Beeing trying to find malware/rootkit myself, as I suspect that is the problem here, but everything I threw at it, has not helped. Asking for some help here, hoping you can find something I haven't been able to. I have not done system restore.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2015
Ran by Sam D (administrator) on SAMD-PC (25-07-2015 12:00:19)
Running from C:\Users\Sam D\Downloads
Loaded Profiles: Sam D (Available Profiles: Sam D)
Platform: Microsoft Windows 7 Ultimate (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Ellora Assets Corp.) C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [159744 2007-07-02] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Fences] => C:\Program Files\Stardock\Fences\Fences.exe [4031152 2013-11-26] (Stardock Corporation)
Winlogon\Notify\klogon: C:\Windows\system32\klogon.dll [2010-10-05] (Kaspersky Lab ZAO)
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6715160 2015-07-08] (SUPERAntiSpyware)
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\...\Run: [Dropbox Update] => C:\Users\Sam D\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-16] (Dropbox, Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2015-06-19] (Microsoft Corporation)
Startup: C:\Users\Sam D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Sam D\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=SKY2&ocid=SKY2DHP&osmkt=en-us
URLSearchHook: HKU\S-1-5-21-3192665374-2718563871-2505210960-1000 - (No Name) - {5F9575C2-1AB4-4883-8505-5C6D0DFDF2D5} - No File
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
Toolbar: HKLM - KeywordSpy™ SEO/PPC - {0AE831B0-427E-4D0A-BC88-4BA47E7471C3} - C:\Program Files\KeywordSpy SEOPPC Plug-in\KeywordSpySEO.dll [2010-07-31] ()
Toolbar: HKU\.DEFAULT -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3192665374-2718563871-2505210960-1000 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3192665374-2718563871-2505210960-1000 -> KeywordSpy™ SEO/PPC - {0AE831B0-427E-4D0A-BC88-4BA47E7471C3} - C:\Program Files\KeywordSpy SEOPPC Plug-in\KeywordSpySEO.dll [2010-07-31] ()
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Handler: WSAMAllMyTubechrome - {C985F516-9C03-4F90 - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{753E788B-AD78-4CDD-B153-CDD66A6584E0}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630
FF DefaultSearchEngine.US: Google
FF Homepage: gmail.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-02-10] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-07-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3192665374-2718563871-2505210960-1000: @acestream.net/acestreamplugin,version=3.0.12 -> C:\Users\Sam D\AppData\Roaming\ACEStream\player\npace_plugin.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-02-10] (Microsoft Corporation)
FF Extension: Copy Urls Expert - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\copy-urls-expert@kashiif-gmail.com.xpi [2015-07-20]
FF Extension: MozBar - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\toolbar@seomoz.org.xpi [2015-06-28]
FF Extension: PPCWebSpy Toolbar - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\{86c18b42-e466-45a9-ae7a-9b95ba6f5640}.xpi [2015-05-17]
FF Extension: SEO Global For Google Search™ - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\{B97F57B9-1B42-4aed-9475-0022600C62DC}.xpi [2015-06-24]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2015-05-31]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-07-08]
FF HKLM\...\Firefox\Extensions: [AMAllMyTube@Aimersoft.com] - C:\ProgramData\Aimersoft\YouTube Downloader\AMAllMyTube@Aimersoft.com
FF Extension: Aimersoft YouTube Downloader - C:\ProgramData\Aimersoft\YouTube Downloader\AMAllMyTube@Aimersoft.com [2015-05-31]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Webbing) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fblcpdlednddbkcdbkkaiggjipjjgpdp [2014-10-15]
CHR Extension: (DivX HiQ) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae [2012-07-28]
CHR Extension: (NextCouup) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\goeeobfmefldgbbdlmjdjagkkhmmnopi [2014-10-08]
CHR Extension: (GoSavvE) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hgdnccifmkfafkohlbeailfepfjbmdna [2014-09-25]
CHR Extension: (OpptOn) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hnojomgcmohiefbikenglccliaogccbn [2014-09-27]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-07-28]
CHR Extension: (HTML5ify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jikbjpjgjmmdhcmlagappehlpiljoaop [2015-03-12]
CHR Extension: (Codec-V) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho [2012-07-28]
CHR Extension: (Deezify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kpkbhaapafmlmgodhicgpngihalhepll [2015-02-14]
CHR Extension: (GoSSave) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lhijjoggceedllbdndfjjnjpomecffad [2014-10-08]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-07-28]
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google Drive) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-18]
CHR Extension: (Poper Blocker) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-07-01]
CHR Extension: (APK Downloader) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cgihflhdpokeobcfimliamffejfnmfii [2014-10-26]
CHR Extension: (Image Downloader) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2014-10-16]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014-11-25]
CHR Extension: (Video Downloader professional) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2014-11-17]
CHR Extension: (Webbing) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fblcpdlednddbkcdbkkaiggjipjjgpdp [2014-10-15]
CHR Extension: (AdBlock) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-07-01]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-11]
CHR Extension: (Google Wallet) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (SEO Global For Google Search™) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ojgmigafbpedhdilmemphfklkbghlphi [2015-06-24]
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3
CHR Extension: (Google Docs) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-27]
CHR Extension: (Google Drive) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-27]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-27]
CHR Extension: (YouTube) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-27]
CHR Extension: (Google Search) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-27]
CHR Extension: (HTML5ify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\jikbjpjgjmmdhcmlagappehlpiljoaop [2015-03-12]
CHR Extension: (Deezify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kpkbhaapafmlmgodhicgpngihalhepll [2015-02-14]
CHR Extension: (Google Wallet) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-27]
CHR Extension: (Gmail) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-27]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
CHR HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\SAMD~1\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-22] (SUPERAntiSpyware.com)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-09-11] (Freemake) [File not signed]
R2 FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-09-11] (Ellora Assets Corp.) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [35992 2015-02-16] ()
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [132184 2010-06-09] (Kaspersky Lab ZAO)
