The result of FRST.txt :
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-01-2017
Ran by Hp (administrator) on HP-PC (08-01-2017 07:20:32)
Running from C:\Users\Hp\Desktop
Loaded Profiles: Hp (Available Profiles: Hp)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Program Files (x86)\Andromax M2Y\FI_Eject.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\CalendarTool\2.0.0.1000040\CalendarServ.exe
() C:\Windows\svchost.exe
(Microsoft Corporation) C:\ProgramData\Windows Security\winsecurity.exe
() C:\Program Files (x86)\CalendarTool\2.0.0.1000040\calendar.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Users\Hp\AppData\Roaming\WMPNetworkAcSvc\WMPNetworkAcSvc.exe
(Microsoft Corporation) C:\Windows\csrss.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Network\Dsq\network\sysnetwk.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
() C:\ProgramData\wintools\UpdateModule.exe
(win tech) C:\ProgramData\wintools\wintool.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\sdclt.exe
(Google Inc.) C:\Program Files (x86)\Standoor\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-1463942549-299140565-3030456123-1000\...\MountPoints2: {3dff35f6-a945-11e6-ab15-48d224c769c0} - F:\Setup.exe
HKU\S-1-5-21-1463942549-299140565-3030456123-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKLM\...\Providers\hnmqypeb: C:\Program Files (x86)\CalendarTool\\local64spl.dll [143360 2016-11-30] ()
ShellExecuteHooks: No Name - {F4DD6538-A73A-11E6-92ED-64006A5CFC23} - C:\Users\Hp\AppData\Roaming\Ckichmebcult\Vvushvonich.dll -> No File
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.3.0.dll [2016-12-22] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-1463942549-299140565-3030456123-1000] => Proxy is enabled.
ProxyServer: [S-1-5-21-1463942549-299140565-3030456123-1000] => http=127.0.0.1:8080;https=127.0.0.1:8080
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{2736959F-E4E4-49C3-9DD2-9C010BAEB7E6}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{5200CAA2-6F41-4D00-8CAD-62D966DC75B9}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{B0787000-1D35-4BB2-AD2B-631061BF3613}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{F301A4A5-665F-4292-8604-E76958A70455}: [DhcpNameServer] 192.168.42.129
ManualProxies: 1http=127.0.0.1:8080;https=127.0.0.1:8080
Internet Explorer:
==================
HKU\S-1-5-21-1463942549-299140565-3030456123-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
HKU\S-1-5-21-1463942549-299140565-3030456123-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.amisites.com/search/?type=ds&ts=1480929300&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
HKU\S-1-5-21-1463942549-299140565-3030456123-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
HKU\S-1-5-21-1463942549-299140565-3030456123-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
HKU\S-1-5-21-1463942549-299140565-3030456123-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.amisites.com/search/?type=ds&ts=1480929300&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.amisites.com/search/?type=ds&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1463942549-299140565-3030456123-1000 -> {18940D58-68D5-487E-9555-82E7058814BA} URL = hxxps://id.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Java\bin\ssv.dll [2016-11-13] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Java\bin\jp2ssv.dll [2016-11-13] (Oracle Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.amisites.com/?type=sc&ts=1480660357&z=&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
FireFox:
========
FF DefaultProfile: ltkfw9oj.default
FF ProfilePath: C:\Users\Hp\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\ltkfw9oj.default\Profiles\ltkfw9oj.default [not found]
FF ProfilePath: C:\Users\Hp\AppData\Roaming\Mozilla\Firefox\Profiles\ltkfw9oj.default [2017-01-08]
FF NewTab: Mozilla\Firefox\Profiles\ltkfw9oj.default -> hxxp://www.trotux.com/?z=efaa451c2174b4eb465641eg3zcbdeezbqfg8tatfg&from=isr&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&type=hp
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ltkfw9oj.default -> trotux
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ltkfw9oj.default -> trotux
FF Homepage: Mozilla\Firefox\Profiles\ltkfw9oj.default -> hxxp://www.amisites.com/?type=hp&ts=1482225069&z=edb8002a85984f4c53167bcg1zbb2o3o9ocw1e0mdg&from=archer1028&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
