W4yneb0t
2016-04-14, 02:16
I ran a .exe from an untrusted source after scanning it with MSE and receiving a "no threats found". Immediately after running it, my user account settings were changed to never ask for permission before doing admin things, my browser homepage was set to yessearches, the programs yessearches and wajam appeared in the control panel programs list, and a bunch of gibberish-named processes appeared in the task manager. I manually removed both programs in control panel, closed the processes and reset the account settings. I also deleted the offending .exe, but I can't seem to remove its containing folder because it's "in use". I didn't reboot the PC. I used tweaking, FRST and aswmbr as instructed. In FRST, there was no "all users" checkbox. Addition.txt was too large to attach despite having the 3 things unchecked as the instructions said, so I split it up.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-04-2016
Ran by ndjokic (administrator) on NDJOKIC-PC (13-04-2016 23:09:58)
Running from C:\Users\ndjokic\Desktop\av\frst
Loaded Profiles: ndjokic (Available Profiles: ndjokic)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(TechSmith Corporation) C:\Program Files (x86)\Camtasia\TscHelp.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Gorenie) C:\Users\ndjokic\AppData\Local\Temp\dxdiag.exe
(PortableApps.com) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\ChromiumPortable.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-27] (IDT, Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2804976 2013-10-30] (Synaptics Incorporated)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [chromebrowser] => "C:\Windows\chromebrowser.exe"
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {6a70d0d2-ff26-11e1-b4b9-806e6f6e6963} - F:\SWSETUP\APPINSTL\hpsoftwaresetup.exe
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {daf1934d-3319-11e2-b636-930c393050a1} - H:\setup.exe
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {f21576c4-3c71-11e2-9a04-402cf41c83ea} - G:\autorun\autorun.exe
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158
Tcpip\..\Interfaces\{578D35C4-7A6D-4670-80A2-46D787BCE321}: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158
Tcpip\..\Interfaces\{FF11C6AE-3BBF-47EC-ADA4-DDC7154832BE}: [DhcpNameServer] 7.254.254.254
Internet Explorer:
==================
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://ch.search.yahoo.com/?type=435371&fr=spigot-yhp-ie
SearchScopes: HKU\S-1-5-21-132009455-2026092721-3990303557-1000 -> {69168FDA-9A00-4BF6-979E-D9BE7DCAAAC4} URL = hxxps://ch.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=435371&p={searchTerms}
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-27] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-27] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: hxxp://www.yessearches.com/?ts=AHEqA3IsA30qCE..&v=20160412&uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&mode=ffseng
FF DefaultSearchEngine: yessearches
FF DefaultSearchEngine.US: data:text/plain,browser.search.defaultenginename.US=yessearches
FF SelectedSearchEngine: yessearches
FF Homepage: hxxp://www.yessearches.com/?ts=AHEqA3IsA30qCE..&v=20160412&uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&mode=ffseng
FF Keyword.URL: hxxp://www.yessearches.com/chrome.php?uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&ts=AHEqA3IsA30qCE..&v=20160412&mode=ffexttoolbar&q=
FF NetworkProxy: "autoconfig_url", "http://r-1.ch/twitch.pac"
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-20] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-20] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll [2013-06-26] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2013-08-30] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2010-02-15] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-08-30] (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-132009455-2026092721-3990303557-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ndjokic\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-132009455-2026092721-3990303557-1000: ubisoft.com/uplaypc -> C:\games\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll [No File]
FF SearchPlugin: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\searchplugins\yahoo_ff.xml [2015-11-30]
FF SearchPlugin: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-04-13]
FF SearchPlugin: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\yahoo_ff.xml [2015-11-30]
FF Extension: Rehost Image - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\rehostimage@engy.us.xpi [2016-01-22]
FF Extension: Classic Theme Restorer - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2016-04-10]
FF Extension: ChatZilla - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2016-04-13]
FF Extension: FoxyProxy Standard - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\foxyproxy@eric.h.jung [2016-04-13]
FF Extension: Classic Theme Restorer - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2016-04-10]
FF Extension: ReChat for Twitch™ - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\firefox@rechat.org.xpi [2015-05-29]
FF Extension: FoxyProxy Standard - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\foxyproxy@eric.h.jung [2016-02-18]
FF Extension: YouTube Center - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2015-05-29]
FF Extension: Rehost Image - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\rehostimage@engy.us.xpi [2016-01-22]
FF Extension: ChatZilla - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2015-10-27]
FF Extension: Adblock Plus - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Team Liquid Streams - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{db09811d-efff-4339-a548-8550c7238a30}.xpi [2015-05-29]
FF Extension: GsearchFinder - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [2016-04-12]
FF Extension: ReChat for Twitch™ - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\firefox@rechat.org.xpi [2015-05-29]
FF Extension: YouTube Center - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2015-05-29]
FF Extension: Adblock Plus - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Team Liquid Streams - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{db09811d-efff-4339-a548-8550c7238a30}.xpi [2015-05-29]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-08-30] [not signed]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=4D9800C4DDE8C5E588289AA4A0C32695&v=20160412&ts=AHEqA3IsA30qCE..