R1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11352 2010-06-09] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [488536 2010-12-26] (Kaspersky Lab)
S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [22104 2010-04-22] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [19984 2009-11-02] (Kaspersky Lab)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [98520 2015-07-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2014-11-05] (The OpenVPN Project)
S3 TSVAD_PCM; C:\Windows\System32\drivers\tsvadpcm.sys [28432 2014-08-15] (Windows (R) Win 7 DDK provider)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2014-11-28] (RealVNC Ltd.)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [116736 2014-09-02] (Webroot)
S3 catchme; \??\C:\Users\SAMD~1\AppData\Local\Temp\catchme.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-25 12:00 - 2015-07-25 12:01 - 00024169 _____ C:\Users\Sam D\Downloads\FRST.txt
2015-07-25 12:00 - 2015-07-25 12:00 - 00000000 ____D C:\FRST
2015-07-25 11:59 - 2015-07-25 11:59 - 01650688 _____ (Farbar) C:\Users\Sam D\Downloads\FRST.exe
2015-07-25 02:14 - 2015-07-25 02:14 - 00028527 _____ C:\ComboFix.txt
2015-07-25 01:43 - 2015-07-25 01:43 - 00001098 _____ C:\Users\Sam D\Desktop\ComboFix - Shortcut.lnk
2015-07-25 01:40 - 2015-07-25 01:42 - 00003448 _____ C:\Users\Sam D\Desktop\Rkill.txt
2015-07-25 01:39 - 2015-07-25 01:39 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\Sam D\Downloads\rkill.exe
2015-07-25 01:22 - 2015-07-25 01:22 - 00002982 _____ C:\Users\Sam D\Desktop\JRT.txt
2015-07-25 00:48 - 2015-07-25 00:48 - 02248704 _____ C:\Users\Sam D\Downloads\adwcleaner_4.208.exe
2015-07-25 00:47 - 2015-07-25 00:48 - 01798288 _____ (Malwarebytes Corporation) C:\Users\Sam D\Downloads\JRT (1).exe
2015-07-25 00:33 - 2015-07-25 00:34 - 18705480 _____ C:\Users\Sam D\Downloads\RogueKiller.exe
2015-07-24 23:42 - 2015-07-24 23:43 - 07269656 _____ (Bitdefender LLC) C:\Users\Sam D\Downloads\BootkitRemoval_x86.exe
2015-07-24 22:40 - 2015-07-25 11:33 - 00002828 _____ C:\Windows\setupact.log
2015-07-24 22:40 - 2015-07-25 02:06 - 00001430 _____ C:\Windows\PFRO.log
2015-07-24 22:40 - 2015-07-24 22:40 - 00000000 _____ C:\Windows\setuperr.log
2015-07-24 21:56 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2015-07-24 21:56 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2015-07-24 21:56 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2015-07-24 21:55 - 2015-07-25 02:14 - 00000000 ____D C:\Qoobox
2015-07-24 16:56 - 2015-07-24 16:58 - 05633622 ____R (Swearware) C:\Users\Sam D\Downloads\ComboFix.exe
2015-07-24 16:51 - 2015-07-24 16:52 - 04404952 _____ (Kaspersky Lab ZAO) C:\Users\Sam D\Downloads\tdsskiller.exe
2015-07-24 13:43 - 2015-07-25 00:02 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-07-24 13:41 - 2015-07-24 16:38 - 00000000 ____D C:\Users\Sam D\Desktop\mbar
2015-07-24 13:40 - 2015-07-24 13:41 - 00380416 _____ C:\Users\Sam D\Downloads\y6so8ixt.exe
2015-07-24 13:38 - 2015-07-24 13:40 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Sam D\Downloads\mbar-1.09.1.1004.exe
2015-07-24 12:27 - 2015-07-24 12:27 - 00000177 _____ C:\Users\Sam D\Desktop\scrapebox.txt
2015-07-24 11:12 - 2015-07-24 11:12 - 00000000 ____D C:\Program Files\ESET
2015-07-24 11:11 - 2015-07-24 11:11 - 02870984 _____ (ESET) C:\Users\Sam D\Downloads\esetsmartinstaller_enu.exe
2015-07-24 10:59 - 2015-07-24 11:04 - 06754696 _____ C:\Users\Sam D\Downloads\CCl3aner5.07.5261.rar
2015-07-22 12:37 - 2015-07-22 12:37 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheBestSpinner3
2015-07-22 12:37 - 2015-07-22 12:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TheBestSpinner3
2015-07-22 12:37 - 2015-07-22 12:37 - 00000000 ____D C:\Program Files\TheBestSpinner3
2015-07-22 12:28 - 2015-07-22 12:28 - 00784723 _____ C:\Users\Sam D\Downloads\bonus_super_spun_articles_55afc6468bce4.zip
2015-07-21 22:53 - 2015-07-21 22:53 - 05509505 _____ C:\Users\Sam D\Downloads\SetupTheBestSpinner3.exe
2015-07-21 22:53 - 2015-07-21 22:53 - 00784723 _____ C:\Users\Sam D\Downloads\bonus_super_spun_articles_55af074bbc3ca.zip
2015-07-21 22:31 - 2015-07-21 22:32 - 00000000 ____D C:\Users\Sam D\Downloads\SetupTheBestSpinner3.421
2015-07-21 22:22 - 2015-07-21 22:22 - 00000000 ____D C:\Users\Sam D\Downloads\TBS2k15 (1)
2015-07-21 21:18 - 2015-07-21 21:18 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-07-21 20:23 - 2015-07-24 12:54 - 00000000 ____D C:\Users\Sam D\Desktop\San antonio articles stuff
2015-07-21 15:15 - 2015-07-21 16:03 - 00000000 ____D C:\Users\Sam D\Downloads\KeywordResearcher
2015-07-21 15:15 - 2015-07-21 15:15 - 02852471 _____ C:\Users\Sam D\Downloads\KeywordResearcher.rar
2015-07-21 15:15 - 2015-01-09 04:19 - 08483504 _____ C:\Users\Sam D\Desktop\KeywordResearcher.exe
2015-07-21 15:14 - 2015-07-21 15:14 - 03717120 _____ (Microsoft Corporation) C:\Users\Sam D\Downloads\KeywordResearcher9Latest.exe
2015-07-19 18:44 - 2015-07-22 11:22 - 00000000 ____D C:\Users\Sam D\Desktop\New folder (2)
2015-07-19 00:01 - 2015-07-19 00:01 - 01874588 _____ C:\Users\Sam D\Downloads\Fiverr SEO Gigs Handbook.zip
2015-07-18 18:38 - 2015-07-18 18:39 - 61902129 _____ C:\Users\Sam D\Downloads\X-SpinnerBeta (1).zip
2015-07-17 20:54 - 2015-07-17 20:55 - 155415094 _____ C:\Users\Sam D\Downloads\Wirecast_Play_6_0_5 (1).zip
2015-07-17 20:47 - 2015-07-17 20:47 - 06537216 _____ C:\Users\Sam D\Downloads\flashmedialiveencoder_3.2_wwe_signed.msi
2015-07-17 18:13 - 2015-07-18 15:55 - 00000000 ____D C:\Users\Sam D\Documents\Camtasia Studio
2015-07-17 18:09 - 2015-07-17 18:09 - 00001128 _____ C:\Users\Public\Desktop\Camtasia Studio 8.lnk
2015-07-17 18:09 - 2015-07-17 18:09 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2015-07-17 18:09 - 2015-07-17 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2015-07-17 18:08 - 2015-07-17 18:08 - 00000000 ____D C:\Program Files\Common Files\TechSmith Shared
2015-07-17 18:07 - 2015-07-17 18:07 - 00000000 ____D C:\Program Files\TechSmith
2015-07-17 17:54 - 2015-07-17 17:55 - 00000000 ____D C:\Users\Sam D\Documents\TechSmith Camtasia Studio 8.5.1 Build 1962 RePack by KpoJIuK
2015-07-17 16:45 - 2015-07-17 16:45 - 00000165 ____H C:\Users\Sam D\Desktop\~$Sales call log and organizer1 sam.xlsx
2015-07-17 00:19 - 2015-07-17 00:19 - 00001710 _____ C:\Users\Sam D\Desktop\FreemakeVD - Shortcut.lnk
2015-07-17 00:19 - 2015-07-17 00:19 - 00000000 ____D C:\Users\Sam D\Documents\Freemake
2015-07-17 00:14 - 2015-07-17 00:14 - 03705660 _____ C:\Users\Sam D\Downloads\julie martinz.rar
2015-07-17 00:12 - 2015-07-17 00:12 - 01428393 _____ C:\Users\Sam D\Downloads\dr perkins reports.rar
2015-07-17 00:04 - 2015-07-17 01:39 - 56338278 _____ C:\Users\Sam D\Downloads\brooks ballard stuff.rar
2015-07-17 00:00 - 2015-07-17 00:00 - 00000000 ____D C:\Users\Sam D\Downloads\Archive-d013
2015-07-16 23:53 - 2015-07-16 23:53 - 00469218 _____ C:\Users\Sam D\Downloads\alex fetanax reports.rar
2015-07-16 23:29 - 2015-07-16 23:29 - 00001344 _____ C:\Users\Public\Desktop\Aimersoft YouTube Downloader.lnk
2015-07-16 23:24 - 2015-07-16 23:25 - 00000000 ____D C:\Users\Sam D\Documents\SEO Content Machine
2015-07-16 23:22 - 2015-07-16 23:22 - 15140358 _____ C:\Users\Sam D\Downloads\SEOCNTNTMCHN.zip
2015-07-16 21:39 - 2015-07-16 21:39 - 00000165 ____H C:\Users\Sam D\Downloads\~$DrPerkins-KeywordRanking-Report (8).xlsx
2015-07-16 15:32 - 2015-07-16 15:57 - 00000000 ____D C:\Users\Sam D\Downloads\X-SpinnerBeta
2015-07-15 21:50 - 2015-07-15 21:50 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\JonathanLeger.com