FF Homepage: Mozilla\Firefox\Profiles\ltkfw9oj.default -> hxxp://id.hao123.com/?tn=sdkc_inner_hp_23_hao123_id&guid=1aca176ce9a007af3f10c9c6d1df84f4
FF Extension: (Firefox Hotfix) - C:\Users\Hp\AppData\Roaming\Mozilla\Firefox\Profiles\ltkfw9oj.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-11-05]
FF Extension: (Search and New Tab by Yahoo) - C:\Users\Hp\AppData\Roaming\Mozilla\Firefox\Profiles\ltkfw9oj.default\Extensions\jid1-16aeif9OQIRKxA@jetpack.xpi [2016-11-13]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Hp\AppData\Roaming\Mozilla\Firefox\Profiles\ltkfw9oj.default\features\{6e2b5a80-7333-41e5-ae7b-0d0cf5dfcb53}\malware-remediation@mozilla.org.xpi [2016-11-05]
FF SearchPlugin: C:\Users\Hp\AppData\Roaming\Mozilla\Firefox\Profiles\ltkfw9oj.default\searchplugins\amisites.xml [2016-12-02]
FF SearchPlugin: C:\Users\Hp\AppData\Roaming\Mozilla\Firefox\Profiles\ltkfw9oj.default\searchplugins\k7fap1un.xml [2016-11-30]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-11-03] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-04-26] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-11-03] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Java\bin\dtplugin\npDeployJava1.dll [2016-11-13] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Java\bin\plugin2\npjp2.dll [2016-11-13] (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1463942549-299140565-3030456123-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Hp\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-1463942549-299140565-3030456123-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Hp\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://www.amisites.com/?type=sc&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.amisites.com/?type=hp&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.amisites.com/search/?type=ds&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX&q={searchTerms}
CHR DefaultSearchKeyword: ChromeDefaultData -> amisites
CHR Profile: C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-01-08] <==== ATTENTION
CHR Extension: (Google Docs) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-30]
CHR Extension: (Google Drive) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-30]
CHR Extension: (YouTube) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-01]
CHR Extension: (Yahoo Partner) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fabhkdeopjkcpkmofliimbjckmocfiom [2016-11-30]
CHR Extension: (Google Docs Offline) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-30]
CHR Extension: (Skype) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-11-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-30]
CHR Extension: (Fast search) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pbdpajcdgknpendpmecafmopknefafha [2016-11-30]
CHR Extension: (Gmail) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-30]
CHR Extension: (Chrome Media Router) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-30]
CHR Extension: (easychrome) - C:\Users\Hp\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk [2016-11-30]
CHR Profile: C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default [2016-11-30]
CHR Extension: (Google Docs) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-04]
CHR Extension: (Google Drive) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-04]
CHR Extension: (YouTube) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-04]
CHR Extension: (Yahoo Partner) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabhkdeopjkcpkmofliimbjckmocfiom [2016-11-13]
CHR Extension: (Google Docs Offline) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-04]
CHR Extension: (Skype) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-11-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-04]
CHR Extension: (Fast search) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbdpajcdgknpendpmecafmopknefafha [2016-11-30]
CHR Extension: (Gmail) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-04]
CHR Extension: (Chrome Media Router) - C:\Users\Hp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-05]
CHR HKLM-x32\...\Chrome\Extension: [fabhkdeopjkcpkmofliimbjckmocfiom] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome.VCI4MJNHV6IMIW2DQYIRA47YYU - c:\users\hp\appdata\local\google\chrome\APPLIC~1\chrome.exe hxxp://www.amisites.com/?type=sc&ts=1483622447&z=47f8e5f52d3fff6d062f8eagfzab6c6q3ocofzdwae&from=che0812&uid=HGSTXHTS545050A7E380_TE85134P11WR2C11WR2CX
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-02-06] (ArcSoft Inc.)
