Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

taskeng.exe popping up randomly and i cant open Farbar's Recovery Scan Tool


  • This topic is locked This topic is locked
22 replies to this topic

#1 pandapeter

pandapeter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 04 May 2018 - 01:58 AM

hello i need help to fix it, its happen when im download something on some website then some virus is running taskeng.exe on my computer, and I cant find where it is.

 

i've already fix it but didnt work, and when i open FRST.exe suddenly auto close and when i wanna download FRST my web browser suddenly auto close too. i really need help to fix this problem, thank you...

 

im sorry for my bad english.

 



BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,683 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:51 PM

Posted 04 May 2018 - 07:14 AM

Hi pandapeter :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.
  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens
  • As long as I'm assisting you on BleepingComputer, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against BleepingComputer's rules
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread
This being said, it's time to clean-up some malware, so let's get started, shall we? :)

Can you boot in Safe Mode and run a scan with Malwarebytes?

j1Bynr2.pngMalwarebytes - Clean Mode
  • Download and install the free version of Malwarebytes
    Note: If you have Malwarebytes already installed, you don't need to install it again. Simply start from the next bullet point
  • Once Malwarebytes is installed, launch it and let it update his database. You might have to click on the little arrow by Scan Status in the middle right pane for it to do so
  • Once the database update is complete, click on the Scan tab, then select the Threat Scan button and click on Start Scan
  • Let the scan run, the time required to complete the scan depends of your system and computer specs
  • Once the scan is complete, make sure that the first checkbox at the top is checked (which will automatically check every detected item), then click on the Quarantine Selected button
    • If it asks you to restart your computer to complete the removal, do so
  • Click on Export Summary after the deletion (in the bottom-left corner) and select Copy to Clipboard. Paste the content in your next reply

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 04 May 2018 - 07:43 AM

Hi aura thanks for helping me, i was trying use FRST again and its work i dont know how, so i will copy FRST and Additional.txt here..

 

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03.05.2018
Ran by CA (administrator) on CA-PC (04-05-2018 19:32:56)
Running from C:\Users\CA\Desktop
Loaded Profiles: CA (Available Profiles: CA)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\BCMWLTRY.EXE
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Smadsoft) C:\Program Files (x86)\SMADAV\SMΔRTP.exe
(H.D.S. Hungary) C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Mozilla) C:\Users\CA\AppData\Roaming\LiveUpdate351.exe
(SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Smadav Software) C:\Program Files (x86)\SMADAV\SmadavProtect64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
() C:\Windows\mssecsvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(LINE Corporation) C:\Users\CA\AppData\Local\LINE\bin\current\LINE.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Farbar) C:\Users\CA\Desktop\FRostenglish.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [7177728 2018-05-04] (Broadcom Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-24] (IDT, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [315880 2018-01-05] (Adobe Systems, Incorporated)
HKLM-x32\...\Run: [UCam_Menu] => "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [319360 2012-03-14] (Hewlett-Packard Company)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SMΔRT-Protection] => C:\Program Files (x86)\Smadav\SMΔRTP.exe [1903696 2018-04-13] (Smadsoft)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Run: [LiveUpdate351.exe] => C:\Users\CA\AppData\Roaming\LiveUpdate351.exe .. [3695104 2018-05-04] (Mozilla)
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [1] Mshta.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [2] powershell.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [3] bitsadmin.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\MountPoints2: {eedca44a-896c-11e7-9fa9-e4115b455bed} - F:\WIN\setup.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Winlogon: [Shell] explorer.exe, C:\Users\CA\AppData\Roaming\DE25E01C-A553-C0F0-1FF2-A9F4C346ED68\a7b0f190-da75-71cb-1ccb-ae35102fc239.exe <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2018-02-04]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS)
Startup: C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\drrheeta.lnk [2018-05-04]
Startup: C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jdwujvsd.lnk [2018-05-04]
GroupPolicy: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{E423BEC1-2BF0-4D9C-8DE2-EAD0EF615D99}: [DhcpNameServer] 192.168.100.1
 
Internet Explorer:
==================
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2017-08-21] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2017-08-21] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2017-08-21] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2017-08-21] (Oracle Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 40jr9pt9.default
FF ProfilePath: C:\Users\CA\AppData\Roaming\Mozilla\Firefox\Profiles\40jr9pt9.default [2018-05-04]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2018-01-13]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\CA\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\CA\AppData\Roaming\IDM\idmmzcc5 [2018-01-31] [Legacy] [not signed]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]
FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2017-08-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2017-08-21] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2017-08-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2017-08-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-29] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultSearchURL: Default -> hxxp://srchbar.com/?q={searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Profile: C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default [2018-05-04]
CHR Extension: (Docs) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-20]
CHR Extension: (YouTube) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-20]
CHR Extension: (Space & Patterns) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkdmjaboldkklmcomdamidplnfpnmmmd [2017-10-26]
CHR Extension: (Stay secure with CyberGhost VPN Free Proxy) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffbkglfijbcbgblgflchnbphjdllaogb [2018-05-04]
CHR Extension: (Google Docs Offline) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-20]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-04-26]
CHR Extension: (WhatsChrome Extension) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbhfoiaobflocffnclkigpkeoagheimn [2018-05-04]
CHR Extension: (VidPlay) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mniicboehgimlhnmhkijibenmangpaea [2018-04-04]
CHR Extension: (Internet Download Manager (IDM)) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpnamocnciebhgnpcnmoodclmocfcdig [2017-11-13]
CHR Extension: (IDM Integration Module) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-03-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Search Manager) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej [2018-04-24]
CHR Extension: (Gmail) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-20]
CHR Extension: (Chrome Media Router) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-29]
CHR Profile: C:\Users\CA\AppData\Local\Google\Chrome\User Data\System Profile [2018-04-09]
CHR HKLM\...\Chrome\Extension: [ijahobfejgeblmkpcmgpelfibgnnjpil] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3044604572-4114186790-410436043-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ijahobfejgeblmkpcmgpelfibgnnjpil] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3044604572-4114186790-410436043-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ijahobfejgeblmkpcmgpelfibgnnjpil] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [imhlianhlhdicjchlbmbfaefhhjencbe] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]
CHR HKLM-x32\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
"qijtttrd" => service was unlocked. <==== ATTENTION
 
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) [File not signed]
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1547200 2017-11-01] ()
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-09-19] (Hi-Rez Studios) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [365440 2012-03-14] (Hewlett-Packard Company)
S3 mracsvc; C:\Windows\System32\mracsvc.exe [8010968 2018-02-27] (LLC Mail.Ru)
R2 mssecsvc2.0; C:\WINDOWS\mssecsvc.exe [3723264 2018-04-03] () [File not signed]
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-11-15] (Nero AG)
S2 qijtttrd; C:\Windows\SysWOW64\qijtttrd\zerrutjo.exe [0 ] () <==== ATTENTION (zero byte File/Folder)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S2 saiyitechnology; C:\ProgramData\yahoochrome_D\desktop35.exe [512312 2018-02-25] (PandaViewer)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-24] (IDT, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [5862400 2018-05-04] (Broadcom Corporation) [File not signed]
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 blackberryncm; C:\Windows\System32\DRIVERS\blackberryncm6_AMD64.sys [36360 2016-04-06] (BlackBerry)
S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [7238880 2018-02-27] (LLC Mail.Ru)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [46408 2017-06-02] (SteelSeries ApS)
R3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [54560 2018-01-10] (SteelSeries ApS)
R3 swivsp; C:\Windows\System32\DRIVERS\swivspnt.sys [23552 2007-03-26] (Sierra Wireless Inc.)
S3 SWNC8UA3; C:\Windows\System32\DRIVERS\swnc8ua3.sys [283136 2010-01-28] (Sierra Wireless Inc.)
S3 SWUMXA3; C:\Windows\System32\DRIVERS\swumxa3.sys [206848 2009-12-08] (Sierra Wireless Inc.)
R3 SzCCID; C:\Windows\System32\DRIVERS\SzCCID.sys [39936 2013-09-24] (Generic)
S3 CLMirrorDriver; system32\DRIVERS\CLMirrorDriver.sys [X]
S3 clwvd7; system32\DRIVERS\clwvd7.sys [X]
S3 swmsflt; system32\DRIVERS\swmsflt.sys [X]
S3 SWUMX20; system32\DRIVERS\swumx20.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-05-04 19:32 - 2018-05-04 19:33 - 000018785 _____ C:\Users\CA\Desktop\FRST.txt
2018-05-04 19:32 - 2018-05-04 13:13 - 002405376 _____ (Farbar) C:\Users\CA\Desktop\FRostenglish.exe
2018-05-04 19:31 - 2018-05-04 19:31 - 001897081 _____ C:\Users\CA\Desktop\FRST64.zip
2018-05-04 19:23 - 2018-05-04 19:23 - 000182784 _____ C:\Users\CA\AppData\Roaming\338792838.exe
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ C:\Users\CA\AppData\Roaming\HXTORXRDQ3PMD7TPT
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ C:\Users\CA\AppData\Roaming\HOWTODECRYPTFILES.html
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ C:\Users\CA\AppData\HOWTODECRYPTFILES.html
2018-05-04 19:19 - 2018-05-04 19:33 - 000003454 _____ C:\Windows\System32\Tasks\NYAN
2018-05-04 19:18 - 2018-05-04 19:18 - 000000000 ___HD C:\Users\Public\Documents\AdobeGC
2018-05-04 19:03 - 2018-05-04 19:03 - 003695104 ____H (Mozilla) C:\Users\CA\AppData\Roaming\LiveUpdate351.exe
2018-05-04 17:57 - 2018-05-04 18:26 - 2435590635 _____ C:\Users\CA\Desktop\[AWBatch] Saiki Kusuo no Ψ-nan (720p).rar
2018-05-04 17:38 - 2018-04-27 00:43 - 000000000 ____D C:\Users\CA\Desktop\Smadav11.9.2.pro.kuyhAa.Me
2018-05-04 17:25 - 2018-05-04 17:25 - 000003138 _____ C:\Windows\System32\Tasks\smadav
2018-05-04 17:25 - 2018-05-04 17:25 - 000001032 _____ C:\Users\Public\Desktop\SMADΔV.lnk
2018-05-04 17:25 - 2018-05-04 17:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus
2018-05-04 17:23 - 2018-05-04 17:24 - 001631020 _____ C:\Users\CA\Desktop\Smadav11.9.2.pro.kuyhAa.Me.rar
2018-05-04 16:25 - 2018-05-04 16:25 - 000000000 _____ C:\Windows\system32\ZeoMount.dat
2018-05-04 16:17 - 2018-05-04 16:17 - 000000000 ____D C:\Windows\System32\Tasks\HardDiskSentinel
2018-05-04 15:51 - 2018-05-04 15:51 - 000000000 ____D C:\Users\CA\AppData\Local\MegaBackup Corp
2018-05-04 15:46 - 2018-05-04 15:46 - 000000000 ____D C:\Users\CA\AppData\Local\IsolatedStorage
2018-05-04 15:44 - 2018-05-04 15:44 - 000000000 ____D C:\ProgramData\MegaBackup Corp
2018-05-04 13:16 - 2018-05-04 13:17 - 000000000 ____D C:\FRST
2018-05-04 12:46 - 2018-05-04 12:46 - 000003156 _____ C:\Windows\System32\Tasks\{0C43A0F7-BFA3-4C05-A71C-5E92F57D7EDD}
2018-05-04 12:45 - 2018-05-04 12:43 - 003952640 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2018-05-04 12:45 - 2018-05-04 12:43 - 003617792 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2018-05-04 12:44 - 2018-05-04 12:43 - 000006656 _____ C:\Windows\system32\bcmwlrc.dll
2018-05-03 20:38 - 2018-05-03 20:38 - 000000931 _____ C:\Users\Public\Desktop\Balsamiq Mockups 3.lnk
2018-05-03 20:38 - 2018-05-03 20:38 - 000000000 ____D C:\Program Files (x86)\Balsamiq Mockups 3
2018-05-03 20:17 - 2018-05-03 15:05 - 000621056 _____ (afjlvnxtrathtdqbgq) C:\Users\CA\AppData\Roaming\product.dll
2018-05-03 20:17 - 2018-05-03 14:55 - 000091648 _____ (pdseoqukseiznoragm) C:\Users\CA\AppData\Roaming\command.dll
2018-05-03 20:16 - 2018-05-04 19:19 - 000000000 _RSHD C:\Users\CA\AppData\Roaming\DE25E01C-A553-C0F0-1FF2-A9F4C346ED68
2018-05-03 20:16 - 2018-05-03 20:16 - 000003614 _____ C:\Windows\System32\Tasks\{76EB22B3-42EE-954A-BCC7-8F1A207C1E60}
2018-05-03 20:16 - 2018-05-03 20:16 - 000003416 _____ C:\Windows\System32\Tasks\WinHostStartForMachine
2018-05-03 20:16 - 2018-05-03 20:16 - 000003408 _____ C:\Windows\System32\Tasks\{B267D8DF-F4B3-A902-4DF9-4EE4AD85936F}
2018-05-03 20:16 - 2018-05-03 20:16 - 000000003 _____ C:\Users\CA\AppData\Local\wbem.ini
2018-05-03 20:16 - 2018-05-03 20:16 - 000000000 ____D C:\ProgramData\yahoochrome_D
2018-05-03 20:15 - 2018-05-04 19:22 - 000003568 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 2796787680
2018-05-03 20:15 - 2018-05-04 19:21 - 000003568 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 4086469641
2018-05-03 20:15 - 2018-05-03 20:17 - 004173824 _____ (ChemTable Software) C:\Users\CA\AppData\Roaming\setup.exe
2018-05-03 20:15 - 2018-05-03 20:15 - 000003562 _____ C:\Windows\System32\Tasks\FastDataX Task
2018-05-03 20:15 - 2018-05-03 20:15 - 000000000 ____D C:\Windows\SysWOW64\qijtttrd
2018-05-03 20:15 - 2018-05-03 20:15 - 000000000 ____D C:\Users\Public\Documents\XMUpdate
2018-05-03 20:15 - 2018-05-03 20:15 - 000000000 ____D C:\Users\CA\AppData\Local\FastDataX
2018-05-03 20:15 - 2018-05-03 20:15 - 000000000 ____D C:\ProgramData\e9bb71e0-6dd5-1
2018-05-03 20:15 - 2018-05-03 20:15 - 000000000 ____D C:\ProgramData\e9bb71e0-6353-0
2018-04-29 09:17 - 2018-04-29 09:17 - 000040516 _____ C:\Users\CA\Downloads\augmented reality.pptx
2018-04-21 05:27 - 2018-04-23 08:14 - 000024545 _____ C:\Users\CA\Desktop\bagas.zip
2018-04-10 17:50 - 2018-05-04 19:24 - 000000000 ____D C:\Users\CA\AppData\Local\Discord
2018-04-10 17:50 - 2018-04-10 23:49 - 000000000 ____D C:\Users\CA\AppData\Roaming\discord
2018-04-10 17:50 - 2018-04-10 17:50 - 000000000 ____D C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2018-04-10 17:50 - 2018-04-10 17:50 - 000000000 ____D C:\Users\CA\AppData\Local\SquirrelTemp
2018-04-06 15:37 - 2018-04-06 15:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
2018-04-06 15:37 - 2018-04-06 15:37 - 000000000 ____D C:\Program Files (x86)\WinPcap
2018-04-06 15:09 - 2018-04-06 15:09 - 001677310 _____ C:\Users\CA\Desktop\SOSIO FINAL.zip
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-05-04 19:32 - 2009-07-14 12:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2018-05-04 19:32 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\inf
2018-05-04 19:26 - 2017-12-14 09:14 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-05-04 19:26 - 2009-07-14 12:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-05-04 19:24 - 2017-11-13 19:53 - 000000000 ____D C:\Users\CA\AppData\Local\Battle.net
2018-05-04 19:23 - 2017-08-29 11:58 - 000000148 _____ C:\Users\CA\AppData\default.pls.3336996838.ransomed@india.com
2018-05-04 19:22 - 2018-03-18 23:20 - 000000488 _____ C:\Windows\Tasks\Yahoo! Powered merar.job
2018-05-04 18:34 - 2017-12-04 16:35 - 000000000 ____D C:\Users\CA\AppData\Roaming\Spotify
2018-05-04 18:32 - 2018-01-31 10:13 - 000000000 ____D C:\Users\CA\AppData\Roaming\DMCache
2018-05-04 17:38 - 2017-07-14 00:04 - 000000000 __SHD C:\[Smad-Cage]
2018-05-04 17:25 - 2017-07-14 00:04 - 000000000 ____D C:\Users\CA\AppData\Roaming\Smadav
2018-05-04 17:25 - 2017-07-14 00:04 - 000000000 ____D C:\Program Files (x86)\SMADAV
2018-05-04 17:10 - 2017-07-14 00:04 - 000000000 ____D C:\Users\CA\AppData\LocalLow\Mozilla
2018-05-04 16:45 - 2017-09-23 17:00 - 000000000 ____D C:\Program Files (x86)\Steam
2018-05-04 16:25 - 2017-07-21 23:22 - 000000000 ____D C:\ProgramData\Package Cache
2018-05-04 16:17 - 2017-07-14 00:30 - 000000000 ____D C:\Users\CA\AppData\Roaming\Hard Disk Sentinel
2018-05-04 16:17 - 2017-07-14 00:30 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2018-05-04 15:38 - 2009-07-14 11:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-05-04 15:38 - 2009-07-14 11:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-05-04 15:18 - 2018-01-31 10:13 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2018-05-04 15:18 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\Resources
2018-05-04 14:37 - 2017-12-04 16:39 - 000000000 ____D C:\Users\CA\AppData\Local\Spotify
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\lv-LV
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\lt-LT
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\et-EE
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\Help
2018-05-04 12:46 - 2017-07-13 19:13 - 000000000 ____D C:\SWSetup
2018-05-04 12:43 - 2017-07-13 19:44 - 001058816 _____ (Broadcom Corporation) C:\Windows\system32\BCMLogon.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 007930368 _____ (Broadcom Corporation) C:\Windows\system32\BCMWLCPL.CPL
2018-05-04 12:43 - 2017-07-13 19:43 - 004961800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcredist_x64.exe
2018-05-04 12:43 - 2017-07-13 19:43 - 004698112 _____ (Broadcom Corporation) C:\Windows\system32\bcmttls.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 003161088 _____ (Microsoft Corporation) C:\Windows\system32\vcredist_x64.exe
2018-05-04 12:43 - 2017-07-13 19:43 - 000073728 _____ (Broadcom Corporation) C:\Windows\system32\wltrynt.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 000022632 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcm42rly.sys
2018-05-04 12:43 - 2017-07-13 19:43 - 000000446 _____ C:\Windows\SysWOW64\vcredist_x64.bat
2018-05-04 12:43 - 2017-07-13 19:43 - 000000445 _____ C:\Windows\system32\vcredist_x64.bat
2018-05-04 10:51 - 2017-12-13 19:30 - 000000000 ____D C:\Windows\Minidump
2018-05-04 10:51 - 2017-11-05 12:57 - 000000440 __RSH C:\ProgramData\ntuser.pol
2018-05-04 10:50 - 2017-12-13 19:30 - 326937963 _____ C:\Windows\MEMORY.DMP
2018-05-04 10:01 - 2017-09-06 23:48 - 000007596 _____ C:\Users\CA\AppData\Local\Resmon.ResmonCfg
2018-05-04 09:59 - 2017-07-13 19:10 - 000001443 _____ C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-05-03 22:28 - 2009-07-14 12:08 - 000032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-05-03 21:20 - 2018-03-18 23:20 - 000000000 ____D C:\ProgramData\{C29307F0-48D1-8D36-CE17-1374545598BA}
2018-05-03 20:38 - 2017-11-03 15:54 - 000000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Balsamiq Mockups 3.lnk
2018-05-02 22:56 - 2018-01-31 10:13 - 000000000 ____D C:\Users\CA\AppData\Roaming\IDM
2018-05-02 00:21 - 2018-03-19 00:21 - 000000262 _____ C:\Users\CA\AppData\Roaming\WB.CFG
2018-04-28 18:06 - 2017-11-12 13:59 - 000002184 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-04-28 00:21 - 2018-03-28 00:21 - 000000000 ____D C:\Users\CA\AppData\Local\{0B733D2F-2FDB-5197-4243-747F662B88E7}
2018-04-26 13:17 - 2017-09-30 07:54 - 003514368 ____S C:\Windows\tasksche.exe
2018-04-21 11:08 - 2017-09-30 07:54 - 003514368 ____S C:\Windows\qeriuwjhrf
2018-04-10 17:42 - 2017-12-14 09:14 - 000774004 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-04-08 11:08 - 2017-07-14 00:00 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-04-07 21:55 - 2017-10-01 16:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
 