2015-07-15 21:50 - 2015-07-15 21:50 - 00000000 ____D C:\Users\Sam D\AppData\Local\JonathanLeger.com
2015-07-15 21:40 - 2015-07-21 22:23 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts.bak
2015-07-15 21:38 - 2015-07-15 21:38 - 00002597 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hosts File Editor.lnk
2015-07-15 21:38 - 2015-07-15 21:38 - 00000000 ____D C:\Program Files\Hosts File Editor
2015-07-15 21:37 - 2015-07-15 21:37 - 00965632 _____ C:\Users\Sam D\Downloads\HostsFileEditorSetup-1.0.0.msi
2015-07-15 21:35 - 2015-07-15 21:35 - 05478738 _____ C:\Users\Sam D\Downloads\TBS2k15.rar
2015-07-15 21:35 - 2015-07-15 21:35 - 00000000 ____D C:\Users\Sam D\Downloads\TBS2k15
2015-07-15 20:48 - 2015-07-15 21:08 - 62928929 _____ C:\Users\Sam D\Downloads\X-SpinnerBeta.zip
2015-07-15 20:38 - 2015-07-15 20:42 - 00000000 ____D C:\Users\Sam D\Downloads\spinnerchiefiiirelease
2015-07-15 20:31 - 2015-07-15 20:34 - 143837293 _____ C:\Users\Sam D\Downloads\spinnerchiefiiirelease.zip
2015-07-15 19:50 - 2015-07-15 19:50 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\TechSmith
2015-07-14 20:06 - 2015-07-14 20:56 - 155415094 _____ C:\Users\Sam D\Downloads\Wirecast_Play_6_0_5.zip
2015-07-09 22:37 - 2015-07-09 22:38 - 08009896 _____ (TeamViewer GmbH) C:\Users\Sam D\Downloads\TeamViewer_Setup_en.exe
2015-07-09 20:27 - 2015-07-09 20:29 - 34862410 _____ C:\Users\Sam D\Downloads\SuperStreamTube.zip
2015-07-09 00:21 - 2015-07-09 00:22 - 74709456 _____ C:\Users\Sam D\Downloads\lvp-module-2-all-ad-commercials-zipped.zip
2015-07-08 21:42 - 2015-07-08 22:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-07-05 22:52 - 2015-07-05 22:57 - 198186937 _____ C:\Users\Sam D\Downloads\13freeplrvideos.zip
2015-07-05 22:43 - 2015-07-05 22:44 - 43332581 _____ C:\Users\Sam D\Downloads\usfreeadstraffic.zip
2015-07-05 22:42 - 2015-07-05 22:43 - 23271937 _____ C:\Users\Sam D\Downloads\youtubeeditor.zip
2015-07-05 22:29 - 2015-07-05 22:29 - 11159654 _____ C:\Users\Sam D\Downloads\PetGroomingTempPLR09JH.zip
2015-07-05 22:15 - 2015-07-05 22:17 - 60621578 _____ C:\Users\Sam D\Downloads\Offline How To Videos for Local Businesses Set 1.zip
2015-07-05 21:56 - 2015-07-05 21:56 - 17449904 _____ C:\Users\Sam D\Downloads\Groomers-postcards.zip
2015-07-05 15:37 - 2015-07-06 17:31 - 00001721 _____ C:\Users\Sam D\Desktop\pi victorville.txt
2015-07-04 12:46 - 2015-07-04 12:47 - 00000000 ____D C:\Users\Sam D\AppData\Local\Windows Live Writer
2015-07-04 12:46 - 2015-07-04 12:46 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Windows Live Writer
2015-07-03 21:06 - 2015-07-03 21:07 - 00189484 _____ C:\Users\Sam D\Downloads\3.5x2_businesscard.zip
2015-07-02 19:46 - 2015-07-02 19:46 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Disruptive Innovations SARL
2015-07-02 19:46 - 2015-07-02 19:46 - 00000000 ____D C:\Users\Sam D\AppData\Local\Disruptive Innovations SARL
2015-07-02 19:45 - 2015-07-02 19:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueGriffon
2015-07-02 19:45 - 2015-07-02 19:45 - 00000000 ____D C:\Program Files\BlueGriffon
2015-07-02 17:06 - 2015-07-02 17:06 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\KompoZer
2015-07-02 17:05 - 2015-07-02 17:05 - 00000000 ____D C:\Users\Sam D\Downloads\kompozer-0.7.10-win32
2015-07-02 16:50 - 2015-07-02 16:50 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Nvu
2015-07-02 16:19 - 2015-07-02 16:19 - 00000000 ____D C:\Users\Sam D\Downloads\2015 Minecraft account giveaways
2015-07-02 13:54 - 2015-07-17 00:12 - 00000000 ____D C:\Users\Sam D\Desktop\youtube comment method
2015-07-01 12:57 - 2015-07-01 12:57 - 00860501 _____ C:\Users\Sam D\Downloads\medlin.zip
2015-06-30 16:34 - 2015-06-30 16:34 - 00000165 ____H C:\Users\Sam D\Desktop\~$50_old_usa_pva_gmail_accounts.xlsx
2015-06-29 17:09 - 2015-07-23 18:18 - 00007604 _____ C:\Users\Sam D\AppData\Local\Resmon.ResmonCfg
2015-06-26 23:06 - 2015-06-26 23:06 - 00000000 ____D C:\Users\Sam D\AppData\Local\Deshaker
2015-06-25 02:33 - 2015-06-25 02:33 - 00000159 _____ C:\Users\Sam D\Downloads\Delicious.txt
2015-06-25 02:33 - 2015-06-25 02:33 - 00000123 _____ C:\Users\Sam D\Downloads\Diigo.txt
2015-06-25 00:23 - 2015-06-25 00:24 - 17713160 _____ (Microsoft Corporation) C:\Users\Sam D\Downloads\wsemp.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-25 11:57 - 2015-05-31 22:59 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-07-25 11:49 - 2014-12-29 19:27 - 01272075 _____ C:\Windows\WindowsUpdate.log
2015-07-25 11:37 - 2015-02-01 21:05 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-25 11:37 - 2014-09-29 01:47 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-25 11:36 - 2015-03-15 21:10 - 00000000 ___RD C:\Users\Sam D\Dropbox
2015-07-25 11:35 - 2015-03-15 21:06 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Dropbox
2015-07-25 11:34 - 2014-09-29 01:47 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-25 11:34 - 2014-08-28 09:19 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-25 11:33 - 2011-04-14 23:32 - 00000000 ____D C:\ProgramData\NVIDIA
2015-07-25 11:33 - 2009-07-14 00:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-25 02:07 - 2009-07-13 22:04 - 00000215 _____ C:\Windows\system.ini
2015-07-25 01:46 - 2011-01-10 19:42 - 00000000 ___HD C:\Users\Sam D\AppData\Local\Apps\2.0
2015-07-25 01:45 - 2009-07-14 00:34 - 00016624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-25 01:45 - 2009-07-14 00:34 - 00016624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-25 01:44 - 2011-02-06 20:38 - 00000000 ____D C:\Windows\pss
2015-07-25 01:31 - 2015-02-16 11:09 - 00000000 ____D C:\AdwCleaner
2015-07-25 01:15 - 2015-06-16 16:05 - 00000918 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3192665374-2718563871-2505210960-1000UA.job
2015-07-25 01:10 - 2014-09-28 02:12 - 00000000 ____D C:\Users\Sam D
2015-07-25 01:06 - 2014-09-27 13:30 - 00000000 ____D C:\ProgramData\RogueKiller
2015-07-25 00:34 - 2014-09-27 13:30 - 00035064 _____ C:\Windows\system32\Drivers\TrueSight.sys
2015-07-24 22:57 - 2009-07-13 22:37 - 00000000 __RHD C:\Users\Default
2015-07-24 22:39 - 2009-07-13 22:03 - 59506688 _____ C:\Windows\system32\config\SOFTWARE.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 28311552 _____ C:\Windows\system32\config\SYSTEM.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 00524288 _____ C:\Windows\system32\config\DEFAULT.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 00028672 _____ C:\Windows\system32\config\SAM.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 00020480 _____ C:\Windows\system32\config\SECURITY.bak
2015-07-24 22:38 - 2014-09-27 02:51 - 00000000 ____D C:\Windows\ERDNT
2015-07-24 20:11 - 2015-02-12 01:59 - 00002042 _____ C:\Users\Sam D\Documents\Default.rdp
2015-07-24 13:57 - 2014-09-27 20:28 - 00000000 ____D C:\Users\Sam D\AppData\Local\CrashDumps
2015-07-24 13:42 - 2014-08-28 09:18 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-07-24 12:55 - 2011-04-24 19:50 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\Skype
2015-07-24 02:15 - 2015-06-16 16:05 - 00000866 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3192665374-2718563871-2505210960-1000Core.job
2015-07-22 20:07 - 2009-09-24 15:40 - 00000000 ____D C:\Program Files\CCleaner
2015-07-21 20:25 - 2015-06-22 14:09 - 00000000 ____D C:\Users\Sam D\Desktop\New folder
2015-07-20 16:50 - 2015-05-31 16:04 - 00000000 ____D C:\ProgramData\Aimersoft YouTube Downloader
2015-07-18 20:22 - 2015-05-31 22:24 - 00123556 _____ C:\Users\Sam D\AppData\Roaming\net.telestream.wirecast.xml
