Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-02-2016
Ran by John (administrator) on DADSPC (14-02-2016 10:42:51)
Running from C:\Users\John\Desktop
Loaded Profiles: John (Available Profiles: John & DefaultAppPool)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Astrill) C:\Program Files (x86)\Astrill\ASOvpnSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.5\ToolbarUpdater.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.5\loggingserver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Astrill) C:\Program Files (x86)\Astrill\astrill.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Voobly) C:\Program Files (x86)\Voobly\voobly.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2014-02-16] (Hewlett-Packard )
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2014-02-16] (IDT, Inc.)
HKLM-x32\...\Run: [BtTray] => c:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [379904 2013-01-10] (IVT Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3873704 2016-02-01] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [837640 2015-12-08] (DivX, LLC)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2857544 2016-02-02] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2014-11-03] (Razer Inc.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [179624 2016-01-12] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\...\Run: [Voobly] => C:\Program Files (x86)\Voobly\voobly.exe [159744 2015-01-12] (Voobly)
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50622080 2016-01-19] (Skype Technologies S.A.)
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\...\Run: [Astrill] => C:\Program Files (x86)\Astrill\astrill.exe [7213592 2015-12-17] (Astrill)
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566952 2014-06-24] (Safer-Networking Ltd.)
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\...\MountPoints2: {453b0e54-7e58-11e3-be6e-806e6f6e6963} - "E:\SETUP.EXE"
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2016-02-02]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk.disabled -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
AutoConfigURL: [S-1-5-21-1569399677-2339013464-2643545198-1001] => hxxp://
Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\ASProxy.dll [391192 2015-09-03] (Astrill)
Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\ASProxy.dll [391192 2015-09-03] (Astrill)
Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\ASProxy.dll [391192 2015-09-03] (Astrill)
Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\ASProxy.dll [391192 2015-09-03] (Astrill)
Winsock: Catalog9 15 C:\WINDOWS\SysWOW64\ASProxy.dll [391192 2015-09-03] (Astrill)
Winsock: Catalog9-x64 01 C:\WINDOWS\system32\ASProxy64.dll [555032 2015-09-03] (Astrill)
Winsock: Catalog9-x64 02 C:\WINDOWS\system32\ASProxy64.dll [555032 2015-09-03] (Astrill)
Winsock: Catalog9-x64 03 C:\WINDOWS\system32\ASProxy64.dll [555032 2015-09-03] (Astrill)
Winsock: Catalog9-x64 04 C:\WINDOWS\system32\ASProxy64.dll [555032 2015-09-03] (Astrill)
Winsock: Catalog9-x64 15 C:\WINDOWS\system32\ASProxy64.dll [555032 2015-09-03] (Astrill)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{C391C4FB-21DA-44EC-ACCD-854B50ECE956}: [DhcpNameServer]
Tcpip\..\Interfaces\{D61DDEC4-5FD5-4C57-8A9E-DA4363CA3F60}: [DhcpNameServer]
Tcpip\..\Interfaces\{F3685BC7-A488-4FD1-9C59-325FD2214783}: [DhcpNameServer]
Internet Explorer:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
HKU\S-1-5-21-1569399677-2339013464-2643545198-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp:// ?{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp:// ?{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-1569399677-2339013464-2643545198-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://{43FC9FB8-A529-459F-B400-F1190F4F31FB}&mid=f8fbbb7488c147d29dc39913f0ed10a1-3f14605c5294c24fc80f29d9b02977255938e260&lang=en&ds=AVG&coid=avgtbavg&cmpid=0116tb&pr=fr&d=2014-11-07 18:23:36&v={searchTerms}
SearchScopes: HKU\S-1-5-21-1569399677-2339013464-2643545198-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp:// ?{searchTerms}&keyword={searchTerms}
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\\AVG Web TuneUp.dll [2016-02-02] (AVG)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll => No File
BHO-x32: No Name -> {601ED020-FB6C-11D3-87D8-0050DA59922B} -> No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\\AVG Web TuneUp.dll [2016-02-02] (AVG)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2015-10-19] (Hewlett-Packard Company)
Toolbar: HKU\S-1-5-21-1569399677-2339013464-2643545198-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [2001-02-12] (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [2001-02-12] (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [2001-02-12] (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [2001-02-12] (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [2001-02-12] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [2001-02-12] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [2001-02-12] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.2.0\ViProtocol.dll [2014-12-09] (AVG Secure Search)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FF Plugin: -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-09] ()
FF Plugin: VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-09] ()
FF Plugin-x32: VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2015-12-02] (DivX, LLC)
FF Plugin-x32: WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-02-16] (Intel Corporation)
FF Plugin-x32: WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-02-16] (Intel Corporation)
FF Plugin-x32:,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-02-12] (Google Inc.)
FF Plugin-x32: Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-02-12] (Google Inc.)