R2 CDROM_Eject_Smart_907; C:\Program Files (x86)\Andromax M2Y\FI_Eject.exe [346624 2016-03-18] () [File not signed]
S4 Convxxxx; C:\Users\Hp\AppData\Roaming\hbehb\UvConverter.exe [393728 2016-12-01] () [File not signed]
S3 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
S3 DbxSvc; C:\Windows\system32\DbxSvc.exe [42096 2016-12-22] (Dropbox, Inc.)
S4 ed2kidle; C:\Program Files (x86)\amuleC1\ed2k.exe [237568 2016-12-19] (hxxp://www.amule.org/) [File not signed]
S3 GoogleChromeUpService; C:\ProgramData\service.exe [1620992 2016-11-30] () [File not signed] <==== ATTENTION
R2 GubedZL; C:\Program Files (x86)\Gubed\GubedZL.dll [133632 2017-01-05] () [File not signed]
S3 Gubed_WMI; C:\Program Files (x86)\Gubed_WMI\Gubed_WMI.exe [109056 2016-12-23] () [File not signed]
R3 iThemes5; C:\Program Files (x86)\Common Files\Services\iThemes.dll [568832 2016-12-09] () [File not signed] <==== ATTENTION
S3 ose64; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [538112 2017-01-03] () [File not signed]
S3 ShareItSvc; C:\Program Files (x86)\SHAREit\SHAREit\Shareit.Service.exe [33224 2016-04-15] (SHAREit Technologies Co.Ltd)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [332800 2013-02-05] (IDT, Inc.) [File not signed]
R2 TheCalendarService; C:\Program Files (x86)\CalendarTool\2.0.0.1000040\CalendarServ.exe [157296 2016-11-30] ()
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2009-07-14] (Microsoft Corporation) [DependOnService: iThemes5]<==== ATTENTION
S3 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2016-09-23] (SHAREit Technologies Co.Ltd)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-05-16] (Microsoft Corporation)
R2 Windows; C:\Windows\svchost.exe [177152 2016-11-30] () [File not signed] <==== ATTENTION
R2 WindowsSecurity; C:\ProgramData\Windows Security\winsecurity.exe [1265664 2016-10-26] (Microsoft Corporation) [File not signed] <==== ATTENTION
R2 WinSAPSvc; C:\ProgramData\WinSAPSvc\WinSAP.dll [186368 2017-01-05] () [File not signed]
R2 WMPNetworkAcSvc; C:\Users\Hp\AppData\Roaming\WMPNetworkAcSvc\WMPNetworkAcSvc.exe [5091840 2016-11-10] () [File not signed] <==== ATTENTION
S4 XBox; C:\Program Files\XBox\XBLive.exe [6342584 2016-06-13] (Microsoft Corporation) <==== ATTENTION
S4 Zerdgeghevse; C:\Program Files (x86)\Dojeygerfick\pighzabodomCln.dll [276480 2016-11-30] () [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-11-30] (REALiX)
S3 ucdrv; C:\Windows\System32\drivers:ucdrv-x64.sys [80850 ] (UC Web Inc.) <==== ATTENTION
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-08 07:20 - 2017-01-08 07:23 - 00024916 _____ C:\Users\Hp\Desktop\FRST.txt
2017-01-08 07:20 - 2017-01-08 07:20 - 00000000 ____D C:\FRST
2017-01-08 06:57 - 2017-01-08 06:58 - 02418688 _____ (Farbar) C:\Users\Hp\Desktop\FRST64.exe
2017-01-08 06:55 - 2017-01-08 06:55 - 00132597 _____ C:\Users\Hp\Desktop\hosts.zip
2017-01-08 06:48 - 2017-01-08 06:48 - 00077328 _____ C:\Windows\ntbtlog.txt
2017-01-08 06:44 - 2017-01-08 06:44 - 01106888 _____ (Bleeping Computer, LLC) C:\Users\Hp\AppData\Roaming\rkill64.exe
