Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Pc possibly infected with a Keylogger.


  • This topic is locked This topic is locked

#1
Helpmeout12

Helpmeout12

    Member

  • Member
  • PipPip
  • 15 posts

So about 3 months ago I downloaded something a little risky. About 1 month after I received an email saying that my Facebook had an attempted log in from China. I would like to note that never in my life has any account been hacked. In that 1 month I am 100% sure I did not enter in any passwords anywhere, they were all saved to my browser. However I had to enter my password for facebook and about 1 week after doing so was when the attempted log in happened. So I found a forum to help me out to see if there was any viruses on my computer. They ran me through I don't know how many different kinds of virus scans and I thought everything was fine. Fast forward to two days ago there was another attempted log in to a different website which had a different password to the one that was used to get to my facebook. So now I am siting here not sure what to do, and am here now looking for some help. At the point that I am at right now I can only assume that my computer has some sort of key logger. There is absolutely no way that the last two accounts passwords could have been in the hands of someone without so. The program that I downloaded did ask to download did ask to make changes to my driver if that helps you guys help my situation out. 


Edited by Helpmeout12, 21 April 2016 - 11:37 PM.

  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)

Everything gets download to the desktop and tools are "Run as administrator."

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

  • 0

#3
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Sorry for the late reply, email didn't notify me but I just followed this so hopefully i get emails now :)
 
 
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
Ran by Josefina (administrator) on GUADALUPE (25-04-2016 02:44:08)
Running from C:\Users\Josefina\Downloads
Loaded Profiles: Josefina (Available Profiles: Josefina)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
( ) C:\Windows\System32\dleacoms.exe
( Rsupport Corporation) C:\Program Files (x86)\RSUPPORT\MobizenService\MobizenService.exe
(OctaneVPN) C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\octanevpnsrvc.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\RSUPPORT\MobizenService\dat\adb.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(Spotify Ltd) C:\Users\Josefina\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Insight Software Solutions) C:\Program Files (x86)\ShortKeys2\shklite.exe
() C:\Program Files (x86)\OctaneVPN\octanevpn.exe
(TOSHIBA) C:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TDUSrv64.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
() C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\Josefina\AppData\Local\Razer\InGameEngine\cache\RzStats.Manager\RzCefRenderProcess.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Eric Zhang) C:\Users\Josefina\Desktop\EZBlocker.exe
(Microsoft Corporation) C:\Windows\System32\SndVol.exe
(Spotify Ltd) C:\Users\Josefina\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Josefina\AppData\Roaming\Spotify\SpotifyCrashService.exe
(Spotify Ltd) C:\Users\Josefina\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Josefina\AppData\Roaming\Spotify\Spotify.exe
() C:\Program Files\AutoHotkey\AutoHotkey.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Josefina\Downloads\FRST64 (1).exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-01-20] (Realtek Semiconductor)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-10-08] (TOSHIBA Corporation)
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179288 2014-01-04] (TOSHIBA Corporation)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296008 2013-10-21] (TOSHIBA Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-03-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516512 2013-07-23] (TOSHIBA)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [593216 2015-08-31] (Razer Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66328 2016-03-30] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [807392 2016-03-10] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\Run: [Spotify Web Helper] => C:\Users\Josefina\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1525360 2016-04-16] (Spotify Ltd)
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3586848 2016-02-17] (Nota Inc.)
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [51662464 2016-04-08] (Skype Technologies S.A.)
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\Run: [NetUptimeMonitor] => C:\Program Files (x86)\Net Uptime Monitor\NetUptimeMonitor.exe
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\RunOnce: [Application Restart #1] => C:\Users\Josefina\AppData\Local\Pokki\Engine\HostAppService.exe  --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable- (the data entry has 555 more characters).
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-03-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-03-30] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-03-30] (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys Lite.lnk [2014-08-11]
ShortcutTarget: ShortKeys Lite.lnk -> C:\Program Files (x86)\ShortKeys2\shklite.exe (Insight Software Solutions)
Startup: C:\Users\Josefina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OctaneVPN.lnk [2016-01-13]
ShortcutTarget: OctaneVPN.lnk -> C:\Program Files (x86)\OctaneVPN\octanevpn.exe ()
Startup: C:\Users\Josefina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-02-26]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyEnable: [S-1-5-21-328124280-1994820816-3203177752-1001] => Proxy is enabled.
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 68.105.28.12
Tcpip\..\Interfaces\{50356B71-1720-4E53-9A83-75422809EF35}: [DhcpNameServer] 192.168.1.1 68.105.28.12
Tcpip\..\Interfaces\{A3CDCC32-6451-40A0-960E-00C6CDEC270C}: [DhcpNameServer] 10.10.2.1
Tcpip\..\Interfaces\{C4CA73C3-BE41-48FE-9D4C-6AC0B598965C}: [DhcpNameServer] 192.168.1.1 68.105.28.12
 
Internet Explorer:
==================
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.twitch.tv/directory/following
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com/?pc=TNJB
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-20] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-24] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-24] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-05-07] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Josefina\AppData\Roaming\Mozilla\Firefox\Profiles\yrpp3yb8.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-10] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-10] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-04-23] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-328124280-1994820816-3203177752-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Josefina\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-10-08] (Unity Technologies ApS)
FF Extension: Avira Browser Safety - C:\Users\Josefina\AppData\Roaming\Mozilla\Firefox\Profiles\yrpp3yb8.default\Extensions\[email protected] [2016-02-25]
FF Extension: Adblock Plus - C:\Users\Josefina\AppData\Roaming\Mozilla\Firefox\Profiles\yrpp3yb8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-03-14] [not signed]
 