FF Plugin-x32:,version=0.9.19 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll [2012-01-13] (Veetle Inc)
FF Plugin-x32:,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll [2012-01-13] (Veetle Inc)
FF Plugin-x32:,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: -> C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll [2002-06-07] ()
FF Plugin-x32:,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] ()
FF Plugin HKU\S-1-5-21-1569399677-2339013464-2643545198-1001: -> C:\Users\John\AppData\Roaming\HewlettPackard\HPDetect\\npHPDetect.dll [2012-08-30] (HP)
CHR HomePage: Default -> hxxps://¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzuzy0C0ByCyDyE0FtA0FyB0D0A0EtBtCtAtN0D0Tzu0StCyEzytAtN1L2XzutAtFtCyBtFzytFtDtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2SyEzyzyzyyEyDtCyDtGyBtAyDyCtGyCyDtBzztGyBzzzzyBtGzyyEtAyDtCzz0CyD0F0FtCtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0AzzyD0C0AyB0AtG0B0DzyyBtGyEyCyB0DtGzz0EyE0FtG0FyEtBtDzztA0E0Ezy0AtByB2QtN0A0LzuyE%26cr%3D1001654787%26a%3Dwncy_nxtad_16_05%26os_ver%3D6.3%26os%3DWindows%2B8.1
CHR StartupUrls: Default -> "hxxp://"
CHR Profile: C:\Users\John\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-12]
CHR Extension: (Google Docs) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-12]
CHR Extension: (Google Drive) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-12]
CHR Extension: (YouTube) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-12]
CHR Extension: (Adblock Plus) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-12]
CHR Extension: (Google Search) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-12]
CHR Extension: (Video Downloader professional) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2016-02-12]
CHR Extension: (Google Sheets) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-12]
CHR Extension: (Google Docs Offline) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-12]
CHR Extension: (Gmail) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-12]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASOVPNHelper; C:\Program Files (x86)\Astrill\ASOvpnSvc.exe [602136 2015-11-19] (Astrill)
S3 ASProxy; C:\Program Files (x86)\Astrill\ASProxy.exe [2607640 2015-09-03] (Astrill)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [604144 2016-02-01] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3881184 2016-02-01] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1048488 2016-01-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [561104 2016-02-01] (AVG Technologies CZ, s.r.o.)
R2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1619704 2013-03-26] (IVT Corporation)
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2013-01-10] (IVT Corporation) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [25800 2015-09-28] (Hewlett-Packard Company)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315352 2014-11-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-02-16] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2014-02-16] (Intel Corporation)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [183488 2014-10-31] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1740760 2014-09-03] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [337920 2014-02-16] (IDT, Inc.) [File not signed]
R2 vToolbarUpdater40.2.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.5\ToolbarUpdater.exe [1936968 2016-02-02] (AVG Secure Search)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1205832 2016-02-02] ()
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 asvpndrv; C:\Windows\system32\DRIVERS\asvpndrv.sys [31744 2014-05-17] (Astrill)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2016-01-05] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [272304 2016-01-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [260528 2016-01-22] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [23472 2016-01-08] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [315840 2015-12-16] (AVG Technologies CZ, s.r.o.)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [132608 2015-01-29] (Microsoft Corporation)
S3 BthHFAud; C:\Windows\system32\DRIVERS\BthHfAud.sys [32768 2014-10-08] (Microsoft Corporation)
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [49584 2013-03-25] (Ralink Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-12-04] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2014-02-16] (Intel Corporation)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.)
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [39592 2014-09-04] (Razer Inc)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2014-10-31] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [129600 2014-11-17] (Razer, Inc.)
R1 SDHookDriver; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [64160 2014-04-25] ()
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2016-02-04] (Duplex Secure Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S1 qknfd; system32\drivers\qknfd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-14 10:42 - 2016-02-14 10:43 - 00027661 _____ C:\Users\John\Desktop\FRST.txt
2016-02-14 10:33 - 2016-02-14 10:42 - 00000000 ____D C:\FRST
2016-02-14 10:32 - 2016-02-14 10:32 - 02370560 _____ (Farbar) C:\Users\John\Desktop\FRST64.exe