2015-07-18 20:21 - 2015-05-31 22:24 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Wirecast for YouTube
2015-07-18 13:05 - 2014-12-09 17:36 - 00000000 ____D C:\_acestream_cache_
2015-07-17 20:48 - 2012-11-01 17:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2015-07-17 20:48 - 2011-01-08 00:40 - 00000000 ____D C:\Program Files\Adobe
2015-07-17 20:48 - 2010-12-26 19:38 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\Adobe
2015-07-17 19:58 - 2010-12-26 20:04 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\BitTorrent
2015-07-17 19:57 - 2014-11-01 02:45 - 00000000 ____D C:\Windows\Minidump
2015-07-17 18:09 - 2011-01-21 17:10 - 00000000 ____D C:\ProgramData\TechSmith
2015-07-17 10:17 - 2012-04-11 17:57 - 00117272 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2015-07-17 10:16 - 2009-07-14 00:33 - 00446912 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-17 01:40 - 2015-03-05 16:36 - 56410227 _____ C:\Users\Sam D\Downloads\BrooksBallardFineHomesEstates.zip
2015-07-17 01:17 - 2014-12-11 21:37 - 00000000 ____D C:\Program Files\Citrix
2015-07-17 01:12 - 2015-06-19 23:46 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Stardock
2015-07-17 01:12 - 2015-06-19 23:46 - 00000000 ____D C:\Users\Sam D\AppData\Local\Stardock
2015-07-17 01:12 - 2015-06-19 23:46 - 00000000 ____D C:\ProgramData\Stardock
2015-07-17 01:12 - 2015-06-19 23:45 - 00000000 ____D C:\Program Files\Stardock
2015-07-17 00:51 - 2014-12-07 23:21 - 00000000 ____D C:\Users\Sam D\AppData\Local\Deployment
2015-07-17 00:49 - 2015-03-11 13:29 - 00000000 ____D C:\Users\Sam D\AppData\Local\Mozilla
2015-07-17 00:49 - 2015-03-11 12:57 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Mozilla
2015-07-17 00:43 - 2011-01-10 03:16 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-07-17 00:43 - 2009-07-14 00:56 - 00000000 ____D C:\Windows\system32\winrm
2015-07-17 00:00 - 2015-06-10 19:25 - 00000000 ____D C:\Users\Sam D\AppData\Local\IIIQ
2015-07-16 23:55 - 2015-03-07 01:09 - 00000000 ____D C:\Users\Sam D\Downloads\Archive-9cd1
2015-07-16 23:39 - 2014-09-28 11:22 - 00118056 _____ C:\Users\Sam D\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-16 23:24 - 2015-06-12 22:37 - 00000000 ____D C:\Users\Sam D\AppData\Local\Satin_Blue
2015-07-16 23:07 - 2011-04-19 13:06 - 02721183 _____ C:\Windows\system32\oodbs.lor
2015-07-16 13:20 - 2015-03-25 20:59 - 00000000 ____D C:\Users\Sam D\Desktop\PPC Business
2015-07-16 12:36 - 2015-05-05 21:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-07-15 23:49 - 2012-02-21 15:48 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\vlc
2015-07-14 20:10 - 2014-12-27 14:03 - 00023398 _____ C:\Users\Sam D\Desktop\50_old_usa_pva_gmail_accounts.xlsx
2015-07-14 16:37 - 2012-04-22 12:39 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-14 16:37 - 2011-05-20 16:13 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-14 15:16 - 2014-10-30 23:55 - 00000000 ____D C:\Users\Sam D\Desktop\Consulting
2015-07-14 15:00 - 2011-04-06 14:25 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\Media Player Classic
2015-07-14 14:41 - 2015-06-02 18:12 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\HandBrake
2015-07-14 14:05 - 2015-06-08 19:50 - 00096511 _____ C:\Users\Sam D\.websiteauditor.properties
2015-07-14 14:05 - 2015-06-08 19:50 - 00000000 ____D C:\Users\Sam D\.websiteauditor
2015-07-14 14:03 - 2015-06-17 01:12 - 00000000 ____D C:\Users\Sam D\.ranktracker
2015-07-14 14:03 - 2014-11-07 01:57 - 00137380 _____ C:\Users\Sam D\.ranktracker.properties
2015-07-14 14:02 - 2010-12-26 20:11 - 00000000 ____D C:\Users\Sam D\Desktop\entertainment
2015-07-14 13:59 - 2014-09-28 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-07-14 11:56 - 2014-12-26 17:27 - 00000000 ____D C:\Users\Sam D\Desktop\proxy stuff and related
2015-07-14 11:34 - 2014-09-29 01:48 - 00002131 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-13 16:04 - 2011-01-08 18:45 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\FileZilla
2015-07-11 01:20 - 2014-10-31 15:05 - 00000000 ___RD C:\Program Files\Skype
2015-07-11 01:20 - 2011-04-24 19:49 - 00000000 ____D C:\ProgramData\Skype
2015-07-10 17:39 - 2015-02-10 17:02 - 00000000 ____D C:\Users\Sam D\Desktop\Ripoffreport Stuff
2015-07-10 14:20 - 2015-02-01 00:24 - 00000000 ____D C:\Users\Sam D\AppData\Local\Commando
2015-07-09 12:14 - 2014-09-28 17:01 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-08 15:37 - 2015-04-20 14:31 - 00040553 _____ C:\Users\Sam D\Desktop\Sales call log and organizer1 sam.xlsx
2015-07-08 15:06 - 2015-04-20 10:16 - 00000000 ____D C:\Users\Sam D\Desktop\Attorney Combined Files
2015-07-04 12:46 - 2013-02-28 23:35 - 00001406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-07-04 12:46 - 2013-02-28 23:21 - 00000000 ____D C:\Users\Sam D\AppData\Local\Windows Live
2015-07-02 19:38 - 2015-01-18 01:01 - 00001952 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2015-07-02 19:38 - 2011-01-08 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-07-02 19:38 - 2011-01-08 18:45 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2015-07-02 13:56 - 2015-02-17 19:50 - 00000000 ____D C:\Users\Sam D\Desktop\customer info
2015-07-01 23:36 - 2009-04-24 18:28 - 00052736 _____ C:\Users\Sam D\Desktop\affiliate list.v1.xls
2015-06-27 15:24 - 2014-08-28 09:18 - 00001066 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-27 15:24 - 2014-08-28 09:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-27 15:24 - 2014-08-28 09:17 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-26 12:47 - 2014-12-29 17:57 - 00005632 _____ C:\Users\Sam D\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Files in the root of some directories =======
2014-09-17 21:05 - 2014-09-17 21:05 - 11249152 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2014-03-18 14:13 - 2014-03-18 14:14 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files\Common Files\wruninstall.exe
2011-01-10 02:44 - 2011-01-10 02:44 - 0874496 ____H (ExtremeCoderz) C:\Users\Sam D\AppData\Roaming\MultiPoster4.exe
2015-05-31 22:24 - 2015-07-18 20:22 - 0123556 _____ () C:\Users\Sam D\AppData\Roaming\net.telestream.wirecast.xml
2015-06-01 00:15 - 2015-06-01 00:15 - 0014543 _____ () C:\Users\Sam D\AppData\Roaming\net_telestream_wirecast_partner_AFL9067099885_brandingimage_destination.png
2015-06-01 00:15 - 2015-06-01 00:15 - 0014186 _____ () C:\Users\Sam D\AppData\Roaming\net_telestream_wirecast_partner_AFL9067099885_brandingimage_main.png
2011-01-10 02:44 - 2011-01-10 02:44 - 0000324 ____H () C:\Users\Sam D\AppData\Roaming\settings.cfg
2014-12-29 17:57 - 2015-06-26 12:47 - 0005632 _____ () C:\Users\Sam D\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-19 12:34 - 2015-04-02 21:27 - 0000600 _____ () C:\Users\Sam D\AppData\Local\PUTTY.RND
2015-06-29 17:09 - 2015-07-23 18:18 - 0007604 _____ () C:\Users\Sam D\AppData\Local\Resmon.ResmonCfg
2014-12-15 13:45 - 2014-12-15 13:45 - 0000000 _____ () C:\Users\Sam D\AppData\Local\{EA8A6224-C8D9-48BF-8C16-038572217C9F}
Some files in TEMP:
====================
C:\Users\Sam D\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5sdnxp.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-16 13:40
==================== End of log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2015
Ran by Sam D (administrator) on SAMD-PC (25-07-2015 12:00:19)
Running from C:\Users\Sam D\Downloads
Loaded Profiles: Sam D (Available Profiles: Sam D)