Chrome: 
=======
CHR Profile: C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2016-03-20]
CHR Extension: (Google Drive) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (Dwarf Galaxy NGC 4449 Theme) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\babcfbkleafekpcmmmcdjfengfddbjpe [2015-01-09]
CHR Extension: (YouTube) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Bing Pong Helper) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\cohnfldcnegepfhhfbcgecblgjdcmcka [2016-04-22]
CHR Extension: (Google Search) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2016-03-09]
CHR Extension: (Avira Browser Safety) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-04-12]
CHR Extension: (Google Docs Offline) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (AdBlock) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-04-15]
CHR Extension: (Cenafy) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndchmakhfaakbkhnkdgambadneloplnn [2015-11-03]
CHR Extension: (Gmail) - C:\Users\Josefina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-27]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [140288 2014-03-20] () [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [955736 2016-03-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [466504 2016-03-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [466504 2016-03-10] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1424880 2016-03-10] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [272304 2016-03-30] (Avira Operations GmbH & Co. KG)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [814464 2015-02-08] ()
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-02-19] (BitRaider, LLC)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
R2 dlea_device; C:\Windows\system32\dleacoms.exe [1054888 2009-07-01] ( )
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 Mobizen plugin; C:\Program Files (x86)\RSUPPORT\MobizenService\MobizenService.exe [3353872 2015-12-28] ( Rsupport Corporation)
R2 OctaneVPNSrvc; C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\octanevpnsrvc.exe [845342 2015-07-07] (OctaneVPN) [File not signed]
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [37504 2016-03-10] (The OpenVPN Project)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187824 2016-03-21] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc.)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [132864 2016-04-06] (Razer Inc.)
R2 RzSurroundVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe [4254720 2015-07-28] (A-Volute) [File not signed]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-30] (DEVGURU Co., LTD.)
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-23] (Microsoft Corporation)
S2 ZAMSvc; "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /service [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17640 2013-10-24] (Advanced Micro Devices, INC.)
S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. )
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3881984 2014-01-06] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-12-20] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128664 2016-03-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [137952 2016-03-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [35488 2016-02-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [68936 2016-03-10] (Avira Operations GmbH & Co. KG)
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-02-19] (BitRaider)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
S3 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc.)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [293592 2014-02-11] (Realtek Semiconductor Corp.)
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc)
S3 RZMAELSTROMVADService; C:\Windows\system32\drivers\RzMaelstromVAD.sys [32768 2014-06-09] (Windows ® Win 7 DDK provider)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-03-10] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137840 2016-03-30] (Razer, Inc.)
R3 RZSURROUNDVADService; C:\Windows\system32\drivers\RzSurroundVAD.sys [40640 2015-07-28] (Windows ® Win 7 DDK provider)
R3 SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver_AMDASF.sys [30448 2014-03-25] (Synaptics Incorporated)
S3 ss_conn_usb_driver; C:\Windows\System32\Drivers\ss_conn_usb_driver.sys [26392 2014-12-30] (DEVGURU Co., LTD.)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [33168 2013-10-10] (Windows ® Win 7 DDK provider)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-03-23] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-03-23] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-25 02:44 - 2016-04-25 02:45 - 00022418 _____ C:\Users\Josefina\Downloads\FRST.txt
2016-04-25 02:43 - 2016-04-25 02:43 - 02375680 _____ (Farbar) C:\Users\Josefina\Downloads\FRST64 (1).exe
2016-04-24 18:30 - 2016-04-24 18:30 - 00738368 _____ (Oracle Corporation) C:\Users\Josefina\Downloads\chromeinstall-8u91.exe
2016-04-24 17:46 - 2016-04-24 17:58 - 00000000 ____D C:\Users\Josefina\Desktop\spotfiy
2016-04-21 21:32 - 2016-04-21 21:33 - 00000000 ____D C:\Users\Josefina\AppData\Local\PokerStars.USNJ
2016-04-21 21:32 - 2016-04-21 21:32 - 00001985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars NJ.lnk
2016-04-21 21:32 - 2016-04-21 21:32 - 00001979 _____ C:\Users\Public\Desktop\PokerStars NJ.lnk
2016-04-21 21:32 - 2016-04-21 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.USNJ
2016-04-21 21:29 - 2016-04-21 21:33 - 00000000 ____D C:\Program Files (x86)\PokerStars.USNJ
2016-04-21 21:26 - 2016-04-21 21:28 - 82539184 _____ (PokerStars) C:\Users\Josefina\Downloads\PokerStarsInstallUSNJ.exe
2016-04-20 18:34 - 2016-04-20 18:34 - 00000935 _____ C:\Users\Public\Desktop\OpenVPN GUI.lnk
2016-04-20 18:33 - 2016-04-20 18:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN
2016-04-20 18:33 - 2016-04-20 18:34 - 00000000 ____D C:\Program Files\TAP-Windows
2016-04-20 18:33 - 2016-04-20 18:34 - 00000000 ____D C:\Program Files\OpenVPN
2016-04-20 18:33 - 2016-04-20 18:33 - 00000000 ____D C:\Users\Josefina\Desktop\octtn
2016-04-20 18:33 - 2016-04-20 18:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TAP-Windows
2016-04-20 18:32 - 2016-04-20 18:32 - 01816664 _____ C:\Users\Josefina\Desktop\openvpn-install-2.3.10-I603-x86_64.exe
2016-04-20 18:31 - 2016-04-20 18:32 - 01816664 _____ C:\Users\Josefina\Downloads\openvpn-install-2.3.10-I603-x86_64.exe
2016-04-19 11:34 - 2016-04-19 21:56 - 00000000 ____D C:\Users\Josefina\AppData\Local\Jagex
2016-04-19 11:34 - 2016-04-19 21:56 - 00000000 ____D C:\ProgramData\Jagex
2016-04-19 11:34 - 2016-04-19 11:34 - 00000177 _____ C:\Users\Public\Desktop\RuneScape Launcher.url
2016-04-19 11:34 - 2016-04-19 11:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jagex
2016-04-19 11:34 - 2016-04-19 11:34 - 00000000 ____D C:\Program Files\Jagex
2016-04-19 11:33 - 2015-08-22 06:42 - 00901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:42 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-04-19 11:33 - 2015-08-22 06:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-04-19 11:30 - 2016-04-19 11:30 - 03859928 _____ (Jagex Ltd ) C:\Users\Josefina\Downloads\RuneScape-Setup.exe
2016-04-15 22:12 - 2016-04-15 22:12 - 00001268 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
2016-04-15 22:11 - 2016-03-10 11:17 - 00044144 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpmgrk.sys
2016-04-15 22:09 - 2016-04-15 22:09 - 122010296 _____ (Razer Inc. ) C:\Users\Josefina\Downloads\RazerCortexSetup_7.1.14.12241.exe
2016-04-15 13:47 - 2016-04-15 13:47 - 00000382 _____ C:\Users\Josefina\Documents\NetUptime 20160415 132959.txt
2016-04-15 00:02 - 2016-04-15 00:02 - 00000000 ____D C:\Users\Josefina\jagexcache5
2016-04-15 00:02 - 2016-04-15 00:02 - 00000000 ____D C:\Users\Josefina\jagexcache4
2016-04-15 00:02 - 2016-04-15 00:02 - 00000000 ____D C:\Users\Josefina\jagexcache3
2016-04-15 00:02 - 2016-04-15 00:02 - 00000000 ____D C:\Users\Josefina\jagexcache2
2016-04-14 14:07 - 2016-04-14 14:07 - 00000382 _____ C:\Users\Josefina\Documents\NetUptime 20160414 140649.txt
2016-04-13 14:52 - 2016-04-13 14:52 - 00000382 _____ C:\Users\Josefina\Documents\NetUptime 20160413 143254.txt