2017-01-08 06:41 - 2017-01-08 06:41 - 00001055 _____ C:\Users\Public\Desktop\Andromax M2Y.lnk
2017-01-08 06:41 - 2017-01-08 06:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andromax M2Y
2017-01-08 06:41 - 2017-01-08 06:41 - 00000000 ____D C:\Program Files (x86)\Andromax M2Y
2017-01-08 06:34 - 2017-01-08 06:34 - 01106888 _____ (Bleeping Computer, LLC) C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\rkill64.exe
2017-01-07 08:57 - 2017-01-08 06:33 - 00001093 _____ C:\Users\Hp\Desktop\rkill - Shortcut.lnk
2017-01-07 08:57 - 2017-01-07 07:14 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Hp\AppData\Roaming\rkill.exe
2017-01-07 07:15 - 2017-01-08 06:45 - 00002998 _____ C:\Users\Hp\Desktop\Rkill.txt
2017-01-07 07:15 - 2017-01-08 06:45 - 00000000 ____D C:\Users\Hp\Desktop\rkill
2017-01-07 07:15 - 2017-01-07 07:15 - 03977168 _____ C:\Users\Hp\Downloads\AdwCleaner.exe
2017-01-07 07:13 - 2017-01-07 07:14 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\rkill.exe
2017-01-06 16:41 - 2017-01-06 16:41 - 00000000 ____D C:\Users\Hp\AppData\Roaming\Umeng
2017-01-06 16:40 - 2017-01-06 16:40 - 00000000 ____D C:\Users\Hp\AppData\Local\SHAREit Technologies
2017-01-06 16:40 - 2017-01-06 16:40 - 00000000 ____D C:\Program Files (x86)\SHAREit Technologies
2017-01-06 16:34 - 2017-01-06 16:34 - 06586160 _____ (SHAREit Technologies Co.Ltd ) C:\Users\Hp\Downloads\SHAREit-KCWEB.exe
2017-01-06 16:24 - 2017-01-06 16:42 - 00000000 ____D C:\Users\Hp\Downloads\SHAREit
2017-01-06 16:24 - 2017-01-06 16:40 - 00001206 _____ C:\Users\Public\Desktop\SHAREit.lnk
2017-01-06 16:24 - 2017-01-06 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit
2017-01-06 16:24 - 2017-01-06 16:24 - 00000000 ____D C:\Users\Hp\AppData\Local\SHAREit
2017-01-06 16:24 - 2017-01-06 16:24 - 00000000 ____D C:\Users\Hp\AppData\Local\Lenovo
2017-01-06 16:24 - 2017-01-06 16:24 - 00000000 ____D C:\ProgramData\Lenovo
2017-01-06 16:24 - 2017-01-06 16:24 - 00000000 ____D C:\Program Files (x86)\SHAREit
2017-01-06 16:23 - 2017-01-06 16:24 - 05181720 _____ (Lenovo ) C:\Users\Hp\Downloads\SHAREitSoftonic.exe
2017-01-06 11:16 - 2017-01-06 11:16 - 00000000 ____D C:\Users\Hp\Documents\aMule Downloads
2017-01-05 21:20 - 2017-01-06 11:16 - 00000000 ____D C:\Users\Hp\AppData\Roaming\aMule
2017-01-05 21:20 - 2017-01-05 21:20 - 00000000 ____D C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amuleC
2017-01-05 21:20 - 2017-01-05 21:20 - 00000000 ____D C:\Program Files (x86)\amuleC1
2017-01-05 15:12 - 2017-01-05 15:31 - 00000000 ____D C:\Windows\system32\appmgmt
2017-01-05 15:10 - 2017-01-05 15:10 - 00000000 ____D C:\Users\Hp\AppData\Local\Pivot Animator
2017-01-05 07:49 - 2017-01-05 07:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-01-04 21:01 - 2017-01-04 21:01 - 00000020 _____ C:\Users\Hp\Desktop\wwww.rar
2017-01-03 18:25 - 2017-01-03 18:25 - 00000000 ____D C:\ProgramData\Pivot Animator
2017-01-03 18:05 - 2017-01-05 15:09 - 00001030 _____ C:\Users\Public\Desktop\Pivot Animator.lnk
2017-01-03 18:05 - 2017-01-05 15:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pivot Animator
