsoft\btstack.dll",init
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [Otsxics] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Admin\AppData\Local\Idlksoft\CurlCommssplsh90.dll
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [2074811022] => C:\Users\Admin\AppData\Local\Yiram\Aepalg.exe [199168 2016-02-09] ()
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\RunOnce: [Uninstall C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Admin\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\MountPoints2: {db52898d-462a-11e5-9bc3-28d244f003a2} - "G:\VZW_Software_upgrade_assistant.exe" 
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\MountPoints2: {e2d9893b-b040-11e5-8273-303a64f6d3a3} - "F:\VZW_Software_upgrade_assistant.exe" 
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\MountPoints2: {f6e73824-317f-11e5-8268-303a64f6d3a7} - "F:\VZW_Software_upgrade_assistant.exe" 
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll [2014-06-23] (Hightail Inc.)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk [2015-11-12]
ShortcutTarget: Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\Admin\AppData\Roaming\VERIZON\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GoPro Importer.lnk [2015-04-06]
ShortcutTarget: GoPro Importer.lnk -> C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe (GoPro)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2015-11-16]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{1d3ab227-b7cf-4654-b8b0-9cb3ae2e8d43}: [DhcpNameServer] 150.211.1.3
Tcpip\..\Interfaces\{2e31806c-0ddc-4d05-a636-d4f2b1ca942c}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{5399A7C0-95D8-4556-9CB3-C7BF1F5F0C24}: [DhcpNameServer] 8.8.8.8
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4206410717-698191494-857776807-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://home.lenovo.com
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://home.lenovo.com
SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-4206410717-698191494-857776807-1002 -> {D1C7282F-2245-4084-BFBB-EDF42C425580} URL = 
 
FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ifopsb3u.default-1433227142002
FF DefaultSearchEngine.US: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-19] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-19] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-12] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: Sony Corporation/PMCADownloader -> C:\ProgramData\Sony Corporation\PMCADownloader\1.1.1975.475\npPMCADownloader.dll [2012-10-17] (Sony Network Entertainment International LLC)
FF Plugin-x32: Sony Corporation/PMCADownloaderHelper -> C:\ProgramData\Sony Corporation\PMCADownloader\1.1.1975.475\PMCADownloaderHelper.exe [2012-10-17] (Sony Network Entertainment International LLC)
FF Plugin-x32: Sony Corporation/PMCADownloaderLib -> C:\ProgramData\Sony Corporation\PMCADownloader\1.1.1975.475\PMCADownloaderLib.dll [2012-10-17] (Sony Network Entertainment International LLC)
FF Plugin HKU\S-1-5-21-4206410717-698191494-857776807-1002: @acestream.net/acestreamplugin,version=3.0.11 -> C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll [2015-09-24] (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-4206410717-698191494-857776807-1002: @acestream.net/acestreamplugin,version=3.0.12 -> C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll [2015-09-24] (Innovative Digital Technologies)
FF Extension: Video DownloadHelper - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ifopsb3u.default-1433227142002\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-10-29]
FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\ifopsb3u.default-1433227142002\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-19]
FF HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
FF Extension: Ace Stream Web Extension - C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2015-12-18]
 