2016-04-13 01:00 - 2016-04-13 01:00 - 00000083 _____ C:\Users\Josefina\Desktop\markmywords.txt
2016-04-12 13:22 - 2016-04-12 13:22 - 00000382 _____ C:\Users\Josefina\Documents\NetUptime 20160412 132135.txt
2016-04-12 00:26 - 2016-04-12 00:26 - 00000384 _____ C:\Users\Josefina\Documents\NetUptime 20160412 002559.txt
2016-04-11 13:45 - 2016-04-11 13:47 - 00000382 _____ C:\Users\Josefina\Documents\NetUptime 20160411 134517.txt
2016-04-11 00:02 - 2016-04-11 00:02 - 00000384 _____ C:\Users\Josefina\Documents\NetUptime 20160411 000004.txt
2016-04-10 15:31 - 2016-04-10 16:00 - 00000382 _____ C:\Users\Josefina\Documents\NetUptime 20160410 153002.txt
2016-04-10 00:16 - 2016-04-10 00:17 - 46798944 _____ (Maxthon International ltd.) C:\Users\Josefina\Downloads\mx4.9.1.1000 (1).exe
2016-04-10 00:14 - 2016-04-10 00:14 - 00000008 _____ C:\Users\Josefina\Desktop\untitled(1)
2016-04-10 00:10 - 2016-04-10 00:10 - 00000008 _____ C:\Users\Josefina\Desktop\untitled
2016-04-09 23:59 - 2016-04-10 00:00 - 46798944 _____ (Maxthon International ltd.) C:\Users\Josefina\Downloads\mx4.9.1.1000.exe
2016-04-09 15:46 - 2016-04-09 16:07 - 00000380 _____ C:\Users\Josefina\Documents\NetUptime 20160409 152303.txt
2016-04-08 20:33 - 2016-04-08 21:04 - 00000538 _____ C:\Users\Josefina\Documents\NetUptime 20160408 203348.txt
2016-04-08 19:22 - 2016-04-08 19:56 - 00000380 _____ C:\Users\Josefina\Documents\NetUptime 20160408 192001.txt
2016-04-07 20:28 - 2016-04-07 21:25 - 00000568 _____ C:\Users\Josefina\Documents\NetUptime 20160407 202807.txt
2016-04-07 19:42 - 2016-04-07 20:27 - 00000538 _____ C:\Users\Josefina\Documents\NetUptime 20160407 194153.txt
2016-04-07 19:39 - 2016-04-07 19:39 - 17752712 _____ (Microsoft Corporation) C:\Users\Josefina\Downloads\NUMSetup.exe
2016-04-03 21:50 - 2016-04-21 21:18 - 00000124 _____ C:\Users\Josefina\Desktop\Dharocker(1).ahk
2016-04-03 21:41 - 2016-04-21 14:15 - 00000000 ____D C:\Users\Josefina\Desktop\ahk script
2016-03-30 12:27 - 2016-03-30 12:27 - 03081488 _____ C:\Users\Josefina\Downloads\AutoHotkey112305_Install (3).exe
2016-03-30 12:23 - 2016-03-30 12:24 - 00000000 ____D C:\Users\Josefina\Desktop\ahk
2016-03-30 12:23 - 2016-03-30 12:23 - 00575274 _____ C:\Users\Josefina\Downloads\AutoHotkey112305_x64.zip
2016-03-30 12:23 - 2016-03-30 12:23 - 00575274 _____ C:\Users\Josefina\Desktop\AutoHotkey112305_x64.zip
2016-03-30 12:20 - 2016-03-30 12:20 - 03081488 _____ C:\Users\Josefina\Downloads\AutoHotkey112305_Install (2).exe
2016-03-30 12:20 - 2016-03-30 12:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
2016-03-30 12:20 - 2016-03-30 12:20 - 00000000 ____D C:\Program Files\AutoHotkey
2016-03-29 02:52 - 2016-03-29 02:52 - 03081488 _____ C:\Users\Josefina\Downloads\AutoHotkey112305_Install (1).exe
2016-03-29 02:46 - 2016-03-29 02:46 - 03081488 _____ C:\Users\Josefina\Downloads\AutoHotkey112305_Install.exe
2016-03-28 23:41 - 2016-03-28 23:41 - 00006847 _____ C:\Users\Josefina\Desktop\^09F478495FEAC78BCBDA8775F8AA9F996987B1932EEBD31A22^pimgpsh_thumbnail_win_distr.jpg
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-25 02:45 - 2015-04-09 02:30 - 00000000 _____ C:\Windows\system32\RzSurroundVADAudioDeviceManager_log.txt
2016-04-25 02:44 - 2016-03-17 13:53 - 00000000 ____D C:\FRST
2016-04-25 02:43 - 2014-06-24 00:56 - 00000000 ____D C:\Users\Josefina\AppData\Roaming\Spotify
2016-04-25 02:40 - 2014-06-23 18:53 - 00000000 ____D C:\Users\Josefina\AppData\Roaming\Skype
2016-04-25 02:38 - 2014-06-23 18:15 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-328124280-1994820816-3203177752-1001
2016-04-25 02:04 - 2014-05-21 12:01 - 00000926 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-25 01:07 - 2014-06-23 18:29 - 00000047 _____ C:\Users\Josefina\jagex_cl_oldschool_LIVE.dat
2016-04-24 23:51 - 2014-06-24 00:57 - 00000000 ____D C:\Users\Josefina\AppData\Local\Spotify
2016-04-24 23:19 - 2016-03-12 01:34 - 00000376 _____ C:\Users\Josefina\Desktop\EZBlocker-log.txt
2016-04-24 18:38 - 2014-06-23 18:29 - 00000000 ____R C:\Users\Josefina\random.dat
2016-04-24 18:38 - 2014-06-23 18:06 - 00000000 ____D C:\Users\Josefina
2016-04-24 18:34 - 2014-09-18 02:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-04-24 18:34 - 2014-09-18 02:29 - 00000000 ____D C:\Program Files (x86)\Java
2016-04-24 18:32 - 2015-12-13 00:19 - 00000000 ____D C:\Users\Josefina\.oracle_jre_usage
2016-04-24 18:32 - 2014-09-18 02:29 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-04-24 17:46 - 2016-03-09 16:17 - 00000000 ____D C:\Users\Josefina\AppData\Local\Eric_Zhang
2016-04-24 17:12 - 2016-01-13 10:27 - 00000000 ____D C:\Users\Josefina\AppData\Roaming\OctaneVPN
2016-04-24 17:11 - 2014-09-11 22:31 - 00000000 __RDO C:\Users\Josefina\OneDrive
2016-04-24 17:11 - 2014-05-21 12:01 - 00000922 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-21 12:58 - 2016-02-25 12:24 - 00001121 _____ C:\Users\Public\Desktop\Avira Launcher.lnk
2016-04-21 12:58 - 2016-02-25 12:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-04-21 12:58 - 2014-05-21 11:25 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-21 12:54 - 2014-05-21 11:28 - 17334188 _____ C:\Windows\SysWOW64\rootpa.e2e
2016-04-21 12:53 - 2013-08-22 07:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-20 20:32 - 2015-12-10 12:12 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-04-20 20:32 - 2014-06-23 18:53 - 00000000 ____D C:\ProgramData\Skype
2016-04-20 18:51 - 2016-01-10 20:19 - 00000000 ____D C:\Users\Josefina\AppData\Roaming\.tribot
2016-04-20 18:38 - 2014-07-15 11:34 - 00000000 ____D C:\Program Files (x86)\Verizon
2016-04-20 18:37 - 2014-08-03 09:20 - 00000000 ____D C:\Users\Josefina\AppData\Roaming\Verizon
2016-04-20 13:56 - 2013-08-22 08:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-04-20 13:55 - 2013-08-22 06:36 - 00000000 ____D C:\Windows\Inf
2016-04-20 13:51 - 2015-04-23 10:04 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-04-20 13:38 - 2013-08-22 08:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-20 13:38 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\AppReadiness
2016-04-19 22:49 - 2014-06-30 10:50 - 05214720 ___SH C:\Users\Josefina\Desktop\Thumbs.db
2016-04-19 11:59 - 2014-09-17 23:27 - 00000000 ____D C:\Program Files (x86)\SwiftKit
2016-04-19 11:34 - 2013-08-22 08:20 - 00000000 ____D C:\Windows\CbsTemp
2016-04-19 11:28 - 2014-06-24 20:33 - 00000047 _____ C:\Users\Josefina\jagex_cl_runescape_LIVE.dat
2016-04-17 20:05 - 2014-05-21 12:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-04-16 01:52 - 2016-03-18 20:24 - 00000000 ____D C:\Program Files\9-lab
2016-04-15 22:13 - 2014-09-02 20:38 - 00000000 ____D C:\Users\Josefina\AppData\Local\Razer
2016-04-15 22:12 - 2014-12-06 17:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2016-04-15 22:11 - 2014-09-02 20:36 - 00000000 ____D C:\ProgramData\Razer
2016-04-15 22:11 - 2014-09-02 20:36 - 00000000 ____D C:\Program Files (x86)\Razer
2016-04-14 14:25 - 2015-11-02 21:31 - 00000312 _____ C:\Users\Josefina\Desktop\AutoHotkey.ahk
2016-04-13 16:45 - 2014-07-10 10:44 - 00453280 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-13 00:06 - 2014-06-23 18:07 - 00000000 ____D C:\Users\Josefina\AppData\Local\Packages
2016-04-11 00:09 - 2014-07-08 15:15 - 00000000 ____D C:\Users\Josefina\AppData\Local\CrashDumps
2016-04-10 23:57 - 2016-03-18 21:36 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2016-04-10 17:03 - 2015-04-08 15:09 - 00000000 ____D C:\Users\Josefina\AppData\LocalLow\Adblock Plus for IE
2016-04-10 17:00 - 2016-03-18 21:36 - 00155097 _____ C:\Windows\ZAM.krnl.trace
2016-04-10 17:00 - 2016-03-18 21:36 - 00001071 _____ C:\Windows\ZAM_Guard.krnl.trace
2016-04-07 13:09 - 2014-06-23 18:16 - 00002186 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-07 13:09 - 2014-06-23 18:16 - 00002174 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-06 16:06 - 2016-03-19 22:53 - 00000000 ____D C:\Users\Josefina\Desktop\screenshot
2016-04-04 02:17 - 2014-04-10 22:08 - 00863592 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-30 12:20 - 2013-08-22 12:12 - 00000000 ____D C:\Windows\ShellNew
2016-03-30 11:43 - 2014-12-06 17:30 - 00137840 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpnk.sys
 