==================== Files in the root of some directories =======
 
2017-08-29 21:11 - 2017-08-29 21:11 - 000000000 _____ () C:\Users\CA\GD1_D_8282.js
2018-05-04 19:23 - 2018-05-04 19:23 - 000182784 _____ () C:\Users\CA\AppData\Roaming\338792838.exe
2018-05-03 20:17 - 2018-05-03 14:55 - 000091648 _____ (pdseoqukseiznoragm) C:\Users\CA\AppData\Roaming\command.dll
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ () C:\Users\CA\AppData\Roaming\HOWTODECRYPTFILES.html
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ () C:\Users\CA\AppData\Roaming\HXTORXRDQ3PMD7TPT
2018-05-04 19:03 - 2018-05-04 19:03 - 003695104 ____H (Mozilla) C:\Users\CA\AppData\Roaming\LiveUpdate351.exe
2018-05-03 20:17 - 2018-05-03 15:05 - 000621056 _____ (afjlvnxtrathtdqbgq) C:\Users\CA\AppData\Roaming\product.dll
2018-05-03 20:15 - 2018-05-03 20:17 - 004173824 _____ (ChemTable Software) C:\Users\CA\AppData\Roaming\setup.exe
2018-03-19 00:21 - 2018-05-02 00:21 - 000000262 _____ () C:\Users\CA\AppData\Roaming\WB.CFG
2017-09-06 23:48 - 2018-05-04 10:01 - 000007596 _____ () C:\Users\CA\AppData\Local\Resmon.ResmonCfg
2018-05-03 20:16 - 2018-05-03 20:16 - 000000003 _____ () C:\Users\CA\AppData\Local\wbem.ini
 
Some files in TEMP:
====================
2018-05-03 20:16 - 2018-05-03 20:16 - 001536696 _____ (BANANA SUMMER LIMITED) C:\Users\CA\AppData\Local\Temp\1525353357VE9tmpdown.exe
2018-05-04 15:11 - 2018-05-04 15:11 - 000301056 _____ (89898) C:\Users\CA\AppData\Local\Temp\2293.tmp.exe
2018-05-04 19:01 - 2018-05-04 19:03 - 000000000 _____ () C:\Users\CA\AppData\Local\Temp\231D.tmp.exe
2018-05-03 20:15 - 2018-05-03 20:15 - 000755250 ___SH () C:\Users\CA\AppData\Local\Temp\7F53.tmp.exe
2018-05-03 20:16 - 2018-05-03 20:17 - 000282624 _____ () C:\Users\CA\AppData\Local\Temp\AudioCarder.exe
2018-05-03 20:16 - 2018-05-03 20:16 - 001046528 _____ () C:\Users\CA\AppData\Local\Temp\AudioConverter.exe
2018-05-03 20:17 - 2018-05-03 20:17 - 000335872 _____ () C:\Users\CA\AppData\Local\Temp\AudioInformer.exe
2018-05-04 15:22 - 2018-05-04 15:22 - 000218112 _____ () C:\Users\CA\AppData\Local\Temp\B85D.tmp.exe
2018-05-03 20:15 - 2018-05-03 20:15 - 002565448 _____ () C:\Users\CA\AppData\Local\Temp\but-setup-9.exe
2018-05-03 20:16 - 2018-05-03 20:16 - 000282624 _____ () C:\Users\CA\AppData\Local\Temp\C385.tmp.exe
2018-05-03 20:16 - 2018-05-03 20:16 - 000307200 _____ (2345.com) C:\Users\CA\AppData\Local\Temp\CE6F.tmp.exe
2018-05-03 20:15 - 2018-05-03 20:15 - 001549592 _____ (                                                            ) C:\Users\CA\AppData\Local\Temp\data.exe
2017-12-09 20:12 - 2017-09-05 19:08 - 000047108 _____ () C:\Users\CA\AppData\Local\Temp\hiru.exe
2018-05-04 15:44 - 2018-05-04 15:44 - 001353168 _____ (MegaBackup Corp) C:\Users\CA\AppData\Local\Temp\Ins12A6.tmp.exe
2018-05-03 20:16 - 2018-05-03 20:16 - 000791354 _____ (g3Q3rO3W5r9rYt2coTND                                        ) C:\Users\CA\AppData\Local\Temp\installer.exe
2018-05-03 20:15 - 2018-05-03 20:16 - 001568768 _____ () C:\Users\CA\AppData\Local\Temp\installer_mi.exe
2018-05-04 19:01 - 2018-05-04 19:01 - 003695104 _____ (Mozilla) C:\Users\CA\AppData\Local\Temp\iZqesnKyidTFQBoEwzkW.exe
2018-05-03 20:17 - 2018-05-03 20:17 - 001177088 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\CA\AppData\Local\Temp\libeay32.dll
2018-05-03 20:16 - 2018-05-03 20:15 - 000195896 _____ () C:\Users\CA\AppData\Local\Temp\rerun.exe
2018-05-04 19:23 - 2018-05-04 19:23 - 000625152 _____ () C:\Users\CA\AppData\Local\Temp\reset.exe
2018-05-03 20:16 - 2018-05-03 20:16 - 009660360 _____ () C:\Users\CA\AppData\Local\Temp\s2s.exe
2018-05-03 20:15 - 2018-05-03 20:15 - 000677050 _____ (                                                            ) C:\Users\CA\AppData\Local\Temp\setup.exe
2018-05-03 20:17 - 2018-05-03 20:17 - 000270336 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\CA\AppData\Local\Temp\ssleay32.dll
2018-05-03 20:15 - 2018-05-03 20:15 - 000655872 _____ () C:\Users\CA\AppData\Local\Temp\UmmiDownloader.exe
2018-05-03 20:15 - 2018-05-03 20:15 - 000195896 _____ () C:\Users\CA\AppData\Local\Temp\zdj.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-04-28 00:52
 