Chrome: 
=======
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-24]
CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-24]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-03]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-04]
CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-03]
CHR Extension: (Google Sheets) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-24]
CHR Extension: (Google Docs Offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-27]
CHR Extension: (Ace Stream Web Extension) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2016-01-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-08]
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-24]
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-31]
CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-31]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-31]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-31]
CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-31]
CHR Extension: (Google Sheets) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-31]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2016-01-31]
CHR Extension: (Google Docs Offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-31]
CHR Extension: (Ace Stream Web Extension) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2016-01-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-31]
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-31]
CHR HKU\S-1-5-21-4206410717-698191494-857776807-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe [69448 2015-10-14] (Google Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [135072 2015-08-24] (ELAN Microelectronics Corp.)
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2011-08-18] (Hewlett-Packard Co.) [File not signed]
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373160 2015-12-19] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-21] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-09-26] (Lenovo(beijing) Limited)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1872808 2015-11-27] (Maxthon)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-12] (DEVGURU Co., LTD.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-29] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-29] (Microsoft Corporation)
S3 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AsusVBus; C:\Windows\System32\drivers\AsusVBus.sys [39704 2015-10-07] (Windows ® Win 7 DDK provider)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [84472 2015-10-07] (ASUS Corporation)
R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [165376 2015-10-29] (Microsoft Corporation)
R3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [36864 2015-10-29] (Microsoft Corporation)
S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-05-31] (Disc Soft Ltd)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [263952 2015-12-16] (Intel Corporation)
S1 kabmxvfg; C:\WINDOWS\system32\drivers\kabmxvfg.sys [55168 2016-02-08] (Microsoft Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3485696 2015-10-29] (Intel Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-18] (Realtek                                            )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-29] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-29] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-29] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S1 aqzupkcn; \??\C:\WINDOWS\system32\drivers\aqzupkcn.sys [X]
S1 bqedchup; \??\C:\WINDOWS\system32\drivers\bqedchup.sys [X]
S1 fyeqatxx; \??\C:\WINDOWS\system32\drivers\fyeqatxx.sys [X]
S1 jjzhthsg; \??\C:\WINDOWS\system32\drivers\jjzhthsg.sys [X]
S1 kcuqfhcq; \??\C:\WINDOWS\system32\drivers\kcuqfhcq.sys [X]
S1 kvxzbphp; \??\C:\WINDOWS\system32\drivers\kvxzbphp.sys [X]
S1 lbcbkgqt; \??\C:\WINDOWS\system32\drivers\lbcbkgqt.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-09 20:13 - 2016-02-09 20:13 - 00060076 _____ C:\Users\Admin\Desktop\Addition.txt
2016-02-09 20:00 - 2016-02-09 20:02 - 00060076 _____ C:\Users\Admin\Downloads\Addition.txt
2016-02-09 19:59 - 2016-02-09 20:18 - 00028679 _____ C:\Users\Admin\Downloads\FRST.txt
2016-02-09 19:58 - 2016-02-09 20:18 - 00000000 ____D C:\FRST
2016-02-09 19:58 - 2016-02-09 19:58 - 02370560 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2016-02-09 19:36 - 2016-02-09 19:36 - 00000000 ___HD C:\OneDriveTemp
2016-02-08 08:27 - 2016-02-09 19:42 - 00000000 ____D C:\Users\Admin\AppData\Local\WLGR
2016-02-08 08:27 - 2016-02-08 08:27 - 00055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kabmxvfg.sys
2016-02-08 08:27 - 2016-02-08 08:27 - 00000000 ____D C:\Users\Admin\AppData\Local\TWZ
2016-02-07 21:46 - 2016-02-07 21:46 - 00000000 ____H C:\ProgramData\cm-lock
2016-02-07 21:06 - 2016-02-07 21:36 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-02-07 21:05 - 2016-02-07 21:05 - 00000000 ____D C:\WINDOWS\pss
2016-02-07 18:34 - 2016-02-07 18:34 - 00896504 _____ (Microsoft Corporation) C:\Users\Admin\Desktop\mssstool64.exe
2016-02-06 01:32 - 2016-02-09 19:42 - 00000000 ____D C:\Users\Admin\AppData\Local\Yiram
2016-02-05 05:26 - 2016-02-05 05:26 - 00052784 _____ C:\Users\Admin\AppData\Roaming\meta-index
2016-02-05 05:26 - 2016-02-05 05:26 - 00002022 _____ C:\Users\Admin\AppData\Roaming\AssessorshipSpatSizzle
2016-02-04 22:44 - 2016-02-05 06:36 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-02-04 13:37 - 2016-02-04 13:37 - 00049152 _____ C:\Users\Admin\AppData\Roaming\legislative.dll
2016-02-02 23:09 - 2016-02-02 23:09 - 00000000 ____D C:\Users\Admin\Downloads\FroKnowsPhoto - Go Above and Beyond Auto
2016-02-02 22:21 - 2016-02-02 22:21 - 00000000 ____D C:\Users\Admin\Downloads\FroKnowsPhoto - Beginner Flash Guide - E_M_A
2016-02-02 13:48 - 2016-02-02 13:48 - 00086261 _____ C:\Users\Admin\AppData\Roaming\simplesect.in.toc.xml
2016-02-02 13:48 - 2016-02-02 13:48 - 00001946 _____ C:\Users\Admin\AppData\Roaming\GleyCenobite
2016-02-02 02:04 - 2016-02-02 02:04 - 00051453 _____ C:\Users\Admin\AppData\Roaming\ETHK-B5-V
2016-02-02 02:04 - 2016-02-02 02:04 - 00001524 _____ C:\Users\Admin\AppData\Roaming\InfidelSchlemiel
2016-02-01 21:41 - 2016-02-01 21:41 - 00068096 _____ C:\Users\Admin\AppData\Roaming\science.dll
2016-02-01 10:06 - 2016-02-01 10:06 - 00050277 _____ C:\Users\Admin\AppData\Roaming\html.stylesheet.type.xml
2016-02-01 10:06 - 2016-02-01 10:06 - 00001666 _____ C:\Users\Admin\AppData\Roaming\HandcuffPleasureDitch
2016-02-01 02:41 - 2016-02-01 02:41 - 00045056 _____ C:\Users\Admin\AppData\Roaming\cruor.dll
2016-02-01 02:25 - 2016-02-01 02:25 - 00057344 _____ C:\Users\Admin\AppData\Roaming\fortyniner.dll
2016-01-31 21:21 - 2016-01-15 22:23 - 08728920 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-01-31 21:21 - 2016-01-15 22:20 - 06971752 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-01-31 21:21 - 2016-01-15 21:44 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-01-31 21:21 - 2016-01-15 21:35 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-01-31 21:21 - 2016-01-15 21:32 - 24602624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-01-31 21:21 - 2016-01-15 21:26 - 19338752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-01-31 21:21 - 2016-01-15 21:24 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-01-31 21:20 - 2016-01-15 22:37 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-01-31 21:20 - 2016-01-15 22:36 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-31 21:20 - 2016-01-15 22:36 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-01-31 21:20 - 2016-01-15 22:34 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-31 21:20 - 2016-01-15 22:24 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-01-31 21:20 - 2016-01-15 22:23 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-31 21:20 - 2016-01-15 22:23 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-31 21:20 - 2016-01-15 22:23 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-01-31 21:20 - 2016-01-15 22:23 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-31 21:20 - 2016-01-15 22:23 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-01-31 21:20 - 2016-01-15 22:21 - 22572624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-01-31 21:20 - 2016-01-15 22:21 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-01-31 21:20 - 2016-01-15 22:20 - 06600904 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-01-31 21:20 - 2016-01-15 22:20 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-01-31 21:20 - 2016-01-15 22:20 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-01-31 21:20 - 2016-01-15 22:20 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-01-31 21:20 - 2016-01-15 22:19 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-01-31 21:20 - 2016-01-15 22:19 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-01-31 21:20 - 2016-01-15 22:17 - 21125400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-01-31 21:20 - 2016-01-15 22:16 - 05238360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-01-31 21:20 - 2016-01-15 22:13 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-01-31 21:20 - 2016-01-15 22:13 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-01-31 21:20 - 2016-01-15 22:12 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-01-31 21:20 - 2016-01-15 22:09 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-01-31 21:20 - 2016-01-15 22:08 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-01-31 21:20 - 2016-01-15 22:08 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-01-31 21:20 - 2016-01-15 21:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-01-31 21:20 - 2016-01-15 21:45 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-31 21:20 - 2016-01-15 21:44 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-01-31 21:20 - 2016-01-15 21:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-01-31 21:20 - 2016-01-15 21:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-01-31 21:20 - 2016-01-15 21:43 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-01-31 21:20 - 2016-01-15 21:42 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-31 21:20 - 2016-01-15 21:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-01-31 21:20 - 2016-01-15 21:41 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-01-31 21:20 - 2016-01-15 21:40 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-01-31 21:20 - 2016-01-15 21:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-01-31 21:20 - 2016-01-15 21:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-01-31 