2016-02-14 10:31 - 2016-02-14 10:31 - 00002262 _____ C:\Users\Public\Desktop\ - Registry Backup.lnk
2016-02-14 10:31 - 2016-02-14 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
2016-02-14 10:30 - 2016-02-14 10:31 - 00016199 _____ C:\WINDOWS\ - Registry Backup Setup Log.txt
2016-02-14 10:29 - 2016-02-14 10:29 - 04777232 _____ ( C:\Users\John\Desktop\tweaking.com_registry_backup_setup.exe
2016-02-13 21:48 - 2016-02-13 21:48 - 00000000 ____D C:\Users\John\AppData\Local\HP Quick Start
2016-02-13 21:45 - 2016-02-13 21:45 - 04584344 _____ (Google) C:\Users\John\Downloads\chrome_cleanup_tool.exe
2016-02-12 15:30 - 2016-02-12 15:30 - 00002315 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-12 15:30 - 2016-02-12 15:30 - 00002286 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-12 15:29 - 2016-02-14 10:34 - 00000908 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-12 15:29 - 2016-02-13 15:34 - 00000904 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-12 15:29 - 2016-02-12 15:29 - 00003880 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-12 15:29 - 2016-02-12 15:29 - 00003644 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-12 15:29 - 2016-02-12 15:29 - 00000000 ____D C:\Users\John\AppData\Local\Deployment
2016-02-12 12:22 - 2016-02-12 12:22 - 00000000 ____D C:\Users\John\AppData\Roaming\Macromedia
2016-02-11 14:33 - 2016-02-11 14:32 - 00450979 ____R C:\WINDOWS\system32\Drivers\etc\hosts.20160211-143319.backup
2016-02-11 14:32 - 2016-02-11 13:33 - 00450979 ____R C:\WINDOWS\system32\Drivers\etc\hosts.20160211-143240.backup
2016-02-11 13:33 - 2015-08-12 20:20 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20160211-133353.backup
2016-02-11 11:10 - 2016-02-11 11:10 - 00558336 _____ (Safer-Networking Ltd. ) C:\Users\John\Downloads\spybot2-license.exe
2016-02-10 08:17 - 2016-02-10 08:17 - 54329568 _____ (Microsoft Corporation) C:\Users\John\Downloads\Windows-KB890830-x64-V5.33.exe
2016-02-10 00:47 - 2016-02-06 05:48 - 25839104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-02-10 00:47 - 2016-02-06 05:24 - 02887680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-02-10 00:47 - 2016-02-06 05:01 - 20366848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-02-10 00:47 - 2016-02-06 04:43 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-02-10 00:47 - 2016-02-06 04:32 - 14458368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-02-10 00:47 - 2016-02-06 04:16 - 12857856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-02-10 00:47 - 2016-02-06 04:09 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-02-10 00:47 - 2016-02-06 03:54 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-02-09 19:44 - 2016-02-11 12:16 - 00001771 _____ C:\WINDOWS\wininit.ini
2016-02-09 19:14 - 2016-02-09 19:14 - 00002458 _____ C:\WINDOWS\system32\.crusader
2016-02-09 17:04 - 2016-01-10 12:50 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-09 17:04 - 2016-01-10 12:31 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-09 17:04 - 2016-01-10 12:16 - 00898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2016-02-09 17:04 - 2016-01-10 12:14 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-09 17:04 - 2016-01-10 12:12 - 00532480 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2016-02-09 17:04 - 2016-01-10 11:58 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-09 17:04 - 2016-01-10 11:51 - 00702976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2016-02-09 17:04 - 2016-01-10 11:49 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2016-02-09 17:04 - 2016-01-10 11:40 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-09 17:03 - 2016-01-22 03:01 - 22365992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-02-09 17:03 - 2016-01-22 02:11 - 19794896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-02-09 17:03 - 2016-01-22 01:40 - 00571904 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-02-09 17:03 - 2016-01-22 01:29 - 06052352 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-02-09 17:03 - 2016-01-22 01:28 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-09 17:03 - 2016-01-22 01:27 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-02-09 17:03 - 2016-01-22 01:02 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-02-09 17:03 - 2016-01-22 00:55 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-02-09 17:03 - 2016-01-22 00:52 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-09 17:03 - 2016-01-22 00:51 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-02-09 17:03 - 2016-01-22 00:50 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2016-02-09 17:03 - 2016-01-22 00:48 - 00718336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-02-09 17:03 - 2016-01-22 00:48 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-02-09 17:03 - 2016-01-22 00:47 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-02-09 17:03 - 2016-01-22 00:46 - 02123264 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-02-09 17:03 - 2016-01-22 00:35 - 04611072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-02-09 17:03 - 2016-01-22 00:31 - 02597376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-02-09 17:03 - 2016-01-22 