==================== End of FRST.txt ============================ 



#4 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 04 May 2018 - 07:44 AM

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03.05.2018
Ran by CA (04-05-2018 19:33:47)
Running from C:\Users\CA\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2017-07-13 12:09:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3044604572-4114186790-410436043-500 - Administrator - Disabled)
CA (S-1-5-21-3044604572-4114186790-410436043-1000 - Administrator - Enabled) => C:\Users\CA
Guest (S-1-5-21-3044604572-4114186790-410436043-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe After Effects CC 2018 (HKLM-x32\...\AEFT_15_0_0) (Version: 15.0.0 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.1.53.7 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2018 (HKLM-x32\...\PPRO_12_0_0) (Version: 12.0.0 - Adobe Systems Incorporated)
Adobe Reader XI  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.20) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated)
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\{F24F876B-7D71-4BD6-88E9-614D3BB84238}) (Version: 1.7.38.0 - Alcor Micro Corp.) Hidden
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\SZCCID) (Version: 1.7.38.0 - Alcor Micro Corp.)
Amazon Redshift ODBC Driver 64-bit (HKLM\...\{788C401A-726B-4CE7-8BC2-89FD7967A6ED}) (Version: 1.2.7 - Amazon Corporate LLC)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.11 Beta1 - Michael Tippach)
Balsamiq Mockups 3 (HKLM-x32\...\{DD3D206D-0E2A-13E1-C0CE-DC751907F1D4}) (Version: 3.5.15 - Balsamiq SRL) Hidden
Balsamiq Mockups 3 (HKLM-x32\...\BalsamiqMockups3.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1) (Version: 3.5.15 - Balsamiq SRL)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.100.82.143 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.100.82.143 - Broadcom Corporation)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{51DD370C-6690-424E-9674-5F14468B323F}) (Version: 15.0.0.487 - Corel Corporation)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\{51DD370C-6690-424E-9674-5F14468B323F}) (Version: 15.0.487 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Capture (HKLM-x32\...\{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Common (HKLM-x32\...\{CA3861BA-1D96-4D66-B577-318E1602C4F3}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Connect (HKLM-x32\...\{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Custom Data (HKLM-x32\...\{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Draw (HKLM-x32\...\{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - EN (HKLM-x32\...\{E34C6AA4-AE8E-4677-912A-92FC2E039DD9}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Filters (HKLM-x32\...\{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - FontNav (HKLM-x32\...\{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - IPM (HKLM-x32\...\{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (HKLM-x32\...\{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Photozoom Plugin (HKLM-x32\...\{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Redist (HKLM-x32\...\{59123CCF-FED2-46FF-9293-D1DC80042219}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Setup Files (HKLM-x32\...\{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VBA (HKLM-x32\...\{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VideoBrowser (HKLM-x32\...\{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VSTA (HKLM-x32\...\{260ED378-2B8C-4831-ADAE-D0712D119AC5}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (HKLM\...\{66C10F29-31F0-4A9B-B2CF-465F488AE086}) (Version: 15.0.487 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - WT (HKLM-x32\...\{9244E956-5939-4B88-930C-0699D4AB2B95}) (Version: 15.0 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 (HKLM-x32\...\{B399C91E-96F2-4265-9884-1C9A10E9FCF4}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW® Graphics Suite X5 (HKLM-x32\...\_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.0.0.486 - Corel Corporation)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1002 - CyberLink Corp.)
Deckadance 2 (HKLM-x32\...\Deckadance 2) (Version: 2.0 - Image-Line)
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.11 - Bloodshed Software)
Discord (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Discord) (Version: 0.0.300 - Discord Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FastDataX 1.20 (HKLM-x32\...\FastDataX_is1) (Version: 1.20 - )
FBS Trader 4 (HKLM-x32\...\FBS Trader 4) (Version: 4.00 - MetaQuotes Software Corp.)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
GlassFish Server Open Source Edition 4.1.1 (HKLM\...\nbi-glassfish-mod-4.1.1.0.1) (Version:  - )
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.1.49.5139 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.139 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Hard Disk Sentinel PRO (HKLM-x32\...\Hard Disk Sentinel_is1) (Version:  - HDS)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HP Battery Check (HKLM-x32\...\HP Battery Check) (Version: 4.3.2.2 - Hewlett-Packard)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.5.9.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)
IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version:  - Image-Line)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel® Network Connections Drivers (HKLM\...\PROSet) (Version: 15.4 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 101 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.17 - Oracle Corporation)
Java SE Development Kit 8 Update 101 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180101}) (Version: 8.0.1010.13 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LINE (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\LINE) (Version: 5.7.0.1660 - LINE Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{E534493E-80D2-4E37-8020-3ECAC55D9DB5}) (Version: 10.53.6000.34 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{49e969a1-2990-464d-92b5-25f6f34573c6}) (Version: 12.0.40664.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{d2c8df0e-f15d-4426-9e51-f13f329f9cb4}) (Version: 12.0.40664.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25711 (HKLM-x32\...\{1bffbfc8-3cfb-4b1d-aca9-64f1c7c9f811}) (Version: 14.12.25711.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25711 (HKLM-x32\...\{f381fb0a-b38e-44ab-bca5-7f651c8c6b93}) (Version: 14.12.25711.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Movavi Video Editor 14 Plus (HKLM-x32\...\Movavi Video Editor 14 Plus) (Version: 14.1.1 - Movavi)
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0.1 - Mozilla)
MPC-HC 1.7.13 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.13 - MPC-HC Team)
MySQL Connector/ODBC 5.3 (HKLM\...\{EB0CFCBD-B0C8-4F0F-ACF4-8B674A19B459}) (Version: 5.3.8 - Oracle Corporation)
Nero 8 Essentials (HKLM-x32\...\{65A54DC3-5FF6-4C75-906E-3EA1A3B71033}) (Version: 8.10.376 - Nero AG)
NetBeans IDE 8.2 (HKLM\...\nbi-nb-base-8.2.0.0.201609300101) (Version: 8.2 - NetBeans.org)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
psqlODBC_x64 (HKLM\...\{3D4F4C5A-28C7-441D-81DC-2AA2C1A61B6A}) (Version: 09.06.0201 - PostgreSQL Global Development Group)
R for Windows 3.4.0 (HKLM\...\R for Windows 3.4.0_is1) (Version: 3.4.0 - R Core Team)
Ruby 2.4.2-2-x64 (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\RubyInstaller-2.4-x64-mingw32_is1) (Version: 2.4.2-2 - RubyInstaller Team)
SMADAV version 11.9.0 (HKLM-x32\...\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1) (Version: 11.9.0 - Smadsoft)
Spotify (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Spotify) (Version: 1.0.77.338.g758ebd78 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteelSeries Engine 3.11.11 (HKLM\...\SteelSeries Engine 3) (Version: 3.11.11 - SteelSeries ApS)
Sublime Text Build 3143 (HKLM\...\Sublime Text 3_is1) (Version:  - Sublime HQ Pty Ltd)
Tableau 10.4 (10400.17.1103.1137) (HKLM\...\{8D3E15C5-DA5C-4655-BF04-AB1AEB27F389}) (Version: 10.4.782 - Tableau Software) Hidden
Tableau 10.4 (10400.17.1103.1137) (HKLM-x32\...\{9894f7c2-d617-453e-bbc1-46c65b10da39}) (Version: 10.4.782 - Tableau Software)
uTorrent Web (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\utweb) (Version: 0.13.0 - BitTorrent, Inc.)
VCRedistSetup (HKLM-x32\...\{3921A67A-5AB1-4E48-9444-C71814CF3027}) (Version: 1.0.0 - Nero AG) Hidden
VLC media player 1.1.10 (HKLM-x32\...\VLC media player) (Version: 1.1.10 - VideoLAN)
Windows Driver Package - Microsoft (xusb21) XnaComposite  (08/13/2009 2.1.0.1349) (HKLM\...\0AEBEF6F936CFE16E003F7E141631FAB754D9816) (Version: 08/13/2009 2.1.0.1349 - Microsoft)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.50 beta 5 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.5 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
Yahoo! Powered (HKLM-x32\...\{AC0244C2-FC82-9542-4D02-E5C29D823642}) (Version:  - ) <==== ATTENTION
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2017-06-23] (Tonec Inc.)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll [2007-11-05] (Nero AG)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers3: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\SMADAV\SmadExtc64.dll [2017-06-08] (Smadsoft)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-10-21] (Intel Corporation)
ContextMenuHandlers6: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\SMADAV\SmadExtc64.dll [2017-06-08] (Smadsoft)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-07-02] (Alexander Roshal)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {052C68D3-73BD-4AF0-ACAA-89C957B24331} - System32\Tasks\AdobeGCInvoker-1.0-CA-PC-CA => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {0EB17036-21CD-4C16-A87E-6DD17BEFB473} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-12] (Google Inc.)
Task: {115D43CF-7560-4739-99BF-F933DC0AEF5C} - System32\Tasks\Yahoo! Powered merar => C:\Windows\system32\wscript.exe "C:\ProgramData\{C29307F0-48D1-8D36-CE17-1374545598BA}\cefi.txt" "68747470733a2f2f71616a6f6c6f732e636f6d" "//B" "//E:jscript" "--IsErIk" <==== ATTENTION
Task: {40B25CD6-FB29-47A6-A9F2-613BFCF9818B} - System32\Tasks\NYAN => C:\Users\CA\AppData\Roaming\LiveUpdate351.exe [2018-05-04] (Mozilla) <==== ATTENTION
Task: {41D67A66-8405-45B4-A0E4-48A485343748} - System32\Tasks\synhelper\{24242D0D-60B7-4DD4-A8E5-5AE8A242D0A3} => C:\Users\CA\AppData\Roaming\24242D0D-60B7-4DD4-A8E5-5AE8A242D0A3\synhelper.exe [2013-05-01] () <==== ATTENTION
Task: {431785B4-245B-462D-86C4-7F7C26C93A73} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23] (Adobe Systems Incorporated)
Task: {643484F7-DB26-42D1-BE9C-289863CA3E62} - System32\Tasks\Opera scheduled Autoupdate 4086469641 => C:\Windows\system32\cmd.exe /c start "" "C:\Users\CA\AppData\Roaming\Microsoft\Windows\jdwujvsd\rgedwfhs.exe"
Task: {6728962E-5750-42DA-A864-C5FBCE52610F} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2018-04-13] (Smadsoft)
Task: {73C9AB02-494C-45D3-B9E0-81E9F4B6E101} - System32\Tasks\{F39EDABB-AACB-4A4B-BDE4-6762DDA0F5FE} => C:\Windows\system32\pcalua.exe -a "C:\Users\CA\Downloads\flp\sylenth\Sylenth 2.2 (electronic-dancemusic.blogspot.com)\Lennar.Digital.Sylenth1.VSTi.v2.2.1.1.x86\sylenth Setup.exe" -d "C:\Users\CA\Downloads\flp\sylenth\Sylenth 2.2 (electronic-dancemusic.blogspot.com)\Lennar.Digital.Sylenth1.VSTi.v2.2.1.1.x86"
Task: {87AFE983-DCF3-4126-ACDC-06C826AF71E1} - System32\Tasks\{76EB22B3-42EE-954A-BCC7-8F1A207C1E60} => C:\Windows\SysWOW64\sEUEjYqgX.exe [1601-01-03] (Microsoft Corporation)
Task: {AA5803C1-5C69-4EFD-8FE5-4664E8AD2812} - System32\Tasks\Opera scheduled Autoupdate 2796787680 => C:\Windows\system32\cmd.exe /c start "" "C:\Users\CA\AppData\Roaming\Microsoft\Windows\drrheeta\rgedwfhs.exe"
Task: {AE6C21B8-DA93-4322-874C-E038FBF293E0} - System32\Tasks\FastDataX Task => C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE
Task: {AEF841DD-0AC7-4534-97D2-985F918714BE} - System32\Tasks\{B267D8DF-F4B3-A902-4DF9-4EE4AD85936F} => C:\Windows\SysWOW64\yceIw.exe [1601-01-03] (Microsoft Corporation)
Task: {B92BCEB6-5B29-46D4-B756-DAC9C1C96959} - System32\Tasks\{0C43A0F7-BFA3-4C05-A71C-5E92F57D7EDD} => C:\Windows\system32\pcalua.exe -a "D:\DRIVER_HP2560\DRIVER HP2560P\sp58782_WIFI.exe" -d "D:\DRIVER_HP2560\DRIVER HP2560P"
Task: {CCCDD8DD-CEEC-40DF-B5D1-7FD74A488E35} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_CA => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [2015-01-13] (H.D.S. Hungary)
Task: {D0527ECA-732F-4D98-83A3-58D0AFB5C553} - System32\Tasks\svchost => c:\windows\resources\svchost.exe <==== ATTENTION
Task: {D8335A58-9322-40FD-BFFC-8C0F3ECA430E} - System32\Tasks\WinHostStartForMachine => C:\ProgramData\winhost.exe <==== ATTENTION
Task: {D946EF1D-D228-4658-B66F-47C8D114AE80} - System32\Tasks\{11206277-16F1-440F-A25F-D78E6B836550} => C:\Windows\system32\pcalua.exe -a D:\deff\app\PremierePro2018.12.0.0.224.kuyhAa.Me\AUTORUN.exe -d D:\deff\app\PremierePro2018.12.0.0.224.kuyhAa.Me
Task: {FEC1B4E2-14D1-43AE-9410-40E298511E8A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-12] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Yahoo! Powered merar.job => C:\Windows\system32\wscript.ex C:\ProgramData\{C29307F0-48D1-8D36-CE17-1374545598BA}\cefi.txt <==== ATTENTION
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2010-01-30 02:40 - 2010-01-30 02:40 - 004254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-03-24 21:38 - 2010-03-24 21:38 - 008794976 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2011-10-21 08:49 - 2011-10-21 08:49 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-09-30 07:54 - 2018-04-03 08:23 - 003723264 ____S () C:\WINDOWS\mssecsvc.exe
2018-03-31 16:53 - 2018-03-31 16:53 - 004357496 _____ () C:\Users\CA\AppData\Local\LINE\bin\current\ampkit_windows.dll
2018-03-31 16:53 - 2018-03-31 16:53 - 015233896 _____ () C:\Users\CA\AppData\Local\LINE\bin\current\opengl32sw.dll
2010-01-30 02:41 - 2010-01-30 02:41 - 004254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-03-24 21:17 - 2010-03-24 21:17 - 008794464 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 09:34 - 2018-03-19 18:14 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\CA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.100.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{B332EE7A-D91F-42C8-B214-F26AA5996190}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{6BCEF1B4-4633-400D-85A2-0A3FB671036C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{55B02266-3B72-4439-905E-571513BB9029}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LINE.exe
FirewallRules: [{6FACACDF-3A3E-4FF9-BDAC-7053AEDEAA22}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LINE.exe
FirewallRules: [{54CC28C0-6A51-4F96-821B-5157312C562F}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LineUpdater.exe
FirewallRules: [{F7FA6E46-7DA0-467E-9D93-47E2B698A9C0}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LineUpdater.exe
FirewallRules: [{86745F39-458E-4A59-A83F-434F7F87AFF7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{59D98BEA-84D3-4362-940A-8E412CC1CC4F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C4E421BF-0C9B-4C4A-A98D-4814CBD2E57F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{942F21D1-09B4-45D4-9DDA-0112CD17CDEE}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{382A9B6B-CBFC-462A-95B2-19FC6168B704}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{088809A8-27CA-4D4C-A38C-6F400EF0F0FC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{16C0D42E-EBFF-4289-B5C9-1385BF360253}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{A4FF59FB-223F-4AD6-AD3B-D423C1B6B4F4}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{69FFD830-DFA1-4EF5-A065-27BDA2FCB8B6}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{042B349F-FCAE-43B7-9FD6-5EE935106D9A}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{4E2C1110-89C9-48A5-896C-D6B4A2FA4C33}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [UDP Query User{7CD1FC60-5F78-4A27-982C-0A9CA0D8FF82}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [TCP Query User{A231AFE8-D3FC-4B07-A4BA-BF0B70518882}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{545250C8-B5F3-4F8A-96C4-138C1FA2CDAC}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{435F7CD6-5127-404B-98D1-B871B24F4B9B}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{2874833A-09D5-48A4-B13A-7A2AF475FD94}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{529D04E0-0657-47CF-89AE-69814452E814}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [UDP Query User{18F7CAC7-580E-4F19-9746-753EFD473859}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [TCP Query User{1E3C7CAC-12A4-43F9-A553-8CE7983BF206}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{5C182B7F-BBEE-4837-85DA-7EDB524ECD17}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [TCP Query User{C0CEE23F-69AE-4EAF-8726-52A6F727E332}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{E1DCC975-C45F-4304-92CE-0377417059B4}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [{43B65750-73DB-42C5-A09B-11BBA4673443}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{515B43DE-75B5-40D4-A124-4700D36DB28D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{554ECFB7-013E-47F8-81DA-DE9A052E3CCA}] => (Allow) D:\SteamLibrary\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{851ABA89-1488-4187-A99D-C88976D2D1E4}] => (Allow) D:\SteamLibrary\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{2E393DD9-8C28-461D-93DB-C632F8E61F3B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{115F75D8-206E-4D28-B254-2CBEFA72A568}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{A90AC2D8-D0C9-4102-B354-7F75D14B8CCE}D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe
FirewallRules: [UDP Query User{EE2A5292-3D2D-4FA0-8C44-FE7001C6579E}D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe
FirewallRules: [{35C730ED-5F06-47B1-9FCF-F99432C3FB3E}] => (Allow) C:\Program Files (x86)\Nox\bin\Nox.exe
FirewallRules: [{DF88A946-8269-4910-B119-B43225AF6652}] => (Allow) C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe
FirewallRules: [{6C9CB2D2-85FF-4F5B-8D4C-F402A10ADDB0}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{D437EA37-2BD0-45E5-B436-D68DB62F9681}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{9382B4D7-6400-4CA9-AC5A-13C1F2C32DDA}] => (Allow) C:\Users\CA\AppData\Roaming\uTorrent Web\utweb.exe
FirewallRules: [{64D1A898-0511-4ACC-AB76-8FA331AF545E}] => (Allow) C:\Users\CA\AppData\Roaming\uTorrent Web\utweb.exe
FirewallRules: [{91411C3F-2863-404A-8871-11B6363F617D}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{5F8EEECE-3CE2-4DF8-8E39-6852530978AB}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{E801C2AC-61E6-4955-B36E-E36081DAA6C5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMux.exe] => Enabled:SwiApiMux
 
==================== Restore Points =========================
 
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
Name: Base System Device
Description: Base System Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/04/2018 07:39:33 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
 
 
Operation:
   Instantiating VSS server
 
Error: (05/04/2018 07:39:33 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]
 
 
Operation:
   Instantiating VSS server
 
Error: (05/04/2018 07:28:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: desktop35.exe, version: 1.0.0.11, time stamp: 0x5a928139
Faulting module name: desktop35.exe, version: 1.0.0.11, time stamp: 0x5a928139
Exception code: 0x40000015
Fault offset: 0x0001454c
Faulting process id: 0xb98
Faulting application start time: 0x01d3e3a3271327b9
Faulting application path: C:\ProgramData\yahoochrome_D\desktop35.exe
Faulting module path: C:\ProgramData\yahoochrome_D\desktop35.exe
Report Id: ad0ee6fc-4f96-11e8-a3a1-e4115b455bed
 
Error: (05/04/2018 07:26:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: hkcmd.exe, version: 8.15.10.2559, time stamp: 0x4ea1a4aa
Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c8f9
Exception code: 0xc0000005
Fault offset: 0x0000000000020a4a
Faulting process id: 0x8b8
Faulting application start time: 0x01d3e3a31abf8fdd
Faulting application path: C:\Windows\System32\hkcmd.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 682e0e5e-4f96-11e8-a3a1-20107a20cb6e
 
Error: (05/04/2018 07:26:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (05/04/2018 07:20:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: desktop35.exe, version: 1.0.0.11, time stamp: 0x5a928139
Faulting module name: desktop35.exe, version: 1.0.0.11, time stamp: 0x5a928139
Exception code: 0x40000015
Fault offset: 0x0001454c
Faulting process id: 0x8b4
Faulting application start time: 0x01d3e3a2050979e8
Faulting application path: C:\ProgramData\yahoochrome_D\desktop35.exe
Faulting module path: C:\ProgramData\yahoochrome_D\desktop35.exe
Report Id: 8aedd624-4f95-11e8-84d6-e4115b455bed
 
Error: (05/04/2018 07:19:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: hkcmd.exe, version: 8.15.10.2559, time stamp: 0x4ea1a4aa
Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c8f9
Exception code: 0xc0000005
Fault offset: 0x0000000000020a4a
Faulting process id: 0xff0
Faulting application start time: 0x01d3e3a212530850
Faulting application path: C:\Windows\System32\hkcmd.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 5a01ed4a-4f95-11e8-84d6-e4115b455bed
 
Error: (05/04/2018 07:18:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
 
System errors:
=============
Error: (05/04/2018 07:28:41 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The saiyi technology limit service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (05/04/2018 07:26:03 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:25:06 PM on ‎5/‎4/‎2018 was unexpected.
 
Error: (05/04/2018 07:20:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The saiyi technology limit service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (05/04/2018 07:19:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
 
Error: (05/04/2018 07:18:17 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:11:55 PM on ‎5/‎4/‎2018 was unexpected.
 
Error: (05/04/2018 03:30:49 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The saiyi technology limit service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (05/04/2018 03:30:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
 
Error: (05/04/2018 10:53:30 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The saiyi technology limit service terminated unexpectedly.  It has done this 1 time(s).
 
 
CodeIntegrity:
===================================
 
Date: 2018-05-04 19:37:15.523
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-04 19:32:18.262
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-04 19:31:25.782
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-04 19:26:19.212
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-04 19:26:15.952
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-04 19:23:35.799
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-04 19:23:13.943
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-04 19:23:02.582
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2520M CPU @ 2.50GHz
Percentage of memory in use: 55%
Total physical RAM: 4006.36 MB
Available physical RAM: 1791.27 MB
Total Virtual: 8010.91 MB
Available Virtual: 5282.43 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:82.76 GB) (Free:13.86 GB) NTFS
Drive d: (MASTER) (Fixed) (Total:150.02 GB) (Free:111.36 GB) NTFS
 
\\?\Volume{e8d55db0-6838-11e7-8925-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 9A196842)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=82.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=150 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#5 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,683 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:51 PM

Posted 04 May 2018 - 07:46 AM

Looks like you are infected with Kovter. Booting in Safe Mode and running a scan with Malwarebytes should get rid of the infection :) Do that and provide me the Malwarebytes log afterwards.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#6 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 04 May 2018 - 08:59 AM

hello aura this is the 2nd result. i really sorry i've made a mistake, i didn't get the 1st report because after quarantine i restart my laptop then i didn't get the report, i've check in history there is empty. i just remember the 1st scan has so many threat maybe about 200...

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 5/4/18
Scan Time: 8:37 PM
Log File: 4a7d9fb5-4fa0-11e8-929a-e4115b455bed.json
Administrator: Yes
 
-Software Information-
Version: 3.4.5.2467
Components Version: 1.0.342
Update Package Version: 1.0.4984
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: CA-PC\CA
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 277835
Threats Detected: 2
Threats Quarantined: 2
Time Elapsed: 4 min, 52 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 2
Trojan.MalPack, C:\USERS\CA\APPDATA\LOCAL\TEMP\B85D.TMP.EXE, Delete-on-Reboot, [3813], [518570],1.0.4984
Trojan.MalPack, C:\USERS\CA\APPDATA\LOCAL\TEMP\69084, Delete-on-Reboot, [3813], [518570],1.0.4984
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)


#7 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,683 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:51 PM

Posted 04 May 2018 - 12:06 PM

All good, no worries :) Now, can you run a new scan with FRST (under a normal boot) and provide me a fresh set of logs? I'll make sure that Kovter is indeed gone.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#8 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 05 May 2018 - 07:53 AM

here the result 

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03.05.2018
Ran by CA (administrator) on CA-PC (05-05-2018 19:40:36)
Running from C:\Users\CA\Desktop
Loaded Profiles: CA (Available Profiles: CA)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\BCMWLTRY.EXE
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Smadsoft) C:\Program Files (x86)\SMADAV\SMΔRTP.exe
(H.D.S. Hungary) C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Acronis) C:\Users\CA\AppData\Roaming\LiveUpdate358.exe
(SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AdobeGCClient.exe
(Smadav Software) C:\Program Files (x86)\SMADAV\SmadavProtect64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Farbar) C:\Users\CA\Desktop\FRostenglish.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [7177728 2018-05-04] (Broadcom Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-24] (IDT, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [315880 2018-01-05] (Adobe Systems, Incorporated)
HKLM-x32\...\Run: [UCam_Menu] => "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [319360 2012-03-14] (Hewlett-Packard Company)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SMΔRT-Protection] => C:\Program Files (x86)\Smadav\SMΔRTP.exe [1903696 2018-04-13] (Smadsoft)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Run: [LiveUpdate358.exe] => C:\Users\CA\AppData\Roaming\LiveUpdate358.exe .. [12449152 2018-05-04] (Acronis)
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [1] Mshta.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [2] powershell.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [3] bitsadmin.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\MountPoints2: {eedca44a-896c-11e7-9fa9-e4115b455bed} - F:\WIN\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2018-02-04]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS)
Startup: C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\drrheeta.lnk [2018-05-05]
Startup: C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jdwujvsd.lnk [2018-05-05]
GroupPolicy: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{E423BEC1-2BF0-4D9C-8DE2-EAD0EF615D99}: [DhcpNameServer] 192.168.100.1
 