CHR StartupUrls: Default -> "hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=4D9800C4DDE8C5E588289AA4A0C32695&v=20160412&ts=AHEqA3IsA30qCE.."
CHR DefaultSearchURL: Default -> hxxp://www.yessearches.com/chrome.php?q={searchTerms}&ts=AHEqA3IsA30qCE..&v=20160412&uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&mode=nnnb
CHR DefaultSearchKeyword: Default -> yessearches
CHR Profile: C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-05]
CHR Extension: (Google Drive) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-05]
CHR Extension: (Adblock for Youtube™) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-03-13]
CHR Extension: (Google Search) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tampermonkey) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2016-04-12]
CHR Extension: (Custom Zoom) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\flacjbeghjebdkbgdlncibepomldoebh [2016-02-08]
CHR Extension: (AdBlock) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-18]
CHR Extension: (RealDownloader) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2015-08-05]
CHR Extension: (Google Hangouts) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2016-03-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (Gmail) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-05]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 BugreportW; C:\Program Files (x86)\yesbnd\mbat.exe [990336 2016-04-12] ()
S2 FedaryqeuleServerSrv; C:\Program Files (x86)\Fedaryqeule\FedaryqeuleServerSrv.exe [315872 2016-04-12] ()
S4 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-28] (Hewlett-Packard Company)
S4 ImDskSvc; C:\Windows\system32\imdsksvc.exe [11264 2012-07-30] (Olof Lagerkvist) [File not signed]
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2009-10-20] (CACE Technologies, Inc.)
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S4 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2014-11-04] (Tunngle.net GmbH) [File not signed]
S4 VMAuthdService; C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [79872 2012-08-15] (VMware, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AWEAlloc; C:\Windows\System32\DRIVERS\awealloc.sys [18384 2012-02-16] (Olof Lagerkvist)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R2 ImDisk; C:\Windows\System32\DRIVERS\imdisk.sys [38416 2012-07-30] (Olof Lagerkvist)
R0 johci; C:\Windows\System32\DRIVERS\johci.sys [26712 2011-01-18] (JMicron Technology Corp.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [47632 2009-10-20] (CACE Technologies, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826048 2010-12-21] ()
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [105816 2012-09-13] (Oracle Corporation)
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31384 2012-08-15] (VMware, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.)
S3 ALSysIO; \??\C:\Users\ndjokic\AppData\Local\Temp\ALSysIO64.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-13 23:08 - 2016-04-13 23:09 - 00000000 ____D C:\FRST
2016-04-13 23:03 - 2016-04-13 23:03 - 00000207 _____ C:\Windows\tweaking.com-regbackup-NDJOKIC-PC-Windows-7-Professional-(64-bit).dat
2016-04-13 23:02 - 2016-04-13 23:10 - 00000000 ____D C:\Users\ndjokic\Desktop\av
2016-04-13 22:41 - 2016-04-13 22:48 - 00000000 ____D C:\Program Files (x86)\yesbnd
2016-04-13 22:41 - 2016-04-13 22:42 - 00000000 ____D C:\Users\ndjokic\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-13 22:41 - 2016-04-13 22:41 - 00014686 _____ C:\Windows\System32\Tasks\Fedaryqeule Server
2016-04-13 22:41 - 2016-04-13 22:41 - 00014508 _____ C:\Windows\System32\Tasks\Ninight Collector
2016-04-13 22:41 - 2016-04-13 22:41 - 00000000 ____D C:\Program Files (x86)\Ninight
2016-04-13 22:41 - 2016-04-13 22:41 - 00000000 ____D C:\Program Files (x86)\Fedaryqeule
2016-04-13 22:40 - 2016-04-13 22:41 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-04-13 22:40 - 2016-04-13 22:40 - 02614035 _____ C:\Windows\chromebrowser.exe
2016-04-10 22:19 - 2016-04-10 23:40 - 00000000 ____D C:\Users\ndjokic\Desktop\fab ub tutorial
2016-04-01 09:35 - 2016-04-01 09:35 - 00000137 _____ C:\Users\ndjokic\Desktop\Steambirds Alliance.url
2016-03-30 22:53 - 2016-03-30 22:53 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\.mono
2016-03-30 22:53 - 2016-03-30 22:53 - 00000000 ____D C:\Users\ndjokic\AppData\LocalLow\SpryFox