2017-01-03 18:05 - 2017-01-05 15:09 - 00000000 ____D C:\Program Files (x86)\Pivot Animator
2017-01-03 18:04 - 2017-01-03 18:04 - 00538112 _____ C:\Users\Hp\AppData\Roaming\Ground.exe
2017-01-02 12:48 - 2017-01-02 12:48 - 00007605 _____ C:\Users\Hp\AppData\Local\Resmon.ResmonCfg
2016-12-31 21:40 - 2016-12-31 21:56 - 45609064 _____ C:\Users\Hp\Downloads\GrowtopiaInstaller.exe
2016-12-30 16:30 - 2016-12-31 21:57 - 00000864 _____ C:\Users\Hp\Desktop\Growtopia.lnk
2016-12-30 15:55 - 2016-12-30 15:55 - 00000000 ____D C:\Program Files (x86)\Gubed
2016-12-29 11:41 - 2016-12-29 11:41 - 00103424 _____ (Advanced Micro Devices) C:\Windows\system32\DelayAPO.dll
2016-12-29 11:41 - 2016-12-29 11:41 - 00096256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys
2016-12-28 12:13 - 2016-12-28 12:13 - 00059452 _____ C:\Users\Public\Documents\SIGVERIF.TXT
2016-12-24 13:13 - 2016-12-24 13:15 - 00013030 _____ C:\PDOXUSRS.NET
2016-12-22 19:51 - 2016-12-23 20:41 - 00000000 ____D C:\Program Files (x86)\Gubed_WMI
2016-12-22 02:15 - 2016-12-22 02:15 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2016-12-22 02:15 - 2016-12-22 02:15 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2016-12-22 02:15 - 2016-12-22 02:15 - 00075888 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2016-12-22 02:15 - 2016-12-22 02:15 - 00042096 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2016-12-13 21:01 - 2016-12-17 22:07 - 00000688 _____ C:\Windows\SysWOW64\cookies.log
2016-12-13 17:58 - 2016-12-13 18:58 - 00000000 ____D C:\ProgramData\wintools
2016-12-13 17:58 - 2016-12-13 17:58 - 00014452 _____ C:\Windows\System32\Tasks\WinTOOL
2016-12-13 17:21 - 2016-12-30 15:54 - 00000000 ____D C:\Program Files (x86)\yaceu78a
2016-12-11 08:11 - 2016-12-11 08:11 - 00000000 ____D C:\Users\Hp\AppData\Local\Standoor
2016-12-11 05:05 - 2016-12-23 20:40 - 00000000 _____ C:\Users\Public\Documents\report.dat
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-01-08 07:21 - 2016-11-03 18:57 - 00002503 ____H C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-01-08 07:21 - 2016-11-03 18:57 - 00002381 ____H C:\Users\Hp\Desktop\Google Chrome.lnk
2017-01-08 07:21 - 2016-11-03 18:57 - 00001153 ____H C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-01-08 07:21 - 2016-11-03 18:57 - 00001141 ____H C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-01-08 07:21 - 2016-11-03 18:43 - 00001449 ____H C:\Users\Hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-01-08 07:14 - 2016-11-05 07:57 - 00001046 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-01-08 06:58 - 2009-07-14 13:13 - 00713888 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-08 06:58 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\inf
2017-01-08 06:55 - 2016-11-30 07:26 - 00000000 ____D C:\Users\Hp\AppData\Roaming\WMPNetworkAcSvc
2017-01-08 06:50 - 2016-12-06 10:14 - 00000040 _____ C:\Program Files (x86)\settings.dat
2017-01-08 06:50 - 2016-11-30 07:26 - 00000034 _____ C:\Users\Public\Documents\{DE764086-1C0A-4DD3-90BA-0B93BDD794BE}