00:31 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-02-09 17:03 - 2016-01-22 00:28 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-02-09 17:03 - 2016-01-22 00:27 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2016-02-09 17:03 - 2016-01-22 00:25 - 14467072 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-02-09 17:03 - 2016-01-22 00:25 - 00687104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-02-09 17:03 - 2016-01-22 00:25 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-02-09 17:03 - 2016-01-22 00:24 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-02-09 17:03 - 2016-01-22 00:14 - 12879360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-02-09 17:03 - 2016-01-22 00:08 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-02-09 17:03 - 2016-01-22 00:07 - 02778624 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-02-09 17:03 - 2016-01-22 00:07 - 02120704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-02-09 17:03 - 2016-01-22 00:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-02-09 17:03 - 2016-01-21 23:58 - 02464256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-02-09 17:03 - 2016-01-19 14:14 - 07453024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-02-09 17:03 - 2016-01-19 14:13 - 02175008 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-09 17:03 - 2016-01-19 14:13 - 01063464 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-09 17:03 - 2016-01-19 14:12 - 01737088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-02-09 17:03 - 2016-01-19 14:12 - 01133744 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-02-09 17:03 - 2016-01-19 13:23 - 01564496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-09 17:03 - 2016-01-19 13:23 - 01501496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-02-09 17:03 - 2016-01-19 13:23 - 00548024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-09 17:03 - 2016-01-19 13:15 - 00246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-09 17:03 - 2016-01-19 12:30 - 00862720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-02-09 17:03 - 2016-01-19 11:37 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2016-02-09 17:03 - 2016-01-14 20:42 - 00033472 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-02-09 17:03 - 2016-01-14 15:44 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-02-09 17:03 - 2016-01-14 15:44 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-02-09 17:03 - 2016-01-14 15:44 - 00696320 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-02-09 17:03 - 2016-01-14 15:44 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-02-09 17:03 - 2016-01-14 15:44 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-02-09 17:03 - 2016-01-14 15:44 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-02-09 17:03 - 2016-01-10 14:37 - 00442720 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-02-09 17:03 - 2016-01-10 14:37 - 00136912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-02-09 17:03 - 2016-01-10 13:39 - 00332640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-02-09 17:03 - 2016-01-10 13:15 - 00401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-02-09 17:03 - 2016-01-10 13:15 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2016-02-09 17:03 - 2016-01-10 12:43 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-02-09 17:03 - 2016-01-10 12:09 - 01442304 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-09 17:03 - 2016-01-10 12:09 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-02-09 17:03 - 2016-01-10 12:02 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-09 17:03 - 2016-01-10 11:56 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2016-02-09 17:03 - 2016-01-10 11:51 - 03707392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-02-09 17:03 - 2016-01-10 11:43 - 00801792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-09 17:03 - 2016-01-10 11:39 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2016-02-09 17:03 - 2016-01-10 11:38 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2016-02-09 17:03 - 2016-01-10 11:36 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2016-02-09 17:03 - 2016-01-10 11:36 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2016-02-09 17:03 - 2016-01-10 11:35 - 02243584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2016-02-09 17:03 - 2016-01-10 11:35 - 00897024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-02-09 17:03 - 2016-01-10 11:29 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2016-02-09 17:03 - 2016-01-10 11:29 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2016-02-09 17:03 - 2016-01-10 11:27 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2016-02-09 17:03 - 2016-01-10 11:26 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-02-09 17:03 - 2016-01-07 13:34 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-02-09 17:03 - 2016-01-06 13:25 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-09 17:03 - 2015-12-29 10:45 - 07783936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-02-09 17:03 - 2015-12-29 10:45 - 07075328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glcndFilter.dll
2016-02-09 17:03 - 2015-12-29 10:43 - 05267968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glcndFilter.dll