Internet Explorer:
==================
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2017-08-21] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2017-08-21] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2017-08-21] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2017-08-21] (Oracle Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 40jr9pt9.default
FF ProfilePath: C:\Users\CA\AppData\Roaming\Mozilla\Firefox\Profiles\40jr9pt9.default [2018-05-04]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2018-01-13]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\CA\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\CA\AppData\Roaming\IDM\idmmzcc5 [2018-01-31] [Legacy] [not signed]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]
FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2017-08-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2017-08-21] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2017-08-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2017-08-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-29] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default [2018-05-05]
CHR Extension: (Docs) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-20]
CHR Extension: (YouTube) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-20]
CHR Extension: (Space & Patterns) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkdmjaboldkklmcomdamidplnfpnmmmd [2017-10-26]
CHR Extension: (Stay secure with CyberGhost VPN Free Proxy) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffbkglfijbcbgblgflchnbphjdllaogb [2018-05-04]
CHR Extension: (Google Docs Offline) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-20]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-04-26]
CHR Extension: (WhatsChrome Extension) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbhfoiaobflocffnclkigpkeoagheimn [2018-05-04]
CHR Extension: (VidPlay) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mniicboehgimlhnmhkijibenmangpaea [2018-04-04]
CHR Extension: (Internet Download Manager (IDM)) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpnamocnciebhgnpcnmoodclmocfcdig [2017-11-13]
CHR Extension: (IDM Integration Module) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-03-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-20]
CHR Extension: (Chrome Media Router) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-29]
CHR Profile: C:\Users\CA\AppData\Local\Google\Chrome\User Data\System Profile [2018-04-09]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) [File not signed]
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1547200 2017-11-01] ()
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-09-19] (Hi-Rez Studios) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [365440 2012-03-14] (Hewlett-Packard Company)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
S3 mracsvc; C:\Windows\System32\mracsvc.exe [8010968 2018-02-27] (LLC Mail.Ru)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-11-15] (Nero AG)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-24] (IDT, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [5862400 2018-05-04] (Broadcom Corporation) [File not signed]
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 blackberryncm; C:\Windows\System32\DRIVERS\blackberryncm6_AMD64.sys [36360 2016-04-06] (BlackBerry)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [76192 2018-03-19] ()
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193768 2018-05-04] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [112864 2018-05-05] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [44768 2018-05-05] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-05-04] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [93816 2018-05-05] (Malwarebytes)
S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [7238880 2018-02-27] (LLC Mail.Ru)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [46408 2017-06-02] (SteelSeries ApS)
R3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [54560 2018-01-10] (SteelSeries ApS)
R3 swivsp; C:\Windows\System32\DRIVERS\swivspnt.sys [23552 2007-03-26] (Sierra Wireless Inc.)
S3 SWNC8UA3; C:\Windows\System32\DRIVERS\swnc8ua3.sys [283136 2010-01-28] (Sierra Wireless Inc.)
S3 SWUMXA3; C:\Windows\System32\DRIVERS\swumxa3.sys [206848 2009-12-08] (Sierra Wireless Inc.)
S3 SzCCID; C:\Windows\System32\DRIVERS\SzCCID.sys [39936 2013-09-24] (Generic)
S3 CLMirrorDriver; system32\DRIVERS\CLMirrorDriver.sys [X]
S3 clwvd7; system32\DRIVERS\clwvd7.sys [X]
S3 swmsflt; system32\DRIVERS\swmsflt.sys [X]
S3 SWUMX20; system32\DRIVERS\swumx20.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-05-05 19:40 - 2018-05-05 19:42 - 000003454 _____ C:\Windows\System32\Tasks\NYAN
2018-05-05 09:41 - 2018-01-13 15:14 - 000000000 ____D C:\Users\CA\Desktop\[AWBatch] Saiki Kusuo no Ψ-nan (720p)
2018-05-04 20:50 - 2018-05-04 20:50 - 012449152 ____H (Acronis) C:\Users\CA\AppData\Roaming\LiveUpdate358.exe
2018-05-04 20:43 - 2018-05-04 20:43 - 000001366 _____ C:\Users\CA\Desktop\report.txt
2018-05-04 20:29 - 2018-05-05 19:39 - 000112864 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-05-04 20:29 - 2018-05-05 19:39 - 000093816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-05-04 20:13 - 2018-05-05 19:39 - 000044768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-05-04 20:13 - 2018-05-04 20:32 - 000193768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-05-04 20:13 - 2018-05-04 20:13 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-05-04 20:13 - 2018-05-04 20:13 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-05-04 20:13 - 2018-05-04 20:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-05-04 20:13 - 2018-05-04 20:13 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-05-04 20:13 - 2018-05-04 20:13 - 000000000 ____D C:\Program Files\Malwarebytes
2018-05-04 20:13 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-05-04 20:11 - 2018-05-04 20:11 - 071942408 _____ (Malwarebytes ) C:\Users\CA\Desktop\mb3-setup-1878.1878-3.4.5.2467.exe
2018-05-04 20:09 - 2018-05-04 20:32 - 000289238 _____ C:\Windows\ntbtlog.txt
2018-05-04 19:32 - 2018-05-05 19:41 - 000017575 _____ C:\Users\CA\Desktop\FRST.txt
2018-05-04 19:32 - 2018-05-04 13:13 - 002405376 _____ (Farbar) C:\Users\CA\Desktop\FRostenglish.exe
2018-05-04 19:31 - 2018-05-04 19:31 - 001897081 _____ C:\Users\CA\Desktop\FRST64.zip
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ C:\Users\CA\AppData\Roaming\HXTORXRDQ3PMD7TPT
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ C:\Users\CA\AppData\Roaming\HOWTODECRYPTFILES.html
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ C:\Users\CA\AppData\HOWTODECRYPTFILES.html
2018-05-04 19:18 - 2018-05-05 19:38 - 000000000 ___HD C:\Users\Public\Documents\AdobeGC
2018-05-04 17:57 - 2018-05-04 18:26 - 2435590635 _____ C:\Users\CA\Desktop\[AWBatch] Saiki Kusuo no Ψ-nan (720p).rar
2018-05-04 17:38 - 2018-04-27 00:43 - 000000000 ____D C:\Users\CA\Desktop\Smadav11.9.2.pro.kuyhAa.Me
2018-05-04 17:25 - 2018-05-04 17:25 - 000003138 _____ C:\Windows\System32\Tasks\smadav
2018-05-04 17:25 - 2018-05-04 17:25 - 000001032 _____ C:\Users\Public\Desktop\SMADΔV.lnk
2018-05-04 17:25 - 2018-05-04 17:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus
2018-05-04 17:23 - 2018-05-04 17:24 - 001631020 _____ C:\Users\CA\Desktop\Smadav11.9.2.pro.kuyhAa.Me.rar
2018-05-04 16:25 - 2018-05-04 16:25 - 000000000 _____ C:\Windows\system32\ZeoMount.dat
2018-05-04 16:17 - 2018-05-04 16:17 - 000000000 ____D C:\Windows\System32\Tasks\HardDiskSentinel
2018-05-04 15:51 - 2018-05-04 15:51 - 000000000 ____D C:\Users\CA\AppData\Local\MegaBackup Corp
2018-05-04 15:46 - 2018-05-04 15:46 - 000000000 ____D C:\Users\CA\AppData\Local\IsolatedStorage
2018-05-04 15:44 - 2018-05-04 15:44 - 000000000 ____D C:\ProgramData\MegaBackup Corp
2018-05-04 13:16 - 2018-05-05 19:40 - 000000000 ____D C:\FRST
2018-05-04 12:46 - 2018-05-04 12:46 - 000003156 _____ C:\Windows\System32\Tasks\{0C43A0F7-BFA3-4C05-A71C-5E92F57D7EDD}
2018-05-04 12:45 - 2018-05-04 12:43 - 003952640 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2018-05-04 12:45 - 2018-05-04 12:43 - 003617792 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2018-05-04 12:44 - 2018-05-04 12:43 - 000006656 _____ C:\Windows\system32\bcmwlrc.dll
2018-05-03 20:38 - 2018-05-03 20:38 - 000000931 _____ C:\Users\Public\Desktop\Balsamiq Mockups 3.lnk
2018-05-03 20:38 - 2018-05-03 20:38 - 000000000 ____D C:\Program Files (x86)\Balsamiq Mockups 3
2018-05-03 20:16 - 2018-05-04 19:19 - 000000000 _RSHD C:\Users\CA\AppData\Roaming\DE25E01C-A553-C0F0-1FF2-A9F4C346ED68
2018-05-03 20:16 - 2018-05-03 20:16 - 000003614 _____ C:\Windows\System32\Tasks\{76EB22B3-42EE-954A-BCC7-8F1A207C1E60}
2018-05-03 20:16 - 2018-05-03 20:16 - 000003408 _____ C:\Windows\System32\Tasks\{B267D8DF-F4B3-A902-4DF9-4EE4AD85936F}
2018-05-03 20:16 - 2018-05-03 20:16 - 000000003 _____ C:\Users\CA\AppData\Local\wbem.ini
2018-05-03 20:15 - 2018-05-04 20:26 - 000000000 ____D C:\Windows\SysWOW64\qijtttrd
2018-05-03 20:15 - 2018-05-04 19:22 - 000003568 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 2796787680
2018-05-03 20:15 - 2018-05-04 19:21 - 000003568 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 4086469641
2018-05-03 20:15 - 2018-05-03 20:17 - 004173824 _____ (ChemTable Software) C:\Users\CA\AppData\Roaming\setup.exe
2018-04-29 09:17 - 2018-04-29 09:17 - 000040516 _____ C:\Users\CA\Downloads\augmented reality.pptx
2018-04-21 05:27 - 2018-04-23 08:14 - 000024545 _____ C:\Users\CA\Desktop\bagas.zip
2018-04-10 17:50 - 2018-05-04 19:24 - 000000000 ____D C:\Users\CA\AppData\Local\Discord
2018-04-10 17:50 - 2018-04-10 23:49 - 000000000 ____D C:\Users\CA\AppData\Roaming\discord
2018-04-10 17:50 - 2018-04-10 17:50 - 000000000 ____D C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2018-04-10 17:50 - 2018-04-10 17:50 - 000000000 ____D C:\Users\CA\AppData\Local\SquirrelTemp
2018-04-06 15:37 - 2018-04-06 15:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
2018-04-06 15:37 - 2018-04-06 15:37 - 000000000 ____D C:\Program Files (x86)\WinPcap
2018-04-06 15:09 - 2018-04-06 15:09 - 001677310 _____ C:\Users\CA\Desktop\SOSIO FINAL.zip
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-05-05 19:39 - 2017-12-14 09:14 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-05-05 19:38 - 2009-07-14 12:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-05-05 15:02 - 2017-09-23 17:00 - 000000000 ____D C:\Program Files (x86)\Steam
2018-05-05 09:40 - 2009-07-14 11:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-05-05 09:40 - 2009-07-14 11:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-05-04 23:06 - 2017-12-04 16:35 - 000000000 ____D C:\Users\CA\AppData\Roaming\Spotify
2018-05-04 20:33 - 2017-07-14 00:04 - 000000000 ____D C:\Users\CA\AppData\LocalLow\Mozilla
2018-05-04 19:32 - 2009-07-14 12:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2018-05-04 19:32 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\inf
2018-05-04 19:24 - 2017-11-13 19:53 - 000000000 ____D C:\Users\CA\AppData\Local\Battle.net
2018-05-04 19:23 - 2017-08-29 11:58 - 000000148 _____ C:\Users\CA\AppData\default.pls.3336996838.ransomed@india.com
2018-05-04 18:32 - 2018-01-31 10:13 - 000000000 ____D C:\Users\CA\AppData\Roaming\DMCache
2018-05-04 17:38 - 2017-07-14 00:04 - 000000000 __SHD C:\[Smad-Cage]
2018-05-04 17:25 - 2017-07-14 00:04 - 000000000 ____D C:\Users\CA\AppData\Roaming\Smadav
2018-05-04 17:25 - 2017-07-14 00:04 - 000000000 ____D C:\Program Files (x86)\SMADAV
2018-05-04 16:25 - 2017-07-21 23:22 - 000000000 ____D C:\ProgramData\Package Cache
2018-05-04 16:17 - 2017-07-14 00:30 - 000000000 ____D C:\Users\CA\AppData\Roaming\Hard Disk Sentinel
2018-05-04 16:17 - 2017-07-14 00:30 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2018-05-04 15:18 - 2018-01-31 10:13 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2018-05-04 15:18 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\Resources
2018-05-04 14:37 - 2017-12-04 16:39 - 000000000 ____D C:\Users\CA\AppData\Local\Spotify
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\lv-LV
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\lt-LT
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\et-EE
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\Help
2018-05-04 12:46 - 2017-07-13 19:13 - 000000000 ____D C:\SWSetup
2018-05-04 12:43 - 2017-07-13 19:44 - 001058816 _____ (Broadcom Corporation) C:\Windows\system32\BCMLogon.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 007930368 _____ (Broadcom Corporation) C:\Windows\system32\BCMWLCPL.CPL
2018-05-04 12:43 - 2017-07-13 19:43 - 004961800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcredist_x64.exe
2018-05-04 12:43 - 2017-07-13 19:43 - 004698112 _____ (Broadcom Corporation) C:\Windows\system32\bcmttls.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 003161088 _____ (Microsoft Corporation) C:\Windows\system32\vcredist_x64.exe
2018-05-04 12:43 - 2017-07-13 19:43 - 000073728 _____ (Broadcom Corporation) C:\Windows\system32\wltrynt.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 000022632 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcm42rly.sys
2018-05-04 12:43 - 2017-07-13 19:43 - 000000446 _____ C:\Windows\SysWOW64\vcredist_x64.bat
2018-05-04 12:43 - 2017-07-13 19:43 - 000000445 _____ C:\Windows\system32\vcredist_x64.bat
2018-05-04 10:51 - 2017-12-13 19:30 - 000000000 ____D C:\Windows\Minidump
2018-05-04 10:51 - 2017-11-05 12:57 - 000000440 __RSH C:\ProgramData\ntuser.pol
2018-05-04 10:50 - 2017-12-13 19:30 - 326937963 _____ C:\Windows\MEMORY.DMP
2018-05-04 10:01 - 2017-09-06 23:48 - 000007596 _____ C:\Users\CA\AppData\Local\Resmon.ResmonCfg
2018-05-04 09:59 - 2017-07-13 19:10 - 000001443 _____ C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-05-03 22:28 - 2009-07-14 12:08 - 000032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-05-03 20:38 - 2017-11-03 15:54 - 000000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Balsamiq Mockups 3.lnk
2018-05-02 22:56 - 2018-01-31 10:13 - 000000000 ____D C:\Users\CA\AppData\Roaming\IDM
2018-05-02 00:21 - 2018-03-19 00:21 - 000000262 _____ C:\Users\CA\AppData\Roaming\WB.CFG
2018-04-28 18:06 - 2017-11-12 13:59 - 000002184 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-04-28 00:21 - 2018-03-28 00:21 - 000000000 ____D C:\Users\CA\AppData\Local\{0B733D2F-2FDB-5197-4243-747F662B88E7}
2018-04-10 17:42 - 2017-12-14 09:14 - 000774004 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-04-08 11:08 - 2017-07-14 00:00 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-04-07 21:55 - 2017-10-01 16:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
 
==================== Files in the root of some directories =======
 
2017-08-29 21:11 - 2017-08-29 21:11 - 000000000 _____ () C:\Users\CA\GD1_D_8282.js
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ () C:\Users\CA\AppData\Roaming\HOWTODECRYPTFILES.html
2018-05-04 19:23 - 2018-05-04 19:23 - 000003804 _____ () C:\Users\CA\AppData\Roaming\HXTORXRDQ3PMD7TPT
2018-05-04 20:50 - 2018-05-04 20:50 - 012449152 ____H (Acronis) C:\Users\CA\AppData\Roaming\LiveUpdate358.exe
2018-05-03 20:15 - 2018-05-03 20:17 - 004173824 _____ (ChemTable Software) C:\Users\CA\AppData\Roaming\setup.exe
2018-03-19 00:21 - 2018-05-02 00:21 - 000000262 _____ () C:\Users\CA\AppData\Roaming\WB.CFG
2017-09-06 23:48 - 2018-05-04 10:01 - 000007596 _____ () C:\Users\CA\AppData\Local\Resmon.ResmonCfg
2018-05-03 20:16 - 2018-05-03 20:16 - 000000003 _____ () C:\Users\CA\AppData\Local\wbem.ini
 
Some files in TEMP:
====================
2018-05-04 15:11 - 2018-05-04 15:11 - 000301056 _____ (89898) C:\Users\CA\AppData\Local\Temp\2293.tmp.exe
2018-05-04 19:01 - 2018-05-04 19:03 - 000000000 _____ () C:\Users\CA\AppData\Local\Temp\231D.tmp.exe
2018-05-03 20:17 - 2018-05-03 20:17 - 000335872 _____ () C:\Users\CA\AppData\Local\Temp\AudioInformer.exe
2018-05-03 20:16 - 2018-05-03 20:16 - 000307200 _____ (2345.com) C:\Users\CA\AppData\Local\Temp\CE6F.tmp.exe
2018-05-04 15:44 - 2018-05-04 15:44 - 001353168 _____ (MegaBackup Corp) C:\Users\CA\AppData\Local\Temp\Ins12A6.tmp.exe
2018-05-04 19:01 - 2018-05-04 19:01 - 003695104 _____ (Mozilla) C:\Users\CA\AppData\Local\Temp\iZqesnKyidTFQBoEwzkW.exe
2018-05-03 20:17 - 2018-05-03 20:17 - 001177088 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\CA\AppData\Local\Temp\libeay32.dll
2018-05-04 19:23 - 2018-05-04 19:23 - 000625152 _____ () C:\Users\CA\AppData\Local\Temp\reset.exe
2018-05-03 20:17 - 2018-05-03 20:17 - 000270336 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\CA\AppData\Local\Temp\ssleay32.dll
2018-05-04 20:50 - 2018-05-04 20:50 - 012449152 _____ (Acronis) C:\Users\CA\AppData\Local\Temp\tmpEE46.tmp.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-04-28 00:52
 
==================== End of FRST.txt ============================

Edited by pandapeter, 05 May 2018 - 07:59 AM.