21:20 - 2016-01-15 21:40 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-01-31 21:20 - 2016-01-15 21:39 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-01-31 21:20 - 2016-01-15 21:38 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-01-31 21:20 - 2016-01-15 21:38 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-01-31 21:20 - 2016-01-15 21:38 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-01-31 21:20 - 2016-01-15 21:38 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-01-31 21:20 - 2016-01-15 21:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-01-31 21:20 - 2016-01-15 21:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-01-31 21:20 - 2016-01-15 21:37 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-01-31 21:20 - 2016-01-15 21:37 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-01-31 21:20 - 2016-01-15 21:36 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-01-31 21:20 - 2016-01-15 21:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2016-01-31 21:20 - 2016-01-15 21:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-01-31 21:20 - 2016-01-15 21:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-01-31 21:20 - 2016-01-15 21:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-01-31 21:20 - 2016-01-15 21:35 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-01-31 21:20 - 2016-01-15 21:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-01-31 21:20 - 2016-01-15 21:34 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-01-31 21:20 - 2016-01-15 21:34 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-01-31 21:20 - 2016-01-15 21:34 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-01-31 21:20 - 2016-01-15 21:34 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-31 21:20 - 2016-01-15 21:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-01-31 21:20 - 2016-01-15 21:33 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-01-31 21:20 - 2016-01-15 21:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-01-31 21:20 - 2016-01-15 21:33 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-01-31 21:20 - 2016-01-15 21:32 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-01-31 21:20 - 2016-01-15 21:32 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-01-31 21:20 - 2016-01-15 21:31 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-01-31 21:20 - 2016-01-15 21:31 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-01-31 21:20 - 2016-01-15 21:31 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-01-31 21:20 - 2016-01-15 21:31 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-01-31 21:20 - 2016-01-15 21:31 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-01-31 21:20 - 2016-01-15 21:30 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-01-31 21:20 - 2016-01-15 21:30 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-01-31 21:20 - 2016-01-15 21:30 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-01-31 21:20 - 2016-01-15 21:30 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-01-31 21:20 - 2016-01-15 21:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-01-31 21:20 - 2016-01-15 21:30 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-01-31 21:20 - 2016-01-15 21:29 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-01-31 21:20 - 2016-01-15 21:29 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-01-31 21:20 - 2016-01-15 21:28 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-01-31 21:20 - 2016-01-15 21:28 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-01-31 21:20 - 2016-01-15 21:28 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-31 21:20 - 2016-01-15 21:28 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-01-31 21:20 - 2016-01-15 21:28 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-01-31 21:20 - 2016-01-15 21:27 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-01-31 21:20 - 2016-01-15 21:26 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-01-31 21:20 - 2016-01-15 21:26 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-01-31 21:20 - 2016-01-15 21:26 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-01-31 21:20 - 2016-01-15 21:26 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-31 21:20 - 2016-01-15 21:25 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-01-31 21:20 - 2016-01-15 21:25 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-01-31 21:20 - 2016-01-15 21:25 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-01-31 21:20 - 2016-01-15 21:24 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-01-31 21:20 - 2016-01-15 21:24 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-01-31 21:20 - 2016-01-15 21:24 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-01-31 21:20 - 2016-01-15 21:24 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-01-31 21:20 - 2016-01-15 21:23 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-01-31 21:20 - 2016-01-15 21:23 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-01-31 21:20 - 2016-01-15 21:21 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-01-31 21:20 - 2016-01-15 21:20 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-01-31 21:20 - 2016-01-15 21:20 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-31 21:20 - 2016-01-15 21:20 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-01-31 21:20 - 2016-01-15 21:20 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-01-31 21:20 - 2016-01-15 21:19 - 12126208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-01-31 21:20 - 2016-01-15 21:19 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-01-31 21:20 - 2016-01-15 21:19 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-01-31 21:20 - 2016-01-15 21:19 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-01-31 21:20 - 2016-01-15 21:19 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-01-31 21:20 - 2016-01-15 21:18 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-01-31 21:20 - 2016-01-15 21:18 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-31 21:20 - 2016-01-15 21:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-01-31 21:20 - 2016-01-15 21:16 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-01-31 21:20 - 2016-01-15 21:16 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-01-31 21:20 - 2016-01-15 21:15 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-01-31 21:20 - 2016-01-15 21:14 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-01-31 21:20 - 2016-01-15 21:14 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-01-31 21:20 - 2016-01-15 21:11 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-01-31 21:20 - 2016-01-15 21:09 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-01-31 21:05 - 2016-02-09 19:39 - 00001605 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AsusSmartGestureDetector.lnk
2016-01-31 21:04 - 2016-02-08 18:28 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture
2016-01-31 20:57 - 2016-01-31 20:57 - 00003628 _____ C:\WINDOWS\System32\Tasks\ASUS Smart Gesture Launcher
2016-01-31 20:56 - 2016-01-31 20:56 - 63628251 _____ C:\Users\Admin\Desktop\RemoteLinkSetup.zip
2016-01-31 20:56 - 2016-01-31 20:56 - 00001390 _____ C:\Users\Public\Desktop\ASUS Smart Gesture.lnk
2016-01-31 20:56 - 2016-01-31 20:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2016-01-31 20:56 - 2016-01-31 20:56 - 00000000 ____D C:\Program Files (x86)\ASUS
2016-01-31 20:46 - 2016-01-31 20:46 - 00004300 _____ C:\Users\Admin\Desktop\VLCDIRECT(1).BAT
2016-01-31 14:52 - 2016-01-31 20:36 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2016-01-31 13:55 - 2016-02-09 20:00 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-31 13:55 - 2016-02-08 18:28 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-31 13:55 - 2016-02-04 21:01 - 00002283 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-31 13:55 - 2016-02-04 21:01 - 00002271 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-31 13:55 - 2016-01-31 13:55 - 00003974 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-01-31 13:55 - 2016-01-31 13:55 - 00003742 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-30 13:02 - 2016-01-30 13:02 - 00052712 _____ C:\Users\Admin\AppData\Roaming\grm1901phon.env
2016-01-30 13:02 - 2016-01-30 13:02 - 00002179 _____ C:\Users\Admin\AppData\Roaming\ZygodactylMagnetonOroide
2016-01-27 21:48 - 2016-01-27 21:48 - 00243851 _____ C:\Users\Admin\Desktop\F60111123.pdf
2016-01-26 22:41 - 2016-02-07 17:28 - 00000000 ____D C:\Users\Admin\Desktop\BIKES
2016-01-16 13:50 - 2016-01-04 18:51 - 07477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-01-16 13:50 - 2016-01-04 18:51 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-01-16 13:50 - 2016-01-04 18:51 - 01141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-01-16 13:50 - 2016-01-04 18:50 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2016-01-16 13:50 - 2016-01-04 18:48 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2016-01-16 13:50 - 2016-01-04 18:45 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-01-16 13:50 - 2016-01-04 18:42 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-01-16 13:50 - 2016-01-04 18:37 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-01-16 13:50 - 2016-01-04 18:37 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-01-16 13:50 - 2016-01-04 18:37 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-01-16 13:50 - 2016-01-04 18:37 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-01-16 13:50 - 2016-01-04 18:37 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2016-01-16 13:50 - 2016-01-04 18:36 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-01-16 13:50 - 2016-01-04 18:33 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-01-16 13:50 - 2016-01-04 18:33 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-01-16 13:50 - 2016-01-04 18:33 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-01-16 13:50 - 2016-01-04 18:33 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2016-01-16 13:50 - 2016-01-04 18:33 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-01-16 13:50 - 2016-01-04 18:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-01-16 13:50 - 2016-01-04 18:27 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-01-16 13:50 - 2016-01-04 18:24 - 00796352 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-01-16 13:50 - 2016-01-04 18:23 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-01-16 13:50 - 2016-01-04 18:23 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-01-16 13:50 - 2016-01-04 18:23 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2016-01-16 13:50 - 2016-01-04 18:23 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-16 13:50 - 2016-01-04 18:21 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-01-16 13:50 - 2016-01-04 18:17 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2016-01-16 13:50 - 2016-01-04 18:16 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