2017-01-08 06:49 - 2016-11-05 07:57 - 00001042 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-01-08 06:49 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-08 06:46 - 2009-07-14 12:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-08 06:46 - 2009-07-14 12:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-07 09:13 - 2016-11-30 07:25 - 00000000 ____D C:\Users\Hp\AppData\Roaming\CalendarTool
2017-01-07 08:53 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\registration
2017-01-07 07:10 - 2016-11-22 19:42 - 00000000 ____D C:\Users\Hp\AppData\Local\Growtopia
2017-01-06 20:06 - 2016-12-06 10:14 - 00000114 _____ C:\Program Files (x86)\metadata
2017-01-06 20:06 - 2016-12-06 10:14 - 00000000 ____D C:\Program Files (x86)\reports
2017-01-06 20:05 - 2016-11-03 18:55 - 00000000 ____D C:\KMPlayer
2017-01-06 19:51 - 2009-07-14 11:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-01-06 09:12 - 2016-11-30 21:27 - 00000000 ____D C:\ProgramData\WinSAPSvc
2017-01-05 15:29 - 2016-11-30 07:27 - 00000000 ____D C:\Windows\system32\SSL
2017-01-05 15:27 - 2016-11-03 18:50 - 00000000 ____D C:\Program Files (x86)\Google
2017-01-05 15:23 - 2016-11-03 18:51 - 00000000 ____D C:\Users\Hp\AppData\Local\Google
2017-01-05 15:23 - 2016-11-03 18:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
2017-01-05 15:15 - 2016-11-03 19:24 - 00000000 ____D C:\Program Files (x86)\SMADAV
2017-01-05 15:15 - 2016-11-03 18:52 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2017-01-05 15:13 - 2016-11-30 21:17 - 00000000 ____D C:\ProgramData\ProductData
2017-01-05 14:08 - 2016-11-30 21:17 - 00002874 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (Hp)
2017-01-05 07:50 - 2016-11-05 07:57 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-01-05 06:52 - 2016-11-30 07:26 - 00000000 ____D C:\Program Files (x86)\Dojeygerfick
2017-01-04 21:27 - 2016-11-30 21:27 - 00000000 ____D C:\Program Files (x86)\k7fap1un
2017-01-03 18:05 - 2016-11-30 23:46 - 00000000 ____D C:\Users\Public\Documents\iSkysoft
2017-01-03 18:05 - 2016-11-13 14:33 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-01-03 18:05 - 2016-11-13 10:07 - 00538112 _____ C:\Users\Hp\Desktop\chromeinstall-8u111.exe
2017-01-03 18:05 - 2016-11-05 07:57 - 00538112 _____ C:\Users\Hp\Downloads\DropboxInstaller.exe
2017-01-03 18:05 - 2016-11-03 18:53 - 00000000 ____D C:\Program Files\MPC-HC
2017-01-03 18:05 - 2016-11-03 18:53 - 00000000 ____D C:\Program Files\IDT
2017-01-03 18:05 - 2016-11-03 18:50 - 00000000 ____D C:\Transtool
2017-01-03 18:05 - 2016-11-03 18:44 - 00000000 ____D C:\Program Files\WinRAR
2016-12-30 15:55 - 2016-11-30 21:28 - 00000000 ____D C:\Program Files (x86)\WinArcher
2016-12-30 11:30 - 2016-11-29 23:51 - 01847990 _____ C:\Windows\cb1887ec4bff0b9fcb063659f324c1e8.exe
2016-12-30 11:27 - 2009-07-14 13:08 - 00032572 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-12-29 11:43 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\catroot
2016-12-29 11:41 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\DriverStore