#9 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 05 May 2018 - 08:00 AM

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03.05.2018
Ran by CA (05-05-2018 19:42:24)
Running from C:\Users\CA\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2017-07-13 12:09:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3044604572-4114186790-410436043-500 - Administrator - Disabled)
CA (S-1-5-21-3044604572-4114186790-410436043-1000 - Administrator - Enabled) => C:\Users\CA
Guest (S-1-5-21-3044604572-4114186790-410436043-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe After Effects CC 2018 (HKLM-x32\...\AEFT_15_0_0) (Version: 15.0.0 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.1.53.7 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2018 (HKLM-x32\...\PPRO_12_0_0) (Version: 12.0.0 - Adobe Systems Incorporated)
Adobe Reader XI  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.20) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated)
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\{F24F876B-7D71-4BD6-88E9-614D3BB84238}) (Version: 1.7.38.0 - Alcor Micro Corp.) Hidden
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\SZCCID) (Version: 1.7.38.0 - Alcor Micro Corp.)
Amazon Redshift ODBC Driver 64-bit (HKLM\...\{788C401A-726B-4CE7-8BC2-89FD7967A6ED}) (Version: 1.2.7 - Amazon Corporate LLC)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.11 Beta1 - Michael Tippach)
Balsamiq Mockups 3 (HKLM-x32\...\{DD3D206D-0E2A-13E1-C0CE-DC751907F1D4}) (Version: 3.5.15 - Balsamiq SRL) Hidden
Balsamiq Mockups 3 (HKLM-x32\...\BalsamiqMockups3.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1) (Version: 3.5.15 - Balsamiq SRL)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.100.82.143 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.100.82.143 - Broadcom Corporation)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{51DD370C-6690-424E-9674-5F14468B323F}) (Version: 15.0.0.487 - Corel Corporation)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\{51DD370C-6690-424E-9674-5F14468B323F}) (Version: 15.0.487 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Capture (HKLM-x32\...\{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Common (HKLM-x32\...\{CA3861BA-1D96-4D66-B577-318E1602C4F3}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Connect (HKLM-x32\...\{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Custom Data (HKLM-x32\...\{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Draw (HKLM-x32\...\{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - EN (HKLM-x32\...\{E34C6AA4-AE8E-4677-912A-92FC2E039DD9}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Filters (HKLM-x32\...\{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - FontNav (HKLM-x32\...\{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - IPM (HKLM-x32\...\{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (HKLM-x32\...\{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Photozoom Plugin (HKLM-x32\...\{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Redist (HKLM-x32\...\{59123CCF-FED2-46FF-9293-D1DC80042219}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Setup Files (HKLM-x32\...\{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VBA (HKLM-x32\...\{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VideoBrowser (HKLM-x32\...\{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VSTA (HKLM-x32\...\{260ED378-2B8C-4831-ADAE-D0712D119AC5}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (HKLM\...\{66C10F29-31F0-4A9B-B2CF-465F488AE086}) (Version: 15.0.487 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - WT (HKLM-x32\...\{9244E956-5939-4B88-930C-0699D4AB2B95}) (Version: 15.0 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 (HKLM-x32\...\{B399C91E-96F2-4265-9884-1C9A10E9FCF4}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW® Graphics Suite X5 (HKLM-x32\...\_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.0.0.486 - Corel Corporation)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1002 - CyberLink Corp.)
Deckadance 2 (HKLM-x32\...\Deckadance 2) (Version: 2.0 - Image-Line)
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.11 - Bloodshed Software)
Discord (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Discord) (Version: 0.0.300 - Discord Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FBS Trader 4 (HKLM-x32\...\FBS Trader 4) (Version: 4.00 - MetaQuotes Software Corp.)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
GlassFish Server Open Source Edition 4.1.1 (HKLM\...\nbi-glassfish-mod-4.1.1.0.1) (Version:  - )
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.1.49.5139 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.139 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Hard Disk Sentinel PRO (HKLM-x32\...\Hard Disk Sentinel_is1) (Version:  - HDS)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HP Battery Check (HKLM-x32\...\HP Battery Check) (Version: 4.3.2.2 - Hewlett-Packard)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.5.9.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)
IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version:  - Image-Line)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel® Network Connections Drivers (HKLM\...\PROSet) (Version: 15.4 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 101 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.17 - Oracle Corporation)
Java SE Development Kit 8 Update 101 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180101}) (Version: 8.0.1010.13 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LINE (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\LINE) (Version: 5.7.0.1660 - LINE Corporation)
Malwarebytes version 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{E534493E-80D2-4E37-8020-3ECAC55D9DB5}) (Version: 10.53.6000.34 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{49e969a1-2990-464d-92b5-25f6f34573c6}) (Version: 12.0.40664.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{d2c8df0e-f15d-4426-9e51-f13f329f9cb4}) (Version: 12.0.40664.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25711 (HKLM-x32\...\{1bffbfc8-3cfb-4b1d-aca9-64f1c7c9f811}) (Version: 14.12.25711.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25711 (HKLM-x32\...\{f381fb0a-b38e-44ab-bca5-7f651c8c6b93}) (Version: 14.12.25711.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Movavi Video Editor 14 Plus (HKLM-x32\...\Movavi Video Editor 14 Plus) (Version: 14.1.1 - Movavi)
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0.1 - Mozilla)
MPC-HC 1.7.13 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.13 - MPC-HC Team)
MySQL Connector/ODBC 5.3 (HKLM\...\{EB0CFCBD-B0C8-4F0F-ACF4-8B674A19B459}) (Version: 5.3.8 - Oracle Corporation)
Nero 8 Essentials (HKLM-x32\...\{65A54DC3-5FF6-4C75-906E-3EA1A3B71033}) (Version: 8.10.376 - Nero AG)
NetBeans IDE 8.2 (HKLM\...\nbi-nb-base-8.2.0.0.201609300101) (Version: 8.2 - NetBeans.org)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
psqlODBC_x64 (HKLM\...\{3D4F4C5A-28C7-441D-81DC-2AA2C1A61B6A}) (Version: 09.06.0201 - PostgreSQL Global Development Group)
R for Windows 3.4.0 (HKLM\...\R for Windows 3.4.0_is1) (Version: 3.4.0 - R Core Team)
Ruby 2.4.2-2-x64 (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\RubyInstaller-2.4-x64-mingw32_is1) (Version: 2.4.2-2 - RubyInstaller Team)
SMADAV version 11.9.0 (HKLM-x32\...\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1) (Version: 11.9.0 - Smadsoft)
Spotify (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Spotify) (Version: 1.0.77.338.g758ebd78 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteelSeries Engine 3.11.11 (HKLM\...\SteelSeries Engine 3) (Version: 3.11.11 - SteelSeries ApS)
Sublime Text Build 3143 (HKLM\...\Sublime Text 3_is1) (Version:  - Sublime HQ Pty Ltd)
Tableau 10.4 (10400.17.1103.1137) (HKLM\...\{8D3E15C5-DA5C-4655-BF04-AB1AEB27F389}) (Version: 10.4.782 - Tableau Software) Hidden
Tableau 10.4 (10400.17.1103.1137) (HKLM-x32\...\{9894f7c2-d617-453e-bbc1-46c65b10da39}) (Version: 10.4.782 - Tableau Software)
uTorrent Web (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\utweb) (Version: 0.13.0 - BitTorrent, Inc.)
VCRedistSetup (HKLM-x32\...\{3921A67A-5AB1-4E48-9444-C71814CF3027}) (Version: 1.0.0 - Nero AG) Hidden
VLC media player 1.1.10 (HKLM-x32\...\VLC media player) (Version: 1.1.10 - VideoLAN)
Windows Driver Package - Microsoft (xusb21) XnaComposite  (08/13/2009 2.1.0.1349) (HKLM\...\0AEBEF6F936CFE16E003F7E141631FAB754D9816) (Version: 08/13/2009 2.1.0.1349 - Microsoft)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.50 beta 5 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.5 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2017-06-23] (Tonec Inc.)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll [2007-11-05] (Nero AG)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers3: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\SMADAV\SmadExtc64.dll [2017-06-08] (Smadsoft)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-10-21] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\SMADAV\SmadExtc64.dll [2017-06-08] (Smadsoft)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-07-02] (Alexander Roshal)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {052C68D3-73BD-4AF0-ACAA-89C957B24331} - System32\Tasks\AdobeGCInvoker-1.0-CA-PC-CA => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {0EB17036-21CD-4C16-A87E-6DD17BEFB473} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-12] (Google Inc.)
Task: {3EEBCC92-8E20-4770-B6FC-05DFB500915D} - System32\Tasks\NYAN => C:\Users\CA\AppData\Roaming\LiveUpdate358.exe [2018-05-04] (Acronis) <==== ATTENTION
Task: {41D67A66-8405-45B4-A0E4-48A485343748} - System32\Tasks\synhelper\{24242D0D-60B7-4DD4-A8E5-5AE8A242D0A3} => C:\Users\CA\AppData\Roaming\24242D~1\synhelper.exe <==== ATTENTION
Task: {431785B4-245B-462D-86C4-7F7C26C93A73} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23] (Adobe Systems Incorporated)
Task: {643484F7-DB26-42D1-BE9C-289863CA3E62} - System32\Tasks\Opera scheduled Autoupdate 4086469641 => C:\Windows\system32\cmd.exe /c start "" "C:\Users\CA\AppData\Roaming\Microsoft\Windows\jdwujvsd\rgedwfhs.exe"
Task: {6728962E-5750-42DA-A864-C5FBCE52610F} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2018-04-13] (Smadsoft)
Task: {73C9AB02-494C-45D3-B9E0-81E9F4B6E101} - System32\Tasks\{F39EDABB-AACB-4A4B-BDE4-6762DDA0F5FE} => C:\Windows\system32\pcalua.exe -a "C:\Users\CA\Downloads\flp\sylenth\Sylenth 2.2 (electronic-dancemusic.blogspot.com)\Lennar.Digital.Sylenth1.VSTi.v2.2.1.1.x86\sylenth Setup.exe" -d "C:\Users\CA\Downloads\flp\sylenth\Sylenth 2.2 (electronic-dancemusic.blogspot.com)\Lennar.Digital.Sylenth1.VSTi.v2.2.1.1.x86"
Task: {87AFE983-DCF3-4126-ACDC-06C826AF71E1} - System32\Tasks\{76EB22B3-42EE-954A-BCC7-8F1A207C1E60} => C:\Windows\SysWOW64\sEUEjYqgX.exe [1601-01-03] (Microsoft Corporation)
Task: {AA5803C1-5C69-4EFD-8FE5-4664E8AD2812} - System32\Tasks\Opera scheduled Autoupdate 2796787680 => C:\Windows\system32\cmd.exe /c start "" "C:\Users\CA\AppData\Roaming\Microsoft\Windows\drrheeta\rgedwfhs.exe"
Task: {AEF841DD-0AC7-4534-97D2-985F918714BE} - System32\Tasks\{B267D8DF-F4B3-A902-4DF9-4EE4AD85936F} => C:\Windows\SysWOW64\yceIw.exe [1601-01-03] (Microsoft Corporation)
Task: {B92BCEB6-5B29-46D4-B756-DAC9C1C96959} - System32\Tasks\{0C43A0F7-BFA3-4C05-A71C-5E92F57D7EDD} => C:\Windows\system32\pcalua.exe -a "D:\DRIVER_HP2560\DRIVER HP2560P\sp58782_WIFI.exe" -d "D:\DRIVER_HP2560\DRIVER HP2560P"
Task: {CCCDD8DD-CEEC-40DF-B5D1-7FD74A488E35} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_CA => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [2015-01-13] (H.D.S. Hungary)
Task: {D946EF1D-D228-4658-B66F-47C8D114AE80} - System32\Tasks\{11206277-16F1-440F-A25F-D78E6B836550} => C:\Windows\system32\pcalua.exe -a D:\deff\app\PremierePro2018.12.0.0.224.kuyhAa.Me\AUTORUN.exe -d D:\deff\app\PremierePro2018.12.0.0.224.kuyhAa.Me
Task: {FEC1B4E2-14D1-43AE-9410-40E298511E8A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-12] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2010-01-30 02:40 - 2010-01-30 02:40 - 004254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-03-24 21:38 - 2010-03-24 21:38 - 008794976 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2011-10-21 08:49 - 2011-10-21 08:49 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2018-05-04 20:13 - 2018-03-27 13:47 - 002492704 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2018-05-04 20:13 - 2018-03-12 15:09 - 002300192 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 09:34 - 2018-03-19 18:14 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\CA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.100.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{B332EE7A-D91F-42C8-B214-F26AA5996190}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{6BCEF1B4-4633-400D-85A2-0A3FB671036C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{55B02266-3B72-4439-905E-571513BB9029}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LINE.exe
FirewallRules: [{6FACACDF-3A3E-4FF9-BDAC-7053AEDEAA22}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LINE.exe
FirewallRules: [{54CC28C0-6A51-4F96-821B-5157312C562F}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LineUpdater.exe
FirewallRules: [{F7FA6E46-7DA0-467E-9D93-47E2B698A9C0}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LineUpdater.exe
FirewallRules: [{86745F39-458E-4A59-A83F-434F7F87AFF7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{59D98BEA-84D3-4362-940A-8E412CC1CC4F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C4E421BF-0C9B-4C4A-A98D-4814CBD2E57F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{942F21D1-09B4-45D4-9DDA-0112CD17CDEE}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{382A9B6B-CBFC-462A-95B2-19FC6168B704}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{088809A8-27CA-4D4C-A38C-6F400EF0F0FC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{16C0D42E-EBFF-4289-B5C9-1385BF360253}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{A4FF59FB-223F-4AD6-AD3B-D423C1B6B4F4}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{69FFD830-DFA1-4EF5-A065-27BDA2FCB8B6}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{042B349F-FCAE-43B7-9FD6-5EE935106D9A}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{4E2C1110-89C9-48A5-896C-D6B4A2FA4C33}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [UDP Query User{7CD1FC60-5F78-4A27-982C-0A9CA0D8FF82}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [TCP Query User{A231AFE8-D3FC-4B07-A4BA-BF0B70518882}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{545250C8-B5F3-4F8A-96C4-138C1FA2CDAC}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{435F7CD6-5127-404B-98D1-B871B24F4B9B}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{2874833A-09D5-48A4-B13A-7A2AF475FD94}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{529D04E0-0657-47CF-89AE-69814452E814}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [UDP Query User{18F7CAC7-580E-4F19-9746-753EFD473859}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [TCP Query User{1E3C7CAC-12A4-43F9-A553-8CE7983BF206}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{5C182B7F-BBEE-4837-85DA-7EDB524ECD17}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [TCP Query User{C0CEE23F-69AE-4EAF-8726-52A6F727E332}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{E1DCC975-C45F-4304-92CE-0377417059B4}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [{43B65750-73DB-42C5-A09B-11BBA4673443}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{515B43DE-75B5-40D4-A124-4700D36DB28D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{554ECFB7-013E-47F8-81DA-DE9A052E3CCA}] => (Allow) D:\SteamLibrary\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{851ABA89-1488-4187-A99D-C88976D2D1E4}] => (Allow) D:\SteamLibrary\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{2E393DD9-8C28-461D-93DB-C632F8E61F3B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{115F75D8-206E-4D28-B254-2CBEFA72A568}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{A90AC2D8-D0C9-4102-B354-7F75D14B8CCE}D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe
FirewallRules: [UDP Query User{EE2A5292-3D2D-4FA0-8C44-FE7001C6579E}D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe
FirewallRules: [{35C730ED-5F06-47B1-9FCF-F99432C3FB3E}] => (Allow) C:\Program Files (x86)\Nox\bin\Nox.exe
FirewallRules: [{DF88A946-8269-4910-B119-B43225AF6652}] => (Allow) C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe
FirewallRules: [{6C9CB2D2-85FF-4F5B-8D4C-F402A10ADDB0}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{D437EA37-2BD0-45E5-B436-D68DB62F9681}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{9382B4D7-6400-4CA9-AC5A-13C1F2C32DDA}] => (Allow) C:\Users\CA\AppData\Roaming\uTorrent Web\utweb.exe
FirewallRules: [{64D1A898-0511-4ACC-AB76-8FA331AF545E}] => (Allow) C:\Users\CA\AppData\Roaming\uTorrent Web\utweb.exe
FirewallRules: [{91411C3F-2863-404A-8871-11B6363F617D}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{5F8EEECE-3CE2-4DF8-8E39-6852530978AB}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{E801C2AC-61E6-4955-B36E-E36081DAA6C5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMux.exe] => Enabled:SwiApiMux
 
==================== Restore Points =========================
 
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
Name: Base System Device
Description: Base System Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/05/2018 07:48:57 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
 
 
Operation:
   Instantiating VSS server
 
Error: (05/05/2018 07:48:57 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]
 
 
Operation:
   Instantiating VSS server
 
Error: (05/05/2018 07:40:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: hkcmd.exe, version: 8.15.10.2559, time stamp: 0x4ea1a4aa
Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c8f9
Exception code: 0xc0000005
Fault offset: 0x0000000000020a4a
Faulting process id: 0x5e4
Faulting application start time: 0x01d3e46e0630ba53
Faulting application path: C:\Windows\System32\hkcmd.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 6fdd5e95-5061-11e8-a3bb-e4115b455bed
 
Error: (05/05/2018 07:39:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (05/05/2018 03:01:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program dota2.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 15f0
 
Start Time: 01d3e43f62f36757
 
Termination Time: 1763
 
Application Path: D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
 
Report Id: 8e80e276-503a-11e8-aba1-e4115b455bed
 
Error: (05/05/2018 09:39:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: hkcmd.exe, version: 8.15.10.2559, time stamp: 0x4ea1a4aa
Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c8f9
Exception code: 0xc0000005
Fault offset: 0x0000000000020a4a
Faulting process id: 0xfc0
Faulting application start time: 0x01d3e4198cce7a76
Faulting application path: C:\Windows\System32\hkcmd.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 7bbd361b-500d-11e8-aba1-e4115b455bed
 
Error: (05/05/2018 09:33:15 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (05/04/2018 11:08:19 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
 
 
Operation:
   Instantiating VSS server
 
 
System errors:
=============
Error: (05/05/2018 07:38:32 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 3:14:38 PM on ‎5/‎5/‎2018 was unexpected.
 