2016-01-16 13:50 - 2016-01-04 17:57 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
2016-01-16 13:50 - 2016-01-04 17:56 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2016-01-16 13:50 - 2016-01-04 17:54 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-01-16 13:50 - 2016-01-04 17:50 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-01-16 13:50 - 2016-01-04 17:50 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-01-16 13:50 - 2016-01-04 17:49 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-16 13:50 - 2016-01-04 17:49 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-01-16 13:50 - 2016-01-04 17:49 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
2016-01-16 13:50 - 2016-01-04 17:48 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-16 13:50 - 2016-01-04 17:48 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-01-16 13:50 - 2016-01-04 17:47 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-01-16 13:50 - 2016-01-04 17:47 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-01-16 13:50 - 2016-01-04 17:45 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-01-16 13:50 - 2016-01-04 17:45 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-01-16 13:50 - 2016-01-04 17:43 - 00953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-01-16 13:50 - 2016-01-04 17:43 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-01-16 13:50 - 2016-01-04 17:43 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-01-16 13:50 - 2016-01-04 17:41 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-01-16 13:50 - 2016-01-04 17:40 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2016-01-16 13:50 - 2016-01-04 17:40 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2016-01-16 13:50 - 2016-01-04 17:39 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-01-16 13:50 - 2016-01-04 17:39 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-01-16 13:50 - 2016-01-04 17:39 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-01-16 13:50 - 2016-01-04 17:38 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-01-16 13:50 - 2016-01-04 17:36 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2016-01-16 13:50 - 2016-01-04 17:30 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-01-16 13:50 - 2016-01-04 17:30 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-01-16 13:50 - 2016-01-04 17:29 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-01-16 13:50 - 2016-01-04 17:28 - 07826432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-01-16 13:50 - 2016-01-04 17:28 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-01-16 13:50 - 2016-01-04 17:25 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-01-16 13:49 - 2016-01-04 17:57 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-01-16 13:49 - 2016-01-04 17:54 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
2016-01-16 13:49 - 2016-01-04 17:53 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2016-01-16 13:49 - 2016-01-04 17:52 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-01-16 13:49 - 2016-01-04 17:51 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-01-16 13:49 - 2016-01-04 17:51 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-16 13:49 - 2016-01-04 17:49 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-01-16 13:49 - 2016-01-04 17:49 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-01-16 13:49 - 2016-01-04 17:48 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
2016-01-16 13:49 - 2016-01-04 17:47 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2016-01-16 13:49 - 2016-01-04 17:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2016-01-16 13:49 - 2016-01-04 17:43 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-01-16 13:49 - 2016-01-04 17:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-01-16 13:49 - 2016-01-04 17:41 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2016-01-16 13:49 - 2016-01-04 17:39 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2016-01-16 13:49 - 2016-01-04 17:36 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-01-13 13:48 - 2016-01-13 13:48 - 00001958 _____ C:\Users\Admin\AppData\Roaming\ActionInfo.java
2016-01-13 13:48 - 2016-01-13 13:48 - 00000986 _____ C:\Users\Admin\AppData\Roaming\abstract.notitle.enabled.xml
2016-01-12 00:45 - 2016-01-12 21:45 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Local Stores
2016-01-12 00:21 - 2016-01-12 00:21 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recover My Files v5
2016-01-12 00:21 - 2016-01-12 00:21 - 00000000 ____D C:\Program Files\CodeMeter
2016-01-12 00:21 - 2016-01-12 00:21 - 00000000 ____D C:\Program Files (x86)\GetData
2016-01-12 00:21 - 2016-01-12 00:21 - 00000000 ____D C:\Program Files (x86)\CodeMeter
2016-01-12 00:21 - 2013-11-27 12:26 - 00917352 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\system32\WibuCm64.dll
2016-01-12 00:21 - 2013-11-27 12:26 - 00719720 _____ (WIBU-SYSTEMS AG) C:\WINDOWS\SysWOW64\WibuCm32.dll
2016-01-12 00:20 - 2016-02-07 14:15 - 00000000 ____D C:\Users\Admin\AppData\Local\Idlksoft
2016-01-12 00:19 - 2016-01-12 00:19 - 00003446 _____ C:\WINDOWS\System32\Tasks\ThinPrint AutoConnect component for 32 bit applications
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-09 20:15 - 2015-05-12 21:11 - 00000000 ____D C:\Users\Admin\Documents\272
2016-02-09 20:00 - 2015-03-15 22:23 - 00000000 ____D C:\Users\Admin\AppData\Roaming\vlc
2016-02-09 19:41 - 2015-08-09 14:00 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe
2016-02-09 19:39 - 2016-01-04 19:23 - 00004152 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{29254992-1F40-49A0-A403-F4187B8BB024}
2016-02-09 19:39 - 2015-10-01 20:33 - 00000000 ____D C:\Users\Admin\AppData\Local\Spotify
2016-02-09 19:39 - 2015-10-01 20:32 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Spotify
2016-02-09 19:38 - 2015-11-17 20:02 - 00000000 ____D C:\Program Files (x86)\Steam
2016-02-09 19:38 - 2015-10-29 23:21 - 00000000 ____D C:\WINDOWS\INF
2016-02-09 19:38 - 2015-07-29 22:33 - 00881036 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-09 19:36 - 2014-11-25 22:46 - 00000000 ___RD C:\Users\Admin\OneDrive
2016-02-08 18:27 - 2015-12-17 03:20 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-02-08 18:27 - 2015-07-29 22:43 - 00000000 __SHD C:\Users\Admin\IntelGraphicsProfiles
2016-02-08 18:27 - 2015-05-31 17:29 - 00000350 _____ C:\WINDOWS\Tasks\EMRDYTPUD1.job
2016-02-08 08:34 - 2015-03-16 21:07 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-02-08 08:27 - 2015-04-06 20:27 - 00000000 ____D C:\Program Files (x86)\QuickTime
2016-02-07 21:45 - 2015-12-17 03:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-07 21:45 - 2015-10-29 22:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-02-07 21:08 - 2015-04-08 21:20 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-02-07 20:57 - 2015-03-15 21:54 - 00000000 ___HD C:\$SysReset
2016-02-07 18:32 - 2015-10-01 20:00 - 00000000 ____D C:\Users\Admin\Desktop\412
2016-02-07 18:24 - 2015-03-23 20:54 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Maxthon3
2016-02-06 01:01 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-05 06:36 - 2015-12-17 03:20 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-02-04 22:31 - 2015-03-22 17:58 - 00000000 ____D C:\Users\Admin\AppData\Roaming\.ACEStream
2016-02-04 21:33 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\rescache
2016-02-04 21:16 - 2015-07-29 22:51 - 00002374 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-03 22:04 - 2015-04-19 11:22 - 00000000 ____D C:\Users\Admin\AppData\Roaming\uTorrent
2016-02-01 23:08 - 2015-12-17 03:26 - 00000000 ____D C:\Users\Admin
2016-02-01 23:08 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-02-01 20:18 - 2014-10-17 08:20 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-01 20:14 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-02-01 20:14 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-02-01 20:13 - 2015-10-29 23:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-02-01 20:13 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-02-01 20:13 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-02-01 20:13 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-02-01 20:13 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-02-01 20:11 - 2015-10-29 23:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-01 20:10 - 2014-10-17 08:26 - 00000000 ____D C:\Users\Admin\AppData\Local\Packages
2016-01-31 21:31 - 2015-10-29 23:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-01-31 20:57 - 2014-09-26 23:28 - 00000000 ____D C:\Program Files\DIFX
2016-01-31 20:17 - 2015-06-24 20:48 - 00000000 ____D C:\Program Files (x86)\Google
2016-01-31 14:19 - 2015-06-09 09:59 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-31 14:19 - 2015-06-09 09:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-30 13:55 - 2014-10-30 18:50 - 00000000 ____D C:\Users\Admin\Desktop\C
2016-01-30 10:59 - 2014-10-16 21:56 - 00000000 ___HD C:\_acestream_cache_
2016-01-24 12:41 - 2015-12-20 20:18 - 00000000 ____D C:\Users\Admin\Desktop\RAW
2016-01-17 01:26 - 2015-03-17 20:07 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-01-16 13:53 - 2015-03-17 20:07 - 143671360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-01-16 13:52 - 2015-06-09 09:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-16 13:30 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\L2Schemas
2016-01-13 08:37 - 2016-01-06 23:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-01-13 08:37 - 2015-12-17 03:26 - 00000000 ____D C:\Users\UpdatusUser
2016-01-13 08:37 - 2015-03-15 22:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-01-12 00:13 - 2015-04-08 21:19 - 00001182 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-01-12 00:13 - 2015-04-08 21:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-01-12 00:13 - 2015-04-08 21:19 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-01-12 00:09 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-01-11 21:15 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
 