2016-12-28 12:13 - 2009-07-14 11:20 - 00000000 ___RD C:\Users\Public\Documents
2016-12-23 20:40 - 2016-12-05 21:59 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2016-12-23 20:37 - 2016-11-30 08:09 - 00000000 ____D C:\Users\Hp\Documents\WebCam Media
2016-12-20 18:39 - 2016-11-13 10:13 - 00000000 ____D C:\Users\Hp\AppData\Roaming\.minecraft
2016-12-20 15:38 - 2016-11-30 21:17 - 00000000 ____D C:\ProgramData\IObit
2016-12-17 20:16 - 2016-11-04 18:09 - 00003614 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1463942549-299140565-3030456123-1000UA
2016-12-17 20:16 - 2016-11-04 18:09 - 00003342 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1463942549-299140565-3030456123-1000Core
2016-12-17 20:16 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\Tasks
2016-12-13 09:00 - 2016-11-30 21:27 - 00000000 ____D C:\ProgramData\ChelfNotify
2016-12-10 21:45 - 2016-12-04 14:59 - 00000000 ____D C:\Users\Hp\AppData\Local\Microsoft Games
2016-12-10 18:10 - 2009-07-14 10:34 - 00500330 _____ C:\Windows\system32\Drivers\etc\HOSTS
2016-12-09 16:47 - 2009-07-14 12:54 - 00524288 ___SH C:\Windows\system32\config\COMPONENTS{016888b9-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
==================== Files in the root of some directories =======
2016-12-06 10:14 - 2017-01-06 20:06 - 0000114 _____ () C:\Program Files (x86)\metadata
2016-12-06 10:14 - 2017-01-08 06:50 - 0000040 _____ () C:\Program Files (x86)\settings.dat
2017-01-03 18:04 - 2017-01-03 18:04 - 0538112 _____ () C:\Users\Hp\AppData\Roaming\Ground.exe
2017-01-07 08:57 - 2017-01-07 07:14 - 2030536 _____ (Bleeping Computer, LLC) C:\Users\Hp\AppData\Roaming\rkill.exe
2017-01-08 06:44 - 2017-01-08 06:44 - 1106888 _____ (Bleeping Computer, LLC) C:\Users\Hp\AppData\Roaming\rkill64.exe
2017-01-02 12:48 - 2017-01-02 12:48 - 0007605 _____ () C:\Users\Hp\AppData\Local\Resmon.ResmonCfg
2016-11-30 07:26 - 2016-11-30 07:26 - 1620992 _____ () C:\ProgramData\service.exe
C:\Windows\svchost.exe
ATTENTION ====> Check for partition/boot infection.
Files to move or delete:
====================
C:\ProgramData\service.exe
Some files in TEMP:
====================
C:\Users\Hp\AppData\Local\Temp\5F25.tmp.exe
C:\Users\Hp\AppData\Local\Temp\Browser_V5.7.15319.5_r_4634_(Build1608291541).exe
C:\Users\Hp\AppData\Local\Temp\DriverBoosterSetup.exe
C:\Users\Hp\AppData\Local\Temp\jg3.6.0.exe
C:\Users\Hp\AppData\Local\Temp\KuaiZip_Setup_lz2_01.exe
C:\Users\Hp\AppData\Local\Temp\libeay32.dll
C:\Users\Hp\AppData\Local\Temp\marketator_id.exe
C:\Users\Hp\AppData\Local\Temp\setup.exe
C:\Users\Hp\AppData\Local\Temp\sqlite3.dll
C:\Users\Hp\AppData\Local\Temp\wajam_install.exe
C:\Users\Hp\AppData\Local\Temp\_BAGAS31_ Setup.exe
C:\Users\Hp\AppData\Local\Temp\~ct9BC2.tmp.dll
C:\Users\Hp\AppData\Local\Temp\~ctB470.tmp.dll
C:\Users\Hp\AppData\Local\Temp\~ctCB3B.tmp.dll
Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\Drivers\ecf5946c16df65fefa5085217810da4c.sys
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-01-05 14:42
==================== End of FRST.txt ============================