Some files in TEMP:
====================
C:\Users\Josefina\AppData\Local\Temp\avgnt.exe
C:\Users\Josefina\AppData\Local\Temp\togl_31c151da5.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-04-15 13:41
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Josefina (2016-03-17 13:55:38)
Running from C:\Users\Josefina\Desktop
Windows 8.1 (X64) (2014-06-24 01:07:44)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-328124280-1994820816-3203177752-500 - Administrator - Disabled)
Guest (S-1-5-21-328124280-1994820816-3203177752-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-328124280-1994820816-3203177752-1003 - Limited - Enabled)
Josefina (S-1-5-21-328124280-1994820816-3203177752-1001 - Administrator - Enabled) => C:\Users\Josefina
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{77588F59-3C58-4675-8EEE-998E5BC33CF4}) (Version: 1.4 - Eyeo GmbH)
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.182 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07)  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.14) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.14 - Adobe Systems Incorporated)
AirServer Universal (x64) (HKLM\...\{6E97BF1A-1BC4-4624-8841-C5B03F234C87}) (Version: 3.1.5 - App Dynamic)
Amazon 1Button App (HKLM-x32\...\{893CB813-4179-4BFE-8D33-ABCC38816B48}) (Version: 1.0.6 - Amazon)
Amazon Kindle (HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\Amazon Kindle) (Version: 1.15.0.43061 - Amazon)
AMD Catalyst Install Manager (HKLM\...\{F80AA689-1C29-E046-3BA4-73A675AE865E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros)
AutoHotkey 1.1.22.07 (HKLM\...\AutoHotkey) (Version: 1.1.22.07 - Lexikos)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.16.282 - Avira Operations GmbH & Co. KG)
Avira Launcher (HKLM-x32\...\{3b87484e-d70b-4b4f-ad59-2ae89571e2cf}) (Version: 1.1.56.9119 - Avira Operations GmbH & Co. KG)
Avira Launcher (x32 Version: 1.1.56.9119 - Avira Operations GmbH & Co. KG) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cain & Abel 4.9.56 (HKLM-x32\...\Cain & Abel 4.9.56) (Version:  - )
Camtasia Studio 8 (HKLM-x32\...\{765AD29A-7EF5-4456-8F6F-83467E52AB52}) (Version: 8.4.3.1792 - TechSmith Corporation)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3920.05 - CyberLink Corp.)
Digital Pass Launcher (HKLM-x32\...\{2359C6E9-DE4F-4FDA-9C12-AE6EFC2EE330}) (Version: 1.0.0.0 - TOSHIBA America Information Systems, Inc)
Equalify v2.5.3 (Stable) (HKLM-x32\...\{33EC4F70-9F4B-406F-BB2A-F75A285E927D}) (Version: 2.5.3.0 - Equalify)
Equalizer APO (HKLM\...\EqualizerAPO) (Version: 0.9.1 - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)
Google Drive (HKLM-x32\...\{895D0391-459F-4D45-B8DD-13F0DE70C66E}) (Version: 1.28.1549.1322 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
Gyazo 3.2.1 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
IHA_MessageCenter (HKLM-x32\...\{91228D59-1017-4884-ABC2-B3C018F7295B}) (Version: 2.0.50 - Verizon)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.9.31 - www.leaguereplays.com)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.292.3 - McAfee, Inc.)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4805.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\OneDriveSetup.exe) (Version: 17.3.6302.0225 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mobizen (HKLM-x32\...\{BA0D3A44-BCEE-4C8B-BCD4-F7F1E64F41E3}) (Version: 2.19.0.1 - RSUPPORT)
Mozilla Firefox 36.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 36.0.1 (x86 en-US)) (Version: 36.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 36.0.1 - Mozilla)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.3 - Notepad++ Team)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4805.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4805.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4805.1003 - Microsoft Corporation) Hidden
OldSchool RuneScape Launcher 1.2.4 (HKLM-x32\...\{5D394B1B-03A1-43BC-BBA9-53BC880F86F3}) (Version: 1.2.4 - Jagex Ltd)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
osu! (HKLM-x32\...\{92428af5-bffa-4c6a-8a6a-30980a440af0}) (Version: latest - ppy Pty Ltd)
Razer Surround (HKLM-x32\...\Razer Surround) (Version: 1.05.18 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.27599 - Razer Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29077 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.24.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7173 - Realtek Semiconductor Corp.)
RuneScape Launcher 1.2.4 (HKLM-x32\...\{789FF9AB-5FE2-43C8-9FBE-1C3CF9E8A6E9}) (Version: 1.2.4 - Jagex Ltd)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.53.0 - Samsung Electronics Co., Ltd.)
ShortKeys Lite (HKLM-x32\...\ShortKeys Lite) (Version: 2.3.2.1 - Insight Software Solutions, Inc.)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\Spotify) (Version: 1.0.25.127.g58007b4c - Spotify AB)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
SwiftKit (HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\SwiftKit) (Version:  - )
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 18.1.7.2 - Synaptics Incorporated)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TOSHIBA Application Installer (HKLM\...\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.6 - Toshiba Corporation)
TOSHIBA Audio Enhancement (HKLM\...\{1515F5E3-29EA-4CD1-A981-032D88880F09}) (Version: 2.0.18.0 - Toshiba Corporation)
TOSHIBA Display Utility (HKLM\...\{484A4296-6F3D-4182-8CFA-D664F7DA34AA}) (Version: 1.1.17.0 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{94D2A899-0C34-4420-880E-AE337E635AB0}) (Version: 2.4.2.6403 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{1844CFE2-EBA3-490A-8A5E-9BFC646342FD}) (Version: 1.1.5.6402 - Toshiba Corporation)
TOSHIBA Password Utility (HKLM-x32\...\{2DB90351-FBAA-472B-9F12-6E1EBBB354DE}) (Version: v2.1.0.22 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.2.00.56006005 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{BFE4C813-4DD4-4B1C-97F4-76A459055C8D}) (Version: 2.6.13 - Toshiba Corporation)
TOSHIBA Start (HKLM-x32\...\{4F0F44AF-90E9-4A6E-9E82-354A3AB79F22}) (Version: 1.0.0.2 - TOSHIBA America Information Systems, Inc)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0033 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{4D57ED72-6B01-40BD-9CA9-012B8FC09CEB}) (Version: 2.0.1.32003 - Toshiba Corporation)
TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.6 - TOSHIBA)
Unity Web Player (HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\UnityWebPlayer) (Version: 4.5.5f1 - Unity Technologies ApS)
Vz In-Home Agent (HKLM-x32\...\VzInHomeAgent) (Version: 9.0.63.0 - Verizon)
VzDownloadManager (HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\VzDownloadManager) (Version: 2.0.0.16 - Verizon)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.11 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {13B3C597-EF56-4D85-8559-CE5031B68E67} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\WSCStub.exe
Task: {14DF1E8B-A87C-4058-8477-755D228551E7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {14EAD3BF-AF61-4C7A-B816-9C423EDA4835} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
Task: {23AAAC72-D291-42D9-BBCB-F6EB3B967599} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {24B0CFAC-3C93-4726-A82B-5D366188BF9C} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-03-25] (Synaptics Incorporated)
Task: {3573C722-AA4E-4238-9F7B-7B812181162E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {41E5FC1C-F3C7-47C4-9556-EA749923FF7B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-10] (Adobe Systems Incorporated)
Task: {4E129DD4-4194-478D-93B3-A3AB80451A99} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-09-24] (TOSHIBA Corporation)
Task: {6253AE21-5C4A-447F-BF33-F140FD85919B} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\SymErr.exe