2016-03-30 22:53 - 2016-03-30 22:53 - 00000000 ____D C:\ProgramData\.mono
2016-03-28 12:02 - 2016-03-28 12:02 - 00000221 _____ C:\Users\ndjokic\Desktop\TrackMania Nations Forever.url
2016-03-27 18:53 - 2016-04-13 22:03 - 00000000 ____D C:\Users\ndjokic\Documents\TrackMania
2016-03-27 18:53 - 2016-03-28 12:25 - 00000000 ____D C:\ProgramData\TrackMania
2016-03-26 11:09 - 2016-03-26 11:09 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\Crunchy Games
2016-03-26 10:46 - 2016-03-26 10:46 - 00000222 _____ C:\Users\ndjokic\Desktop\StarBreak.url
2016-03-23 17:25 - 2016-03-23 17:25 - 00085593 _____ C:\Users\ndjokic\Desktop\toocscraj.txt
2016-03-23 17:09 - 2016-03-23 17:09 - 00001149 _____ C:\Users\ndjokic\Desktop\toocsp.txt
2016-03-23 17:05 - 2016-03-23 17:05 - 00005648 _____ C:\Users\ndjokic\Desktop\toocscrdb.txt
2016-03-16 11:54 - 2016-03-16 11:56 - 00000000 ____D C:\Users\ndjokic\Desktop\kb
2016-03-14 02:08 - 2016-04-04 10:49 - 00000947 _____ C:\Users\ndjokic\Desktop\justalts.txt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-13 23:10 - 2015-09-11 22:43 - 00017089 _____ C:\Users\ndjokic\Desktop\sb.txt
2016-04-13 22:48 - 2015-08-05 16:34 - 00002068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-13 22:48 - 2015-08-05 16:34 - 00002056 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-13 22:48 - 2014-07-23 15:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-04-13 22:48 - 2012-09-15 13:51 - 00001873 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-13 22:48 - 2012-09-15 13:51 - 00001861 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-04-13 22:48 - 2012-09-15 13:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-04-13 22:45 - 2012-09-15 16:09 - 00000000 ____D C:\games
2016-04-13 22:43 - 2012-09-18 10:23 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\uTorrent
2016-04-13 22:29 - 2014-07-03 21:29 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-13 22:22 - 2009-07-14 06:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-13 22:22 - 2009-07-14 06:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-13 22:14 - 2014-01-27 21:49 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-13 21:46 - 2012-09-18 08:37 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\Skype
2016-04-13 21:41 - 2015-04-18 17:50 - 00003229 _____ C:\Users\ndjokic\Desktop\calendar.txt
2016-04-13 19:21 - 2014-01-27 21:49 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-13 19:01 - 2015-08-06 00:09 - 00000000 ____D C:\Users\ndjokic\Desktop\job stuff
2016-04-13 18:58 - 2013-09-06 20:32 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\TS3Client
2016-04-13 14:12 - 2015-05-05 14:14 - 00006812 _____ C:\Users\ndjokic\Desktop\todo coding.txt
2016-04-13 13:35 - 2012-10-11 21:28 - 00000000 ____D C:\Users\ndjokic\.VirtualBox
2016-04-12 01:00 - 2013-02-02 21:17 - 00000000 ____D C:\Users\ndjokic\Desktop\dls
2016-04-11 21:41 - 2013-07-11 18:26 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\vlc
2016-04-10 22:23 - 2009-07-14 07:13 - 00786766 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-10 22:23 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-10 22:21 - 2015-11-14 15:01 - 00000000 ____D C:\Users\ndjokic\Desktop\sb vid
2016-04-10 22:19 - 2015-11-14 13:15 - 00000000 ____D C:\Users\ndjokic\Desktop\screenrec
2016-04-10 11:01 - 2014-04-23 06:45 - 00003370 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 11:01 - 2014-04-23 06:45 - 00003240 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 07:52 - 2014-08-19 11:19 - 00003348 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 07:52 - 2014-08-19 11:19 - 00003218 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 07:52 - 2012-12-31 19:09 - 00000000 ____D C:\Users\ndjokic\AppData\Local\TSVNCache
2016-04-10 07:51 - 2012-10-11 14:18 - 00000000 ____D C:\ProgramData\VMware
2016-04-10 07:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-08 00:15 - 2016-03-01 16:26 - 00001023 _____ C:\Users\ndjokic\Desktop\fabdoublegav.ahk
2016-04-08 00:15 - 2016-02-18 20:31 - 00001045 _____ C:\Users\ndjokic\Desktop\fabgav.ahk
2016-04-08 00:15 - 2016-02-17 17:35 - 00001015 _____ C:\Users\ndjokic\Desktop\fab.ahk
2016-04-08 00:15 - 2016-01-23 22:00 - 00000993 _____ C:\Users\ndjokic\Desktop\dw autoswitch.ahk
2016-04-08 00:14 - 2016-01-27 17:41 - 00001130 _____ C:\Users\ndjokic\Desktop\fab old.ahk