Platform: Microsoft Windows 7 Ultimate (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Ellora Assets Corp.) C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [159744 2007-07-02] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Fences] => C:\Program Files\Stardock\Fences\Fences.exe [4031152 2013-11-26] (Stardock Corporation)
Winlogon\Notify\klogon: C:\Windows\system32\klogon.dll [2010-10-05] (Kaspersky Lab ZAO)
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6715160 2015-07-08] (SUPERAntiSpyware)
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6369048 2015-05-08] (Piriform Ltd)
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\...\Run: [Dropbox Update] => C:\Users\Sam D\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-16] (Dropbox, Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2015-06-19] (Microsoft Corporation)
Startup: C:\Users\Sam D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Sam D\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Sam D\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-06-20] (Google)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=SKY2&ocid=SKY2DHP&osmkt=en-us
URLSearchHook: HKU\S-1-5-21-3192665374-2718563871-2505210960-1000 - (No Name) - {5F9575C2-1AB4-4883-8505-5C6D0DFDF2D5} - No File
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
Toolbar: HKLM - KeywordSpy™ SEO/PPC - {0AE831B0-427E-4D0A-BC88-4BA47E7471C3} - C:\Program Files\KeywordSpy SEOPPC Plug-in\KeywordSpySEO.dll [2010-07-31] ()
Toolbar: HKU\.DEFAULT -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3192665374-2718563871-2505210960-1000 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-3192665374-2718563871-2505210960-1000 -> KeywordSpy™ SEO/PPC - {0AE831B0-427E-4D0A-BC88-4BA47E7471C3} - C:\Program Files\KeywordSpy SEOPPC Plug-in\KeywordSpySEO.dll [2010-07-31] ()
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Handler: WSAMAllMyTubechrome - {C985F516-9C03-4F90 - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{753E788B-AD78-4CDD-B153-CDD66A6584E0}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630
FF DefaultSearchEngine.US: Google
FF Homepage: gmail.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] ()
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-02-10] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-07-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3192665374-2718563871-2505210960-1000: @acestream.net/acestreamplugin,version=3.0.12 -> C:\Users\Sam D\AppData\Roaming\ACEStream\player\npace_plugin.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-02-10] (Microsoft Corporation)
FF Extension: Copy Urls Expert - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\copy-urls-expert@kashiif-gmail.com.xpi [2015-07-20]
FF Extension: MozBar - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\toolbar@seomoz.org.xpi [2015-06-28]
FF Extension: PPCWebSpy Toolbar - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\{86c18b42-e466-45a9-ae7a-9b95ba6f5640}.xpi [2015-05-17]
FF Extension: SEO Global For Google Search™ - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\{B97F57B9-1B42-4aed-9475-0022600C62DC}.xpi [2015-06-24]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Sam D\AppData\Roaming\Mozilla\Firefox\Profiles\f2lvmis4.default-1426352688630\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2015-05-31]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-07-08]
FF HKLM\...\Firefox\Extensions: [AMAllMyTube@Aimersoft.com] - C:\ProgramData\Aimersoft\YouTube Downloader\AMAllMyTube@Aimersoft.com
FF Extension: Aimersoft YouTube Downloader - C:\ProgramData\Aimersoft\YouTube Downloader\AMAllMyTube@Aimersoft.com [2015-05-31]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Webbing) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fblcpdlednddbkcdbkkaiggjipjjgpdp [2014-10-15]
CHR Extension: (DivX HiQ) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae [2012-07-28]
CHR Extension: (NextCouup) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\goeeobfmefldgbbdlmjdjagkkhmmnopi [2014-10-08]
CHR Extension: (GoSavvE) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hgdnccifmkfafkohlbeailfepfjbmdna [2014-09-25]
CHR Extension: (OpptOn) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hnojomgcmohiefbikenglccliaogccbn [2014-09-27]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-07-28]
CHR Extension: (HTML5ify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jikbjpjgjmmdhcmlagappehlpiljoaop [2015-03-12]
CHR Extension: (Codec-V) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho [2012-07-28]
CHR Extension: (Deezify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kpkbhaapafmlmgodhicgpngihalhepll [2015-02-14]
CHR Extension: (GoSSave) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lhijjoggceedllbdndfjjnjpomecffad [2014-10-08]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-07-28]
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google Drive) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-18]
CHR Extension: (Poper Blocker) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-07-01]
CHR Extension: (APK Downloader) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cgihflhdpokeobcfimliamffejfnmfii [2014-10-26]
CHR Extension: (Image Downloader) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2014-10-16]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014-11-25]
CHR Extension: (Video Downloader professional) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2014-11-17]
CHR Extension: (Webbing) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fblcpdlednddbkcdbkkaiggjipjjgpdp [2014-10-15]
CHR Extension: (AdBlock) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-07-01]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-11]
CHR Extension: (Google Wallet) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (SEO Global For Google Search™) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ojgmigafbpedhdilmemphfklkbghlphi [2015-06-24]
CHR Profile: C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3
CHR Extension: (Google Docs) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-27]
CHR Extension: (Google Drive) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-27]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-27]
CHR Extension: (YouTube) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-27]
CHR Extension: (Google Search) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-27]
CHR Extension: (HTML5ify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\jikbjpjgjmmdhcmlagappehlpiljoaop [2015-03-12]
CHR Extension: (Deezify) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kpkbhaapafmlmgodhicgpngihalhepll [2015-02-14]
CHR Extension: (Google Wallet) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-27]
CHR Extension: (Gmail) - C:\Users\Sam D\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-27]
CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
CHR HKU\S-1-5-21-3192665374-2718563871-2505210960-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\SAMD~1\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-22] (SUPERAntiSpyware.com)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-09-11] (Freemake) [File not signed]
R2 FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-09-11] (Ellora Assets Corp.) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [35992 2015-02-16] ()
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [132184 2010-06-09] (Kaspersky Lab ZAO)