2016-02-09 17:03 - 2015-12-29 10:42 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-02-09 17:03 - 2015-12-28 16:42 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSync.dll
2016-02-09 17:03 - 2015-12-28 15:31 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSync.dll
2016-02-09 17:03 - 2015-12-17 13:29 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2016-02-09 17:03 - 2015-12-17 11:17 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2016-02-09 13:33 - 2016-02-09 13:33 - 00000000 ____D C:\Users\John\Documents\ProcAlyzer Dumps
2016-02-09 13:30 - 2016-02-09 13:30 - 00000363 _____ C:\Users\John\Control Panel - Shortcut.lnk
2016-02-09 13:23 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2016-02-09 13:21 - 2016-02-09 13:21 - 00001414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2016-02-09 13:21 - 2016-02-09 13:21 - 00001402 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2016-02-09 13:21 - 2016-02-09 13:21 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2016-02-09 13:21 - 2016-02-09 13:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2016-02-09 13:20 - 2016-02-11 14:34 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-02-09 13:20 - 2016-02-11 11:15 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-02-09 13:20 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2016-02-08 20:34 - 2016-02-08 20:34 - 03039232 _____ C:\Users\John\ntuser.rhk
2016-02-08 20:30 - 2016-02-08 20:40 - 00000478 _____ C:\WINDOWS\Tasks\Wise Registry Cleaner Schedule Task.job
2016-02-08 20:30 - 2016-02-08 20:30 - 00003326 _____ C:\WINDOWS\System32\Tasks\Wise Registry Cleaner Schedule Task
2016-02-08 05:23 - 2016-02-08 05:23 - 00000000 ____D C:\sh4ldr
2016-02-08 05:23 - 2016-02-08 05:23 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-02-08 05:23 - 2016-02-08 05:23 - 00000000 _____ C:\autoexec.bat
2016-02-07 02:53 - 2016-02-07 02:53 - 00001916 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2016-02-07 02:53 - 2016-02-07 02:53 - 00000000 ____D C:\Program Files\HitmanPro
2016-02-07 02:52 - 2016-02-09 19:08 - 00000000 ____D C:\ProgramData\HitmanPro
2016-02-06 17:49 - 2016-02-06 17:50 - 02468442 _____ C:\Users\John\Downloads\forced.mp4
2016-02-06 12:18 - 2016-02-06 12:26 - 00000000 ____D C:\Users\John\Documents\Attachments
2016-02-05 22:05 - 2016-02-11 10:55 - 00000000 ____D C:\Program Files (x86)\No-IP
2016-02-05 22:05 - 2016-02-05 22:05 - 00000000 ____D C:\Users\John\AppData\Local\Vitalwerks
2016-02-05 20:26 - 2016-02-08 22:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jasc Software
2016-02-04 22:25 - 2016-02-04 22:25 - 00000041 ___SH C:\ProgramData\.zreglib
2016-02-04 22:24 - 2016-02-04 22:29 - 00000000 ____D C:\Program Files (x86)\SlySoft
2016-02-04 22:17 - 2016-02-04 22:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Golden Hawk Technology
2016-02-04 22:17 - 2006-03-20 00:00 - 00057344 _____ (NexiTech, Inc.) C:\WINDOWS\SysWOW64\WNASPINT.DLL
2016-02-04 22:09 - 2016-02-04 22:13 - 00868848 _____ (Duplex Secure Ltd.) C:\WINDOWS\system32\Drivers\sptd.sys
2016-02-04 21:45 - 2016-02-04 21:45 - 00001704 _____ C:\Users\John\Desktop\Warcraft 2 Combat Map Editor.lnk
2016-02-04 21:32 - 2016-02-08 22:51 - 00000000 ____D C:\Program Files (x86)\Viewpoint
2016-02-04 21:32 - 2016-02-04 21:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Netscape 7.0
2016-02-04 21:32 - 2016-02-04 21:32 - 00010004 _____ C:\WINDOWS\mozver.dat
2016-02-04 21:31 - 2016-02-04 21:31 - 00003072 _____ C:\WINDOWS\System32\Tasks\{885D906F-296A-4054-A9DC-1129789D4DF3}
2016-02-04 21:20 - 2016-02-08 22:51 - 00000000 ____D C:\Users\John\AppData\Local\Netscape
2016-02-04 21:20 - 2016-02-04 21:32 - 00000335 _____ C:\WINDOWS\nsreg.dat
2016-02-04 21:11 - 2016-02-04 21:11 - 00000000 ____D C:\Program Files\Jasc Software Inc
2016-02-04 21:10 - 2016-02-04 21:11 - 00018994 _____ C:\WINDOWS\Team C8 - 200 Paintshop Pro Plugins Mega-Pack 01 - Filters Setup Log.txt
2016-02-04 21:05 - 2016-02-04 21:05 - 00000000 ____D C:\Program Files (x86)\War2CombatMapEditor
2016-02-04 00:22 - 2016-02-04 00:22 - 00003248 _____ C:\WINDOWS\System32\Tasks\{D80DD150-CBD1-4F3F-8FB0-B796A447F6C9}
2016-02-04 00:21 - 2016-02-04 00:21 - 00001636 _____ C:\Users\John\Desktop\PSP 7.lnk
2016-02-03 23:41 - 2016-02-03 23:43 - 31725159 _____ C:\Users\John\Downloads\
2016-02-03 00:51 - 2016-02-03 00:51 - 01193136 _____ (Corel Corporation) C:\Users\John\Downloads\pspx8.1_seo.exe
2016-02-03 00:34 - 2016-02-03 00:34 - 00003204 _____ C:\WINDOWS\System32\Tasks\{18E4AAEF-0F88-4456-8AE9-B262A884FF88}
2016-02-02 23:38 - 2016-02-02 23:38 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-02-02 23:38 - 2016-02-02 23:38 - 00000000 ____D C:\Users\John\AppData\Local\CEF
2016-02-02 23:37 - 2016-02-02 23:49 - 00000000 ____D C:\Users\John\AppData\Local\{56C7609B-726F-0C23-1FF7-29CB3B9FD553}
2016-02-02 22:26 - 2016-02-02 22:26 - 00000000 ____D C:\ProgramData\BulletProof Software
2016-02-02 21:45 - 2016-02-08 22:51 - 00000000 ____D C:\Users\John\AppData\Local\BulletProof Software
2016-02-02 21:43 - 2016-02-08 22:51 - 00000000 ____D C:\BBB
2016-02-02 21:14 - 2016-02-08 22:51 - 00000000 ____D C:\Program Files (x86)\Jasc Software Inc