Error: (05/04/2018 08:41:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (05/04/2018 08:41:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (05/04/2018 08:41:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (05/04/2018 08:39:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (05/04/2018 08:39:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (05/04/2018 08:39:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (05/04/2018 08:34:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
 
CodeIntegrity:
===================================
 
Date: 2018-05-05 19:46:58.924
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-05 19:44:52.951
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-05 19:40:24.847
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-05 19:40:19.780
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-05 15:03:21.242
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAC64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-05 15:02:59.813
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-05 15:02:05.012
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-05 14:05:30.545
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAC64.dll because the set of per-page image hashes could not be found on the system.
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2520M CPU @ 2.50GHz
Percentage of memory in use: 60%
Total physical RAM: 4006.36 MB
Available physical RAM: 1588.68 MB
Total Virtual: 8010.91 MB
Available Virtual: 5288.05 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:82.76 GB) (Free:11.28 GB) NTFS
Drive d: (MASTER) (Fixed) (Total:150.02 GB) (Free:111.36 GB) NTFS
 
\\?\Volume{e8d55db0-6838-11e7-8925-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 9A196842)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=82.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=150 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#10 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,683 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:51 PM

Posted 06 May 2018 - 01:06 PM

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.
  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

Attached Files


unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#11 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 06 May 2018 - 09:59 PM

Fix result of Farbar Recovery Scan Tool (x64) Version: 06.05.2018 01
Ran by CA (07-05-2018 09:40:06) Run:1
Running from C:\Users\CA\Desktop
Loaded Profiles: CA &  (Available Profiles: CA)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
 
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Run: [LiveUpdate358.exe] => C:\Users\CA\AppData\Roaming\LiveUpdate358.exe .. [12449152 2018-05-04] (Acronis)
Startup: C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\drrheeta.lnk [2018-05-05]
Startup: C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jdwujvsd.lnk [2018-05-05]
GroupPolicy: Restriction <==== ATTENTION
 
S3 mracsvc; C:\Windows\System32\mracsvc.exe [8010968 2018-02-27] (LLC Mail.Ru)
S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [7238880 2018-02-27] (LLC Mail.Ru)
 
Task: {3EEBCC92-8E20-4770-B6FC-05DFB500915D} - System32\Tasks\NYAN => C:\Users\CA\AppData\Roaming\LiveUpdate358.exe [2018-05-04] (Acronis) <==== ATTENTION
Task: {41D67A66-8405-45B4-A0E4-48A485343748} - System32\Tasks\synhelper\{24242D0D-60B7-4DD4-A8E5-5AE8A242D0A3} => C:\Users\CA\AppData\Roaming\24242D~1\synhelper.exe <==== ATTENTION
Task: {643484F7-DB26-42D1-BE9C-289863CA3E62} - System32\Tasks\Opera scheduled Autoupdate 4086469641 => C:\Windows\system32\cmd.exe /c start "" "C:\Users\CA\AppData\Roaming\Microsoft\Windows\jdwujvsd\rgedwfhs.exe"
Task: {73C9AB02-494C-45D3-B9E0-81E9F4B6E101} - System32\Tasks\{F39EDABB-AACB-4A4B-BDE4-6762DDA0F5FE} => C:\Windows\system32\pcalua.exe -a "C:\Users\CA\Downloads\flp\sylenth\Sylenth 2.2 (electronic-dancemusic.blogspot.com)\Lennar.Digital.Sylenth1.VSTi.v2.2.1.1.x86\sylenth Setup.exe" -d "C:\Users\CA\Downloads\flp\sylenth\Sylenth 2.2 (electronic-dancemusic.blogspot.com)\Lennar.Digital.Sylenth1.VSTi.v2.2.1.1.x86"
Task: {87AFE983-DCF3-4126-ACDC-06C826AF71E1} - System32\Tasks\{76EB22B3-42EE-954A-BCC7-8F1A207C1E60} => C:\Windows\SysWOW64\sEUEjYqgX.exe [1601-01-03] (Microsoft Corporation)
Task: {AA5803C1-5C69-4EFD-8FE5-4664E8AD2812} - System32\Tasks\Opera scheduled Autoupdate 2796787680 => C:\Windows\system32\cmd.exe /c start "" "C:\Users\CA\AppData\Roaming\Microsoft\Windows\drrheeta\rgedwfhs.exe"
Task: {AEF841DD-0AC7-4534-97D2-985F918714BE} - System32\Tasks\{B267D8DF-F4B3-A902-4DF9-4EE4AD85936F} => C:\Windows\SysWOW64\yceIw.exe [1601-01-03] (Microsoft Corporation)
Task: {B92BCEB6-5B29-46D4-B756-DAC9C1C96959} - System32\Tasks\{0C43A0F7-BFA3-4C05-A71C-5E92F57D7EDD} => C:\Windows\system32\pcalua.exe -a "D:\DRIVER_HP2560\DRIVER HP2560P\sp58782_WIFI.exe" -d "D:\DRIVER_HP2560\DRIVER HP2560P"
Task: {D946EF1D-D228-4658-B66F-47C8D114AE80} - System32\Tasks\{11206277-16F1-440F-A25F-D78E6B836550} => C:\Windows\system32\pcalua.exe -a D:\deff\app\PremierePro2018.12.0.0.224.kuyhAa.Me\AUTORUN.exe -d D:\deff\app\PremierePro2018.12.0.0.224.kuyhAa.Me
 
C:\ProgramData\ntuser.pol
C:\Users\CA\GD1_D_8282.js
C:\Users\CA\AppData\HOWTODECRYPTFILES.html
C:\Users\CA\AppData\default.pls.3336996838.ransomed@india.com
C:\Users\CA\AppData\Local\{0B733D2F-2FDB-5197-4243-747F662B88E7}
C:\Users\CA\AppData\Local\Temp\2293.tmp.exe
C:\Users\CA\AppData\Local\Temp\231D.tmp.exe
C:\Users\CA\AppData\Local\Temp\AudioInformer.exe
C:\Users\CA\AppData\Local\Temp\CE6F.tmp.exe
C:\Users\CA\AppData\Local\Temp\Ins12A6.tmp.exe
C:\Users\CA\AppData\Local\Temp\iZqesnKyidTFQBoEwzkW.exe
C:\Users\CA\AppData\Local\Temp\libeay32.dll
C:\Users\CA\AppData\Local\Temp\reset.exe
C:\Users\CA\AppData\Local\Temp\ssleay32.dll
C:\Users\CA\AppData\Local\Temp\tmpEE46.tmp.exe
C:\Users\CA\AppData\Roaming\24242D~1
C:\Users\CA\AppData\Roaming\Microsoft\Windows\jdwujvsd6
C:\Users\CA\AppData\Roaming\Microsoft\Windows\drrheeta
C:\Users\CA\AppData\Roaming\LiveUpdate358.exe
C:\Users\CA\AppData\Roaming\HXTORXRDQ3PMD7TPT
C:\Users\CA\AppData\Roaming\HOWTODECRYPTFILES.html
C:\Users\CA\AppData\Roaming\DE25E01C-A553-C0F0-1FF2-A9F4C346ED68
C:\Users\CA\AppData\Roaming\setup.exe
C:\Users\CA\AppData\Local\wbem.ini
C:\Windows\System32\mracsvc.exe
C:\Windows\System32\drivers\mracdrv.sys
C:\Windows\SysWOW64\qijtttrd
C:\Windows\SysWOW64\sEUEjYqgX.exe
C:\Windows\SysWOW64\yceIw.exe
 
EmptyTemp:
*****************
 
Processes closed successfully.
Error: (0) Failed to create a restore point.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKU\S-1-5-21-3044604572-4114186790-410436043-1000\Software\Microsoft\Windows\CurrentVersion\Run\\LiveUpdate358.exe" => removed successfully
C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\drrheeta.lnk => moved successfully
C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jdwujvsd.lnk => moved successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
"HKLM\System\CurrentControlSet\Services\mracsvc" => removed successfully
mracsvc => service removed successfully
"HKLM\System\CurrentControlSet\Services\mracdrv" => removed successfully
mracdrv => service removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3EEBCC92-8E20-4770-B6FC-05DFB500915D} => could not remove. Access Denied.
C:\Windows\System32\Tasks\NYAN => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NYAN" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41D67A66-8405-45B4-A0E4-48A485343748}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41D67A66-8405-45B4-A0E4-48A485343748}" => removed successfully
C:\Windows\System32\Tasks\synhelper\{24242D0D-60B7-4DD4-A8E5-5AE8A242D0A3} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\synhelper\{24242D0D-60B7-4DD4-A8E5-5AE8A242D0A3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{643484F7-DB26-42D1-BE9C-289863CA3E62}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{643484F7-DB26-42D1-BE9C-289863CA3E62}" => removed successfully
C:\Windows\System32\Tasks\Opera scheduled Autoupdate 4086469641 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 4086469641" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{73C9AB02-494C-45D3-B9E0-81E9F4B6E101}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73C9AB02-494C-45D3-B9E0-81E9F4B6E101}" => removed successfully
C:\Windows\System32\Tasks\{F39EDABB-AACB-4A4B-BDE4-6762DDA0F5FE} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F39EDABB-AACB-4A4B-BDE4-6762DDA0F5FE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87AFE983-DCF3-4126-ACDC-06C826AF71E1}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87AFE983-DCF3-4126-ACDC-06C826AF71E1}" => removed successfully
C:\Windows\System32\Tasks\{76EB22B3-42EE-954A-BCC7-8F1A207C1E60} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{76EB22B3-42EE-954A-BCC7-8F1A207C1E60}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AA5803C1-5C69-4EFD-8FE5-4664E8AD2812}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AA5803C1-5C69-4EFD-8FE5-4664E8AD2812}" => removed successfully
C:\Windows\System32\Tasks\Opera scheduled Autoupdate 2796787680 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 2796787680" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AEF841DD-0AC7-4534-97D2-985F918714BE}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AEF841DD-0AC7-4534-97D2-985F918714BE}" => removed successfully
C:\Windows\System32\Tasks\{B267D8DF-F4B3-A902-4DF9-4EE4AD85936F} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B267D8DF-F4B3-A902-4DF9-4EE4AD85936F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B92BCEB6-5B29-46D4-B756-DAC9C1C96959}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B92BCEB6-5B29-46D4-B756-DAC9C1C96959}" => removed successfully
C:\Windows\System32\Tasks\{0C43A0F7-BFA3-4C05-A71C-5E92F57D7EDD} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0C43A0F7-BFA3-4C05-A71C-5E92F57D7EDD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D946EF1D-D228-4658-B66F-47C8D114AE80}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D946EF1D-D228-4658-B66F-47C8D114AE80}" => removed successfully
C:\Windows\System32\Tasks\{11206277-16F1-440F-A25F-D78E6B836550} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{11206277-16F1-440F-A25F-D78E6B836550}" => removed successfully
C:\ProgramData\ntuser.pol => moved successfully
C:\Users\CA\GD1_D_8282.js => moved successfully
C:\Users\CA\AppData\HOWTODECRYPTFILES.html => moved successfully
C:\Users\CA\AppData\default.pls.3336996838.ransomed@india.com => moved successfully
C:\Users\CA\AppData\Local\{0B733D2F-2FDB-5197-4243-747F662B88E7} => moved successfully
C:\Users\CA\AppData\Local\Temp\2293.tmp.exe => moved successfully
C:\Users\CA\AppData\Local\Temp\231D.tmp.exe => moved successfully
C:\Users\CA\AppData\Local\Temp\AudioInformer.exe => moved successfully
C:\Users\CA\AppData\Local\Temp\CE6F.tmp.exe => moved successfully
C:\Users\CA\AppData\Local\Temp\Ins12A6.tmp.exe => moved successfully
C:\Users\CA\AppData\Local\Temp\iZqesnKyidTFQBoEwzkW.exe => moved successfully
C:\Users\CA\AppData\Local\Temp\libeay32.dll => moved successfully
C:\Users\CA\AppData\Local\Temp\reset.exe => moved successfully
C:\Users\CA\AppData\Local\Temp\ssleay32.dll => moved successfully
C:\Users\CA\AppData\Local\Temp\tmpEE46.tmp.exe => moved successfully
"C:\Users\CA\AppData\Roaming\24242D~1" => not found
"C:\Users\CA\AppData\Roaming\Microsoft\Windows\jdwujvsd6" => not found
C:\Users\CA\AppData\Roaming\Microsoft\Windows\drrheeta => moved successfully
C:\Users\CA\AppData\Roaming\LiveUpdate358.exe => moved successfully
C:\Users\CA\AppData\Roaming\HXTORXRDQ3PMD7TPT => moved successfully
C:\Users\CA\AppData\Roaming\HOWTODECRYPTFILES.html => moved successfully
C:\Users\CA\AppData\Roaming\DE25E01C-A553-C0F0-1FF2-A9F4C346ED68 => moved successfully
C:\Users\CA\AppData\Roaming\setup.exe => moved successfully
C:\Users\CA\AppData\Local\wbem.ini => moved successfully
C:\Windows\System32\mracsvc.exe => moved successfully
C:\Windows\System32\drivers\mracdrv.sys => moved successfully
C:\Windows\SysWOW64\qijtttrd => moved successfully
C:\Windows\SysWOW64\sEUEjYqgX.exe => moved successfully
C:\Windows\SysWOW64\yceIw.exe => moved successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 39230394 B
Java, Flash, Steam htmlcache => 22367689 B
Windows/system/drivers => 532737572 B
Edge => 0 B
Chrome => 484783328 B
Firefox => 312975103 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 100688 B
systemprofile32 => 82906 B
LocalService => 115860 B
NetworkService => 81182 B
CA => 3985088726 B
 
RecycleBin => 440519883 B
EmptyTemp: => 5.4 GB temporary data Removed.
 
================================
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 07-05-2018 09:52:16)
 
 
Result of scheduled keys to remove after reboot:
 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3EEBCC92-8E20-4770-B6FC-05DFB500915D} => could not remove. Access Denied.
 
==== End of Fixlog 09:52:16 ====


#12 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,683 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:51 PM

Posted 07 May 2018 - 05:46 AM

Good can you do me a favor? Can you .zip the C:\FRST\Quarantine folder and attach it here for me?

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#13 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,683 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:51 PM

Posted 10 May 2018 - 07:34 AM

Run a new scan with FRST and provide me a fresh set of logs. I'll see if Kovter is indeed gone.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#14 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 10 May 2018 - 10:58 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.05.2018
Ran by CA (administrator) on CA-PC (10-05-2018 22:24:47)
Running from C:\Users\CA\Desktop
Loaded Profiles: CA (Available Profiles: CA)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\BCMWLTRY.EXE
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Smadsoft) C:\Program Files (x86)\SMADAV\SMΔRTP.exe
(H.D.S. Hungary) C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Smadav Software) C:\Program Files (x86)\SMADAV\SmadavProtect64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Discord Inc.) C:\Users\CA\AppData\Local\Discord\app-0.0.301\Discord.exe
(Discord Inc.) C:\Users\CA\AppData\Local\Discord\app-0.0.301\Discord.exe
(Discord Inc.) C:\Users\CA\AppData\Local\Discord\app-0.0.301\Discord.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
() D:\deff\app\selfishnet+wincap\selfishnet\Selfishnet win 7 and above\Selfish.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Google) C:\Users\CA\AppData\Local\Google\Chrome\User Data\SwReporter\28.153.200\software_reporter_tool.exe
(Google) C:\Users\CA\AppData\Local\Google\Chrome\User Data\SwReporter\28.153.200\software_reporter_tool.exe
(Google) C:\Users\CA\AppData\Local\Google\Chrome\User Data\SwReporter\28.153.200\software_reporter_tool.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\CA\Desktop\FRostenglish.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [LiveUpdate358.exe] => "C:\Users\CA\AppData\Roaming\LiveUpdate358.exe" ..
HKLM-x32\...\Run: [UCam_Menu] => "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [319360 2012-03-14] (Hewlett-Packard Company)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SMΔRT-Protection] => C:\Program Files (x86)\Smadav\SMΔRTP.exe [1903696 2018-04-13] (Smadsoft)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4105328 2018-01-11] (Tonec Inc.)
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Run: [Spotify Web Helper] => C:\Users\CA\AppData\Roaming\Spotify\SpotifyWebHelper.exe [0 2018-05-07] ()
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer: [DisallowRun] 1
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [1] Mshta.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [2] powershell.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Policies\Explorer\DisallowRun: [3] bitsadmin.exe
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\MountPoints2: {eedca44a-896c-11e7-9fa9-e4115b455bed} - F:\WIN\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2018-02-04]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{E423BEC1-2BF0-4D9C-8DE2-EAD0EF615D99}: [DhcpNameServer] 192.168.100.1
 