R1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11352 2010-06-09] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [488536 2010-12-26] (Kaspersky Lab)
S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [22104 2010-04-22] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [19984 2009-11-02] (Kaspersky Lab)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [98520 2015-07-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [23040 2014-11-05] (The OpenVPN Project)
S3 TSVAD_PCM; C:\Windows\System32\drivers\tsvadpcm.sys [28432 2014-08-15] (Windows (R) Win 7 DDK provider)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2014-11-28] (RealVNC Ltd.)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [116736 2014-09-02] (Webroot)
S3 catchme; \??\C:\Users\SAMD~1\AppData\Local\Temp\catchme.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-25 12:00 - 2015-07-25 12:01 - 00024169 _____ C:\Users\Sam D\Downloads\FRST.txt
2015-07-25 12:00 - 2015-07-25 12:00 - 00000000 ____D C:\FRST
2015-07-25 11:59 - 2015-07-25 11:59 - 01650688 _____ (Farbar) C:\Users\Sam D\Downloads\FRST.exe
2015-07-25 02:14 - 2015-07-25 02:14 - 00028527 _____ C:\ComboFix.txt
2015-07-25 01:43 - 2015-07-25 01:43 - 00001098 _____ C:\Users\Sam D\Desktop\ComboFix - Shortcut.lnk
2015-07-25 01:40 - 2015-07-25 01:42 - 00003448 _____ C:\Users\Sam D\Desktop\Rkill.txt
2015-07-25 01:39 - 2015-07-25 01:39 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\Sam D\Downloads\rkill.exe
2015-07-25 01:22 - 2015-07-25 01:22 - 00002982 _____ C:\Users\Sam D\Desktop\JRT.txt
2015-07-25 00:48 - 2015-07-25 00:48 - 02248704 _____ C:\Users\Sam D\Downloads\adwcleaner_4.208.exe
2015-07-25 00:47 - 2015-07-25 00:48 - 01798288 _____ (Malwarebytes Corporation) C:\Users\Sam D\Downloads\JRT (1).exe
2015-07-25 00:33 - 2015-07-25 00:34 - 18705480 _____ C:\Users\Sam D\Downloads\RogueKiller.exe
2015-07-24 23:42 - 2015-07-24 23:43 - 07269656 _____ (Bitdefender LLC) C:\Users\Sam D\Downloads\BootkitRemoval_x86.exe
2015-07-24 22:40 - 2015-07-25 11:33 - 00002828 _____ C:\Windows\setupact.log
2015-07-24 22:40 - 2015-07-25 02:06 - 00001430 _____ C:\Windows\PFRO.log
2015-07-24 22:40 - 2015-07-24 22:40 - 00000000 _____ C:\Windows\setuperr.log
2015-07-24 21:56 - 2011-06-26 02:45 - 00256000 _____ C:\Windows\PEV.exe
2015-07-24 21:56 - 2010-11-07 13:20 - 00208896 _____ C:\Windows\MBR.exe
2015-07-24 21:56 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00098816 _____ C:\Windows\sed.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00080412 _____ C:\Windows\grep.exe
2015-07-24 21:56 - 2000-08-30 20:00 - 00068096 _____ C:\Windows\zip.exe
2015-07-24 21:55 - 2015-07-25 02:14 - 00000000 ____D C:\Qoobox
2015-07-24 16:56 - 2015-07-24 16:58 - 05633622 ____R (Swearware) C:\Users\Sam D\Downloads\ComboFix.exe
2015-07-24 16:51 - 2015-07-24 16:52 - 04404952 _____ (Kaspersky Lab ZAO) C:\Users\Sam D\Downloads\tdsskiller.exe
2015-07-24 13:43 - 2015-07-25 00:02 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-07-24 13:41 - 2015-07-24 16:38 - 00000000 ____D C:\Users\Sam D\Desktop\mbar
2015-07-24 13:40 - 2015-07-24 13:41 - 00380416 _____ C:\Users\Sam D\Downloads\y6so8ixt.exe
2015-07-24 13:38 - 2015-07-24 13:40 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Sam D\Downloads\mbar-1.09.1.1004.exe
2015-07-24 12:27 - 2015-07-24 12:27 - 00000177 _____ C:\Users\Sam D\Desktop\scrapebox.txt
2015-07-24 11:12 - 2015-07-24 11:12 - 00000000 ____D C:\Program Files\ESET
2015-07-24 11:11 - 2015-07-24 11:11 - 02870984 _____ (ESET) C:\Users\Sam D\Downloads\esetsmartinstaller_enu.exe
2015-07-24 10:59 - 2015-07-24 11:04 - 06754696 _____ C:\Users\Sam D\Downloads\CCl3aner5.07.5261.rar
2015-07-22 12:37 - 2015-07-22 12:37 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheBestSpinner3
2015-07-22 12:37 - 2015-07-22 12:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TheBestSpinner3
2015-07-22 12:37 - 2015-07-22 12:37 - 00000000 ____D C:\Program Files\TheBestSpinner3
2015-07-22 12:28 - 2015-07-22 12:28 - 00784723 _____ C:\Users\Sam D\Downloads\bonus_super_spun_articles_55afc6468bce4.zip
2015-07-21 22:53 - 2015-07-21 22:53 - 05509505 _____ C:\Users\Sam D\Downloads\SetupTheBestSpinner3.exe
2015-07-21 22:53 - 2015-07-21 22:53 - 00784723 _____ C:\Users\Sam D\Downloads\bonus_super_spun_articles_55af074bbc3ca.zip
2015-07-21 22:31 - 2015-07-21 22:32 - 00000000 ____D C:\Users\Sam D\Downloads\SetupTheBestSpinner3.421
2015-07-21 22:22 - 2015-07-21 22:22 - 00000000 ____D C:\Users\Sam D\Downloads\TBS2k15 (1)
2015-07-21 21:18 - 2015-07-21 21:18 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-07-21 20:23 - 2015-07-24 12:54 - 00000000 ____D C:\Users\Sam D\Desktop\San antonio articles stuff
2015-07-21 15:15 - 2015-07-21 16:03 - 00000000 ____D C:\Users\Sam D\Downloads\KeywordResearcher
2015-07-21 15:15 - 2015-07-21 15:15 - 02852471 _____ C:\Users\Sam D\Downloads\KeywordResearcher.rar
2015-07-21 15:15 - 2015-01-09 04:19 - 08483504 _____ C:\Users\Sam D\Desktop\KeywordResearcher.exe
2015-07-21 15:14 - 2015-07-21 15:14 - 03717120 _____ (Microsoft Corporation) C:\Users\Sam D\Downloads\KeywordResearcher9Latest.exe
2015-07-19 18:44 - 2015-07-22 11:22 - 00000000 ____D C:\Users\Sam D\Desktop\New folder (2)
2015-07-19 00:01 - 2015-07-19 00:01 - 01874588 _____ C:\Users\Sam D\Downloads\Fiverr SEO Gigs Handbook.zip
2015-07-18 18:38 - 2015-07-18 18:39 - 61902129 _____ C:\Users\Sam D\Downloads\X-SpinnerBeta (1).zip
2015-07-17 20:54 - 2015-07-17 20:55 - 155415094 _____ C:\Users\Sam D\Downloads\Wirecast_Play_6_0_5 (1).zip
2015-07-17 20:47 - 2015-07-17 20:47 - 06537216 _____ C:\Users\Sam D\Downloads\flashmedialiveencoder_3.2_wwe_signed.msi
2015-07-17 18:13 - 2015-07-18 15:55 - 00000000 ____D C:\Users\Sam D\Documents\Camtasia Studio
2015-07-17 18:09 - 2015-07-17 18:09 - 00001128 _____ C:\Users\Public\Desktop\Camtasia Studio 8.lnk
2015-07-17 18:09 - 2015-07-17 18:09 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2015-07-17 18:09 - 2015-07-17 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2015-07-17 18:08 - 2015-07-17 18:08 - 00000000 ____D C:\Program Files\Common Files\TechSmith Shared
2015-07-17 18:07 - 2015-07-17 18:07 - 00000000 ____D C:\Program Files\TechSmith
2015-07-17 17:54 - 2015-07-17 17:55 - 00000000 ____D C:\Users\Sam D\Documents\TechSmith Camtasia Studio 8.5.1 Build 1962 RePack by KpoJIuK
2015-07-17 16:45 - 2015-07-17 16:45 - 00000165 ____H C:\Users\Sam D\Desktop\~$Sales call log and organizer1 sam.xlsx
2015-07-17 00:19 - 2015-07-17 00:19 - 00001710 _____ C:\Users\Sam D\Desktop\FreemakeVD - Shortcut.lnk
2015-07-17 00:19 - 2015-07-17 00:19 - 00000000 ____D C:\Users\Sam D\Documents\Freemake
2015-07-17 00:14 - 2015-07-17 00:14 - 03705660 _____ C:\Users\Sam D\Downloads\julie martinz.rar
2015-07-17 00:12 - 2015-07-17 00:12 - 01428393 _____ C:\Users\Sam D\Downloads\dr perkins reports.rar
2015-07-17 00:04 - 2015-07-17 01:39 - 56338278 _____ C:\Users\Sam D\Downloads\brooks ballard stuff.rar
2015-07-17 00:00 - 2015-07-17 00:00 - 00000000 ____D C:\Users\Sam D\Downloads\Archive-d013
2015-07-16 23:53 - 2015-07-16 23:53 - 00469218 _____ C:\Users\Sam D\Downloads\alex fetanax reports.rar
2015-07-16 23:29 - 2015-07-16 23:29 - 00001344 _____ C:\Users\Public\Desktop\Aimersoft YouTube Downloader.lnk
2015-07-16 23:24 - 2015-07-16 23:25 - 00000000 ____D C:\Users\Sam D\Documents\SEO Content Machine
2015-07-16 23:22 - 2015-07-16 23:22 - 15140358 _____ C:\Users\Sam D\Downloads\SEOCNTNTMCHN.zip
2015-07-16 21:39 - 2015-07-16 21:39 - 00000165 ____H C:\Users\Sam D\Downloads\~$DrPerkins-KeywordRanking-Report (8).xlsx