2016-02-02 19:16 - 2016-02-02 19:16 - 00000879 _____ C:\Users\John\Documents\bbbhq.dwt
2016-02-02 18:59 - 2016-02-02 18:59 - 00000000 ____D C:\ProgramData\Macromedia
2016-02-02 18:58 - 2016-02-10 10:01 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2016-02-02 18:58 - 2016-02-10 10:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macromedia
2016-02-02 18:58 - 2016-02-10 10:01 - 00000000 ____D C:\Program Files (x86)\Macromedia
2016-02-02 16:44 - 2016-02-04 21:52 - 00044867 _____ C:\Users\John\Documents\Black Blade Brigade.htm
2016-02-02 16:44 - 2016-02-02 19:28 - 00000000 ____D C:\Users\John\Documents\Black Blade Brigade_files
2016-02-02 16:05 - 2016-02-02 16:05 - 02930208 _____ (NetworkActiv) C:\Users\John\Downloads\NetworkActivWebServerV4.0_PA_3.7.0.exe
2016-02-02 16:04 - 2016-02-02 16:04 - 00622608 _____ (NetworkActiv) C:\Users\John\Downloads\NetworkActivWebServerV3.5.exe
2016-02-02 14:57 - 2016-02-02 14:57 - 00001660 _____ C:\Users\John\Desktop\Warcraft II Map Editor.exe - Shortcut.lnk
2016-02-02 13:50 - 2016-02-02 13:50 - 00000002 _____ C:\Users\John\Documents\gwd_workspace.json
2016-02-02 01:07 - 2016-02-02 01:07 - 00000000 ____D C:\Users\John\Documents\OneNote Notebooks
2016-02-02 01:06 - 2016-02-06 11:13 - 00000000 ____D C:\Users\John\Documents\bbb_index_files
2016-02-02 01:06 - 2016-02-02 01:06 - 00077824 _____ C:\Users\John\Documents\
2016-02-02 01:06 - 2016-02-02 01:06 - 00013132 _____ C:\Users\John\Documents\bbb_index.htm
2016-02-02 00:49 - 2016-02-02 00:49 - 00033881 _____ C:\Users\John\Documents\bbb.htm
2016-02-02 00:49 - 2016-02-02 00:49 - 00000000 ____D C:\Users\John\Documents\bbb_files
2016-02-02 00:46 - 2016-02-02 12:55 - 00254976 _____ C:\Users\John\Documents\
2016-02-02 00:19 - 2016-02-02 00:19 - 00129528 _____ C:\Users\John\AppData\Local\GDIPFONTCACHEV1.DAT
2016-02-01 23:42 - 2016-02-08 22:51 - 00000000 ____D C:\Program Files (x86)\CoffeeCup Software
2016-02-01 23:42 - 2016-02-01 23:42 - 00002179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CoffeeCup DirectFTP.lnk
2016-02-01 23:42 - 2016-02-01 23:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CoffeeCup DirectFTP
2016-02-01 23:33 - 2016-02-01 23:33 - 00003100 _____ C:\WINDOWS\System32\Tasks\{D451E8EB-F2D8-4DAE-BA65-5E56D847B3BA}
2016-02-01 22:39 - 2016-02-01 22:39 - 00000000 ____D C:\Users\John\Documents\HQ
2016-02-01 22:34 - 2016-02-01 22:37 - 00000000 ____D C:\Users\John\Documents\Headquarters
2016-02-01 20:57 - 2016-02-01 20:57 - 00000000 ____D C:\Users\John\AppData\Local\Disruptive Innovations SARL
2016-02-01 19:26 - 2016-02-01 19:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-02-01 19:08 - 2016-02-01 19:12 - 00000000 ____D C:\Users\John\Documents\BBB
2016-02-01 18:02 - 2016-02-01 18:02 - 00000006 ____S C:\ProgramData\9d14874e4867a8275e174fe4445aabd83ba0869d
2016-02-01 18:02 - 2016-02-01 18:02 - 00000000 ____D C:\ProgramData\238559
2016-02-01 18:02 - 2016-02-01 18:02 - 00000000 ____D C:\ProgramData\238459
2016-02-01 04:10 - 2016-02-01 04:10 - 00000000 ____D C:\Users\John\AppData\Local\Globalscape
2016-02-01 04:10 - 2016-02-01 04:10 - 00000000 ____D C:\ProgramData\Globalscape
2016-01-30 20:17 - 2016-01-30 20:17 - 00000001 _____ C:\Users\John\Downloads\
2016-01-29 17:34 - 2016-02-08 20:01 - 00000000 ____D C:\Users\DefaultAppPool
2016-01-29 17:34 - 2016-01-29 17:34 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2016-01-29 17:34 - 2016-01-29 17:34 - 00000000 _SHDL C:\Users\DefaultAppPool\My Documents
2016-01-29 17:34 - 2016-01-29 17:34 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Videos
2016-01-29 17:34 - 2016-01-29 17:34 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Pictures
2016-01-29 17:34 - 2016-01-29 17:34 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\My Music
2016-01-29 17:34 - 2016-01-29 13:04 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Microsoft Help
2016-01-29 17:34 - 2014-02-21 23:37 - 00000369 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2016-01-29 17:34 - 2014-02-21 23:37 - 00000369 _____ C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2016-01-29 17:34 - 2014-02-15 23:06 - 00000000 ____D C:\Users\DefaultAppPool\Documents\hp.system.package.metadata
2016-01-29 17:34 - 2014-02-15 23:06 - 00000000 ____D C:\Users\DefaultAppPool\Documents\hp.applications.package.appdata
2016-01-29 17:34 - 2014-02-15 23:06 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\TuneUp Software
2016-01-29 17:25 - 2016-02-14 00:18 - 00000000 ____D C:\War2Combat
2016-01-29 17:25 - 2016-01-29 17:25 - 00001576 _____ C:\Users\John\Desktop\War2Combat.lnk
2016-01-29 14:52 - 2016-01-29 14:52 - 00000000 _____ C:\WINDOWS\SysWOW64\Access.dat
2016-01-29 13:05 - 2016-02-08 22:51 - 00000000 ____D C:\Program Files (x86)\Microsoft CAPICOM
2016-01-29 13:04 - 2016-01-29 13:04 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2016-01-29 13:04 - 2016-01-29 13:04 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2016-01-29 13:03 - 2016-01-29 13:03 - 00000000 ____D C:\Users\John\Documents\Tunngle
2016-01-29 13:03 - 2015-12-21 17:01 - 00047736 _____ ( C:\WINDOWS\system32\Drivers\tap0901t.sys
2016-01-29 02:03 - 2016-01-29 15:47 - 00000000 ____D C:\Users\John\Desktop\AGEditor3