Internet Explorer:
==================
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2017-08-21] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2017-08-21] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2017-08-21] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2017-08-21] (Oracle Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: 40jr9pt9.default
FF ProfilePath: C:\Users\CA\AppData\Roaming\Mozilla\Firefox\Profiles\40jr9pt9.default [2018-05-07]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2018-01-13]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\CA\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\CA\AppData\Roaming\IDM\idmmzcc5 [2018-01-31] [Legacy] [not signed]
FF HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]
FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2017-08-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2017-08-21] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2017-08-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2017-08-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-29] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR Profile: C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default [2018-05-10]
CHR Extension: (Docs) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-08-20]
CHR Extension: (YouTube) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-08-20]
CHR Extension: (Space & Patterns) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkdmjaboldkklmcomdamidplnfpnmmmd [2017-10-26]
CHR Extension: (Stay secure with CyberGhost VPN Free Proxy) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffbkglfijbcbgblgflchnbphjdllaogb [2018-05-04]
CHR Extension: (Google Docs Offline) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-08-20]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-04-26]
CHR Extension: (WhatsChrome Extension) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbhfoiaobflocffnclkigpkeoagheimn [2018-05-10]
CHR Extension: (VidPlay) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mniicboehgimlhnmhkijibenmangpaea [2018-04-04]
CHR Extension: (Internet Download Manager (IDM)) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpnamocnciebhgnpcnmoodclmocfcdig [2017-11-13]
CHR Extension: (IDM Integration Module) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-03-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-08-20]
CHR Extension: (Chrome Media Router) - C:\Users\CA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-29]
CHR Profile: C:\Users\CA\AppData\Local\Google\Chrome\User Data\System Profile [2018-05-07]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) [File not signed]
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1547200 2017-11-01] ()
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [779392 2018-05-05] (EasyAntiCheat Ltd)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2017-09-19] (Hi-Rez Studios) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [365440 2012-03-14] (Hewlett-Packard Company)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-11-15] (Nero AG)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-10-24] (IDT, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [5862400 2018-05-04] (Broadcom Corporation) [File not signed]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 blackberryncm; C:\Windows\System32\DRIVERS\blackberryncm6_AMD64.sys [36360 2016-04-06] (BlackBerry)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [76192 2018-03-19] ()
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193768 2018-05-04] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [112864 2018-05-10] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [44768 2018-05-10] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-05-04] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [93816 2018-05-10] (Malwarebytes)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 ssdevfactory; C:\Windows\System32\DRIVERS\ssdevfactory.sys [46408 2017-06-02] (SteelSeries ApS)
R3 sshid; C:\Windows\System32\DRIVERS\sshid.sys [54560 2018-01-10] (SteelSeries ApS)
R3 swivsp; C:\Windows\System32\DRIVERS\swivspnt.sys [23552 2007-03-26] (Sierra Wireless Inc.)
S3 SWNC8UA3; C:\Windows\System32\DRIVERS\swnc8ua3.sys [283136 2010-01-28] (Sierra Wireless Inc.)
S3 SWUMXA3; C:\Windows\System32\DRIVERS\swumxa3.sys [206848 2009-12-08] (Sierra Wireless Inc.)
S3 SzCCID; C:\Windows\System32\DRIVERS\SzCCID.sys [39936 2013-09-24] (Generic)
S3 CLMirrorDriver; system32\DRIVERS\CLMirrorDriver.sys [X]
S3 clwvd7; system32\DRIVERS\clwvd7.sys [X]
S3 swmsflt; system32\DRIVERS\swmsflt.sys [X]
S3 SWUMX20; system32\DRIVERS\swumx20.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-05-10 18:53 - 2018-05-10 18:55 - 000000000 ____D C:\Users\CA\AppData\Local\Discord
2018-05-08 22:45 - 2018-05-08 22:45 - 000000000 ____D C:\Users\CA\Desktop\PDK
2018-05-08 22:40 - 2018-05-08 22:40 - 000010828 _____ C:\Users\CA\Desktop\PDK.xlsx
2018-05-07 22:40 - 2018-05-07 22:40 - 000000000 ____D C:\Users\CA\Desktop\KubusTeksturCitra
2018-05-07 20:28 - 2018-05-07 20:28 - 048016549 _____ C:\Users\CA\Downloads\Quarantine (1).zip
2018-05-07 20:22 - 2018-05-07 20:22 - 048016549 _____ C:\Users\CA\Downloads\Quarantine.zip
2018-05-07 20:21 - 2018-05-07 20:21 - 048016549 ____C C:\Users\CA\Desktop\Quarantine.zip
2018-05-07 19:57 - 2018-05-10 21:50 - 000093816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-05-07 17:47 - 2018-05-07 17:47 - 000805747 _____ C:\Users\CA\Desktop\KubusTeksturCitra.zip
2018-05-07 09:51 - 2018-05-07 09:51 - 000000008 __RSH C:\ProgramData\ntuser.pol
2018-05-07 09:40 - 2018-05-07 09:52 - 000012592 _____ C:\Users\CA\Desktop\Fixlog.txt
2018-05-07 09:37 - 2018-05-10 22:20 - 000000000 ____D C:\Users\CA\Desktop\FRST-OlderVersion
2018-05-05 23:17 - 2018-05-05 23:17 - 000000000 ____D C:\Users\CA\AppData\Local\GameAnalytics
2018-05-05 23:17 - 2018-05-05 23:17 - 000000000 ____D C:\Users\CA\AppData\Local\Darwin
2018-05-05 23:16 - 2018-05-05 23:17 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2018-05-05 09:41 - 2018-01-13 15:14 - 000000000 ____D C:\Users\CA\Desktop\[AWBatch] Saiki Kusuo no Ψ-nan (720p)
2018-05-04 20:43 - 2018-05-04 20:43 - 000001366 _____ C:\Users\CA\Desktop\report.txt
2018-05-04 20:29 - 2018-05-10 17:38 - 000112864 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-05-04 20:13 - 2018-05-10 17:38 - 000044768 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-05-04 20:13 - 2018-05-04 20:32 - 000193768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-05-04 20:13 - 2018-05-04 20:13 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-05-04 20:13 - 2018-05-04 20:13 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-05-04 20:13 - 2018-05-04 20:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-05-04 20:13 - 2018-05-04 20:13 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-05-04 20:13 - 2018-05-04 20:13 - 000000000 ____D C:\Program Files\Malwarebytes
2018-05-04 20:13 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-05-04 20:11 - 2018-05-04 20:11 - 071942408 _____ (Malwarebytes ) C:\Users\CA\Desktop\mb3-setup-1878.1878-3.4.5.2467.exe
2018-05-04 20:09 - 2018-05-04 20:32 - 000289238 _____ C:\Windows\ntbtlog.txt
2018-05-04 19:32 - 2018-05-10 22:25 - 000018762 _____ C:\Users\CA\Desktop\FRST.txt
2018-05-04 19:32 - 2018-05-10 22:20 - 002404864 ____C (Farbar) C:\Users\CA\Desktop\FRostenglish.exe
2018-05-04 19:31 - 2018-05-04 19:31 - 001897081 _____ C:\Users\CA\Desktop\FRST64.zip
2018-05-04 17:57 - 2018-05-04 18:26 - 2435590635 _____ C:\Users\CA\Desktop\[AWBatch] Saiki Kusuo no Ψ-nan (720p).rar
2018-05-04 17:38 - 2018-04-27 00:43 - 000000000 ____D C:\Users\CA\Desktop\Smadav11.9.2.pro.kuyhAa.Me
2018-05-04 17:25 - 2018-05-04 17:25 - 000003138 _____ C:\Windows\System32\Tasks\smadav
2018-05-04 17:25 - 2018-05-04 17:25 - 000001032 _____ C:\Users\Public\Desktop\SMADΔV.lnk
2018-05-04 17:25 - 2018-05-04 17:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMADAV Antivirus
2018-05-04 17:23 - 2018-05-04 17:24 - 001631020 _____ C:\Users\CA\Desktop\Smadav11.9.2.pro.kuyhAa.Me.rar
2018-05-04 16:25 - 2018-05-04 16:25 - 000000000 _____ C:\Windows\system32\ZeoMount.dat
2018-05-04 16:17 - 2018-05-04 16:17 - 000000000 ____D C:\Windows\System32\Tasks\HardDiskSentinel
2018-05-04 15:51 - 2018-05-04 15:51 - 000000000 ____D C:\Users\CA\AppData\Local\MegaBackup Corp
2018-05-04 15:46 - 2018-05-04 15:46 - 000000000 ____D C:\Users\CA\AppData\Local\IsolatedStorage
2018-05-04 15:44 - 2018-05-04 15:44 - 000000000 ____D C:\ProgramData\MegaBackup Corp
2018-05-04 13:16 - 2018-05-10 22:24 - 000000000 ___DC C:\FRST
2018-05-04 12:45 - 2018-05-04 12:43 - 003952640 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll
2018-05-04 12:45 - 2018-05-04 12:43 - 003617792 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll
2018-05-04 12:44 - 2018-05-04 12:43 - 000006656 _____ C:\Windows\system32\bcmwlrc.dll
2018-05-03 20:38 - 2018-05-03 20:38 - 000000931 _____ C:\Users\Public\Desktop\Balsamiq Mockups 3.lnk
2018-05-03 20:38 - 2018-05-03 20:38 - 000000000 ____D C:\Program Files (x86)\Balsamiq Mockups 3
2018-04-29 09:17 - 2018-04-29 09:17 - 000040516 _____ C:\Users\CA\Desktop\augmented reality.pptx
2018-04-21 05:27 - 2018-04-23 08:14 - 000024545 _____ C:\Users\CA\Desktop\bagas.zip
2018-04-10 17:50 - 2018-05-10 18:55 - 000000000 ____D C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2018-04-10 17:50 - 2018-05-10 18:55 - 000000000 ____D C:\Users\CA\AppData\Roaming\discord
2018-04-10 17:50 - 2018-05-10 18:54 - 000000000 ____D C:\Users\CA\AppData\Local\SquirrelTemp
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-05-10 17:45 - 2009-07-14 11:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-05-10 17:45 - 2009-07-14 11:45 - 000021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-05-10 17:43 - 2017-09-23 17:00 - 000000000 ____D C:\Program Files (x86)\Steam
2018-05-10 17:38 - 2017-12-14 09:14 - 000000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2018-05-10 17:37 - 2009-07-14 12:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-05-10 15:52 - 2018-01-31 10:13 - 000000000 ____D C:\Users\CA\AppData\Roaming\DMCache
2018-05-08 23:44 - 2017-12-04 16:35 - 000000000 ____D C:\Users\CA\AppData\Roaming\Spotify
2018-05-08 01:12 - 2017-12-04 16:39 - 000000000 ____D C:\Users\CA\AppData\Local\Spotify
2018-05-07 09:40 - 2018-03-18 23:21 - 000000000 ____D C:\Windows\System32\Tasks\synhelper
2018-05-07 09:40 - 2017-07-13 19:09 - 000000000 ____D C:\Users\CA
2018-05-07 09:40 - 2009-07-14 10:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2018-05-07 09:40 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2018-05-04 20:33 - 2017-07-14 00:04 - 000000000 ____D C:\Users\CA\AppData\LocalLow\Mozilla
2018-05-04 19:32 - 2009-07-14 12:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2018-05-04 19:32 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\inf
2018-05-04 19:24 - 2017-11-13 19:53 - 000000000 ____D C:\Users\CA\AppData\Local\Battle.net
2018-05-04 17:38 - 2017-07-14 00:04 - 000000000 __SHD C:\[Smad-Cage]
2018-05-04 17:25 - 2017-07-14 00:04 - 000000000 ____D C:\Users\CA\AppData\Roaming\Smadav
2018-05-04 17:25 - 2017-07-14 00:04 - 000000000 ____D C:\Program Files (x86)\SMADAV
2018-05-04 16:25 - 2017-07-21 23:22 - 000000000 ____D C:\ProgramData\Package Cache
2018-05-04 16:17 - 2017-07-14 00:30 - 000000000 ____D C:\Users\CA\AppData\Roaming\Hard Disk Sentinel
2018-05-04 16:17 - 2017-07-14 00:30 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2018-05-04 15:18 - 2018-01-31 10:13 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2018-05-04 15:18 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\Resources
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\lv-LV
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\lt-LT
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\et-EE
2018-05-04 12:47 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\Help
2018-05-04 12:46 - 2017-07-13 19:13 - 000000000 ____D C:\SWSetup
2018-05-04 12:43 - 2017-07-13 19:44 - 001058816 _____ (Broadcom Corporation) C:\Windows\system32\BCMLogon.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 007930368 _____ (Broadcom Corporation) C:\Windows\system32\BCMWLCPL.CPL
2018-05-04 12:43 - 2017-07-13 19:43 - 004961800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcredist_x64.exe
2018-05-04 12:43 - 2017-07-13 19:43 - 004698112 _____ (Broadcom Corporation) C:\Windows\system32\bcmttls.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 003161088 _____ (Microsoft Corporation) C:\Windows\system32\vcredist_x64.exe
2018-05-04 12:43 - 2017-07-13 19:43 - 000073728 _____ (Broadcom Corporation) C:\Windows\system32\wltrynt.dll
2018-05-04 12:43 - 2017-07-13 19:43 - 000022632 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcm42rly.sys
2018-05-04 12:43 - 2017-07-13 19:43 - 000000446 _____ C:\Windows\SysWOW64\vcredist_x64.bat
2018-05-04 12:43 - 2017-07-13 19:43 - 000000445 _____ C:\Windows\system32\vcredist_x64.bat
2018-05-04 10:51 - 2017-12-13 19:30 - 000000000 ____D C:\Windows\Minidump
2018-05-04 10:50 - 2017-12-13 19:30 - 326937963 _____ C:\Windows\MEMORY.DMP
2018-05-04 10:01 - 2017-09-06 23:48 - 000007596 _____ C:\Users\CA\AppData\Local\Resmon.ResmonCfg
2018-05-04 09:59 - 2017-07-13 19:10 - 000001443 _____ C:\Users\CA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-05-03 22:28 - 2009-07-14 12:08 - 000032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-05-03 20:38 - 2017-11-03 15:54 - 000000943 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Balsamiq Mockups 3.lnk
2018-05-02 22:56 - 2018-01-31 10:13 - 000000000 ____D C:\Users\CA\AppData\Roaming\IDM
2018-05-02 00:21 - 2018-03-19 00:21 - 000000262 _____ C:\Users\CA\AppData\Roaming\WB.CFG
2018-04-28 18:06 - 2017-11-12 13:59 - 000002184 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-04-10 17:42 - 2017-12-14 09:14 - 000774004 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
 
==================== Files in the root of some directories =======
 
2018-03-19 00:21 - 2018-05-02 00:21 - 000000262 _____ () C:\Users\CA\AppData\Roaming\WB.CFG
2017-09-06 23:48 - 2018-05-04 10:01 - 000007596 _____ () C:\Users\CA\AppData\Local\Resmon.ResmonCfg
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-05-08 01:33
 
==================== End of FRST.txt ============================


#15 pandapeter

pandapeter
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 10 May 2018 - 11:00 AM