==================== Files in the root of some directories =======
 
2016-01-13 13:48 - 2016-01-13 13:48 - 0000986 _____ () C:\Users\Admin\AppData\Roaming\abstract.notitle.enabled.xml
2016-01-13 13:48 - 2016-01-13 13:48 - 0001958 _____ () C:\Users\Admin\AppData\Roaming\ActionInfo.java
2015-10-25 13:43 - 2015-10-25 13:43 - 0000132 _____ () C:\Users\Admin\AppData\Roaming\Adobe BMP Format CS6 Prefs
2014-05-07 21:44 - 2014-05-07 21:44 - 0003575 _____ () C:\Users\Admin\AppData\Roaming\Adobe-Japan1-3
2016-02-05 05:26 - 2016-02-05 05:26 - 0002022 _____ () C:\Users\Admin\AppData\Roaming\AssessorshipSpatSizzle
2015-05-19 17:28 - 2015-05-19 17:28 - 0002878 _____ () C:\Users\Admin\AppData\Roaming\backgroundmon.xml
2013-10-01 18:55 - 2013-10-01 18:55 - 0002978 _____ () C:\Users\Admin\AppData\Roaming\basic.css
2014-05-07 20:05 - 2014-05-07 20:05 - 0000524 _____ () C:\Users\Admin\AppData\Roaming\blue 286 bl 3.ADO
2013-10-01 18:54 - 2013-10-01 18:54 - 0001112 _____ () C:\Users\Admin\AppData\Roaming\Ceuta
2014-05-07 20:05 - 2014-05-07 20:05 - 0000524 _____ () C:\Users\Admin\AppData\Roaming\Cool Gray 7 bl 2.ADO
2016-02-01 02:41 - 2016-02-01 02:41 - 0045056 _____ () C:\Users\Admin\AppData\Roaming\cruor.dll
2013-10-01 18:56 - 2013-10-01 18:56 - 0001261 _____ () C:\Users\Admin\AppData\Roaming\docbook-xsl-update
2014-05-07 21:44 - 2014-05-07 21:44 - 0001090 _____ () C:\Users\Admin\AppData\Roaming\ENU.zdct
2016-02-02 02:04 - 2016-02-02 02:04 - 0051453 _____ () C:\Users\Admin\AppData\Roaming\ETHK-B5-V
2014-05-07 21:44 - 2014-05-07 21:44 - 0003667 _____ () C:\Users\Admin\AppData\Roaming\Ext-RKSJ-V
2016-02-01 02:25 - 2016-02-01 02:25 - 0057344 _____ () C:\Users\Admin\AppData\Roaming\fortyniner.dll
2016-02-02 13:48 - 2016-02-02 13:48 - 0001946 _____ () C:\Users\Admin\AppData\Roaming\GleyCenobite
2014-05-07 20:05 - 2014-05-07 20:05 - 0000315 _____ () C:\Users\Admin\AppData\Roaming\goURL_lr_photoshop_kr.csv
2016-01-30 13:02 - 2016-01-30 13:02 - 0052712 _____ () C:\Users\Admin\AppData\Roaming\grm1901phon.env
2016-01-09 03:55 - 2016-01-09 03:55 - 0191504 ___SH () C:\Users\Admin\AppData\Roaming\GYWIaAfVUMIFchWEB
2016-01-09 03:55 - 2016-01-09 03:55 - 0750320 ___SH (AutoIt Team) C:\Users\Admin\AppData\Roaming\GYWIaAfVUMIFchWEBA.exe
2016-01-09 03:55 - 2016-01-09 03:55 - 0046867 ___SH () C:\Users\Admin\AppData\Roaming\GYWIaAfVUMIFchWEBAJ.au3
2016-02-01 10:06 - 2016-02-01 10:06 - 0001666 _____ () C:\Users\Admin\AppData\Roaming\HandcuffPleasureDitch
2016-02-01 10:06 - 2016-02-01 10:06 - 0050277 _____ () C:\Users\Admin\AppData\Roaming\html.stylesheet.type.xml
2016-02-02 02:04 - 2016-02-02 02:04 - 0001524 _____ () C:\Users\Admin\AppData\Roaming\InfidelSchlemiel
2013-10-01 18:55 - 2013-10-01 18:55 - 0002323 _____ () C:\Users\Admin\AppData\Roaming\l10n.xml
2016-02-04 13:37 - 2016-02-04 13:37 - 0049152 _____ () C:\Users\Admin\AppData\Roaming\legislative.dll
2016-02-05 05:26 - 2016-02-05 05:26 - 0052784 _____ () C:\Users\Admin\AppData\Roaming\meta-index
2013-10-01 18:54 - 2013-10-01 18:54 - 0000065 _____ () C:\Users\Admin\AppData\Roaming\Muscat
2013-10-01 18:54 - 2013-10-01 18:54 - 0001144 _____ () C:\Users\Admin\AppData\Roaming\Nipigon
2013-10-01 18:56 - 2013-10-01 18:56 - 0004177 _____ () C:\Users\Admin\AppData\Roaming\param.xml
2015-05-19 17:28 - 2015-05-19 17:28 - 0003491 _____ () C:\Users\Admin\AppData\Roaming\pcdrieee1394.p5m
2014-05-07 20:05 - 2014-05-07 20:05 - 0000112 _____ () C:\Users\Admin\AppData\Roaming\Photorealistic High Contrast.hdt
2014-05-07 21:44 - 2014-05-07 21:44 - 0000638 _____ () C:\Users\Admin\AppData\Roaming\README_uk_UA.txt
2009-06-10 13:06 - 2009-06-10 13:06 - 0003133 _____ () C:\Users\Admin\AppData\Roaming\SceneButtonInset_Alpha1.png
2016-02-01 21:41 - 2016-02-01 21:41 - 0068096 _____ () C:\Users\Admin\AppData\Roaming\science.dll
2013-10-01 18:55 - 2013-10-01 18:55 - 0000262 _____ () C:\Users\Admin\AppData\Roaming\SimpleDocument3.xml
2016-02-02 13:48 - 2016-02-02 13:48 - 0086261 _____ () C:\Users\Admin\AppData\Roaming\simplesect.in.toc.xml
2015-05-19 17:28 - 2015-05-19 17:28 - 0000979 _____ () C:\Users\Admin\AppData\Roaming\standard_keyboard.png
2015-05-19 17:28 - 2015-05-19 17:28 - 0001769 _____ () C:\Users\Admin\AppData\Roaming\systemTools.png
2013-10-01 18:56 - 2013-10-01 18:56 - 0002184 _____ () C:\Users\Admin\AppData\Roaming\title.margin.left.xml
2014-05-07 21:44 - 2014-05-07 21:44 - 0002858 _____ () C:\Users\Admin\AppData\Roaming\UniHojo-UCS2-V
2013-10-01 18:56 - 2013-10-01 18:56 - 0001007 _____ () C:\Users\Admin\AppData\Roaming\xbCollapsibleLists.js.xml
2016-01-30 13:02 - 2016-01-30 13:02 - 0002179 _____ () C:\Users\Admin\AppData\Roaming\ZygodactylMagnetonOroide
2013-10-19 19:54 - 2013-10-19 19:54 - 0182784 _____ (Microsoft Corporation) C:\Users\Admin\AppData\Roaming\Microsoft\btstack.dll
2015-05-31 20:18 - 2015-06-01 21:24 - 0000112 _____ () C:\ProgramData\02s6Lq.dat
2016-02-07 21:46 - 2016-02-07 21:46 - 0000000 ____H () C:\ProgramData\cm-lock
2015-12-17 03:22 - 2015-12-17 03:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-11-16 20:59 - 2015-11-16 21:05 - 0000813 _____ () C:\ProgramData\hpzinstall.log
 