2016-01-28 23:57 - 2016-01-28 23:57 - 00001147 _____ C:\Users\John\Desktop\CoffeeCup Free HTML Editor.lnk
2016-01-28 23:56 - 2016-02-08 22:51 - 00000000 ____D C:\Users\John\Documents\CoffeeCup Software
2016-01-28 23:56 - 2016-01-28 23:56 - 00000000 ____D C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CoffeeCup Software
2016-01-28 23:55 - 2016-02-08 22:51 - 00000000 ____D C:\Users\John\AppData\Roaming\CoffeeCup Software
2016-01-28 22:18 - 2016-02-08 22:51 - 00000000 ____D C:\Users\John\Desktop\NP++
2016-01-28 22:17 - 2016-01-28 22:17 - 02020520 _____ C:\Users\John\Desktop\npp.6.8.8.bin.7z
2016-01-28 22:17 - 2016-01-28 22:17 - 00000000 ____D C:\Users\John\AppData\Roaming\Notepad++
2016-01-28 21:48 - 2016-01-28 21:48 - 00781994 _____ C:\Users\John\Desktop\
2016-01-24 22:55 - 2016-01-24 22:55 - 00001127 _____ C:\Users\John\Desktop\Investments.txt
2016-01-22 15:19 - 2016-01-22 15:19 - 00000000 ____D C:\Users\John\Downloads\Kali
2016-01-22 15:17 - 2016-01-22 15:18 - 02811349 _____ (InstallShield Software Corporation) C:\Users\John\Downloads\kali2613.exe
2016-01-22 15:15 - 2016-01-22 15:15 - 00260528 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx64.sys
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-02-14 10:41 - 2014-04-07 08:43 - 00000000 ____D C:\Users\John\AppData\Roaming\Skype
2016-02-14 10:37 - 2014-01-15 21:01 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1569399677-2339013464-2643545198-1001
2016-02-14 10:31 - 2015-08-12 18:26 - 00000000 ____D C:\Program Files (x86)\
2016-02-14 10:09 - 2015-08-13 19:05 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-02-14 09:51 - 2014-01-22 20:59 - 00000000 ____D C:\ProgramData\MFAData
2016-02-14 09:51 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2016-02-14 08:39 - 2014-01-15 20:53 - 00003914 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4E3A0E6E-0F52-4F4E-99F7-A943C718BF2E}
2016-02-14 01:00 - 2015-12-25 17:29 - 00000000 ____D C:\Users\John\AppData\Roaming\vlc
2016-02-13 22:44 - 2015-12-04 19:59 - 00104448 ___SH C:\Users\John\Downloads\Thumbs.db
2016-02-13 18:00 - 2015-08-12 18:16 - 00000480 _____ C:\WINDOWS\Tasks\ParetoLogic Registration3.job
2016-02-13 02:44 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\rescache
2016-02-12 15:30 - 2014-01-15 20:59 - 00000000 ____D C:\Users\John\AppData\Local\Google
2016-02-12 15:30 - 2014-01-15 20:59 - 00000000 ____D C:\Program Files (x86)\Google
2016-02-12 10:57 - 2014-01-15 21:37 - 00000000 ____D C:\Program Files (x86)\Voobly
2016-02-12 09:44 - 2013-11-14 02:28 - 00992412 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-12 09:44 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\Inf
2016-02-12 09:42 - 2014-02-15 23:24 - 00000000 ___DO C:\Users\John\SkyDrive
2016-02-12 09:42 - 2014-01-31 20:33 - 00000000 ____D C:\Users\John\AppData\Local\CrashDumps
2016-02-12 09:42 - 2013-03-22 13:00 - 00000983 _____ C:\WINDOWS\SysWOW64\bscs.ini
2016-02-12 09:41 - 2015-08-12 18:16 - 00000506 _____ C:\WINDOWS\Tasks\ParetoLogic Update Version3 Startup Task.job
2016-02-12 09:40 - 2013-12-02 09:45 - 00003620 _____ C:\WINDOWS\SysWOW64\LOCALSERVICE.INI
2016-02-12 09:39 - 2013-12-02 09:45 - 00000088 _____ C:\WINDOWS\SysWOW64\LOCALDEVICE.INI
2016-02-12 09:39 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-12 09:34 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-02-12 09:32 - 2015-09-04 07:18 - 00000342 _____ C:\WINDOWS\Tasks\HPCeeScheduleForJohn.job
2016-02-12 09:31 - 2013-08-22 09:44 - 00507936 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-02-12 09:29 - 2015-04-17 03:15 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-02-12 09:29 - 2013-11-14 02:17 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-12 09:29 - 2013-08-22 10:36 - 00000000 ___RD C:\WINDOWS\ToastData
2016-02-12 03:35 - 2015-09-04 07:18 - 00003154 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForJohn
2016-02-12 03:08 - 2015-05-13 22:23 - 00000000 ___RD C:\Users\John\OneDrive
2016-02-12 03:08 - 2015-01-15 21:49 - 00003090 _____ C:\WINDOWS\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-1569399677-2339013464-2643545198-1001
2016-02-11 22:11 - 2014-03-31 07:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-02-11 22:11 - 2012-07-26 03:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-02-10 10:08 - 2015-12-20 14:40 - 00000000 ____D C:\Software
2016-02-10 08:18 - 2014-10-16 23:03 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-10 01:03 - 2013-08-22 10:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-10 01:03 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-10 01:03 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-02-10 00:56 - 2014-01-16 21:49 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-09 21:09 - 2015-12-29 11:09 - 08817344 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2016-02-09 21:09 - 2015-08-13 19:05 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-02-09 19:22 - 2014-04-05 09:08 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-02-09 17:03 - 2015-11-10 16:24 - 00561952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-09 17:03 - 2015-11-10 16:24 - 00177496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-02-09 13:30 - 2014-02-15 23:04 - 00000000 ____D C:\Users\John