2015-07-16 15:32 - 2015-07-16 15:57 - 00000000 ____D C:\Users\Sam D\Downloads\X-SpinnerBeta
2015-07-15 21:50 - 2015-07-15 21:50 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\JonathanLeger.com
2015-07-15 21:50 - 2015-07-15 21:50 - 00000000 ____D C:\Users\Sam D\AppData\Local\JonathanLeger.com
2015-07-15 21:40 - 2015-07-21 22:23 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts.bak
2015-07-15 21:38 - 2015-07-15 21:38 - 00002597 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hosts File Editor.lnk
2015-07-15 21:38 - 2015-07-15 21:38 - 00000000 ____D C:\Program Files\Hosts File Editor
2015-07-15 21:37 - 2015-07-15 21:37 - 00965632 _____ C:\Users\Sam D\Downloads\HostsFileEditorSetup-1.0.0.msi
2015-07-15 21:35 - 2015-07-15 21:35 - 05478738 _____ C:\Users\Sam D\Downloads\TBS2k15.rar
2015-07-15 21:35 - 2015-07-15 21:35 - 00000000 ____D C:\Users\Sam D\Downloads\TBS2k15
2015-07-15 20:48 - 2015-07-15 21:08 - 62928929 _____ C:\Users\Sam D\Downloads\X-SpinnerBeta.zip
2015-07-15 20:38 - 2015-07-15 20:42 - 00000000 ____D C:\Users\Sam D\Downloads\spinnerchiefiiirelease
2015-07-15 20:31 - 2015-07-15 20:34 - 143837293 _____ C:\Users\Sam D\Downloads\spinnerchiefiiirelease.zip
2015-07-15 19:50 - 2015-07-15 19:50 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\TechSmith
2015-07-14 20:06 - 2015-07-14 20:56 - 155415094 _____ C:\Users\Sam D\Downloads\Wirecast_Play_6_0_5.zip
2015-07-09 22:37 - 2015-07-09 22:38 - 08009896 _____ (TeamViewer GmbH) C:\Users\Sam D\Downloads\TeamViewer_Setup_en.exe
2015-07-09 20:27 - 2015-07-09 20:29 - 34862410 _____ C:\Users\Sam D\Downloads\SuperStreamTube.zip
2015-07-09 00:21 - 2015-07-09 00:22 - 74709456 _____ C:\Users\Sam D\Downloads\lvp-module-2-all-ad-commercials-zipped.zip
2015-07-08 21:42 - 2015-07-08 22:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-07-05 22:52 - 2015-07-05 22:57 - 198186937 _____ C:\Users\Sam D\Downloads\13freeplrvideos.zip
2015-07-05 22:43 - 2015-07-05 22:44 - 43332581 _____ C:\Users\Sam D\Downloads\usfreeadstraffic.zip
2015-07-05 22:42 - 2015-07-05 22:43 - 23271937 _____ C:\Users\Sam D\Downloads\youtubeeditor.zip
2015-07-05 22:29 - 2015-07-05 22:29 - 11159654 _____ C:\Users\Sam D\Downloads\PetGroomingTempPLR09JH.zip
2015-07-05 22:15 - 2015-07-05 22:17 - 60621578 _____ C:\Users\Sam D\Downloads\Offline How To Videos for Local Businesses Set 1.zip
2015-07-05 21:56 - 2015-07-05 21:56 - 17449904 _____ C:\Users\Sam D\Downloads\Groomers-postcards.zip
2015-07-05 15:37 - 2015-07-06 17:31 - 00001721 _____ C:\Users\Sam D\Desktop\pi victorville.txt
2015-07-04 12:46 - 2015-07-04 12:47 - 00000000 ____D C:\Users\Sam D\AppData\Local\Windows Live Writer
2015-07-04 12:46 - 2015-07-04 12:46 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Windows Live Writer
2015-07-03 21:06 - 2015-07-03 21:07 - 00189484 _____ C:\Users\Sam D\Downloads\3.5x2_businesscard.zip
2015-07-02 19:46 - 2015-07-02 19:46 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Disruptive Innovations SARL
2015-07-02 19:46 - 2015-07-02 19:46 - 00000000 ____D C:\Users\Sam D\AppData\Local\Disruptive Innovations SARL
2015-07-02 19:45 - 2015-07-02 19:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueGriffon
2015-07-02 19:45 - 2015-07-02 19:45 - 00000000 ____D C:\Program Files\BlueGriffon
2015-07-02 17:06 - 2015-07-02 17:06 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\KompoZer
2015-07-02 17:05 - 2015-07-02 17:05 - 00000000 ____D C:\Users\Sam D\Downloads\kompozer-0.7.10-win32
2015-07-02 16:50 - 2015-07-02 16:50 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Nvu
2015-07-02 16:19 - 2015-07-02 16:19 - 00000000 ____D C:\Users\Sam D\Downloads\2015 Minecraft account giveaways
2015-07-02 13:54 - 2015-07-17 00:12 - 00000000 ____D C:\Users\Sam D\Desktop\youtube comment method
2015-07-01 12:57 - 2015-07-01 12:57 - 00860501 _____ C:\Users\Sam D\Downloads\medlin.zip
2015-06-30 16:34 - 2015-06-30 16:34 - 00000165 ____H C:\Users\Sam D\Desktop\~$50_old_usa_pva_gmail_accounts.xlsx
2015-06-29 17:09 - 2015-07-23 18:18 - 00007604 _____ C:\Users\Sam D\AppData\Local\Resmon.ResmonCfg
2015-06-26 23:06 - 2015-06-26 23:06 - 00000000 ____D C:\Users\Sam D\AppData\Local\Deshaker
2015-06-25 02:33 - 2015-06-25 02:33 - 00000159 _____ C:\Users\Sam D\Downloads\Delicious.txt
2015-06-25 02:33 - 2015-06-25 02:33 - 00000123 _____ C:\Users\Sam D\Downloads\Diigo.txt
2015-06-25 00:23 - 2015-06-25 00:24 - 17713160 _____ (Microsoft Corporation) C:\Users\Sam D\Downloads\wsemp.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-25 11:57 - 2015-05-31 22:59 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-07-25 11:49 - 2014-12-29 19:27 - 01272075 _____ C:\Windows\WindowsUpdate.log
2015-07-25 11:37 - 2015-02-01 21:05 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-25 11:37 - 2014-09-29 01:47 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-25 11:36 - 2015-03-15 21:10 - 00000000 ___RD C:\Users\Sam D\Dropbox
2015-07-25 11:35 - 2015-03-15 21:06 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Dropbox
2015-07-25 11:34 - 2014-09-29 01:47 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-25 11:34 - 2014-08-28 09:19 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-25 11:33 - 2011-04-14 23:32 - 00000000 ____D C:\ProgramData\NVIDIA
2015-07-25 11:33 - 2009-07-14 00:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-25 02:07 - 2009-07-13 22:04 - 00000215 _____ C:\Windows\system.ini
2015-07-25 01:46 - 2011-01-10 19:42 - 00000000 ___HD C:\Users\Sam D\AppData\Local\Apps\2.0
2015-07-25 01:45 - 2009-07-14 00:34 - 00016624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-25 01:45 - 2009-07-14 00:34 - 00016624 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-25 01:44 - 2011-02-06 20:38 - 00000000 ____D C:\Windows\pss
2015-07-25 01:31 - 2015-02-16 11:09 - 00000000 ____D C:\AdwCleaner
2015-07-25 01:15 - 2015-06-16 16:05 - 00000918 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3192665374-2718563871-2505210960-1000UA.job
2015-07-25 01:10 - 2014-09-28 02:12 - 00000000 ____D C:\Users\Sam D
2015-07-25 01:06 - 2014-09-27 13:30 - 00000000 ____D C:\ProgramData\RogueKiller
2015-07-25 00:34 - 2014-09-27 13:30 - 00035064 _____ C:\Windows\system32\Drivers\TrueSight.sys
2015-07-24 22:57 - 2009-07-13 22:37 - 00000000 __RHD C:\Users\Default
2015-07-24 22:39 - 2009-07-13 22:03 - 59506688 _____ C:\Windows\system32\config\SOFTWARE.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 28311552 _____ C:\Windows\system32\config\SYSTEM.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 00524288 _____ C:\Windows\system32\config\DEFAULT.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 00028672 _____ C:\Windows\system32\config\SAM.bak
2015-07-24 22:39 - 2009-07-13 22:03 - 00020480 _____ C:\Windows\system32\config\SECURITY.bak
2015-07-24 22:38 - 2014-09-27 02:51 - 00000000 ____D C:\Windows\ERDNT
2015-07-24 20:11 - 2015-02-12 01:59 - 00002042 _____ C:\Users\Sam D\Documents\Default.rdp
2015-07-24 13:57 - 2014-09-27 20:28 - 00000000 ____D C:\Users\Sam D\AppData\Local\CrashDumps
2015-07-24 13:42 - 2014-08-28 09:18 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-07-24 12:55 - 2011-04-24 19:50 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\Skype
2015-07-24 02:15 - 2015-06-16 16:05 - 00000866 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-3192665374-2718563871-2505210960-1000Core.job
2015-07-22 20:07 - 2009-09-24 15:40 - 00000000 ____D C:\Program Files\CCleaner