Files to move or delete:
====================
C:\ProgramData\02s6Lq.dat
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-02-07 11:17
 
==================== End of FRST.txt ============================

 



BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:43 PM

Posted 10 February 2016 - 09:37 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to the a new file.
 
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

() C:\Users\Admin\AppData\Roaming\ACEStream\updater\ace_update.exe
() C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe
() C:\Users\Public\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exe
() C:\Users\Admin\AppData\Local\Temp\temp\tmp797F.exe
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [AceUpdater] => C:\Users\Admin\AppData\Roaming\ACEStream\updater\ace_update.exe [27000 2015-11-10] ()
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [AceStream] => C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe [27000 2015-12-25] ()
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [BluetoothManage] => rundll32.exe "%appdata%\Microsoft\btstack.dll",init
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [Otsxics] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Admin\AppData\Local\Idlksoft\CurlCommssplsh90.dll
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [2074811022] => C:\Users\Admin\AppData\Local\Yiram\Aepalg.exe [199168 2016-02-09] ()
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4206410717-698191494-857776807-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
FF Plugin HKU\S-1-5-21-4206410717-698191494-857776807-1002: @acestream.net/acestreamplugin,version=3.0.11 -> C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll [2015-09-24] (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-4206410717-698191494-857776807-1002: @acestream.net/acestreamplugin,version=3.0.12 -> C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll [2015-09-24] (Innovative Digital Technologies)
FF HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
FF Extension: Ace Stream Web Extension - C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2015-12-18]
CHR Extension: (Ace Stream Web Extension) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2016-01-10]
CHR Extension: (Ace Stream Web Extension) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2016-01-31]
S3 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [X]
S1 aqzupkcn; \??\C:\WINDOWS\system32\drivers\aqzupkcn.sys [X]
S1 bqedchup; \??\C:\WINDOWS\system32\drivers\bqedchup.sys [X]
S1 fyeqatxx; \??\C:\WINDOWS\system32\drivers\fyeqatxx.sys [X]
S1 jjzhthsg; \??\C:\WINDOWS\system32\drivers\jjzhthsg.sys [X]
S1 kcuqfhcq; \??\C:\WINDOWS\system32\drivers\kcuqfhcq.sys [X]
S1 kvxzbphp; \??\C:\WINDOWS\system32\drivers\kvxzbphp.sys [X]
S1 lbcbkgqt; \??\C:\WINDOWS\system32\drivers\lbcbkgqt.sys [X]
C:\Users\Admin\AppData\Roaming\ACEStream
C:\Users\Admin\AppData\Local\Idlksoft
C:\Users\Public\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exe
C:\Users\Admin\AppData\Local\Temp\temp
C:\Users\Admin\AppData\Local\Yiram
C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt file and include the Addition.txt file that was created by the Farbar tool.

Please let me know what problem persists with this computer.