Task: {6A9D369D-793E-4F71-A544-39D2B438A8B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {7BE26344-0E47-43FA-8205-65BFE019DB49} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-03-15] (Microsoft Corporation)
Task: {7E55F218-D299-40ED-A4DD-D67DB87CEF97} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\SymErr.exe
Task: {7EB01D07-8195-4B72-A5FE-FEA120C242E0} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-328124280-1994820816-3203177752-1001 => C:\Users\Josefina\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-03-12] (Microsoft Corporation)
Task: {A1470C2A-E200-4465-90C4-9CBEB2066920} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {B1E55388-2329-4AA7-8D1F-B775A48BF6EB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {D10EAB60-4EBE-48A6-8312-A4B510F9A376} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-04-23 09:14 - 2009-06-19 09:01 - 00189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\dleadrpp.dll
2014-03-20 08:25 - 2014-03-20 08:25 - 00140288 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2015-04-23 10:04 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-06-23 12:11 - 2015-06-23 12:11 - 00187048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2015-10-28 14:16 - 2015-09-01 09:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-11-07 11:06 - 2014-11-06 18:06 - 01016104 _____ () C:\Program Files (x86)\RSUPPORT\MobizenService\dat\adb.exe
2012-07-18 18:38 - 2012-07-18 18:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2016-01-13 10:27 - 2015-07-07 15:06 - 00819818 _____ () C:\Program Files (x86)\OctaneVPN\octanevpn.exe
2015-07-07 23:58 - 2015-07-07 23:58 - 00292352 _____ () C:\ProgramData\Razer\Synapse\RzStats\RzStats.Manager.exe
2015-11-09 17:42 - 2015-11-09 17:42 - 01459712 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\926020eb508f6968545d6a51fb661fad\Windows.UI.ni.dll
2015-11-09 17:42 - 2015-11-09 17:42 - 00521216 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Data\d07f690ce5d3a2de7c9089a6200d64db\Windows.Data.ni.dll
2013-08-22 00:19 - 2013-08-21 23:54 - 00030208 _____ () C:\Windows\system32\WinMetadata\Windows.Foundation.winmd
2014-03-20 08:25 - 2014-03-20 08:25 - 00016896 _____ () C:\Program Files\ATI Technologies\ATI.ACE\a4\AS4.NativeProxy.dll
2014-10-11 14:06 - 2014-10-11 14:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-01-13 10:27 - 2014-05-03 14:56 - 00027648 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\servicemanager.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00110080 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\pywintypes27.dll
2016-01-13 10:27 - 2014-05-03 14:55 - 00042496 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32service.pyd
2016-01-13 10:27 - 2014-05-03 14:56 - 00100352 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32api.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 00774656 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\_hashlib.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00036864 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32process.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00108544 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32security.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00018432 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32event.pyd
2016-01-13 10:27 - 2014-05-03 14:56 - 00049664 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32evtlog.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 00087552 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\_ctypes.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 00046080 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\_socket.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 01201152 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\_ssl.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00119808 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32file.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00024064 _____ () C:\Program Files (x86)\OctaneVPN\resources\bin\win32\octanevpnsrvc\win32pipe.pyd
2016-01-11 11:36 - 2016-01-11 11:36 - 00932032 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll
2015-03-26 20:46 - 2015-03-26 20:46 - 00422912 _____ () C:\Program Files (x86)\LOLReplay\LOLUtils.dll
2015-09-04 18:42 - 2015-09-04 18:42 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
2016-01-13 10:27 - 2014-12-10 14:25 - 00087552 _____ () C:\Program Files (x86)\OctaneVPN\_ctypes.pyd
2016-01-13 10:27 - 2015-01-15 18:19 - 01853440 _____ () C:\Program Files (x86)\OctaneVPN\PySide.QtCore.pyd
2016-01-13 10:27 - 2015-01-15 18:19 - 00110592 _____ () C:\Program Files (x86)\OctaneVPN\pyside-python2.7.dll
2016-01-13 10:27 - 2015-01-15 18:19 - 00108544 _____ () C:\Program Files (x86)\OctaneVPN\shiboken-python2.7.dll
2016-01-13 10:27 - 2015-01-15 18:19 - 06947328 _____ () C:\Program Files (x86)\OctaneVPN\PySide.QtGui.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 00046080 _____ () C:\Program Files (x86)\OctaneVPN\_socket.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 01201152 _____ () C:\Program Files (x86)\OctaneVPN\_ssl.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 00774656 _____ () C:\Program Files (x86)\OctaneVPN\_hashlib.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 00010240 _____ () C:\Program Files (x86)\OctaneVPN\select.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00110080 _____ () C:\Program Files (x86)\OctaneVPN\pywintypes27.dll
2016-01-13 10:27 - 2014-05-03 14:56 - 00100352 _____ () C:\Program Files (x86)\OctaneVPN\win32api.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00119808 _____ () C:\Program Files (x86)\OctaneVPN\win32file.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00024064 _____ () C:\Program Files (x86)\OctaneVPN\win32pipe.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00108544 _____ () C:\Program Files (x86)\OctaneVPN\win32security.pyd
2016-01-13 10:27 - 2012-09-27 17:28 - 00029184 _____ () C:\Program Files (x86)\OctaneVPN\Crypto.Cipher._AES.pyd
2016-01-13 10:27 - 2012-09-27 17:28 - 00009728 _____ () C:\Program Files (x86)\OctaneVPN\Crypto.Random.OSRNG.winrandom.pyd
2016-01-13 10:27 - 2012-09-27 17:28 - 00010240 _____ () C:\Program Files (x86)\OctaneVPN\Crypto.Util._counter.pyd
2016-01-13 10:27 - 2015-01-15 18:19 - 00644608 _____ () C:\Program Files (x86)\OctaneVPN\PySide.QtNetwork.pyd
2016-01-13 10:27 - 2014-05-03 14:55 - 00018432 _____ () C:\Program Files (x86)\OctaneVPN\win32event.pyd
2016-01-13 10:27 - 2014-12-10 14:25 - 00686080 _____ () C:\Program Files (x86)\OctaneVPN\unicodedata.pyd
2016-02-23 19:25 - 2016-02-23 19:25 - 00325824 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
2015-03-15 01:57 - 2016-03-17 13:45 - 47503472 _____ () C:\Users\Josefina\AppData\Roaming\Spotify\libcef.dll
2015-03-15 01:57 - 2016-03-17 13:45 - 01584240 _____ () C:\Users\Josefina\AppData\Roaming\Spotify\libglesv2.dll
2015-03-15 01:57 - 2016-03-17 13:45 - 00082032 _____ () C:\Users\Josefina\AppData\Roaming\Spotify\libegl.dll
2014-12-06 17:35 - 2014-11-25 19:12 - 40622592 _____ () C:\Users\Josefina\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libcef.dll
2014-12-06 17:36 - 2014-11-25 19:12 - 00911360 _____ () C:\Users\Josefina\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libglesv2.dll
2014-12-06 17:36 - 2014-11-25 19:12 - 00134144 _____ () C:\Users\Josefina\AppData\Local\razer\InGameEngine\cache\RzStats.Manager\cef\libegl.dll
2016-03-14 20:11 - 2016-03-07 19:48 - 01676440 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\libglesv2.dll
2016-03-14 20:11 - 2016-03-07 19:48 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.87\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Josefina\Desktop\signed.papers.jpeg:3or4kl4x13tuuug3Byamue2s4b [85]
AlternateDataStreams: C:\Users\Josefina\Desktop\signed.papers.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\skype.com -> hxxps://apps.skype.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2016-02-18 23:07 - 00000862 ____A C:\Windows\system32\Drivers\etc\hosts
 