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.05.2018
Ran by CA (10-05-2018 22:25:23)
Running from C:\Users\CA\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2017-07-13 12:09:45)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3044604572-4114186790-410436043-500 - Administrator - Disabled)
CA (S-1-5-21-3044604572-4114186790-410436043-1000 - Administrator - Enabled) => C:\Users\CA
Guest (S-1-5-21-3044604572-4114186790-410436043-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe After Effects CC 2018 (HKLM-x32\...\AEFT_15_0_0) (Version: 15.0.0 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.1.53.7 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2018 (HKLM-x32\...\PPRO_12_0_0) (Version: 12.0.0 - Adobe Systems Incorporated)
Adobe Reader XI  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.20) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated)
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\{F24F876B-7D71-4BD6-88E9-614D3BB84238}) (Version: 1.7.38.0 - Alcor Micro Corp.) Hidden
Alcor Micro Smart Card Reader Driver (HKLM-x32\...\SZCCID) (Version: 1.7.38.0 - Alcor Micro Corp.)
Amazon Redshift ODBC Driver 64-bit (HKLM\...\{788C401A-726B-4CE7-8BC2-89FD7967A6ED}) (Version: 1.2.7 - Amazon Corporate LLC)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.11 Beta1 - Michael Tippach)
Balsamiq Mockups 3 (HKLM-x32\...\{DD3D206D-0E2A-13E1-C0CE-DC751907F1D4}) (Version: 3.5.15 - Balsamiq SRL) Hidden
Balsamiq Mockups 3 (HKLM-x32\...\BalsamiqMockups3.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1) (Version: 3.5.15 - Balsamiq SRL)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.100.82.143 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.100.82.143 - Broadcom Corporation)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{51DD370C-6690-424E-9674-5F14468B323F}) (Version: 15.0.0.487 - Corel Corporation)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\{51DD370C-6690-424E-9674-5F14468B323F}) (Version: 15.0.487 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Capture (HKLM-x32\...\{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Common (HKLM-x32\...\{CA3861BA-1D96-4D66-B577-318E1602C4F3}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Connect (HKLM-x32\...\{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Custom Data (HKLM-x32\...\{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Draw (HKLM-x32\...\{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - EN (HKLM-x32\...\{E34C6AA4-AE8E-4677-912A-92FC2E039DD9}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Filters (HKLM-x32\...\{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - FontNav (HKLM-x32\...\{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - IPM (HKLM-x32\...\{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (HKLM-x32\...\{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Photozoom Plugin (HKLM-x32\...\{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Redist (HKLM-x32\...\{59123CCF-FED2-46FF-9293-D1DC80042219}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Setup Files (HKLM-x32\...\{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VBA (HKLM-x32\...\{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VideoBrowser (HKLM-x32\...\{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - VSTA (HKLM-x32\...\{260ED378-2B8C-4831-ADAE-D0712D119AC5}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (HKLM\...\{66C10F29-31F0-4A9B-B2CF-465F488AE086}) (Version: 15.0.487 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 - WT (HKLM-x32\...\{9244E956-5939-4B88-930C-0699D4AB2B95}) (Version: 15.0 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X5 (HKLM-x32\...\{B399C91E-96F2-4265-9884-1C9A10E9FCF4}) (Version: 15.0 - Corel Corporation) Hidden
CorelDRAW® Graphics Suite X5 (HKLM-x32\...\_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}) (Version: 15.0.0.486 - Corel Corporation)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1002 - CyberLink Corp.)
Deckadance 2 (HKLM-x32\...\Deckadance 2) (Version: 2.0 - Image-Line)
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.11 - Bloodshed Software)
Discord (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Discord) (Version: 0.0.301 - Discord Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
FBS Trader 4 (HKLM-x32\...\FBS Trader 4) (Version: 4.00 - MetaQuotes Software Corp.)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
GlassFish Server Open Source Edition 4.1.1 (HKLM\...\nbi-glassfish-mod-4.1.1.0.1) (Version:  - )
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.1.49.5139 - Gretech Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.139 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Hard Disk Sentinel PRO (HKLM-x32\...\Hard Disk Sentinel_is1) (Version:  - HDS)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
HP Battery Check (HKLM-x32\...\HP Battery Check) (Version: 4.3.2.2 - Hewlett-Packard)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.5.9.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)
IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version:  - Image-Line)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel® Network Connections Drivers (HKLM\...\PROSet) (Version: 15.4 - Intel)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 101 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.17 - Oracle Corporation)
Java SE Development Kit 8 Update 101 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180101}) (Version: 8.0.1010.13 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LINE (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\LINE) (Version: 5.7.0.1660 - LINE Corporation)
Malwarebytes version 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{E534493E-80D2-4E37-8020-3ECAC55D9DB5}) (Version: 10.53.6000.34 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000 (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001 (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{49e969a1-2990-464d-92b5-25f6f34573c6}) (Version: 12.0.40664.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{d2c8df0e-f15d-4426-9e51-f13f329f9cb4}) (Version: 12.0.40664.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25711 (HKLM-x32\...\{1bffbfc8-3cfb-4b1d-aca9-64f1c7c9f811}) (Version: 14.12.25711.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25711 (HKLM-x32\...\{f381fb0a-b38e-44ab-bca5-7f651c8c6b93}) (Version: 14.12.25711.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Movavi Video Editor 14 Plus (HKLM-x32\...\Movavi Video Editor 14 Plus) (Version: 14.1.1 - Movavi)
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0.1 - Mozilla)
MPC-HC 1.7.13 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.13 - MPC-HC Team)
MySQL Connector/ODBC 5.3 (HKLM\...\{EB0CFCBD-B0C8-4F0F-ACF4-8B674A19B459}) (Version: 5.3.8 - Oracle Corporation)
Nero 8 Essentials (HKLM-x32\...\{65A54DC3-5FF6-4C75-906E-3EA1A3B71033}) (Version: 8.10.376 - Nero AG)
NetBeans IDE 8.2 (HKLM\...\nbi-nb-base-8.2.0.0.201609300101) (Version: 8.2 - NetBeans.org)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
psqlODBC_x64 (HKLM\...\{3D4F4C5A-28C7-441D-81DC-2AA2C1A61B6A}) (Version: 09.06.0201 - PostgreSQL Global Development Group)
R for Windows 3.4.0 (HKLM\...\R for Windows 3.4.0_is1) (Version: 3.4.0 - R Core Team)
Ruby 2.4.2-2-x64 (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\RubyInstaller-2.4-x64-mingw32_is1) (Version: 2.4.2-2 - RubyInstaller Team)
SMADAV version 11.9.0 (HKLM-x32\...\{8B9FA5FF-3E61-4658-B0DA-E6DDB46D6BAD}_is1) (Version: 11.9.0 - Smadsoft)
Spotify (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\Spotify) (Version: 1.0.77.338.g758ebd78 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteelSeries Engine 3.11.11 (HKLM\...\SteelSeries Engine 3) (Version: 3.11.11 - SteelSeries ApS)
Sublime Text Build 3143 (HKLM\...\Sublime Text 3_is1) (Version:  - Sublime HQ Pty Ltd)
Tableau 10.4 (10400.17.1103.1137) (HKLM\...\{8D3E15C5-DA5C-4655-BF04-AB1AEB27F389}) (Version: 10.4.782 - Tableau Software) Hidden
Tableau 10.4 (10400.17.1103.1137) (HKLM-x32\...\{9894f7c2-d617-453e-bbc1-46c65b10da39}) (Version: 10.4.782 - Tableau Software)
uTorrent Web (HKU\S-1-5-21-3044604572-4114186790-410436043-1000\...\utweb) (Version: 0.13.0 - BitTorrent, Inc.)
VCRedistSetup (HKLM-x32\...\{3921A67A-5AB1-4E48-9444-C71814CF3027}) (Version: 1.0.0 - Nero AG) Hidden
VLC media player 1.1.10 (HKLM-x32\...\VLC media player) (Version: 1.1.10 - VideoLAN)
Windows Driver Package - Microsoft (xusb21) XnaComposite  (08/13/2009 2.1.0.1349) (HKLM\...\0AEBEF6F936CFE16E003F7E141631FAB754D9816) (Version: 08/13/2009 2.1.0.1349 - Microsoft)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.50 beta 5 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.5 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3044604572-4114186790-410436043-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2017-06-23] (Tonec Inc.)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll [2007-11-05] (Nero AG)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers3: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\SMADAV\SmadExtc64.dll [2017-06-08] (Smadsoft)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-10-21] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [SmadExt] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => C:\Program Files (x86)\SMADAV\SmadExtc64.dll [2017-06-08] (Smadsoft)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-07-02] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-07-02] (Alexander Roshal)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {052C68D3-73BD-4AF0-ACAA-89C957B24331} - System32\Tasks\AdobeGCInvoker-1.0-CA-PC-CA => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {0EB17036-21CD-4C16-A87E-6DD17BEFB473} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-12] (Google Inc.)
Task: {431785B4-245B-462D-86C4-7F7C26C93A73} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23] (Adobe Systems Incorporated)
Task: {6728962E-5750-42DA-A864-C5FBCE52610F} - System32\Tasks\smadav => C:\Program Files (x86)\Smadav\SMΔRTP.exe [2018-04-13] (Smadsoft)
Task: {B5C10316-7811-4BAD-A2CE-C1BA4EEDDCDD} - \NYAN -> No File <==== ATTENTION
Task: {CCCDD8DD-CEEC-40DF-B5D1-7FD74A488E35} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_CA => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [2015-01-13] (H.D.S. Hungary)
Task: {FEC1B4E2-14D1-43AE-9410-40E298511E8A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-11-12] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2018-05-04 20:13 - 2018-03-12 15:09 - 002300192 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-05-04 20:13 - 2018-03-27 13:47 - 002492704 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2010-01-30 02:40 - 2010-01-30 02:40 - 004254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-03-24 21:38 - 2010-03-24 21:38 - 008794976 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2018-04-06 15:37 - 2007-05-30 17:42 - 000253952 ____N () D:\deff\app\selfishnet+wincap\selfishnet\Selfishnet win 7 and above\Selfish.exe
2018-04-28 18:05 - 2018-04-26 10:14 - 004443992 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.139\libglesv2.dll
2018-04-28 18:05 - 2018-04-26 10:14 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.139\libegl.dll
2010-01-30 02:41 - 2010-01-30 02:41 - 004254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-03-24 21:17 - 2010-03-24 21:17 - 008794464 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2017-09-23 17:04 - 2018-01-11 09:05 - 000784672 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2017-09-23 17:04 - 2016-09-01 08:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2017-09-23 17:04 - 2016-09-01 08:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2017-09-23 17:04 - 2016-09-01 08:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2017-09-23 17:04 - 2018-04-03 06:34 - 002631968 _____ () C:\Program Files (x86)\Steam\video.dll
2017-12-15 13:52 - 2017-12-20 08:43 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll
2017-12-15 13:52 - 2017-12-20 08:43 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll
2017-12-15 13:52 - 2017-12-20 08:43 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll
2017-12-15 13:52 - 2017-12-20 08:43 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll
2017-12-15 13:52 - 2017-12-20 08:43 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll
2017-09-23 17:04 - 2018-04-03 06:34 - 000977184 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2017-09-23 17:04 - 2016-07-05 05:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-09-23 17:04 - 2018-04-03 06:34 - 000162592 _____ () C:\Program Files (x86)\Steam\bin\audio.dll
2017-09-23 17:04 - 2014-04-09 11:25 - 000071680 _____ () C:\Program Files (x86)\Steam\bin\mssmp3.asi
2017-09-23 17:04 - 2014-04-09 11:25 - 000153088 _____ () C:\Program Files (x86)\Steam\bin\mssvoice.asi
2017-09-23 17:08 - 2017-09-07 09:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2017-09-23 17:08 - 2017-12-14 04:16 - 071471392 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-09-23 17:04 - 2015-09-25 06:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
2018-05-10 18:55 - 2018-04-30 23:01 - 001891672 _____ () C:\Users\CA\AppData\Local\Discord\app-0.0.301\ffmpeg.dll
2018-05-10 18:55 - 2018-04-30 23:01 - 001937752 _____ () C:\Users\CA\AppData\Local\Discord\app-0.0.301\libglesv2.dll
2018-05-10 18:55 - 2018-04-30 23:01 - 000095576 _____ () C:\Users\CA\AppData\Local\Discord\app-0.0.301\libegl.dll
2018-05-10 18:56 - 2018-05-10 18:56 - 009659736 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_voice\discord_voice.node
2018-05-10 18:56 - 2018-05-10 18:56 - 001530712 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_utils\discord_utils.node
2018-05-10 18:56 - 2018-05-10 18:56 - 000512856 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_erlpack\discord_erlpack.node
2018-05-10 18:56 - 2018-05-10 18:56 - 001578840 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_game_utils\discord_game_utils.node
2018-05-10 18:56 - 2018-05-10 18:56 - 001728344 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_overlay2\discord_overlay2.node
2018-05-10 18:56 - 2018-05-10 18:56 - 002722648 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_rpc\discord_rpc.node
2018-05-10 18:56 - 2018-05-10 18:56 - 001636696 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_hook\discord_hook.node
2018-05-10 18:57 - 2018-05-10 18:57 - 001249112 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_vigilante\discord_vigilante.node
2018-05-10 18:57 - 2018-05-10 18:57 - 002760536 _____ () \\?\C:\Users\CA\AppData\Roaming\discord\0.0.301\modules\discord_contact_import\discord_contact_import.node
2018-04-06 15:37 - 2007-06-02 20:08 - 000167936 ____N () D:\deff\app\selfishnet+wincap\selfishnet\Selfishnet win 7 and above\PcapNet.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 09:34 - 2018-03-19 18:14 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3044604572-4114186790-410436043-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\CA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.100.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: ) (ConsentPromptBehaviorUser: ) (EnableLUA: )
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{B332EE7A-D91F-42C8-B214-F26AA5996190}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{6BCEF1B4-4633-400D-85A2-0A3FB671036C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{55B02266-3B72-4439-905E-571513BB9029}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LINE.exe
FirewallRules: [{6FACACDF-3A3E-4FF9-BDAC-7053AEDEAA22}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LINE.exe
FirewallRules: [{54CC28C0-6A51-4F96-821B-5157312C562F}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LineUpdater.exe
FirewallRules: [{F7FA6E46-7DA0-467E-9D93-47E2B698A9C0}] => (Allow) C:\Users\CA\AppData\Local\LINE\bin\5.3.0.1495\LineUpdater.exe
FirewallRules: [{86745F39-458E-4A59-A83F-434F7F87AFF7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{59D98BEA-84D3-4362-940A-8E412CC1CC4F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C4E421BF-0C9B-4C4A-A98D-4814CBD2E57F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{942F21D1-09B4-45D4-9DDA-0112CD17CDEE}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{382A9B6B-CBFC-462A-95B2-19FC6168B704}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{088809A8-27CA-4D4C-A38C-6F400EF0F0FC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{16C0D42E-EBFF-4289-B5C9-1385BF360253}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{A4FF59FB-223F-4AD6-AD3B-D423C1B6B4F4}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{69FFD830-DFA1-4EF5-A065-27BDA2FCB8B6}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{042B349F-FCAE-43B7-9FD6-5EE935106D9A}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{4E2C1110-89C9-48A5-896C-D6B4A2FA4C33}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [UDP Query User{7CD1FC60-5F78-4A27-982C-0A9CA0D8FF82}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [TCP Query User{A231AFE8-D3FC-4B07-A4BA-BF0B70518882}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{545250C8-B5F3-4F8A-96C4-138C1FA2CDAC}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{435F7CD6-5127-404B-98D1-B871B24F4B9B}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{2874833A-09D5-48A4-B13A-7A2AF475FD94}C:\users\ca\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\ca\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{529D04E0-0657-47CF-89AE-69814452E814}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [UDP Query User{18F7CAC7-580E-4F19-9746-753EFD473859}C:\ruby24-x64\bin\ruby.exe] => (Allow) C:\ruby24-x64\bin\ruby.exe
FirewallRules: [TCP Query User{1E3C7CAC-12A4-43F9-A553-8CE7983BF206}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{5C182B7F-BBEE-4837-85DA-7EDB524ECD17}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [TCP Query User{C0CEE23F-69AE-4EAF-8726-52A6F727E332}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{E1DCC975-C45F-4304-92CE-0377417059B4}D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe] => (Block) D:\deff\smite\steamapps\common\smite\binaries\win32\smite.exe
FirewallRules: [{43B65750-73DB-42C5-A09B-11BBA4673443}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{515B43DE-75B5-40D4-A124-4700D36DB28D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{554ECFB7-013E-47F8-81DA-DE9A052E3CCA}] => (Allow) D:\SteamLibrary\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{851ABA89-1488-4187-A99D-C88976D2D1E4}] => (Allow) D:\SteamLibrary\steamapps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{2E393DD9-8C28-461D-93DB-C632F8E61F3B}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{115F75D8-206E-4D28-B254-2CBEFA72A568}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [TCP Query User{A90AC2D8-D0C9-4102-B354-7F75D14B8CCE}D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe
FirewallRules: [UDP Query User{EE2A5292-3D2D-4FA0-8C44-FE7001C6579E}D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe] => (Allow) D:\steamlibrary\steamapps\common\warface\mycomgames\mycomgames.exe
FirewallRules: [{35C730ED-5F06-47B1-9FCF-F99432C3FB3E}] => (Allow) C:\Program Files (x86)\Nox\bin\Nox.exe
FirewallRules: [{DF88A946-8269-4910-B119-B43225AF6652}] => (Allow) C:\Program Files (x86)\Bignox\BigNoxVM\RT\NoxVMHandle.exe
FirewallRules: [{6C9CB2D2-85FF-4F5B-8D4C-F402A10ADDB0}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{D437EA37-2BD0-45E5-B436-D68DB62F9681}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{9382B4D7-6400-4CA9-AC5A-13C1F2C32DDA}] => (Allow) C:\Users\CA\AppData\Roaming\uTorrent Web\utweb.exe
FirewallRules: [{64D1A898-0511-4ACC-AB76-8FA331AF545E}] => (Allow) C:\Users\CA\AppData\Roaming\uTorrent Web\utweb.exe
FirewallRules: [{91411C3F-2863-404A-8871-11B6363F617D}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{5F8EEECE-3CE2-4DF8-8E39-6852530978AB}] => (Allow) D:\SteamLibrary\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{E801C2AC-61E6-4955-B36E-E36081DAA6C5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMux.exe] => Enabled:SwiApiMux
 
==================== Restore Points =========================
 
Check "winmgmt" service or repair WMI.
 
 
==================== Faulty Device Manager Devices =============
 
Name: Base System Device
Description: Base System Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/10/2018 10:25:35 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
 
 
Operation:
   Instantiating VSS server
 
Error: (05/10/2018 10:25:35 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]
 
 
Operation:
   Instantiating VSS server
 
Error: (05/10/2018 10:22:38 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
 
 
Operation:
   Instantiating VSS server
 
Error: (05/10/2018 10:22:38 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]
 
 
Operation:
   Instantiating VSS server
 
Error: (05/10/2018 05:38:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (05/10/2018 09:57:35 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (05/10/2018 01:16:47 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.
 
 
Operation:
   Instantiating VSS server
 
Error: (05/10/2018 01:16:47 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]
 
 
Operation:
   Instantiating VSS server
 
 
System errors:
=============
Error: (05/09/2018 10:25:32 PM) (Source: NetBT) (EventID: 4307) (User: )
Description: Initialization failed because the transport refused to open initial addresses.
 
Error: (05/08/2018 02:10:34 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.
 
Error: (05/07/2018 04:54:30 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{E423BEC1-2BF0-4D9C-8DE2-EAD0EF615D99}.
The backup browser is stopping.
 
Error: (05/07/2018 04:47:04 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 4:45:33 PM on ‎5/‎7/‎2018 was unexpected.
 
Error: (05/07/2018 09:50:45 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\System32\bcmihvsrv64.dll
 
Error: (05/07/2018 09:50:45 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\System32\bcmihvsrv64.dll
 
Error: (05/07/2018 09:50:41 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has stopped unexpectedly.
 
Module Path: C:\Windows\System32\bcmihvsrv64.dll
 
Error: (05/07/2018 09:40:36 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
An instance of the service is already running.
 
 
CodeIntegrity:
===================================
 
Date: 2018-05-10 22:20:55.368
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-10 22:20:30.472
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-10 22:20:26.947
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-10 22:19:59.228
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAR64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-10 21:15:43.939
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAC64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-10 21:15:43.404
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAC64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-10 19:12:20.520
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAC64.dll because the set of per-page image hashes could not be found on the system.
 
Date: 2018-05-10 19:12:19.328
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\AESTAC64.dll because the set of per-page image hashes could not be found on the system.
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2520M CPU @ 2.50GHz
Percentage of memory in use: 64%
Total physical RAM: 4006.36 MB
Available physical RAM: 1406.8 MB
Total Virtual: 8010.91 MB
Available Virtual: 4495.2 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:82.76 GB) (Free:16.21 GB) NTFS
Drive d: (MASTER) (Fixed) (Total:150.02 GB) (Free:111.07 GB) NTFS
 
\\?\Volume{e8d55db0-6838-11e7-8925-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 9A196842)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=82.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=150 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users