2016-04-08 00:14 - 2015-09-22 23:19 - 00000469 _____ C:\Users\ndjokic\Desktop\dw.ahk
2016-04-07 14:53 - 2015-12-26 17:33 - 00009843 _____ C:\Users\ndjokic\Documents\NetUptime.txt
2016-04-04 15:44 - 2014-02-17 15:18 - 00000000 ____D C:\Users\ndjokic\Desktop\stuff
2016-04-04 10:57 - 2015-08-22 17:07 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\Jitsi
2016-04-04 10:57 - 2015-08-22 17:07 - 00000000 ____D C:\Users\ndjokic\AppData\Local\Jitsi
2016-04-02 13:02 - 2013-02-25 05:00 - 00000000 ____D C:\Users\ndjokic\Desktop\permutation stuff
2016-04-01 14:47 - 2015-05-09 20:11 - 00005753 _____ C:\Users\ndjokic\Desktop\task ideas.txt
2016-03-28 12:29 - 2012-09-15 12:29 - 00000000 ____D C:\Users\ndjokic\AppData\Local\VirtualStore
2016-03-26 11:09 - 2014-07-12 00:24 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-22 12:12 - 2015-11-22 14:59 - 00000000 ____D C:\Users\ndjokic\AppData\Local\CrashDumps
2016-03-20 11:33 - 2013-06-29 04:46 - 00000000 ____D C:\Users\ndjokic\AppData\Local\Adobe
2016-03-20 11:32 - 2012-09-20 11:32 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-03-20 11:32 - 2012-09-20 11:32 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-02-04 16:54 - 2015-05-11 21:40 - 0001042 _____ () C:\Users\ndjokic\AppData\Roaming\SpeedRunnersLog.txt
2015-02-27 00:29 - 2015-02-27 00:29 - 0000335 _____ () C:\Users\ndjokic\AppData\Local\Perfmon.PerfmonCfg
2012-10-08 13:00 - 2012-10-08 13:13 - 0000600 _____ () C:\Users\ndjokic\AppData\Local\PUTTY.RND
2013-03-30 21:45 - 2015-10-27 18:20 - 0007635 _____ () C:\Users\ndjokic\AppData\Local\Resmon.ResmonCfg
2015-03-21 11:50 - 2015-03-21 11:50 - 0000000 _____ () C:\Users\ndjokic\AppData\Local\{98C9AFB2-5902-4A3A-B059-FE3063B0560A}
Some files in TEMP:
====================
C:\Users\ndjokic\AppData\Local\Temp\ads.exe
C:\Users\ndjokic\AppData\Local\Temp\appstart.exe
C:\Users\ndjokic\AppData\Local\Temp\CodecFixDivx.exe
C:\Users\ndjokic\AppData\Local\Temp\dxdiag.exe
C:\Users\ndjokic\AppData\Local\Temp\jna1360448439069212405.dll
C:\Users\ndjokic\AppData\Local\Temp\jna294053652032923175.dll
C:\Users\ndjokic\AppData\Local\Temp\jna3065417005596449056.dll
C:\Users\ndjokic\AppData\Local\Temp\jna3081127520328937171.dll
C:\Users\ndjokic\AppData\Local\Temp\jna3392912898606427213.dll
C:\Users\ndjokic\AppData\Local\Temp\jna4842340648409676810.dll
C:\Users\ndjokic\AppData\Local\Temp\jna5499633561028554623.dll
C:\Users\ndjokic\AppData\Local\Temp\SkypeSetup.exe
C:\Users\ndjokic\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 00:47
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-04-2016
Ran by ndjokic (administrator) on NDJOKIC-PC (13-04-2016 23:09:58)
Running from C:\Users\ndjokic\Desktop\av\frst
Loaded Profiles: ndjokic (Available Profiles: ndjokic)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(TechSmith Corporation) C:\Program Files (x86)\Camtasia\TscHelp.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Gorenie) C:\Users\ndjokic\AppData\Local\Temp\dxdiag.exe
(PortableApps.com) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\ChromiumPortable.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
(The Chromium Authors & Aluísio Augusto Silva Gonçalves) C:\Users\ndjokic\Desktop\multibox\StarBreakMultibox\App\Chromium\64\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [835072 2011-01-27] (IDT, Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2804976 2013-10-30] (Synaptics Incorporated)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [chromebrowser] => "C:\Windows\chromebrowser.exe"
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {6a70d0d2-ff26-11e1-b4b9-806e6f6e6963} - F:\SWSETUP\APPINSTL\hpsoftwaresetup.exe
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {daf1934d-3319-11e2-b636-930c393050a1} - H:\setup.exe
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\...\MountPoints2: {f21576c4-3c71-11e2-9a04-402cf41c83ea} - G:\autorun\autorun.exe
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (hxxp://tortoisesvn.net)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158
Tcpip\..\Interfaces\{578D35C4-7A6D-4670-80A2-46D787BCE321}: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158
Tcpip\..\Interfaces\{FF11C6AE-3BBF-47EC-ADA4-DDC7154832BE}: [DhcpNameServer] 7.254.254.254
Internet Explorer:
==================