#3 guitarman77

guitarman77
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:43 PM

Posted 12 February 2016 - 01:50 AM

Fix result of Farbar Recovery Scan Tool (x64) Version:07-02-2016
Ran by Admin (2016-02-11 22:18:44) Run:1
Running from C:\Users\Admin\Downloads
Loaded Profiles: UpdatusUser & Admin (Available Profiles: UpdatusUser & Admin & Administrator)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
 
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
() C:\Users\Admin\AppData\Roaming\ACEStream\updater\ace_update.exe
() C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe
() C:\Users\Public\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exe
() C:\Users\Admin\AppData\Local\Temp\temp\tmp797F.exe
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [AceUpdater] => C:\Users\Admin\AppData\Roaming\ACEStream\updater\ace_update.exe [27000 2015-11-10] ()
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [AceStream] => C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe [27000 2015-12-25] ()
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [BluetoothManage] => rundll32.exe "%appdata%\Microsoft\btstack.dll",init
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [Otsxics] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Admin\AppData\Local\Idlksoft\CurlCommssplsh90.dll
HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Run: [2074811022] => C:\Users\Admin\AppData\Local\Yiram\Aepalg.exe [199168 2016-02-09] ()
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-4206410717-698191494-857776807-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
FF Plugin HKU\S-1-5-21-4206410717-698191494-857776807-1002: @acestream.net/acestreamplugin,version=3.0.11 -> C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll [2015-09-24] (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-4206410717-698191494-857776807-1002: @acestream.net/acestreamplugin,version=3.0.12 -> C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll [2015-09-24] (Innovative Digital Technologies)
FF HKU\S-1-5-21-4206410717-698191494-857776807-1002\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
FF Extension: Ace Stream Web Extension - C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2015-12-18]
CHR Extension: (Ace Stream Web Extension) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2016-01-10]
CHR Extension: (Ace Stream Web Extension) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2016-01-31]
S3 SwitchBoard; "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [X]
S1 aqzupkcn; \??\C:\WINDOWS\system32\drivers\aqzupkcn.sys [X]
S1 bqedchup; \??\C:\WINDOWS\system32\drivers\bqedchup.sys [X]
S1 fyeqatxx; \??\C:\WINDOWS\system32\drivers\fyeqatxx.sys [X]
S1 jjzhthsg; \??\C:\WINDOWS\system32\drivers\jjzhthsg.sys [X]
S1 kcuqfhcq; \??\C:\WINDOWS\system32\drivers\kcuqfhcq.sys [X]
S1 kvxzbphp; \??\C:\WINDOWS\system32\drivers\kvxzbphp.sys [X]
S1 lbcbkgqt; \??\C:\WINDOWS\system32\drivers\lbcbkgqt.sys [X]
C:\Users\Admin\AppData\Roaming\ACEStream
C:\Users\Admin\AppData\Local\Idlksoft
C:\Users\Public\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exe
C:\Users\Admin\AppData\Local\Temp\temp
C:\Users\Admin\AppData\Local\Yiram
C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo
 
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
C:\Users\Admin\AppData\Roaming\ACEStream\updater\ace_update.exe => No running process found
C:\Users\Admin\AppData\Roaming\ACEStream\engine\ace_engine.exe => No running process found
C:\Users\Public\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exe => No running process found
C:\Users\Admin\AppData\Local\Temp\temp\tmp797F.exe => No running process found
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Windows\CurrentVersion\Run\\AceUpdater => value removed successfully
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Windows\CurrentVersion\Run\\AceStream => value removed successfully
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Windows\CurrentVersion\Run\\BluetoothManage => value removed successfully
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Otsxics => value removed successfully
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Microsoft\Windows\CurrentVersion\Run\\2074811022 => value removed successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-4206410717-698191494-857776807-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\MozillaPlugins\@acestream.net/acestreamplugin,version=3.0.11" => key removed successfully
C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll => moved successfully
"HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\MozillaPlugins\@acestream.net/acestreamplugin,version=3.0.12" => key removed successfully
C:\Users\Admin\AppData\Roaming\ACEStream\player\npace_plugin.dll => not found.
HKU\S-1-5-21-4206410717-698191494-857776807-1002\Software\Mozilla\Firefox\Extensions\\acewebextension_unlisted@acestream.org => value removed successfully
C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => moved successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo => moved successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo => moved successfully
SwitchBoard => service removed successfully
aqzupkcn => service removed successfully
bqedchup => service removed successfully
fyeqatxx => service removed successfully
jjzhthsg => service removed successfully
kcuqfhcq => service removed successfully
kvxzbphp => service removed successfully
lbcbkgqt => service removed successfully
C:\Users\Admin\AppData\Roaming\ACEStream => moved successfully
C:\Users\Admin\AppData\Local\Idlksoft => moved successfully
C:\Users\Public\Documents\Microsoft\Assistance\Tools\TPAutoConnect32.exe => moved successfully
C:\Users\Admin\AppData\Local\Temp\temp => moved successfully
C:\Users\Admin\AppData\Local\Yiram => moved successfully
"C:\Users\Admin\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi" => not found.
"C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo" => not found.
"C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo" => not found.
EmptyTemp: => 23.7 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 22:22:51 ====

Attached Files


Edited by guitarman77, 12 February 2016 - 01:51 AM.


#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:43 PM

Posted 12 February 2016 - 09:48 AM

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to the a new file.


Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

[B]Task: {02A66D23-4F51-4849-BAEE-44E612AAD718} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {4244EFBC-552F-4DBB-8CDE-3EB059A6B993} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {4995D922-FB17-4F4B-BE47-3F5DAE91B1EC} - System32\Tasks\Norwood => C:\Program Files\shopperz\Cote.bat <==== ATTENTION
Task: {706468B8-C639-4FC6-A11A-027377B04B42} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {78B2034D-68A9-4782-B34D-95AA3D0278EE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7A9F854B-4413-4DB0-AA10-7F5FFB5C69DC} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9BA88A0F-A826-4D37-9D6A-1BEB07154DBA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {A1C6AC01-9B6A-45BD-B5D3-25A5A07AC14E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {AC8D8933-7C4F-4621-AC82-EE79B27831BA} - \avabvbxvh -> No File <==== ATTENTION
Task: {AEDBD63F-9DC6-4E85-9BF8-1B0E812066AF} - System32\Tasks\EMRDYTPUD1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {CDA92053-A70A-470B-A885-BB47C22C93D3} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {D357F6D0-1916-4C47-9F9A-B1B35F950D02} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {DD725C11-C87F-4297-BD2F-E1FF47313CF7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {E229C0C0-64DC-46E0-9519-BA41626F7970} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {ED04AC71-E45D-4D77-AD07-78FBE5ACFFC5} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\EMRDYTPUD1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
2016-02-09 19:39 - 2016-02-09 19:39 - 00136632 _____ () C:\Users\Admin\AppData\Local\Temp\temp\tmp797F.exe
AlternateDataStreams: C:\WINDOWS\system32\Drivers\kabmxvfg.sys:changelist
AlternateDataStreams: C:\ProgramData\Temp:054203E4
C:\ProgramData\FlashBeat
C:\Users\Admin\AppData\Local\Temp\temp[/B]


End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please paste it in your reply.