2016-02-09 13:23 - 2015-06-22 08:57 - 00000000 ____D C:\Program Files\Common Files\AV
2016-02-09 05:07 - 2015-08-12 18:16 - 00000454 _____ C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
2016-02-08 22:56 - 2016-01-12 22:50 - 00000000 ____D C:\Users\John\AppData\Roaming\PSpad
2016-02-08 22:56 - 2015-12-21 23:33 - 00000000 ____D C:\Users\John\AppData\Roaming\Astrill
2016-02-08 22:56 - 2015-12-21 23:33 - 00000000 ____D C:\Program Files (x86)\Astrill
2016-02-08 22:56 - 2015-04-04 03:02 - 00000000 ___SD C:\WINDOWS\system32\GWX
2016-02-08 22:52 - 2015-12-20 15:00 - 00000000 ____D C:\WINDOWS\SysWOW64\Spool
2016-02-08 22:52 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\registration
2016-02-08 22:51 - 2016-01-12 22:50 - 00000000 ____D C:\Program Files (x86)\PSPad editor
2016-02-08 22:51 - 2016-01-06 14:31 - 00000000 ____D C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2016-02-08 22:51 - 2016-01-06 14:31 - 00000000 ____D C:\Users\John\AppData\Local\Amazon
2016-02-08 22:51 - 2015-12-25 17:28 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2016-02-08 22:51 - 2015-12-25 17:18 - 00000000 ____D C:\Users\John\AppData\Local\converter
2016-02-08 22:51 - 2015-12-25 16:32 - 00000000 ____D C:\Users\John\AppData\Local\fontconfig
2016-02-08 22:51 - 2015-12-25 15:08 - 00000000 ____D C:\Users\John\AppData\Local\RzStats
2016-02-08 22:51 - 2015-12-25 15:03 - 00000000 ____D C:\Users\John\AppData\Roaming\Anvsoft
2016-02-08 22:51 - 2015-12-25 14:30 - 00000000 ____D C:\Users\Public\CyberLink
2016-02-08 22:51 - 2015-12-20 15:00 - 00000000 ____D C:\ProgramData\InstallShield
2016-02-08 22:51 - 2015-12-12 23:30 - 00000000 ____D C:\Users\John\AppData\Roaming\Microsoft Games
2016-02-08 22:51 - 2015-12-12 23:27 - 00000000 ____D C:\Program Files (x86)\GameSpy Arcade
2016-02-08 22:51 - 2015-12-10 22:32 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
2016-02-08 20:46 - 2013-08-22 08:25 - 00000292 _____ C:\WINDOWS\win.ini
2016-02-08 20:28 - 2014-02-01 12:57 - 00000000 ____D C:\Users\John\AppData\Local\HPConnectedMusic
2016-02-06 00:53 - 2014-04-05 09:08 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-02-06 00:53 - 2014-04-05 09:08 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-04 21:11 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\System
2016-02-03 18:48 - 2015-12-20 15:37 - 00000000 ____D C:\Users\John\Documents\My PSP Files
2016-02-03 18:48 - 2015-12-20 14:45 - 00006580 ___SH C:\WINDOWS\SysWOW64\KGyGaAvL.sys
2016-02-03 01:24 - 2014-02-16 19:22 - 00000000 ____D C:\Users\John\AppData\Local\ElevatedDiagnostics
2016-02-02 23:38 - 2013-08-22 10:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-02-02 23:38 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-02-02 22:26 - 2013-12-02 09:26 - 00000000 ____D C:\ProgramData\Temp
2016-02-02 22:06 - 2014-01-15 20:51 - 00000000 ____D C:\Users\John\AppData\Local\VirtualStore
2016-02-02 04:29 - 2014-11-07 18:23 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-02-02 04:28 - 2014-11-07 18:23 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-02-02 04:28 - 2014-11-07 18:23 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-02-01 21:37 - 2015-12-11 13:46 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-02-01 21:37 - 2015-12-11 13:46 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-01 20:27 - 2014-04-07 08:43 - 00000000 ____D C:\ProgramData\Skype
2016-02-01 19:28 - 2013-12-02 09:39 - 00000000 ____D C:\Program Files\7-Zip
2016-02-01 15:25 - 2013-12-02 09:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-01-29 18:50 - 2014-12-04 19:34 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2016-01-29 17:38 - 2014-02-16 01:53 - 00000000 ____D C:\inetpub
2016-01-29 17:38 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-01-29 17:38 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-01-29 13:04 - 2013-04-03 19:17 - 00000000 ____D C:\ProgramData\Package Cache
2016-01-29 01:57 - 2014-12-04 19:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-01-29 01:53 - 2013-12-02 09:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-01-29 01:53 - 2013-08-22 10:36 - 00000000 ____D C:\ProgramData\
2016-01-22 02:56 - 2015-05-21 07:55 - 00000000 ____D C:\Users\John\AppData\Local\Avg
2016-01-22 02:56 - 2014-01-22 21:03 - 00000000 ___HD C:\$AVG
2016-01-16 17:58 - 2014-04-07 08:43 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-15 16:38 - 2015-03-31 08:53 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
==================== Files in the root of some directories =======
2015-12-21 23:33 - 2015-05-05 11:56 - 1701390 _____ () C:\Users\John\AppData\Roaming\addr2line.exe
2014-01-16 18:37 - 2014-07-18 23:31 - 0000210 _____ () C:\Users\John\AppData\Roaming\WB.CFG
2014-02-02 22:22 - 2014-02-02 22:23 - 0003584 _____ () C:\Users\John\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-02-04 22:25 - 2016-02-04 22:25 - 0000041 ___SH () C:\ProgramData\.zreglib
2016-02-01 18:02 - 2016-02-01 18:02 - 0000006 ____S () C:\ProgramData\9d14874e4867a8275e174fe4445aabd83ba0869d
2015-12-25 17:17 - 2015-12-25 17:17 - 0000016 _____ () C:\ProgramData\mntemp
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-02-13 02:06
==================== End of FRST.txt ============================