HKU\S-1-5-21-132009455-2026092721-3990303557-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://ch.search.yahoo.com/?type=435371&fr=spigot-yhp-ie
SearchScopes: HKU\S-1-5-21-132009455-2026092721-3990303557-1000 -> {69168FDA-9A00-4BF6-979E-D9BE7DCAAAC4} URL = hxxps://ch.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=435371&p={searchTerms}
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-27] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-27] (Oracle Corporation)
FireFox:
========
FF ProfilePath: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF NewTab: hxxp://www.yessearches.com/?ts=AHEqA3IsA30qCE..&v=20160412&uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&mode=ffseng
FF DefaultSearchEngine: yessearches
FF DefaultSearchEngine.US: data:text/plain,browser.search.defaultenginename.US=yessearches
FF SelectedSearchEngine: yessearches
FF Homepage: hxxp://www.yessearches.com/?ts=AHEqA3IsA30qCE..&v=20160412&uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&mode=ffseng
FF Keyword.URL: hxxp://www.yessearches.com/chrome.php?uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&ts=AHEqA3IsA30qCE..&v=20160412&mode=ffexttoolbar&q=
FF NetworkProxy: "autoconfig_url", "http://r-1.ch/twitch.pac"
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-20] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-20] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll [2013-06-26] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2013-08-30] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2010-02-15] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-08-30] (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-132009455-2026092721-3990303557-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ndjokic\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-132009455-2026092721-3990303557-1000: ubisoft.com/uplaypc -> C:\games\Trials Evolution Gold Edition\datapack\orbit\npuplaypc.dll [No File]
FF SearchPlugin: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\searchplugins\yahoo_ff.xml [2015-11-30]
FF SearchPlugin: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-04-13]
FF SearchPlugin: C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\yahoo_ff.xml [2015-11-30]
FF Extension: Rehost Image - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\rehostimage@engy.us.xpi [2016-01-22]
FF Extension: Classic Theme Restorer - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2016-04-10]
FF Extension: ChatZilla - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2016-04-13]
FF Extension: FoxyProxy Standard - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\extensions\foxyproxy@eric.h.jung [2016-04-13]
FF Extension: Classic Theme Restorer - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2016-04-10]
FF Extension: ReChat for Twitch™ - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\firefox@rechat.org.xpi [2015-05-29]
FF Extension: FoxyProxy Standard - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\foxyproxy@eric.h.jung [2016-02-18]
FF Extension: YouTube Center - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2015-05-29]
FF Extension: Rehost Image - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\rehostimage@engy.us.xpi [2016-01-22]
FF Extension: ChatZilla - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2015-10-27]
FF Extension: Adblock Plus - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Team Liquid Streams - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\arbmcia9.default-1362714903871\Extensions\{db09811d-efff-4339-a548-8550c7238a30}.xpi [2015-05-29]
FF Extension: GsearchFinder - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [2016-04-12]
FF Extension: ReChat for Twitch™ - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\firefox@rechat.org.xpi [2015-05-29]
FF Extension: YouTube Center - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2015-05-29]
FF Extension: Adblock Plus - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-23]
FF Extension: Team Liquid Streams - C:\Users\ndjokic\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{db09811d-efff-4339-a548-8550c7238a30}.xpi [2015-05-29]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-08-30] [not signed]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=4D9800C4DDE8C5E588289AA4A0C32695&v=20160412&ts=AHEqA3IsA30qCE..