0.0.0.1 mssplus.mcafee.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Josefina\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: 10.10.6.1 - 68.105.28.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{DB631FE9-D53A-4CDF-A87A-7CFA39B93909}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
FirewallRules: [TCP Query User{F2917DB9-D1E0-4DEA-AE90-3B5B4F4E3F09}C:\users\josefina\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josefina\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{DC4B0C6A-9E34-4CE8-9DA9-18D5B60732BD}C:\users\josefina\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josefina\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{3D5A4423-C026-4F27-8E8D-7071F043F56D}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{C7039E5A-258E-4215-94F8-7268791C854E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{D3BD3DB0-D717-41E2-BC6F-9994E3B1E9F0}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{0271FA94-1B69-4522-9D72-930EE4D0ACB6}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{9A79C10B-7A4F-4D93-9A4C-C4D7BBB9177E}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{9384F0D6-6F55-4B25-A19C-C4F31092A1F7}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{3AAD40A0-6250-4288-949B-893E035AB883}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{F27A37FD-D924-4F6F-A7EF-23AF344D94F3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [TCP Query User{832E9121-11DE-4C42-93D0-286595F15E25}C:\users\josefina\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josefina\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{F73EB8AE-1AFA-4C1D-8F59-88D40BFCE08B}C:\users\josefina\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\josefina\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{96399CC5-C682-46A7-BE42-1B11D86C18B3}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{35A64C5A-D901-444B-BF5E-81091883D5B2}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{0DB5A003-5A2D-473F-A63E-3080500CF158}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{76E7B944-ACB6-4F4C-BE26-4C48F26FD315}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{C321B6E8-0FBC-417E-999E-391A561432C2}] => (Allow) C:\Users\Josefina\AppData\Local\Temp\7zS3044.tmp\SymNRT.exe
FirewallRules: [{66187EA6-114C-4900-8870-3F8726843F7E}] => (Allow) C:\Users\Josefina\AppData\Local\Temp\7zS3044.tmp\SymNRT.exe
FirewallRules: [{BA3D66AA-94F2-424F-8462-CCD55AD121E8}] => (Allow) LPort=50000
FirewallRules: [{78395AFE-DC7C-4FCC-869E-07EB9115CE62}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{13574E4B-8537-4D06-82A9-FB67CEF230D4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3109\Agent.exe
FirewallRules: [{89C1EF30-4037-4613-B80D-2C7EB1519865}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe
FirewallRules: [{3FDFFA98-65E3-41D9-B9D4-D4A849E86D93}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe
FirewallRules: [TCP Query User{7C019123-85B9-4FAF-8AE4-C909AB9978BD}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{7D6CA702-E339-4E96-B2DC-2645919C9017}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{7E4C3B47-F2D1-4260-BD6F-B3AE57BF591E}] => (Allow) LPort=50000
FirewallRules: [{AE70EE10-EA6B-4636-9EFC-341FEEB7BAD9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe
FirewallRules: [{1613F250-CE59-4895-AC69-88370C46C4A9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3182\Agent.exe
FirewallRules: [TCP Query User{155E33DC-62D7-4114-9B52-9112A233F54A}C:\program files (x86)\cain\cain.exe] => (Allow) C:\program files (x86)\cain\cain.exe
FirewallRules: [UDP Query User{675FF6B5-7416-4D17-9391-E21FC7EACC1E}C:\program files (x86)\cain\cain.exe] => (Allow) C:\program files (x86)\cain\cain.exe
FirewallRules: [{00D856A1-98C2-4B84-B43E-387E0FABF773}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{61960BDF-16B4-40B6-AD15-87ED1E86E1AF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3235\Agent.exe
FirewallRules: [{DEB3EDA7-24CF-4736-BA29-CF85F768DB56}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{18939171-7376-4232-8F25-B8D1DD97939A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{DC763B3F-8BCB-4068-81D2-CCD2B56F830E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{B2625160-816F-4476-BFF7-6439DDDE842F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{A4A1D583-FD05-4687-928E-59DAB4092159}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{1EEE8DAC-6B50-47CC-96A7-56E595064759}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{001673F2-13AD-44A6-889D-33C2EF7AF8FE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3323\Agent.exe
FirewallRules: [{C106D242-20D0-43FC-B844-6885944D54EB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3323\Agent.exe
FirewallRules: [{F9177802-6F41-4A0E-8695-64B0B06FF539}] => (Allow) LPort=8317
FirewallRules: [TCP Query User{EF40A9AC-969A-46F3-9976-5BC91FFDEFFE}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{40FB78D7-C238-4AEC-A372-3CF453608355}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{30F229EF-2FBA-41BA-96AB-46D15D366BA3}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{504E8A65-38A7-43CA-B28A-DB5B4D224F36}C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) C:\riot games\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [{19F38CCE-EEF2-49CC-91B3-9EE9BB8ABA77}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [{217A4875-E897-4D05-87B0-0775AECE8D42}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe
FirewallRules: [TCP Query User{44A49255-29B6-4438-9183-2EEE22B6D7C7}C:\program files (x86)\lolreplay\lolreplay.exe] => (Allow) C:\program files (x86)\lolreplay\lolreplay.exe
FirewallRules: [UDP Query User{7CB40C52-7987-494F-B3B5-5E4608146885}C:\program files (x86)\lolreplay\lolreplay.exe] => (Allow) C:\program files (x86)\lolreplay\lolreplay.exe
FirewallRules: [TCP Query User{C1AEA2BB-A721-4FEF-BFBB-A7E2DEC2288F}C:\program files (x86)\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [UDP Query User{28DC3DC1-C879-4A73-ACFB-A664AC3EB665}C:\program files (x86)\steam\steamapps\common\dayz\dayz.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dayz\dayz.exe
FirewallRules: [TCP Query User{9598009A-A349-4014-A121-238FA7E80143}C:\users\josefina\appdata\local\id software\quakelive\quakelive.exe] => (Allow) C:\users\josefina\appdata\local\id software\quakelive\quakelive.exe
FirewallRules: [UDP Query User{812F7557-D2AA-4FEB-9FF7-B0100A205BFD}C:\users\josefina\appdata\local\id software\quakelive\quakelive.exe] => (Allow) C:\users\josefina\appdata\local\id software\quakelive\quakelive.exe
FirewallRules: [{4903E948-CF8F-47EF-B082-C8868F9EE385}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{57F4F88A-88B1-4009-910F-2C0A9AA73EEE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0CED098D-DA59-493F-ACE4-737E14AA9C3F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B898CDAF-207E-4263-9D47-D453A1A838D1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{4E78E588-2BE0-4467-8176-4EB6F301E2F2}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{D4BB50C2-DDCE-4C0B-8D38-89DF48516C66}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{4E6EEB6C-7999-434D-BE63-68C99867D07D}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{B384FF1D-A159-472A-A72C-487E719A3BC6}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{72E20B10-8C81-48B5-9959-B868A7126CBD}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{F81DD2BF-EB08-46D4-A2B5-D17CAE6AD330}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D822D03A-1630-4AED-B4CE-1E2DF16C98FB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1B437634-1C06-497A-A9E8-75CA1CFBA188}] => (Allow) C:\Windows\system32\dleacoms.exe
FirewallRules: [{487C1CF0-0821-4E46-9A0F-B58507013D9D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{B2A4CFFA-48D4-4FB2-8F85-64AAF7452307}] => (Allow) C:\Users\Josefina\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [TCP Query User{52E4FA3C-538C-4D3C-A471-782ED82D1B48}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{576D108A-FA48-4F0C-8D91-CBC4B3DFC5BD}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{233DAE45-1F66-4CE5-A1FE-4638FFD9946A}] => (Allow) C:\Program Files (x86)\DolbyAxon\Axon.exe
FirewallRules: [{CE637C89-1498-43FC-A8ED-DF1C5F033445}] => (Allow) C:\Program Files (x86)\DolbyAxon\Axon.exe
FirewallRules: [TCP Query User{8116671A-3BAF-406C-8CE6-6E87D27C477F}C:\users\josefina\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\josefina\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{51E4029B-F73A-477A-BA74-5AC5743E804B}C:\users\josefina\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\josefina\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{F1D1F996-7767-4A32-9A22-AC5DBE2F22E8}] => (Allow) LPort=8317
FirewallRules: [TCP Query User{1E1AED25-305B-4E34-8BE1-7B0927633F80}C:\program files (x86)\mirrorop receiver\mirrorop receiver.exe] => (Allow) C:\program files (x86)\mirrorop receiver\mirrorop receiver.exe
FirewallRules: [UDP Query User{5781671B-8D3B-48AC-B3D6-4B626C4D9BF3}C:\program files (x86)\mirrorop receiver\mirrorop receiver.exe] => (Allow) C:\program files (x86)\mirrorop receiver\mirrorop receiver.exe
FirewallRules: [{ED5359CA-6240-4A0E-BF0F-991BDDBBE461}] => (Allow) C:\Program Files\App Dynamic\AirServer\AirServer.exe
FirewallRules: [{261133B7-4624-468D-8067-62C341EFE3CE}] => (Allow) C:\Program Files\App Dynamic\AirServer\AirServer.exe
FirewallRules: [TCP Query User{681DCD85-8D78-4229-9702-D3DF3EFEA603}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{D040990E-BC97-4CBE-AB2C-8EC3AF5E23B6}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{22EDAC80-B5D3-4B17-AEE5-CA55C6B281E8}] => (Allow) C:\Program Files (x86)\OctaneVPN\resources\bin\win32\openvpn.exe
FirewallRules: [{BF75F5A7-737E-4FBA-B57F-A3AA7EE23A05}] => (Allow) C:\Program Files (x86)\OctaneVPN\octanevpn.exe
FirewallRules: [{37F64EC5-91CF-4E74-9AFB-8EC38CA23D0D}] => (Allow) C:\Program Files (x86)\OctaneVPN\resources\bin\win32\openvpn.exe
FirewallRules: [{FA661404-31C9-4C67-9349-A8D9FC8797A8}] => (Allow) C:\Program Files (x86)\OctaneVPN\resources\bin\win32\openvpn.exe
FirewallRules: [{B6D1C1EB-CCED-4BD4-AE06-6D1F3E457B70}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
26-02-2016 22:50:12 Scheduled Checkpoint
28-02-2016 23:35:30 Removed League of Legends
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/17/2016 01:38:03 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15281
 