2015-07-21 20:25 - 2015-06-22 14:09 - 00000000 ____D C:\Users\Sam D\Desktop\New folder
2015-07-20 16:50 - 2015-05-31 16:04 - 00000000 ____D C:\ProgramData\Aimersoft YouTube Downloader
2015-07-18 20:22 - 2015-05-31 22:24 - 00123556 _____ C:\Users\Sam D\AppData\Roaming\net.telestream.wirecast.xml
2015-07-18 20:21 - 2015-05-31 22:24 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Wirecast for YouTube
2015-07-18 13:05 - 2014-12-09 17:36 - 00000000 ____D C:\_acestream_cache_
2015-07-17 20:48 - 2012-11-01 17:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2015-07-17 20:48 - 2011-01-08 00:40 - 00000000 ____D C:\Program Files\Adobe
2015-07-17 20:48 - 2010-12-26 19:38 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\Adobe
2015-07-17 19:58 - 2010-12-26 20:04 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\BitTorrent
2015-07-17 19:57 - 2014-11-01 02:45 - 00000000 ____D C:\Windows\Minidump
2015-07-17 18:09 - 2011-01-21 17:10 - 00000000 ____D C:\ProgramData\TechSmith
2015-07-17 10:17 - 2012-04-11 17:57 - 00117272 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT
2015-07-17 10:16 - 2009-07-14 00:33 - 00446912 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-17 01:40 - 2015-03-05 16:36 - 56410227 _____ C:\Users\Sam D\Downloads\BrooksBallardFineHomesEstates.zip
2015-07-17 01:17 - 2014-12-11 21:37 - 00000000 ____D C:\Program Files\Citrix
2015-07-17 01:12 - 2015-06-19 23:46 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Stardock
2015-07-17 01:12 - 2015-06-19 23:46 - 00000000 ____D C:\Users\Sam D\AppData\Local\Stardock
2015-07-17 01:12 - 2015-06-19 23:46 - 00000000 ____D C:\ProgramData\Stardock
2015-07-17 01:12 - 2015-06-19 23:45 - 00000000 ____D C:\Program Files\Stardock
2015-07-17 00:51 - 2014-12-07 23:21 - 00000000 ____D C:\Users\Sam D\AppData\Local\Deployment
2015-07-17 00:49 - 2015-03-11 13:29 - 00000000 ____D C:\Users\Sam D\AppData\Local\Mozilla
2015-07-17 00:49 - 2015-03-11 12:57 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\Mozilla
2015-07-17 00:43 - 2011-01-10 03:16 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-07-17 00:43 - 2009-07-14 00:56 - 00000000 ____D C:\Windows\system32\winrm
2015-07-17 00:00 - 2015-06-10 19:25 - 00000000 ____D C:\Users\Sam D\AppData\Local\IIIQ
2015-07-16 23:55 - 2015-03-07 01:09 - 00000000 ____D C:\Users\Sam D\Downloads\Archive-9cd1
2015-07-16 23:39 - 2014-09-28 11:22 - 00118056 _____ C:\Users\Sam D\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-16 23:24 - 2015-06-12 22:37 - 00000000 ____D C:\Users\Sam D\AppData\Local\Satin_Blue
2015-07-16 23:07 - 2011-04-19 13:06 - 02721183 _____ C:\Windows\system32\oodbs.lor
2015-07-16 13:20 - 2015-03-25 20:59 - 00000000 ____D C:\Users\Sam D\Desktop\PPC Business
2015-07-16 12:36 - 2015-05-05 21:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-07-15 23:49 - 2012-02-21 15:48 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\vlc
2015-07-14 20:10 - 2014-12-27 14:03 - 00023398 _____ C:\Users\Sam D\Desktop\50_old_usa_pva_gmail_accounts.xlsx
2015-07-14 16:37 - 2012-04-22 12:39 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-14 16:37 - 2011-05-20 16:13 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-14 15:16 - 2014-10-30 23:55 - 00000000 ____D C:\Users\Sam D\Desktop\Consulting
2015-07-14 15:00 - 2011-04-06 14:25 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\Media Player Classic
2015-07-14 14:41 - 2015-06-02 18:12 - 00000000 ____D C:\Users\Sam D\AppData\Roaming\HandBrake
2015-07-14 14:05 - 2015-06-08 19:50 - 00096511 _____ C:\Users\Sam D\.websiteauditor.properties
2015-07-14 14:05 - 2015-06-08 19:50 - 00000000 ____D C:\Users\Sam D\.websiteauditor
2015-07-14 14:03 - 2015-06-17 01:12 - 00000000 ____D C:\Users\Sam D\.ranktracker
2015-07-14 14:03 - 2014-11-07 01:57 - 00137380 _____ C:\Users\Sam D\.ranktracker.properties
2015-07-14 14:02 - 2010-12-26 20:11 - 00000000 ____D C:\Users\Sam D\Desktop\entertainment
2015-07-14 13:59 - 2014-09-28 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-07-14 11:56 - 2014-12-26 17:27 - 00000000 ____D C:\Users\Sam D\Desktop\proxy stuff and related
2015-07-14 11:34 - 2014-09-29 01:48 - 00002131 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-13 16:04 - 2011-01-08 18:45 - 00000000 ___HD C:\Users\Sam D\AppData\Roaming\FileZilla
2015-07-11 01:20 - 2014-10-31 15:05 - 00000000 ___RD C:\Program Files\Skype
2015-07-11 01:20 - 2011-04-24 19:49 - 00000000 ____D C:\ProgramData\Skype
2015-07-10 17:39 - 2015-02-10 17:02 - 00000000 ____D C:\Users\Sam D\Desktop\Ripoffreport Stuff
2015-07-10 14:20 - 2015-02-01 00:24 - 00000000 ____D C:\Users\Sam D\AppData\Local\Commando
2015-07-09 12:14 - 2014-09-28 17:01 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-07-08 15:37 - 2015-04-20 14:31 - 00040553 _____ C:\Users\Sam D\Desktop\Sales call log and organizer1 sam.xlsx
2015-07-08 15:06 - 2015-04-20 10:16 - 00000000 ____D C:\Users\Sam D\Desktop\Attorney Combined Files
2015-07-04 12:46 - 2013-02-28 23:35 - 00001406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-07-04 12:46 - 2013-02-28 23:21 - 00000000 ____D C:\Users\Sam D\AppData\Local\Windows Live
2015-07-02 19:38 - 2015-01-18 01:01 - 00001952 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2015-07-02 19:38 - 2011-01-08 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-07-02 19:38 - 2011-01-08 18:45 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2015-07-02 13:56 - 2015-02-17 19:50 - 00000000 ____D C:\Users\Sam D\Desktop\customer info
2015-07-01 23:36 - 2009-04-24 18:28 - 00052736 _____ C:\Users\Sam D\Desktop\affiliate list.v1.xls
2015-06-27 15:24 - 2014-08-28 09:18 - 00001066 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-27 15:24 - 2014-08-28 09:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-27 15:24 - 2014-08-28 09:17 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-26 12:47 - 2014-12-29 17:57 - 00005632 _____ C:\Users\Sam D\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Files in the root of some directories =======
2014-09-17 21:05 - 2014-09-17 21:05 - 11249152 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2014-03-18 14:13 - 2014-03-18 14:14 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files\Common Files\wruninstall.exe
2011-01-10 02:44 - 2011-01-10 02:44 - 0874496 ____H (ExtremeCoderz) C:\Users\Sam D\AppData\Roaming\MultiPoster4.exe
2015-05-31 22:24 - 2015-07-18 20:22 - 0123556 _____ () C:\Users\Sam D\AppData\Roaming\net.telestream.wirecast.xml
2015-06-01 00:15 - 2015-06-01 00:15 - 0014543 _____ () C:\Users\Sam D\AppData\Roaming\net_telestream_wirecast_partner_AFL9067099885_brandingimage_destination.png
2015-06-01 00:15 - 2015-06-01 00:15 - 0014186 _____ () C:\Users\Sam D\AppData\Roaming\net_telestream_wirecast_partner_AFL9067099885_brandingimage_main.png
2011-01-10 02:44 - 2011-01-10 02:44 - 0000324 ____H () C:\Users\Sam D\AppData\Roaming\settings.cfg
2014-12-29 17:57 - 2015-06-26 12:47 - 0005632 _____ () C:\Users\Sam D\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-19 12:34 - 2015-04-02 21:27 - 0000600 _____ () C:\Users\Sam D\AppData\Local\PUTTY.RND
2015-06-29 17:09 - 2015-07-23 18:18 - 0007604 _____ () C:\Users\Sam D\AppData\Local\Resmon.ResmonCfg
2014-12-15 13:45 - 2014-12-15 13:45 - 0000000 _____ () C:\Users\Sam D\AppData\Local\{EA8A6224-C8D9-48BF-8C16-038572217C9F}
Some files in TEMP:
====================
C:\Users\Sam D\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5sdnxp.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-16 13:40
==================== End of log ============================