CHR StartupUrls: Default -> "hxxp://www.yessearches.com/?mode=nnnb&ptid=wak&uid=4D9800C4DDE8C5E588289AA4A0C32695&v=20160412&ts=AHEqA3IsA30qCE.."
CHR DefaultSearchURL: Default -> hxxp://www.yessearches.com/chrome.php?q={searchTerms}&ts=AHEqA3IsA30qCE..&v=20160412&uid=4D9800C4DDE8C5E588289AA4A0C32695&ptid=wak&mode=nnnb
CHR DefaultSearchKeyword: Default -> yessearches
CHR Profile: C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-05]
CHR Extension: (Google Drive) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-05]
CHR Extension: (Adblock for Youtube™) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-03-13]
CHR Extension: (Google Search) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Tampermonkey) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2016-04-12]
CHR Extension: (Custom Zoom) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\flacjbeghjebdkbgdlncibepomldoebh [2016-02-08]
CHR Extension: (AdBlock) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-18]
CHR Extension: (RealDownloader) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2015-08-05]
CHR Extension: (Google Hangouts) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2016-03-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-03]
CHR Extension: (Gmail) - C:\Users\ndjokic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-05]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 BugreportW; C:\Program Files (x86)\yesbnd\mbat.exe [990336 2016-04-12] ()
S2 FedaryqeuleServerSrv; C:\Program Files (x86)\Fedaryqeule\FedaryqeuleServerSrv.exe [315872 2016-04-12] ()
S4 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [281656 2011-01-28] (Hewlett-Packard Company)
S4 ImDskSvc; C:\Windows\system32\imdsksvc.exe [11264 2012-07-30] (Olof Lagerkvist) [File not signed]
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2009-10-20] (CACE Technologies, Inc.)
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
S4 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2014-11-04] (Tunngle.net GmbH) [File not signed]
S4 VMAuthdService; C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [79872 2012-08-15] (VMware, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AWEAlloc; C:\Windows\System32\DRIVERS\awealloc.sys [18384 2012-02-16] (Olof Lagerkvist)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R2 ImDisk; C:\Windows\System32\DRIVERS\imdisk.sys [38416 2012-07-30] (Olof Lagerkvist)
R0 johci; C:\Windows\System32\DRIVERS\johci.sys [26712 2011-01-18] (JMicron Technology Corp.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [47632 2009-10-20] (CACE Technologies, Inc.)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826048 2010-12-21] ()
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [105816 2012-09-13] (Oracle Corporation)
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31384 2012-08-15] (VMware, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70256 2012-07-06] (VMware, Inc.)
S3 ALSysIO; \??\C:\Users\ndjokic\AppData\Local\Temp\ALSysIO64.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-13 23:08 - 2016-04-13 23:09 - 00000000 ____D C:\FRST
2016-04-13 23:03 - 2016-04-13 23:03 - 00000207 _____ C:\Windows\tweaking.com-regbackup-NDJOKIC-PC-Windows-7-Professional-(64-bit).dat
2016-04-13 23:02 - 2016-04-13 23:10 - 00000000 ____D C:\Users\ndjokic\Desktop\av
2016-04-13 22:41 - 2016-04-13 22:48 - 00000000 ____D C:\Program Files (x86)\yesbnd
2016-04-13 22:41 - 2016-04-13 22:42 - 00000000 ____D C:\Users\ndjokic\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-13 22:41 - 2016-04-13 22:41 - 00014686 _____ C:\Windows\System32\Tasks\Fedaryqeule Server
2016-04-13 22:41 - 2016-04-13 22:41 - 00014508 _____ C:\Windows\System32\Tasks\Ninight Collector
2016-04-13 22:41 - 2016-04-13 22:41 - 00000000 ____D C:\Program Files (x86)\Ninight
2016-04-13 22:41 - 2016-04-13 22:41 - 00000000 ____D C:\Program Files (x86)\Fedaryqeule
2016-04-13 22:40 - 2016-04-13 22:41 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-04-13 22:40 - 2016-04-13 22:40 - 02614035 _____ C:\Windows\chromebrowser.exe
2016-04-10 22:19 - 2016-04-10 23:40 - 00000000 ____D C:\Users\ndjokic\Desktop\fab ub tutorial
2016-04-01 09:35 - 2016-04-01 09:35 - 00000137 _____ C:\Users\ndjokic\Desktop\Steambirds Alliance.url
2016-03-30 22:53 - 2016-03-30 22:53 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\.mono
2016-03-30 22:53 - 2016-03-30 22:53 - 00000000 ____D C:\Users\ndjokic\AppData\LocalLow\SpryFox
2016-03-30 22:53 - 2016-03-30 22:53 - 00000000 ____D C:\ProgramData\.mono
2016-03-28 12:02 - 2016-03-28 12:02 - 00000221 _____ C:\Users\ndjokic\Desktop\TrackMania Nations Forever.url
2016-03-27 18:53 - 2016-04-13 22:03 - 00000000 ____D C:\Users\ndjokic\Documents\TrackMania
2016-03-27 18:53 - 2016-03-28 12:25 - 00000000 ____D C:\ProgramData\TrackMania
2016-03-26 11:09 - 2016-03-26 11:09 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\Crunchy Games
2016-03-26 10:46 - 2016-03-26 10:46 - 00000222 _____ C:\Users\ndjokic\Desktop\StarBreak.url
2016-03-23 17:25 - 2016-03-23 17:25 - 00085593 _____ C:\Users\ndjokic\Desktop\toocscraj.txt
2016-03-23 17:09 - 2016-03-23 17:09 - 00001149 _____ C:\Users\ndjokic\Desktop\toocsp.txt
2016-03-23 17:05 - 2016-03-23 17:05 - 00005648 _____ C:\Users\ndjokic\Desktop\toocscrdb.txt
2016-03-16 11:54 - 2016-03-16 11:56 - 00000000 ____D C:\Users\ndjokic\Desktop\kb
2016-03-14 02:08 - 2016-04-04 10:49 - 00000947 _____ C:\Users\ndjokic\Desktop\justalts.txt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-13 23:10 - 2015-09-11 22:43 - 00017089 _____ C:\Users\ndjokic\Desktop\sb.txt
2016-04-13 22:48 - 2015-08-05 16:34 - 00002068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-13 22:48 - 2015-08-05 16:34 - 00002056 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-13 22:48 - 2014-07-23 15:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-04-13 22:48 - 2012-09-15 13:51 - 00001873 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-04-13 22:48 - 2012-09-15 13:51 - 00001861 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-04-13 22:48 - 2012-09-15 13:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-04-13 22:45 - 2012-09-15 16:09 - 00000000 ____D C:\games
2016-04-13 22:43 - 2012-09-18 10:23 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\uTorrent
2016-04-13 22:29 - 2014-07-03 21:29 - 00000000 ____D C:\Program Files (x86)\Steam
2016-04-13 22:22 - 2009-07-14 06:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-13 22:22 - 2009-07-14 06:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-13 22:14 - 2014-01-27 21:49 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-13 21:46 - 2012-09-18 08:37 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\Skype
2016-04-13 21:41 - 2015-04-18 17:50 - 00003229 _____ C:\Users\ndjokic\Desktop\calendar.txt
2016-04-13 19:21 - 2014-01-27 21:49 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-13 19:01 - 2015-08-06 00:09 - 00000000 ____D C:\Users\ndjokic\Desktop\job stuff
2016-04-13 18:58 - 2013-09-06 20:32 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\TS3Client
2016-04-13 14:12 - 2015-05-05 14:14 - 00006812 _____ C:\Users\ndjokic\Desktop\todo coding.txt
2016-04-13 13:35 - 2012-10-11 21:28 - 00000000 ____D C:\Users\ndjokic\.VirtualBox
2016-04-12 01:00 - 2013-02-02 21:17 - 00000000 ____D C:\Users\ndjokic\Desktop\dls
2016-04-11 21:41 - 2013-07-11 18:26 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\vlc
2016-04-10 22:23 - 2009-07-14 07:13 - 00786766 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-10 22:23 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-04-10 22:21 - 2015-11-14 15:01 - 00000000 ____D C:\Users\ndjokic\Desktop\sb vid
2016-04-10 22:19 - 2015-11-14 13:15 - 00000000 ____D C:\Users\ndjokic\Desktop\screenrec
2016-04-10 11:01 - 2014-04-23 06:45 - 00003370 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 11:01 - 2014-04-23 06:45 - 00003240 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 07:52 - 2014-08-19 11:19 - 00003348 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 07:52 - 2014-08-19 11:19 - 00003218 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-132009455-2026092721-3990303557-1000
2016-04-10 07:52 - 2012-12-31 19:09 - 00000000 ____D C:\Users\ndjokic\AppData\Local\TSVNCache
2016-04-10 07:51 - 2012-10-11 14:18 - 00000000 ____D C:\ProgramData\VMware
2016-04-10 07:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-08 00:15 - 2016-03-01 16:26 - 00001023 _____ C:\Users\ndjokic\Desktop\fabdoublegav.ahk
2016-04-08 00:15 - 2016-02-18 20:31 - 00001045 _____ C:\Users\ndjokic\Desktop\fabgav.ahk
2016-04-08 00:15 - 2016-02-17 17:35 - 00001015 _____ C:\Users\ndjokic\Desktop\fab.ahk
2016-04-08 00:15 - 2016-01-23 22:00 - 00000993 _____ C:\Users\ndjokic\Desktop\dw autoswitch.ahk
2016-04-08 00:14 - 2016-01-27 17:41 - 00001130 _____ C:\Users\ndjokic\Desktop\fab old.ahk
2016-04-08 00:14 - 2015-09-22 23:19 - 00000469 _____ C:\Users\ndjokic\Desktop\dw.ahk
2016-04-07 14:53 - 2015-12-26 17:33 - 00009843 _____ C:\Users\ndjokic\Documents\NetUptime.txt
2016-04-04 15:44 - 2014-02-17 15:18 - 00000000 ____D C:\Users\ndjokic\Desktop\stuff
2016-04-04 10:57 - 2015-08-22 17:07 - 00000000 ____D C:\Users\ndjokic\AppData\Roaming\Jitsi
2016-04-04 10:57 - 2015-08-22 17:07 - 00000000 ____D C:\Users\ndjokic\AppData\Local\Jitsi
2016-04-02 13:02 - 2013-02-25 05:00 - 00000000 ____D C:\Users\ndjokic\Desktop\permutation stuff
2016-04-01 14:47 - 2015-05-09 20:11 - 00005753 _____ C:\Users\ndjokic\Desktop\task ideas.txt
2016-03-28 12:29 - 2012-09-15 12:29 - 00000000 ____D C:\Users\ndjokic\AppData\Local\VirtualStore
2016-03-26 11:09 - 2014-07-12 00:24 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-22 12:12 - 2015-11-22 14:59 - 00000000 ____D C:\Users\ndjokic\AppData\Local\CrashDumps
2016-03-20 11:33 - 2013-06-29 04:46 - 00000000 ____D C:\Users\ndjokic\AppData\Local\Adobe
2016-03-20 11:32 - 2012-09-20 11:32 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-03-20 11:32 - 2012-09-20 11:32 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-02-04 16:54 - 2015-05-11 21:40 - 0001042 _____ () C:\Users\ndjokic\AppData\Roaming\SpeedRunnersLog.txt
2015-02-27 00:29 - 2015-02-27 00:29 - 0000335 _____ () C:\Users\ndjokic\AppData\Local\Perfmon.PerfmonCfg
2012-10-08 13:00 - 2012-10-08 13:13 - 0000600 _____ () C:\Users\ndjokic\AppData\Local\PUTTY.RND
2013-03-30 21:45 - 2015-10-27 18:20 - 0007635 _____ () C:\Users\ndjokic\AppData\Local\Resmon.ResmonCfg
2015-03-21 11:50 - 2015-03-21 11:50 - 0000000 _____ () C:\Users\ndjokic\AppData\Local\{98C9AFB2-5902-4A3A-B059-FE3063B0560A}
Some files in TEMP:
====================
C:\Users\ndjokic\AppData\Local\Temp\ads.exe
C:\Users\ndjokic\AppData\Local\Temp\appstart.exe
C:\Users\ndjokic\AppData\Local\Temp\CodecFixDivx.exe
C:\Users\ndjokic\AppData\Local\Temp\dxdiag.exe
C:\Users\ndjokic\AppData\Local\Temp\jna1360448439069212405.dll
C:\Users\ndjokic\AppData\Local\Temp\jna294053652032923175.dll
C:\Users\ndjokic\AppData\Local\Temp\jna3065417005596449056.dll
C:\Users\ndjokic\AppData\Local\Temp\jna3081127520328937171.dll
C:\Users\ndjokic\AppData\Local\Temp\jna3392912898606427213.dll
C:\Users\ndjokic\AppData\Local\Temp\jna4842340648409676810.dll
C:\Users\ndjokic\AppData\Local\Temp\jna5499633561028554623.dll
C:\Users\ndjokic\AppData\Local\Temp\SkypeSetup.exe
C:\Users\ndjokic\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-08 00:47
==================== End of FRST.txt ============================