Error: (03/17/2016 01:38:03 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15281
 
Error: (03/17/2016 01:38:03 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (03/17/2016 12:44:21 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073415161
 
Error: (03/16/2016 04:50:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8656687
 
Error: (03/16/2016 04:50:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8656687
 
Error: (03/16/2016 04:50:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (03/16/2016 04:50:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8655156
 
Error: (03/16/2016 04:50:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8655156
 
Error: (03/16/2016 04:50:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (03/17/2016 01:38:44 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
%%1056
 
Error: (03/17/2016 01:38:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The TMachInfo service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/17/2016 01:38:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (03/17/2016 01:38:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/17/2016 01:38:09 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (03/17/2016 01:38:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The TOSHIBA eco Utility Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/17/2016 01:38:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Avira Service Host service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/17/2016 01:38:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SAMSUNG Mobile Connectivity Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/17/2016 01:38:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The RzSurroundVADStreamingService service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
Error: (03/17/2016 01:38:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Razer Game Scanner service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
 
CodeIntegrity:
===================================
  Date: 2016-02-25 11:26:26.439
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-25 11:26:26.300
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-25 02:00:07.926
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-24 22:24:53.471
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-24 18:20:44.000
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-24 18:20:43.863
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-24 18:20:43.643
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-24 18:20:43.507
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-24 18:20:43.367
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-02-24 18:20:42.509
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: AMD A6-6310 APU with AMD Radeon R4 Graphics 
Percentage of memory in use: 56%
Total physical RAM: 5081.23 MB
Available physical RAM: 2216.89 MB
Total Virtual: 7769.23 MB
Available Virtual: 3917.09 MB
 
==================== Drives ================================
 
Drive c: (TI10693600C) (Fixed) (Total:687.9 GB) (Free:504.34 GB) NTFS
Drive e: () (Removable) (Total:14.91 GB) (Free:0.1 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 1 (Size: 14.9 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

  • 0

#4
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello,

Next

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the logfile button and the log will open in Notepad.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished and the PC has rebooted.
  • Please post the content of that log file with your next answer.
  • The report will be saved in the C:\AdwCleaner folder.

    Next

    thisisujrt.gif Please download Junkware Removal Tool to your Desktop.
    Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
    Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
    The tool will open and start scanning your system.
    Please be patient as this can take a while to complete, depending on your system's specifications.
    On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
    Please post the contents of JRT.txt into your reply.

    In your next reply post;
  • The AdwCleaner [SO].txt Log
  • The JRT.txt Log

    I'll return later today.

    Thanks
    Joe :)

  • 0

#5
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
# AdwCleaner v5.113 - Logfile created 25/04/2016 at 11:28:47
# Updated 24/04/2016 by Xplode
# Database : 2016-04-24.3 [Server]
# Operating system : Windows 8.1  (X64)
# Username : Josefina - GUADALUPE
# Running from : C:\Users\Josefina\Downloads\adwcleaner_5.113.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\Users\Josefina\AppData\Local\SweetLabs App Platform
 
***** [ Files ] *****
 
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKCU\Software\SweetLabs App Platform
 
***** [ Web browsers ] *****
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [825 bytes] - [25/04/2016 11:28:47]
C:\AdwCleaner\AdwCleaner[S1].txt - [969 bytes] - [25/04/2016 11:15:25]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [969 bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.5 (04.20.2016)
Operating System: Windows 8.1 x64 
Ran by Josefina (Administrator) on Mon 04/25/2016 at 11:56:31.70
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 1 
 
Successfully deleted: C:\ai_recyclebin (Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 04/25/2016 at 12:01:21.62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • 0

#6
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
  • Reboot your computer if prompted.


    Posting the Malwarebytes log.

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • post that saved log to your next reply.


    After you posted the Malwarebytes do this

    A few items to fix

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
    Open notepad (Start =>All Programs => Accessories => Notepad).
    Copy/Paste the contents of the code box below into Notepad.
    start
    CloseProcesses:
    CreateRestorePoint:
    AlternateDataStreams: C:\Users\Josefina\Desktop\signed.papers.jpeg:3or4kl4x13tuuug3Byamue2s4b [85]
    AlternateDataStreams: C:\Users\Josefina\Desktop\signed.papers.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    CMD: bitsadmin /reset /allusers
    CMD: ipconfig /flushdns
    Emptytemp:
    
  • Click Format and ensure Wordwrap is unchecked.
  • Save as Fixlist.txt to your Desktop (Must be in this location)
  • Run FRST/FRST64 and press the Fix button just once and wait.
  • If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
  • The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.


  • 0

#7
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 4/25/2016
Scan Time: 3:19 PM
Logfile: malwarebytes log.txt
Administrator: Yes
 
Version: 2.2.0.1024
Malware Database: v2016.04.25.05
Rootkit Database: v2016.04.17.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Josefina
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 382473
Time Elapsed: 43 min, 47 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

  • 0

#8
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts

Out of curiosity what did you see in the signed papers files? 

 

Also when I ran the first64 and clicked fixed my anti virus popped up saying that the host file was blocked. I don't know if that effected the fix.


Edited by Helpmeout12, 25 April 2016 - 05:31 PM.

  • 0

#9
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Out of curiosity what did you see in the signed papers files?

A relatively unknown compatibility feature of NTFS, Alternate Data Streams (ADS) provides hackers with a method of hiding root kits or hacker tools on a breached system and allows them to be executed without being detected by the systems administrator.

Do you have the fixlog on the destop ?