Please let me know what problem persists with this computer.


p.s.
If Firefox is acting strange reset the Default Browsing settings:
https://support.mozilla.org/en-US/kb/reset-firefox-easily-fix-problems?utm_expid=65912487-41.djHNRQY0RhaLvvtvcd0BQA.2&utm_referrer=https%3A%2F%2Fwww.google.ca%2F

Clean the Firefox Cache.
https://kb.wisc.edu/page.php?id=15141
===

#5 guitarman77

guitarman77
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:43 PM

Posted 15 February 2016 - 10:08 PM

Fix result of Farbar Recovery Scan Tool (x64) Version:07-02-2016
Ran by Admin (2016-02-13 09:31:38) Run:3
Running from C:\Users\Admin\Downloads
Loaded Profiles: Admin (Available Profiles: UpdatusUser & Admin & Administrator)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

Task: {02A66D23-4F51-4849-BAEE-44E612AAD718} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {4244EFBC-552F-4DBB-8CDE-3EB059A6B993} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {4995D922-FB17-4F4B-BE47-3F5DAE91B1EC} - System32\Tasks\Norwood => C:\Program Files\shopperz\Cote.bat <==== ATTENTION
Task: {706468B8-C639-4FC6-A11A-027377B04B42} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {78B2034D-68A9-4782-B34D-95AA3D0278EE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7A9F854B-4413-4DB0-AA10-7F5FFB5C69DC} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9BA88A0F-A826-4D37-9D6A-1BEB07154DBA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {A1C6AC01-9B6A-45BD-B5D3-25A5A07AC14E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {AC8D8933-7C4F-4621-AC82-EE79B27831BA} - \avabvbxvh -> No File <==== ATTENTION
Task: {AEDBD63F-9DC6-4E85-9BF8-1B0E812066AF} - System32\Tasks\EMRDYTPUD1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {CDA92053-A70A-470B-A885-BB47C22C93D3} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {D357F6D0-1916-4C47-9F9A-B1B35F950D02} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {DD725C11-C87F-4297-BD2F-E1FF47313CF7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {E229C0C0-64DC-46E0-9519-BA41626F7970} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {ED04AC71-E45D-4D77-AD07-78FBE5ACFFC5} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\EMRDYTPUD1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
2016-02-09 19:39 - 2016-02-09 19:39 - 00136632 _____ () C:\Users\Admin\AppData\Local\Temp\temp\tmp797F.exe
AlternateDataStreams: C:\WINDOWS\system32\Drivers\kabmxvfg.sys:changelist
AlternateDataStreams: C:\ProgramData\Temp:054203E4
C:\ProgramData\FlashBeat
C:\Users\Admin\AppData\Local\Temp\temp



End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{02A66D23-4F51-4849-BAEE-44E612AAD718} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree[B]\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4244EFBC-552F-4DBB-8CDE-3EB059A6B993} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4995D922-FB17-4F4B-BE47-3F5DAE91B1EC} => key not found.
C:\WINDOWS\System32\Tasks\Norwood => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norwood => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{706468B8-C639-4FC6-A11A-027377B04B42} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78B2034D-68A9-4782-B34D-95AA3D0278EE} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A9F854B-4413-4DB0-AA10-7F5FFB5C69DC} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BA88A0F-A826-4D37-9D6A-1BEB07154DBA} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1C6AC01-9B6A-45BD-B5D3-25A5A07AC14E} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC8D8933-7C4F-4621-AC82-EE79B27831BA} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbxvh => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEDBD63F-9DC6-4E85-9BF8-1B0E812066AF} => key not found.
C:\WINDOWS\System32\Tasks\EMRDYTPUD1 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EMRDYTPUD1 => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CDA92053-A70A-470B-A885-BB47C22C93D3} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D357F6D0-1916-4C47-9F9A-B1B35F950D02} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD725C11-C87F-4297-BD2F-E1FF47313CF7} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E229C0C0-64DC-46E0-9519-BA41626F7970} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED04AC71-E45D-4D77-AD07-78FBE5ACFFC5} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => key not found.
C:\WINDOWS\Tasks\EMRDYTPUD1.job => not found.
"C:\Users\Admin\AppData\Local\Temp\temp\tmp797F.exe" => not found.
"C:\WINDOWS\system32\Drivers\kabmxvfg.sys" => ":changelist" ADS not found.
"C:\ProgramData\Temp" => ":054203E4" ADS not found.
"C:\ProgramData\FlashBeat" => not found.
"C:\Users\Admin\AppData\Local\Temp\temp
" => not found.
EmptyTemp: => 97.6 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 09:31:44 ====



#6 guitarman77

guitarman77
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:43 PM

Posted 15 February 2016 - 10:10 PM

Computer seems ok now, still get a message here and there about Windows Defender removing malware



#7 nasdaq

nasdaq

  • Malware Response Team
  • 38,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:43 PM

Posted 16 February 2016 - 07:57 AM

still get a message here and there about Windows Defender removing malware

Could this be your problem with Windows Defender?

http://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning/win10-defender-constantly-detecting-non-existent/464672ee-a993-467c-97bb-b738175cbaac

Quoted from the article.

In reply to ThexReason's post on August 10, 2015

edit. Issue solved (apparently) -
WARNING: This workaround may leave the machine vulnerable if the threat is real. Only do this if you've already followed every available malware removal advice there or at specialized sites and are 100% sure there's no malware on your machine.
How: After going in circles, I've done a very simply procedure. First, I've allowed the possible threat, forcing Defender to ignore it. That made it return to it's normal 'all clear' state (green screen and all). That done, I've proceeded to history, allowed items and removed everything from there. The loop ceased and a full scan returned that everything is ok (no threats found). Just to be sure, Malware Bytes was run at security mode and no internet connection.


If still no joy can you give me the contents of the message from Defender.

#8 guitarman77

guitarman77
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:43 PM

Posted 17 February 2016 - 01:27 AM

Thank you very much for all of your help NASDAQ  :thumbup2: :clapping:



#9 nasdaq

nasdaq

  • Malware Response Team
  • 38,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:43 PM

Posted 17 February 2016 - 09:07 AM

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:08:43 PM

Posted 22 February 2016 - 09:16 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users