Please post it
  • 0

#10
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Fix result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
Ran by Josefina (2016-04-25 16:26:24) Run:2
Running from C:\Users\Josefina\Downloads
Loaded Profiles: Josefina &  (Available Profiles: Josefina)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
C:\Program Files\McAfee Security Scan
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
C:\ProgramData\28341ff220e0446c9fff27c4493d622e
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\MountPoints2: {4ed870a2-e9d3-11e4-8397-008cfa816eed} - "F:\LaunchU3.exe" -a
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\...\MountPoints2: {d8c1a4c4-21fc-11e5-83db-008cfa816eed} - "F:\VZW_Software_upgrade_assistant.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-02-18]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.10.6.1
Tcpip\..\Interfaces\{50356B71-1720-4E53-9A83-75422809EF35}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{A3CDCC32-6451-40A0-960E-00C6CDEC270C}: [DhcpNameServer] 10.10.6.1
Tcpip\..\Interfaces\{C4CA73C3-BE41-48FE-9D4C-6AC0B598965C}: [DhcpNameServer] 192.168.0.1
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba13.msn.com/?pc=TNJB
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba13.msn.com/?pc=TNJB
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com/?pc=TNJB
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com/?pc=TNJB
SearchScopes: HKU\S-1-5-21-328124280-1994820816-3203177752-1001 -> DefaultScope {66CC2DE0-B4F8-43AB-BCDA-C3F9DF0DF395} URL =
SearchScopes: HKU\S-1-5-21-328124280-1994820816-3203177752-1001 -> {66CC2DE0-B4F8-43AB-BCDA-C3F9DF0DF395} URL =
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.292\McCHSvc.exe [293128 2016-02-05] (McAfee, Inc.)
2016-02-24 19:34 - 2016-02-24 19:34 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2016-02-18 23:06 - 2016-03-05 19:58 - 00002035 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-02-18 23:06 - 2016-02-18 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 
C:\ProgramData\McAfee Security Scan
C:\Program Files\McAfee Security Scan 
2014-09-29 15:29 - 2015-02-22 03:27 - 0000096 _____ () C:\Users\Josefina\AppData\Roaming\Camdata.ini
2014-09-29 15:29 - 2015-02-22 03:27 - 0000408 _____ () C:\Users\Josefina\AppData\Roaming\CamLayout.ini
2014-09-29 15:29 - 2015-02-22 03:27 - 0000408 _____ () C:\Users\Josefina\AppData\Roaming\CamShapes.ini
2014-09-29 15:29 - 2015-02-22 03:27 - 0004535 _____ () C:\Users\Josefina\AppData\Roaming\CamStudio.cfg
2014-09-29 15:29 - 2015-02-22 03:26 - 0000096 _____ () C:\Users\Josefina\AppData\Roaming\version2.xml
2015-04-24 06:42 - 2016-02-26 22:45 - 0014330 _____ () C:\ProgramData\dleaJSW.log
2015-04-23 09:13 - 2016-02-26 21:42 - 0006900 _____ () C:\ProgramData\dleascan.log
2014-05-21 11:29 - 2014-05-21 11:29 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 
C:\Users\Josefina\MetricCollection.dll 
C:\Users\Josefina\AppData\Local\Temp\avgnt.exe
C:\Users\Josefina\AppData\Local\Temp\oct3D96.tmp.exe
C:\Users\Josefina\AppData\Local\Temp\oct4F86.tmp.exe
C:\Users\Josefina\AppData\Local\Temp\octEB50.tmp.exe
C:\Users\Josefina\AppData\Local\Temp\sqlite3.dll 
Task: {13B3C597-EF56-4D85-8559-CE5031B68E67} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\WSCStub.exe
C:\Program Files (x86)\Norton Internet Security
Task: {3573C722-AA4E-4238-9F7B-7B812181162E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {41E5FC1C-F3C7-47C4-9556-EA749923FF7B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-10] (Adobe Systems Incorporated)
Task: {6253AE21-5C4A-447F-BF33-F140FD85919B} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\SymErr.exe
Task: {7E55F218-D299-40ED-A4DD-D67DB87CEF97} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.3.0.12\SymErr.exe
AlternateDataStreams: C:\Users\Josefina\Desktop\signed.papers.jpeg:3or4kl4x13tuuug3Byamue2s4b [85]
AlternateDataStreams: C:\Users\Josefina\Desktop\signed.papers.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
FirewallRules: [{BA3D66AA-94F2-424F-8462-CCD55AD121E8}] => (Allow) LPort=50000
FirewallRules: [{7E4C3B47-F2D1-4260-BD6F-B3AE57BF591E}] => (Allow) LPort=50000
FirewallRules: [{F9177802-6F41-4A0E-8695-64B0B06FF539}] => (Allow) LPort=8317
C:\Windows\System32\GWX
C:\Windows\SysWOW64\GWX
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state On
RemoveProxy:
CMD: ipconfig /flushdns
hosts:
Emptytemp:
reboot:
end
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
"C:\Program Files\McAfee Security Scan" => not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value not found.
"C:\ProgramData\28341ff220e0446c9fff27c4493d622e" => not found.
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4ed870a2-e9d3-11e4-8397-008cfa816eed} => key not found. 
HKCR\CLSID\{4ed870a2-e9d3-11e4-8397-008cfa816eed} => key not found. 
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8c1a4c4-21fc-11e5-83db-008cfa816eed} => key not found. 
HKCR\CLSID\{d8c1a4c4-21fc-11e5-83db-008cfa816eed} => key not found. 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk => not found.
C:\Program Files\McAfee Security Scan\3.11.292\SSScheduler.exe => not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{50356B71-1720-4E53-9A83-75422809EF35}\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A3CDCC32-6451-40A0-960E-00C6CDEC270C}\\DhcpNameServer => value removed successfully
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C4CA73C3-BE41-48FE-9D4C-6AC0B598965C}\\DhcpNameServer => value removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{66CC2DE0-B4F8-43AB-BCDA-C3F9DF0DF395} => key not found. 
HKCR\CLSID\{66CC2DE0-B4F8-43AB-BCDA-C3F9DF0DF395} => key not found. 
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3 => key not found. 
C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll => not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9 => key not found. 
C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll => not found.
McComponentHostService => service not found.
"C:\ProgramData\28341ff220e0446c9fff27c4493d622e" => not found.
"C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk" => not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus" => not found.
"C:\ProgramData\McAfee Security Scan" => not found.
"C:\Program Files\McAfee Security Scan" => not found.
"C:\Users\Josefina\AppData\Roaming\Camdata.ini" => not found.
"C:\Users\Josefina\AppData\Roaming\CamLayout.ini" => not found.
"C:\Users\Josefina\AppData\Roaming\CamShapes.ini" => not found.
"C:\Users\Josefina\AppData\Roaming\CamStudio.cfg" => not found.
"C:\Users\Josefina\AppData\Roaming\version2.xml" => not found.
"C:\ProgramData\dleaJSW.log" => not found.
"C:\ProgramData\dleascan.log" => not found.
"C:\ProgramData\DP45977C.lfl" => not found.
"C:\Users\Josefina\MetricCollection.dll" => not found.
C:\Users\Josefina\AppData\Local\Temp\avgnt.exe => moved successfully
"C:\Users\Josefina\AppData\Local\Temp\oct3D96.tmp.exe" => not found.
"C:\Users\Josefina\AppData\Local\Temp\oct4F86.tmp.exe" => not found.
"C:\Users\Josefina\AppData\Local\Temp\octEB50.tmp.exe" => not found.
C:\Users\Josefina\AppData\Local\Temp\sqlite3.dll => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13B3C597-EF56-4D85-8559-CE5031B68E67} => key not found. 
C:\Windows\System32\Tasks\Norton WSC Integration => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration => key not found. 
"C:\Program Files (x86)\Norton Internet Security" => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3573C722-AA4E-4238-9F7B-7B812181162E} => key not found. 
C:\Windows\System32\Tasks\Adobe Acrobat Update Task => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41E5FC1C-F3C7-47C4-9556-EA749923FF7B} => key not found. 
C:\Windows\System32\Tasks\Adobe Flash Player Updater => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6253AE21-5C4A-447F-BF33-F140FD85919B} => key not found. 
C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Analyzer => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Analyzer => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E55F218-D299-40ED-A4DD-D67DB87CEF97} => key not found. 
C:\Windows\System32\Tasks\Norton Internet Security\Norton Error Processor => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton Internet Security\Norton Error Processor => key not found. 
"C:\Users\Josefina\Desktop\signed.papers.jpeg" => ":3or4kl4x13tuuug3Byamue2s4b" ADS not found.
"C:\Users\Josefina\Desktop\signed.papers.jpeg" => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BA3D66AA-94F2-424F-8462-CCD55AD121E8} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7E4C3B47-F2D1-4260-BD6F-B3AE57BF591E} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F9177802-6F41-4A0E-8695-64B0B06FF539} => value not found.
"C:\Windows\System32\GWX" => not found.
"C:\Windows\SysWOW64\GWX" => not found.
 
=========  netsh advfirewall reset =========
 
Ok.
 
 
========= End of CMD: =========
 
 
=========  netsh advfirewall set allprofiles state On =========
 
Ok.
 
 
========= End of CMD: =========
 
 
========= RemoveProxy: =========
 
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-328124280-1994820816-3203177752-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-328124280-1994820816-3203177752-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\S-1-5-21-328124280-1994820816-3203177752-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-328124280-1994820816-3203177752-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
 
 
========= End of RemoveProxy: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not restore Hosts.
EmptyTemp: => 860.7 MB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 16:28:12 ====

  • 0

Advertisements


#11
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
That's not the fix I created, who created that fixlist ?
  • 0

#12
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts

I had someone run me through something similar a few months ago on a different website. Did I do something wrong? 


  • 0

#13
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Un-less you're trained in Malware removal you should not be creating your own fixlist. I create the fix list and you run it.

I don't see any harm done. Never veer from directions given and decide to do things on your own.

How is the computer ?

Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Make sure you checkmark Addition.txt box.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.

  • 0

#14
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts

I didn't do anything on my own though. I put the fixlist note on my desktop and pressed fix on frst64. I'm not sure what happened that made it run something else.

 

The computer is running fine.


  • 0

#15
Helpmeout12

Helpmeout12

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts

Should I delete the last Frst/Addition notes before I re-run it?


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP