Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2017
Ran by Ioakim (administrator) on IOAKIM-PC (29-04-2017 14:45:27)
Running from C:\Users\Ioakim\Downloads
Loaded Profiles: Ioakim (Available Profiles: Ioakim)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Cuptony\Application\chrome.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\DriveSettings\Sync\SeagateDriveSettingsService.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(BitTorrent Inc.) C:\Users\Ioakim\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Users\Ioakim\AppData\Roaming\uTorrent\VirusGuard\BitTorrentAntivirus.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5292832 2017-04-05] (IObit)
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Run: [uTorrent] => C:\Users\Ioakim\AppData\Roaming\uTorrent\uTorrent.exe [6103232 2016-08-30] (BitTorrent Inc.)
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Run: [Advanced SystemCare 10] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [3920672 2017-03-30] (IObit)
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\MountPoints2: {24826d50-ba1d-11e6-8dd1-90e6bad41ca2} - F:\setup.exe
ShellExecuteHooks: No Name - {C8FB3CD4-235C-11E7-B46E-64006A5CFC23} - -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => -> No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{49A81AD4-5AD9-4698-AE5D-E537C105A70C}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\S-1-5-21-104129644-4116897664-2065348068-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2017-03-28] (IObit)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF DefaultProfile: 5sfdj974.default
FF ProfilePath: C:\Users\Ioakim\AppData\Roaming\Firefox\Firefox\Profiles\5sfdj974.default [2017-04-27]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2016-11-04] [not signed]
FF HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_192.dll [2016-07-01] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-07-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-01] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_192.dll [2016-07-01] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-07-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-01] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-01] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.ourluckysites.com/?type=hp&ts=1493290145&z=412aa413b3dd25cc9a71bceg5zat5c6o0t7edgaz9c&from=che0812&uid=WDCXWD7500AADS-00M2B0_WD-WCAV5529213392133
CHR Profile: C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-04-28] <==== ATTENTION
CHR Extension: (Google Docs) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-24]
CHR Extension: (Google Drive) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-24]
CHR Extension: (Turn Off the Lights) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2017-04-28]
CHR Extension: (YouTube) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-24]
CHR Extension: (Slinky Elegant) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2017-04-24]
CHR Extension: (Adblock Plus) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-04-24]
CHR Extension: (Google Sheets) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-24]
CHR Extension: (Google Docs Offline) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-24]
CHR Extension: (Evernote Web) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2016-06-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-24]
CHR Extension: (Gmail) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-24]
CHR Extension: (Chrome Media Router) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-28]
CHR Profile: C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2 [2017-04-24] <==== ATTENTION
CHR Extension: (Google Slides) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-16]
CHR Extension: (Google Docs) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-30]
CHR Extension: (Google Drive) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-30]
CHR Extension: (YouTube) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-13]
CHR Extension: (Adblock Plus) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-22]
CHR Extension: (Dark Reader) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2016-12-06]
CHR Extension: (Google Sheets) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-16]
CHR Extension: (Google Docs Offline) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-30]
CHR Extension: (Evernote Web) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2016-09-30]
CHR Extension: (Morpheon Dark) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\mafbdhjdkjnoafhfelkjpchpaepjknad [2017-03-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-16]
CHR Extension: (Gmail) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-30]
CHR Extension: (Chrome Media Router) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MicrosoftCRLSrv; C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig617.dll [117760 2017-04-28] () [File not signed]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1517576 2017-04-18] ()
R2 FreeAgentGoFlex Service; C:\Program Files (x86)\Seagate\DriveSettings\Sync\SeagateDriveSettingsService.exe [91432 2011-02-10] (Seagate Technology LLC)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [33640 2017-04-07] (HP Inc.)
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1764640 2017-03-17] (IObit)
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2017-03-28] (IObit)
R2 Kitty; C:\Users\Ioakim\AppData\Local\Kitty\Kitty.dll [257024 2017-04-28] (kitty) [File not signed] <==== ATTENTION
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S3 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-01] (NVIDIA Corporation)
S3 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-11-17] (NVIDIA Corporation)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2122248 2016-09-01] (Electronic Arts)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed]
S4 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
R2 SNARE; C:\Users\Ioakim\AppData\Local\SNARE\Snare.dll [833536 2017-04-27] (InterSect Alliance Pty Ltd) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Ioakim\AppData\Roaming\WinSAPSvc\WinSAP.dll [550912 2017-04-21] (win) [File not signed] <==== ATTENTION
S2 AppleCloudSvc; C:\ProgramData\Apple\Common\Cloud\WinHelper.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 cryptfd; C:\Windows\System32\drivers\cryptfd.sys [193448 2017-03-03] ()
R3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [33592 2016-11-07] (Dev47Apps)
R3 DroidCamVideo; C:\Windows\System32\DRIVERS\droidcamvideo.sys [229432 2016-11-07] (Dev47Apps)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [271424 2016-12-04] (DT Soft Ltd)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-03-22] ()
R2 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [183576 2016-12-05] (BitDefender LLC)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-04-24] (REALiX(tm))
R1 IMFCameraProtect; C:\Windows\system32\drivers\IMFCameraProtect.sys [34008 2017-03-17] (IObit.com)
R3 IMFDownProtect; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFDownProtect.sys [21360 2017-03-08] (IObit.com)
R3 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22440 2016-12-22] (IObit)
R3 IMFForceDelete; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFForceDelete.sys [15704 2016-11-19] (IObit.com)
S4 IObitUnlocker; C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [36568 2013-09-30] (IObit)
R0 MBAMChameleon; C:\Windows\System32\drivers\MBAMChameleon.sys [186304 2017-04-29] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-04-29] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-04-29] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [251832 2017-04-29] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-04-29] (Malwarebytes)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-11-17] (NVIDIA Corporation)
S3 RegFilter; no ImagePath
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit)
S3 Trufos; C:\Windows\System32\DRIVERS\TRUFOS.sys [520032 2016-12-05] (BitDefender S.R.L.)
S1 ZAM; no ImagePath
S1 ZAM_Guard; no ImagePath
R2 {687703DE-DC6D-4649-892B-B8497854A6AB}; C:\Program Files (x86)\CyberLink\PowerDVD15\Common\NavFilter\000.fcl [29896 2015-03-19] (CyberLink Corp.)
U0 aswVmm; no ImagePath
S3 cpuz138; \??\C:\Users\Ioakim\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] <==== ATTENTION
S3 NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160625.006\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160625.006\EX64.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-29 14:45 - 2017-04-29 14:47 - 00019401 _____ C:\Users\Ioakim\Downloads\FRST.txt
2017-04-29 14:45 - 2017-04-29 14:45 - 02427392 _____ (Farbar) C:\Users\Ioakim\Downloads\FRST64.exe
2017-04-29 14:45 - 2017-04-29 14:45 - 00000000 ____D C:\FRST
2017-04-29 14:04 - 2017-04-29 14:35 - 00007609 _____ C:\Users\Ioakim\AppData\Local\Resmon.ResmonCfg
2017-04-28 16:16 - 2017-04-28 16:16 - 00000000 ____D C:\Users\Public\Documents\Google
2017-04-28 16:16 - 2017-04-28 16:16 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Cuptony
2017-04-28 16:16 - 2017-04-28 16:16 - 00000000 ____D C:\Program Files (x86)\Cuptony
2017-04-28 16:15 - 2017-04-28 16:15 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\WinSAPSvc
2017-04-28 16:15 - 2017-04-28 16:15 - 00000000 ____D C:\Program Files (x86)\AlphaGo
2017-04-28 16:15 - 2017-04-28 16:15 - 00000000 _____ C:\Windows\SysWOW64\33
2017-04-28 13:58 - 2017-04-28 13:58 - 00002826 _____ C:\Windows\System32\Tasks\ASC10_SkipUac_Ioakim
2017-04-28 13:54 - 2017-04-29 14:39 - 00002890 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (Ioakim)
2017-04-27 20:40 - 2017-04-27 21:23 - 00000000 ____D C:\Users\Ioakim\Downloads\Passengers 2016 1080p BluRay x264 DTS-JYK
2017-04-27 20:40 - 2017-04-27 20:40 - 00016711 _____ C:\Users\Ioakim\Downloads\passengers 2016 1080p bluray x264 dts-jyk.torrent
2017-04-27 17:49 - 2017-04-28 16:15 - 00003506 _____ C:\Windows\System32\Tasks\Windows-PG
2017-04-27 14:05 - 2017-04-29 14:36 - 00082720 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-04-27 14:05 - 2017-04-29 14:35 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-04-27 14:05 - 2017-04-29 14:35 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-04-27 14:05 - 2017-04-29 14:35 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-04-27 14:05 - 2017-04-29 13:57 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-04-27 14:05 - 2017-04-27 14:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-04-27 14:05 - 2017-03-22 11:02 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-04-27 14:04 - 2017-04-27 14:04 - 00000000 ____D C:\Program Files\Malwarebytes
2017-04-27 14:03 - 2017-04-27 14:04 - 60107896 _____ (Malwarebytes ) C:\Users\Ioakim\Downloads\mb3-setup-consumer-3.0.6.1469-10103.exe
2017-04-27 13:56 - 2017-04-27 13:56 - 00000007 _____ C:\Windows\SysWOW64\1A45.tmp
2017-04-27 13:56 - 2017-04-27 13:56 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Everness
2017-04-27 13:56 - 2017-04-27 13:56 - 00000000 ____D C:\ProgramData\Apple
2017-04-27 13:54 - 2017-04-27 13:54 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\Firefox
2017-04-27 13:54 - 2017-04-27 13:54 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Firefox
2017-04-27 13:52 - 2017-04-27 13:52 - 00000000 ____D C:\Program Files (x86)\Everness
2017-04-27 13:50 - 2017-04-29 14:36 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-04-27 13:50 - 2017-04-27 17:04 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-04-27 13:49 - 2017-04-28 16:15 - 00000000 _____ C:\Windows\SysWOW64\11
2017-04-27 13:49 - 2017-04-27 13:49 - 00000000 _____ C:\Windows\SysWOW64\22
2017-04-27 02:19 - 2017-04-27 02:19 - 00020865 _____ C:\Users\Ioakim\Downloads\the-witch_english-1326741.zip
2017-04-27 02:08 - 2017-04-27 02:08 - 00023457 _____ C:\Users\Ioakim\Downloads\the.vvitch.a.newengland.folktale.(2015).ara.1cd.(6614040).zip
2017-04-27 02:08 - 2017-04-27 01:07 - 00055205 _____ C:\Users\Ioakim\Downloads\The.Witch.2015.HDRip.XviD.AC3-EVO.srt
2017-04-27 02:08 - 2017-04-27 01:07 - 00006271 _____ C:\Users\Ioakim\Downloads\the.vvitch.a.new.england.(6614040).nfo
2017-04-27 02:07 - 2017-04-27 02:07 - 00010906 _____ C:\Users\Ioakim\Downloads\File203841.zip.htm
2017-04-27 01:23 - 2017-04-27 01:34 - 00000000 ____D C:\Users\Ioakim\Downloads\Zoppo Trump - Zoppo Trump 1971-76
2017-04-27 01:23 - 2017-04-27 01:23 - 00020520 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t3428880.torrent
2017-04-27 01:19 - 2017-04-27 01:35 - 00000000 ____D C:\Users\Ioakim\Downloads\Fleetwood Mac - Peter Green's Fleetwood Mac
2017-04-27 01:19 - 2017-04-27 01:20 - 00000000 ____D C:\Users\Ioakim\Downloads\Fleetwood Mac - The Very Best Of - 2002 [EAC-FLAC-CUE]
2017-04-27 01:19 - 2017-04-27 01:19 - 00015584 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t1453911.torrent
2017-04-27 01:19 - 2017-04-27 01:19 - 00014145 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t1282170.torrent
2017-04-25 22:04 - 2017-04-25 23:49 - 2376545437 ____R C:\Users\Ioakim\Downloads\The.Witch.2015.BluRay.1080p.10bit.5.1.x265.HEVC-Qman[UTR].mkv
2017-04-25 22:04 - 2017-04-25 22:04 - 00012858 _____ C:\Users\Ioakim\Downloads\C355C64957FB5D2042F5D83B4524AAD963A44111.torrent
2017-04-25 12:54 - 2017-04-25 12:56 - 00000000 ____D C:\Users\Ioakim\Downloads\Advanced SystemCare Pro 10.3.0.739 + Patch [CracksNow]
2017-04-25 12:54 - 2017-04-25 12:54 - 00014651 _____ C:\Users\Ioakim\Downloads\34CC9124F81DE6DF5B16B081E7E56DAB0E2C0C04.torrent
2017-04-25 12:51 - 2016-12-05 15:32 - 00520032 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2017-04-25 10:24 - 2017-04-28 16:15 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Kitty
2017-04-25 10:24 - 2017-04-25 10:24 - 00000000 ____D C:\Windows\psgo
2017-04-25 10:23 - 2017-04-27 17:49 - 00000000 ____D C:\Users\Ioakim\AppData\Local\SNARE
2017-04-24 22:59 - 2017-04-24 22:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2017-04-24 22:59 - 2017-03-17 16:39 - 00034008 _____ (IObit.com) C:\Windows\system32\Drivers\IMFCameraProtect.sys
2017-04-24 22:51 - 2017-04-24 22:58 - 00000000 ____D C:\Users\Ioakim\Downloads\IObit Malware Fighter Pro 5.0.2.3788 + Keygen [CracksNow]
2017-04-24 22:50 - 2017-04-24 22:50 - 00014741 _____ C:\Users\Ioakim\Downloads\A948E2D30CA04240ABEB8EA28D7DEB13D8D4ADB6.torrent
2017-04-24 18:30 - 2017-04-24 18:31 - 11583584 _____ (SurfRight B.V.) C:\Users\Ioakim\Downloads\HitmanPro_x64.exe
2017-04-24 17:56 - 2017-04-24 17:56 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Ioakim
2017-04-24 17:56 - 2017-04-24 17:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2017-04-24 17:55 - 2017-04-24 17:55 - 00000000 __SHD C:\Users\Ioakim\AppData\Local\kemgadeojglibflomicgnfeopkdfflnw
2017-04-24 17:54 - 2017-04-24 18:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mgdisk
2017-04-24 17:54 - 2017-04-24 17:54 - 00000000 ____D C:\Users\Public\Documents\XMUpdate
2017-04-24 17:47 - 2017-04-24 17:47 - 02451912 _____ (IObit ) C:\Users\Ioakim\Downloads\unlocker-setup (1).exe
2017-04-24 17:47 - 2017-04-24 17:47 - 00027552 _____ (REALiX(tm)) C:\Windows\SysWOW64\Drivers\HWiNFO64A.SYS
2017-04-24 17:47 - 2017-04-24 17:47 - 00003258 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler
2017-04-24 17:47 - 2017-04-24 17:47 - 00000000 ____D C:\Windows\IObit
2017-04-24 17:47 - 2017-04-24 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4
2017-04-24 17:45 - 2017-04-24 17:46 - 00003174 _____ C:\Windows\System32\Tasks\SmartDefrag_AutoAnalyze
2017-04-24 17:45 - 2017-04-24 17:45 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\Unconfirmed 863075.crdownload
2017-04-24 17:45 - 2017-04-24 17:45 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\smart-defrag-setup (3).exe
2017-04-24 17:45 - 2017-04-24 17:45 - 00003022 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2017-04-24 17:45 - 2017-04-24 17:45 - 00003020 _____ C:\Windows\System32\Tasks\SmartDefrag_Update
2017-04-24 17:45 - 2017-04-24 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2017-04-24 17:45 - 2017-03-09 13:53 - 00045664 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
2017-04-24 17:45 - 2017-03-09 13:53 - 00030744 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
2017-04-24 17:45 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
2017-04-24 17:44 - 2017-04-24 17:45 - 17866872 _____ (IObit ) C:\Users\Ioakim\Downloads\driver_booster_setup (1).exe
2017-04-24 17:44 - 2017-04-24 17:45 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\smart-defrag-setup (1).exe
2017-04-24 17:44 - 2017-04-24 17:44 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\Unconfirmed 162221.crdownload
2017-04-24 17:43 - 2017-04-24 17:44 - 17866872 _____ (IObit ) C:\Users\Ioakim\Downloads\Unconfirmed 582588.crdownload
2017-04-24 17:43 - 2017-04-24 17:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Unlocker
2017-04-24 17:42 - 2017-04-24 17:42 - 02451912 _____ (IObit ) C:\Users\Ioakim\Downloads\unlocker-setup.exe
2017-04-24 14:57 - 2017-04-24 14:57 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A}
2017-04-24 14:50 - 2017-04-24 17:28 - 00000000 ____D C:\Users\Ioakim\Downloads\Advanced SystemCare Pro 10.2.0.721 Multilingual + Keys [SadeemPC]
2017-04-24 14:47 - 2017-04-24 14:47 - 00015153 _____ C:\Users\Ioakim\Downloads\E4089619458C2FD904D95BE84CD48B8512ACC7AD.torrent
2017-04-24 14:24 - 2017-04-24 14:24 - 04089296 _____ C:\Users\Ioakim\Downloads\Unconfirmed 348300.crdownload
2017-04-24 14:19 - 2017-04-24 14:19 - 04089296 _____ C:\Users\Ioakim\Downloads\adwcleaner_6.045.exe
2017-04-18 15:03 - 2017-04-18 15:14 - 00000000 ____D C:\Users\Ioakim\Downloads\Synecdoche, NY
2017-04-18 15:03 - 2017-04-18 15:03 - 00013851 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t1920321.torrent
2017-04-18 02:00 - 2017-04-18 02:00 - 00019219 _____ C:\Users\Ioakim\Downloads\melancholia-english-392564.zip
2017-04-18 01:59 - 2017-04-18 01:59 - 00027076 _____ C:\Users\Ioakim\Downloads\melancholia-english-725425.zip
2017-04-18 01:59 - 2017-04-18 01:59 - 00022210 _____ C:\Users\Ioakim\Downloads\melancholia-english-686401.zip
2017-04-18 01:59 - 2017-04-18 01:59 - 00020265 _____ C:\Users\Ioakim\Downloads\melancholia-english-435376.zip
2017-04-18 01:57 - 2017-04-18 01:57 - 00020139 _____ C:\Users\Ioakim\Downloads\melancholia-english-373799.zip
2017-04-18 01:54 - 2017-04-18 01:54 - 00020484 _____ C:\Users\Ioakim\Downloads\melancholia-english-414517.zip
2017-04-18 01:54 - 2017-04-18 01:54 - 00020233 _____ C:\Users\Ioakim\Downloads\melancholia-english-478409.zip
2017-04-18 00:14 - 2017-04-18 00:20 - 00000000 ____D C:\Users\Ioakim\Downloads\Solefald - World Metal. Kosmopolis Sud (2015)
2017-04-18 00:14 - 2017-04-18 00:14 - 00020876 _____ C:\Users\Ioakim\Downloads\[www.seedpeer.eu] Solefald World Metal Kosmopolis Sud 2015.SEEDPEER.torrent
2017-04-18 00:14 - 2017-04-18 00:14 - 00019770 _____ C:\Users\Ioakim\Downloads\D2DEA94DA6F631E54B2B2A4C47A907D6E53E6019.torrent
2017-04-17 21:11 - 2017-04-18 02:01 - 00000000 ____D C:\Users\Ioakim\Downloads\Melancholia.2011.1080p.BluRay.AAC.5.1.HEVC.x265.sharpysword
2017-04-17 21:10 - 2017-04-17 21:10 - 00026669 _____ C:\Users\Ioakim\Downloads\7D74D96AC9C25FE82B6C9D4FF00F0C926F9A9D5C.torrent
2017-04-17 21:10 - 2017-04-17 21:10 - 00025866 _____ C:\Users\Ioakim\Downloads\7D74D96AC9C25FE82B6C9D4FF00F0C926F9A9D5C (2).torrent
2017-04-17 21:10 - 2017-04-17 21:10 - 00025866 _____ C:\Users\Ioakim\Downloads\7D74D96AC9C25FE82B6C9D4FF00F0C926F9A9D5C (1).torrent
2017-04-12 23:19 - 2017-04-12 23:28 - 00000000 ____D C:\Users\Ioakim\Downloads\Louis.C.K.2017.2017.WEBRip.x264-RARBG
2017-04-12 22:59 - 2017-04-12 23:08 - 00000000 ____D C:\Users\Ioakim\Downloads\Toehider - 2014 - What Kind Of Creature Am I [FLAC]
2017-04-09 19:30 - 2017-04-23 23:47 - 00000000 ____D C:\Users\Ioakim\Downloads\Marillion - **** Everyone And Run (2016) [FLAC]
2017-04-08 04:19 - 2017-04-08 04:21 - 00000000 ____D C:\Users\Ioakim\Downloads\Attalla-2017-Glacial Rule
2017-04-06 02:22 - 2017-02-11 16:33 - 00000000 ____D C:\Users\Ioakim\Downloads\Soen - Lykaia (2017) FLAC + scans
2017-04-06 01:55 - 2017-04-06 02:19 - 435624332 _____ C:\Users\Ioakim\Downloads\Soen---Lykaia-(2017)-FLAC-+-scans.rar
2017-04-04 18:05 - 2017-04-04 18:05 - 16207613 _____ C:\Users\Ioakim\Downloads\Paul-Draper---EP-Two-(EP-2016).rar
2017-04-04 03:03 - 2017-04-18 14:09 - 00000000 ____D C:\Users\Ioakim\Downloads\The Contortionist
2017-04-03 01:48 - 2017-04-17 15:45 - 00000000 ____D C:\Users\Ioakim\Downloads\Karmakanic-Wheel Of Life
2017-04-03 01:48 - 2017-04-17 15:45 - 00000000 ____D C:\Users\Ioakim\Downloads\Karmakanic - In A Perfect World (2011)
2017-04-03 01:48 - 2017-04-03 02:05 - 00000000 ____D C:\Users\Ioakim\Downloads\Karmakanic - Entering The Spectra (2002)
2017-04-03 01:32 - 2017-04-03 01:40 - 00000000 ____D C:\Users\Ioakim\Downloads\The Tea Club - Grappling (2015) [FLAC]
2017-04-01 14:58 - 2017-04-01 15:13 - 00000000 ____D C:\Users\Ioakim\Downloads\Mansun - Attack of the Grey Lantern [FLAC]
2017-04-01 14:41 - 2017-04-15 15:06 - 00000000 ____D C:\Users\Ioakim\Downloads\The Neal Morse Band - 2016 - The Similitude of a Dream [FLAC]
2017-03-30 11:51 - 2017-03-30 11:52 - 70938624 _____ C:\Windows\system32\config\software.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00630784 _____ C:\Windows\system32\config\default.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00032768 _____ C:\Windows\system32\config\security.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00032768 _____ C:\Windows\system32\config\sam.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00000000 ____H C:\asc_rdflag
2017-03-30 02:41 - 2014-10-16 10:27 - 00027424 _____ (IObit) C:\Windows\system32\RegistryDefragBootTime.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-29 14:46 - 2016-06-24 13:02 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\uTorrent
2017-04-29 14:44 - 2009-07-14 07:45 - 00021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-29 14:44 - 2009-07-14 07:45 - 00021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-29 14:35 - 2016-06-27 01:41 - 00000000 ____D C:\Users\Ioakim\AppData\Local\CrashDumps
2017-04-29 14:34 - 2016-06-22 20:29 - 00000000 ____D C:\ProgramData\NVIDIA
2017-04-29 14:33 - 2017-02-16 18:32 - 00002334 ____H C:\Windows\Tasks\{8CE67B9E-3AC8-4ED2-A8EE-28E6FE3D0B51}.job
2017-04-29 14:33 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-29 14:22 - 2016-10-20 14:25 - 00000967 _____ C:\Users\Ioakim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2017-04-29 14:22 - 2016-10-11 14:26 - 00002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-29 04:34 - 2016-06-24 13:17 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\foobar2000
2017-04-28 20:12 - 2016-06-24 14:45 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-28 20:12 - 2016-06-24 14:45 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-27 19:01 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\inf
2017-04-27 17:38 - 2016-09-30 16:21 - 00002068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk
2017-04-27 17:38 - 2016-09-30 16:21 - 00001914 _____ C:\Users\Ioakim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk
2017-04-27 17:33 - 2017-02-16 20:26 - 00000000 ____D C:\Program Files\Layers of Fear
2017-04-27 14:47 - 2016-06-24 13:06 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\IObit
2017-04-27 14:38 - 2016-06-24 13:06 - 00000000 ____D C:\ProgramData\IObit
2017-04-27 14:04 - 2016-10-11 18:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-04-27 13:56 - 2016-12-06 17:01 - 00003788 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003838 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003838 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003776 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003600 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003540 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-06-24 18:58 - 00004456 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-04-27 13:55 - 2017-03-14 14:39 - 00000000 ____D C:\Users\Ioakim\AppData\LocalLow\Mozilla
2017-04-27 13:54 - 2009-07-14 08:13 - 00795674 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-27 04:00 - 2016-06-22 20:09 - 00000000 ____D C:\KMPlayer
2017-04-26 03:26 - 2016-09-22 12:26 - 00000000 ____D C:\Program Files (x86)\Total War Attila
2017-04-25 13:03 - 2016-06-25 17:10 - 00000000 ____D C:\Program Files (x86)\Steam
2017-04-25 12:56 - 2016-06-24 13:06 - 00000000 ____D C:\Users\Ioakim\AppData\LocalLow\IObit
2017-04-25 12:56 - 2016-06-24 13:06 - 00000000 ____D C:\Program Files (x86)\IObit
2017-04-25 12:52 - 2016-06-24 13:06 - 00000000 ____D C:\ProgramData\ProductData
2017-04-24 18:44 - 2002-01-01 00:02 - 00000000 ____D C:\Windows\Minidump
2017-04-24 18:14 - 2016-10-11 18:12 - 00000000 ____D C:\AdwCleaner
2017-04-24 18:12 - 2009-07-14 06:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-04-24 17:56 - 2016-06-24 13:36 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk
2017-04-24 04:56 - 2017-03-08 14:23 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Ubisoft Game Launcher
2017-04-23 14:37 - 2016-06-24 18:58 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-04-13 13:25 - 2009-07-14 08:08 - 00032544 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-12 00:38 - 2017-03-28 19:27 - 00000000 ____D C:\Users\Ioakim\Downloads\The Mute Gods 2016-2017 (Discography)
2017-04-03 01:28 - 2016-06-22 19:47 - 00000000 ____D C:\Users\Ioakim\AppData\Local\ElevatedDiagnostics
2017-04-03 01:27 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\NDF
2017-04-01 02:36 - 2017-03-17 02:58 - 00000000 ____D C:\Users\Ioakim\Downloads\Sun Kil Moon - Benji (Limited Edition) - 2014 (320 kbps)
2017-03-31 01:10 - 2017-03-15 22:32 - 00000000 ____D C:\Users\Ioakim\Downloads\Blackfield - V (2017, Kscope)
==================== Files in the root of some directories =======
2017-04-29 14:04 - 2017-04-29 14:35 - 0007609 _____ () C:\Users\Ioakim\AppData\Local\Resmon.ResmonCfg
2016-11-09 18:58 - 2016-11-09 18:58 - 0000033 _____ () C:\ProgramData\droidcam-settings
2016-11-04 13:11 - 2016-11-07 20:39 - 0001168 _____ () C:\ProgramData\hpzinstall.log
Files to move or delete:
====================
C:\Windows\Tasks\{8CE67B9E-3AC8-4ED2-A8EE-28E6FE3D0B51}.job
Some files in TEMP:
====================
2017-04-24 17:54 - 2017-04-24 17:54 - 0321024 _____ () C:\Users\Ioakim\AppData\Local\Temp\AppHelperV10.exe
2017-04-24 18:11 - 2017-04-24 18:11 - 0340904 _____ (360.cn) C:\Users\Ioakim\AppData\Local\Temp\Inst13__3112295__3f7372633d6c6d266c733d6e37616163383063353938__68616f2e3336302e636e__0c9f.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-04-24 19:47
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2017
Ran by Ioakim (administrator) on IOAKIM-PC (29-04-2017 14:45:27)
Running from C:\Users\Ioakim\Downloads
Loaded Profiles: Ioakim (Available Profiles: Ioakim)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Cuptony\Application\chrome.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\DriveSettings\Sync\SeagateDriveSettingsService.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(BitTorrent Inc.) C:\Users\Ioakim\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Users\Ioakim\AppData\Roaming\uTorrent\VirusGuard\BitTorrentAntivirus.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
Ran by Ioakim (administrator) on IOAKIM-PC (29-04-2017 14:45:27)
Running from C:\Users\Ioakim\Downloads
Loaded Profiles: Ioakim (Available Profiles: Ioakim)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Cuptony\Application\chrome.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\DriveSettings\Sync\SeagateDriveSettingsService.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(BitTorrent Inc.) C:\Users\Ioakim\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Users\Ioakim\AppData\Roaming\uTorrent\VirusGuard\BitTorrentAntivirus.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5292832 2017-04-05] (IObit)
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Run: [uTorrent] => C:\Users\Ioakim\AppData\Roaming\uTorrent\uTorrent.exe [6103232 2016-08-30] (BitTorrent Inc.)
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Run: [Advanced SystemCare 10] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [3920672 2017-03-30] (IObit)
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\MountPoints2: {24826d50-ba1d-11e6-8dd1-90e6bad41ca2} - F:\setup.exe
ShellExecuteHooks: No Name - {C8FB3CD4-235C-11E7-B46E-64006A5CFC23} - -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => -> No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{49A81AD4-5AD9-4698-AE5D-E537C105A70C}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\S-1-5-21-104129644-4116897664-2065348068-1001 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2017-03-28] (IObit)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF DefaultProfile: 5sfdj974.default
FF ProfilePath: C:\Users\Ioakim\AppData\Roaming\Firefox\Firefox\Profiles\5sfdj974.default [2017-04-27]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2016-11-04] [not signed]
FF HKU\S-1-5-21-104129644-4116897664-2065348068-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_192.dll [2016-07-01] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-07-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-01] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_192.dll [2016-07-01] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-07-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-07-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-01] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-01] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.ourluckysites.com/?type=hp&ts=1493290145&z=412aa413b3dd25cc9a71bceg5zat5c6o0t7edgaz9c&from=che0812&uid=WDCXWD7500AADS-00M2B0_WD-WCAV5529213392133
CHR Profile: C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-04-28] <==== ATTENTION
CHR Extension: (Google Docs) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-24]
CHR Extension: (Google Drive) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-24]
CHR Extension: (Turn Off the Lights) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2017-04-28]
CHR Extension: (YouTube) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-24]
CHR Extension: (Slinky Elegant) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2017-04-24]
CHR Extension: (Adblock Plus) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-04-24]
CHR Extension: (Google Sheets) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-24]
CHR Extension: (Google Docs Offline) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-24]
CHR Extension: (Evernote Web) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2016-06-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-24]
CHR Extension: (Gmail) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-24]
CHR Extension: (Chrome Media Router) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-28]
CHR Profile: C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2 [2017-04-24] <==== ATTENTION
CHR Extension: (Google Slides) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-16]
CHR Extension: (Google Docs) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-09-30]
CHR Extension: (Google Drive) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-30]
CHR Extension: (YouTube) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-13]
CHR Extension: (Adblock Plus) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-22]
CHR Extension: (Dark Reader) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2016-12-06]
CHR Extension: (Google Sheets) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-16]
CHR Extension: (Google Docs Offline) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-30]
CHR Extension: (Evernote Web) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2016-09-30]
CHR Extension: (Morpheon Dark) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\mafbdhjdkjnoafhfelkjpchpaepjknad [2017-03-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-16]
CHR Extension: (Gmail) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-30]
CHR Extension: (Chrome Media Router) - C:\Users\Ioakim\AppData\Local\Google\Chrome\User Data\ChromeDefaultData2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-07]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MicrosoftCRLSrv; C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig617.dll [117760 2017-04-28] () [File not signed]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1517576 2017-04-18] ()
R2 FreeAgentGoFlex Service; C:\Program Files (x86)\Seagate\DriveSettings\Sync\SeagateDriveSettingsService.exe [91432 2011-02-10] (Seagate Technology LLC)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [33640 2017-04-07] (HP Inc.)
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1764640 2017-03-17] (IObit)
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2017-03-28] (IObit)
R2 Kitty; C:\Users\Ioakim\AppData\Local\Kitty\Kitty.dll [257024 2017-04-28] (kitty) [File not signed] <==== ATTENTION
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S3 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-01] (NVIDIA Corporation)
S3 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-11-17] (NVIDIA Corporation)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2122248 2016-09-01] (Electronic Arts)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed]
S4 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
R2 SNARE; C:\Users\Ioakim\AppData\Local\SNARE\Snare.dll [833536 2017-04-27] (InterSect Alliance Pty Ltd) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\Ioakim\AppData\Roaming\WinSAPSvc\WinSAP.dll [550912 2017-04-21] (win) [File not signed] <==== ATTENTION
S2 AppleCloudSvc; C:\ProgramData\Apple\Common\Cloud\WinHelper.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 cryptfd; C:\Windows\System32\drivers\cryptfd.sys [193448 2017-03-03] ()
R3 DroidCam; C:\Windows\System32\DRIVERS\droidcam.sys [33592 2016-11-07] (Dev47Apps)
R3 DroidCamVideo; C:\Windows\System32\DRIVERS\droidcamvideo.sys [229432 2016-11-07] (Dev47Apps)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [271424 2016-12-04] (DT Soft Ltd)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-03-22] ()
R2 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [183576 2016-12-05] (BitDefender LLC)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-04-24] (REALiX(tm))
R1 IMFCameraProtect; C:\Windows\system32\drivers\IMFCameraProtect.sys [34008 2017-03-17] (IObit.com)
R3 IMFDownProtect; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFDownProtect.sys [21360 2017-03-08] (IObit.com)
R3 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22440 2016-12-22] (IObit)
R3 IMFForceDelete; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFForceDelete.sys [15704 2016-11-19] (IObit.com)
S4 IObitUnlocker; C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [36568 2013-09-30] (IObit)
R0 MBAMChameleon; C:\Windows\System32\drivers\MBAMChameleon.sys [186304 2017-04-29] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-04-29] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-04-29] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [251832 2017-04-29] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-04-29] (Malwarebytes)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-11-17] (NVIDIA Corporation)
S3 RegFilter; no ImagePath
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit)
S3 Trufos; C:\Windows\System32\DRIVERS\TRUFOS.sys [520032 2016-12-05] (BitDefender S.R.L.)
S1 ZAM; no ImagePath
S1 ZAM_Guard; no ImagePath
R2 {687703DE-DC6D-4649-892B-B8497854A6AB}; C:\Program Files (x86)\CyberLink\PowerDVD15\Common\NavFilter\000.fcl [29896 2015-03-19] (CyberLink Corp.)
U0 aswVmm; no ImagePath
S3 cpuz138; \??\C:\Users\Ioakim\AppData\Local\Temp\cpuz138\cpuz138_x64.sys [X] <==== ATTENTION
S3 NAVENG; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160625.006\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Internet Security\NortonData\22.7.0.76\Definitions\SDSDefs\20160625.006\EX64.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-29 14:45 - 2017-04-29 14:47 - 00019401 _____ C:\Users\Ioakim\Downloads\FRST.txt
2017-04-29 14:45 - 2017-04-29 14:45 - 02427392 _____ (Farbar) C:\Users\Ioakim\Downloads\FRST64.exe
2017-04-29 14:45 - 2017-04-29 14:45 - 00000000 ____D C:\FRST
2017-04-29 14:04 - 2017-04-29 14:35 - 00007609 _____ C:\Users\Ioakim\AppData\Local\Resmon.ResmonCfg
2017-04-28 16:16 - 2017-04-28 16:16 - 00000000 ____D C:\Users\Public\Documents\Google
2017-04-28 16:16 - 2017-04-28 16:16 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Cuptony
2017-04-28 16:16 - 2017-04-28 16:16 - 00000000 ____D C:\Program Files (x86)\Cuptony
2017-04-28 16:15 - 2017-04-28 16:15 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\WinSAPSvc
2017-04-28 16:15 - 2017-04-28 16:15 - 00000000 ____D C:\Program Files (x86)\AlphaGo
2017-04-28 16:15 - 2017-04-28 16:15 - 00000000 _____ C:\Windows\SysWOW64\33
2017-04-28 13:58 - 2017-04-28 13:58 - 00002826 _____ C:\Windows\System32\Tasks\ASC10_SkipUac_Ioakim
2017-04-28 13:54 - 2017-04-29 14:39 - 00002890 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (Ioakim)
2017-04-27 20:40 - 2017-04-27 21:23 - 00000000 ____D C:\Users\Ioakim\Downloads\Passengers 2016 1080p BluRay x264 DTS-JYK
2017-04-27 20:40 - 2017-04-27 20:40 - 00016711 _____ C:\Users\Ioakim\Downloads\passengers 2016 1080p bluray x264 dts-jyk.torrent
2017-04-27 17:49 - 2017-04-28 16:15 - 00003506 _____ C:\Windows\System32\Tasks\Windows-PG
2017-04-27 14:05 - 2017-04-29 14:36 - 00082720 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-04-27 14:05 - 2017-04-29 14:35 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-04-27 14:05 - 2017-04-29 14:35 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-04-27 14:05 - 2017-04-29 14:35 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-04-27 14:05 - 2017-04-29 13:57 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-04-27 14:05 - 2017-04-27 14:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-04-27 14:05 - 2017-03-22 11:02 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-04-27 14:04 - 2017-04-27 14:04 - 00000000 ____D C:\Program Files\Malwarebytes
2017-04-27 14:03 - 2017-04-27 14:04 - 60107896 _____ (Malwarebytes ) C:\Users\Ioakim\Downloads\mb3-setup-consumer-3.0.6.1469-10103.exe
2017-04-27 13:56 - 2017-04-27 13:56 - 00000007 _____ C:\Windows\SysWOW64\1A45.tmp
2017-04-27 13:56 - 2017-04-27 13:56 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Everness
2017-04-27 13:56 - 2017-04-27 13:56 - 00000000 ____D C:\ProgramData\Apple
2017-04-27 13:54 - 2017-04-27 13:54 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\Firefox
2017-04-27 13:54 - 2017-04-27 13:54 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Firefox
2017-04-27 13:52 - 2017-04-27 13:52 - 00000000 ____D C:\Program Files (x86)\Everness
2017-04-27 13:50 - 2017-04-29 14:36 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-04-27 13:50 - 2017-04-27 17:04 - 00000000 _____ C:\Users\Public\Documents\report.dat
2017-04-27 13:49 - 2017-04-28 16:15 - 00000000 _____ C:\Windows\SysWOW64\11
2017-04-27 13:49 - 2017-04-27 13:49 - 00000000 _____ C:\Windows\SysWOW64\22
2017-04-27 02:19 - 2017-04-27 02:19 - 00020865 _____ C:\Users\Ioakim\Downloads\the-witch_english-1326741.zip
2017-04-27 02:08 - 2017-04-27 02:08 - 00023457 _____ C:\Users\Ioakim\Downloads\the.vvitch.a.newengland.folktale.(2015).ara.1cd.(6614040).zip
2017-04-27 02:08 - 2017-04-27 01:07 - 00055205 _____ C:\Users\Ioakim\Downloads\The.Witch.2015.HDRip.XviD.AC3-EVO.srt
2017-04-27 02:08 - 2017-04-27 01:07 - 00006271 _____ C:\Users\Ioakim\Downloads\the.vvitch.a.new.england.(6614040).nfo
2017-04-27 02:07 - 2017-04-27 02:07 - 00010906 _____ C:\Users\Ioakim\Downloads\File203841.zip.htm
2017-04-27 01:23 - 2017-04-27 01:34 - 00000000 ____D C:\Users\Ioakim\Downloads\Zoppo Trump - Zoppo Trump 1971-76
2017-04-27 01:23 - 2017-04-27 01:23 - 00020520 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t3428880.torrent
2017-04-27 01:19 - 2017-04-27 01:35 - 00000000 ____D C:\Users\Ioakim\Downloads\Fleetwood Mac - Peter Green's Fleetwood Mac
2017-04-27 01:19 - 2017-04-27 01:20 - 00000000 ____D C:\Users\Ioakim\Downloads\Fleetwood Mac - The Very Best Of - 2002 [EAC-FLAC-CUE]
2017-04-27 01:19 - 2017-04-27 01:19 - 00015584 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t1453911.torrent
2017-04-27 01:19 - 2017-04-27 01:19 - 00014145 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t1282170.torrent
2017-04-25 22:04 - 2017-04-25 23:49 - 2376545437 ____R C:\Users\Ioakim\Downloads\The.Witch.2015.BluRay.1080p.10bit.5.1.x265.HEVC-Qman[UTR].mkv
2017-04-25 22:04 - 2017-04-25 22:04 - 00012858 _____ C:\Users\Ioakim\Downloads\C355C64957FB5D2042F5D83B4524AAD963A44111.torrent
2017-04-25 12:54 - 2017-04-25 12:56 - 00000000 ____D C:\Users\Ioakim\Downloads\Advanced SystemCare Pro 10.3.0.739 + Patch [CracksNow]
2017-04-25 12:54 - 2017-04-25 12:54 - 00014651 _____ C:\Users\Ioakim\Downloads\34CC9124F81DE6DF5B16B081E7E56DAB0E2C0C04.torrent
2017-04-25 12:51 - 2016-12-05 15:32 - 00520032 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2017-04-25 10:24 - 2017-04-28 16:15 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Kitty
2017-04-25 10:24 - 2017-04-25 10:24 - 00000000 ____D C:\Windows\psgo
2017-04-25 10:23 - 2017-04-27 17:49 - 00000000 ____D C:\Users\Ioakim\AppData\Local\SNARE
2017-04-24 22:59 - 2017-04-24 22:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2017-04-24 22:59 - 2017-03-17 16:39 - 00034008 _____ (IObit.com) C:\Windows\system32\Drivers\IMFCameraProtect.sys
2017-04-24 22:51 - 2017-04-24 22:58 - 00000000 ____D C:\Users\Ioakim\Downloads\IObit Malware Fighter Pro 5.0.2.3788 + Keygen [CracksNow]
2017-04-24 22:50 - 2017-04-24 22:50 - 00014741 _____ C:\Users\Ioakim\Downloads\A948E2D30CA04240ABEB8EA28D7DEB13D8D4ADB6.torrent
2017-04-24 18:30 - 2017-04-24 18:31 - 11583584 _____ (SurfRight B.V.) C:\Users\Ioakim\Downloads\HitmanPro_x64.exe
2017-04-24 17:56 - 2017-04-24 17:56 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Ioakim
2017-04-24 17:56 - 2017-04-24 17:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2017-04-24 17:55 - 2017-04-24 17:55 - 00000000 __SHD C:\Users\Ioakim\AppData\Local\kemgadeojglibflomicgnfeopkdfflnw
2017-04-24 17:54 - 2017-04-24 18:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mgdisk
2017-04-24 17:54 - 2017-04-24 17:54 - 00000000 ____D C:\Users\Public\Documents\XMUpdate
2017-04-24 17:47 - 2017-04-24 17:47 - 02451912 _____ (IObit ) C:\Users\Ioakim\Downloads\unlocker-setup (1).exe
2017-04-24 17:47 - 2017-04-24 17:47 - 00027552 _____ (REALiX(tm)) C:\Windows\SysWOW64\Drivers\HWiNFO64A.SYS
2017-04-24 17:47 - 2017-04-24 17:47 - 00003258 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler
2017-04-24 17:47 - 2017-04-24 17:47 - 00000000 ____D C:\Windows\IObit
2017-04-24 17:47 - 2017-04-24 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4
2017-04-24 17:45 - 2017-04-24 17:46 - 00003174 _____ C:\Windows\System32\Tasks\SmartDefrag_AutoAnalyze
2017-04-24 17:45 - 2017-04-24 17:45 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\Unconfirmed 863075.crdownload
2017-04-24 17:45 - 2017-04-24 17:45 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\smart-defrag-setup (3).exe
2017-04-24 17:45 - 2017-04-24 17:45 - 00003022 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2017-04-24 17:45 - 2017-04-24 17:45 - 00003020 _____ C:\Windows\System32\Tasks\SmartDefrag_Update
2017-04-24 17:45 - 2017-04-24 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2017-04-24 17:45 - 2017-03-09 13:53 - 00045664 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
2017-04-24 17:45 - 2017-03-09 13:53 - 00030744 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
2017-04-24 17:45 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
2017-04-24 17:44 - 2017-04-24 17:45 - 17866872 _____ (IObit ) C:\Users\Ioakim\Downloads\driver_booster_setup (1).exe
2017-04-24 17:44 - 2017-04-24 17:45 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\smart-defrag-setup (1).exe
2017-04-24 17:44 - 2017-04-24 17:44 - 10895424 _____ (IObit ) C:\Users\Ioakim\Downloads\Unconfirmed 162221.crdownload
2017-04-24 17:43 - 2017-04-24 17:44 - 17866872 _____ (IObit ) C:\Users\Ioakim\Downloads\Unconfirmed 582588.crdownload
2017-04-24 17:43 - 2017-04-24 17:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Unlocker
2017-04-24 17:42 - 2017-04-24 17:42 - 02451912 _____ (IObit ) C:\Users\Ioakim\Downloads\unlocker-setup.exe
2017-04-24 14:57 - 2017-04-24 14:57 - 00000000 ____D C:\ProgramData\{74E9F814-C737-42CC-B721-DBBC4059367A}
2017-04-24 14:50 - 2017-04-24 17:28 - 00000000 ____D C:\Users\Ioakim\Downloads\Advanced SystemCare Pro 10.2.0.721 Multilingual + Keys [SadeemPC]
2017-04-24 14:47 - 2017-04-24 14:47 - 00015153 _____ C:\Users\Ioakim\Downloads\E4089619458C2FD904D95BE84CD48B8512ACC7AD.torrent
2017-04-24 14:24 - 2017-04-24 14:24 - 04089296 _____ C:\Users\Ioakim\Downloads\Unconfirmed 348300.crdownload
2017-04-24 14:19 - 2017-04-24 14:19 - 04089296 _____ C:\Users\Ioakim\Downloads\adwcleaner_6.045.exe
2017-04-18 15:03 - 2017-04-18 15:14 - 00000000 ____D C:\Users\Ioakim\Downloads\Synecdoche, NY
2017-04-18 15:03 - 2017-04-18 15:03 - 00013851 _____ C:\Users\Ioakim\Downloads\[rutracker.org].t1920321.torrent
2017-04-18 02:00 - 2017-04-18 02:00 - 00019219 _____ C:\Users\Ioakim\Downloads\melancholia-english-392564.zip
2017-04-18 01:59 - 2017-04-18 01:59 - 00027076 _____ C:\Users\Ioakim\Downloads\melancholia-english-725425.zip
2017-04-18 01:59 - 2017-04-18 01:59 - 00022210 _____ C:\Users\Ioakim\Downloads\melancholia-english-686401.zip
2017-04-18 01:59 - 2017-04-18 01:59 - 00020265 _____ C:\Users\Ioakim\Downloads\melancholia-english-435376.zip
2017-04-18 01:57 - 2017-04-18 01:57 - 00020139 _____ C:\Users\Ioakim\Downloads\melancholia-english-373799.zip
2017-04-18 01:54 - 2017-04-18 01:54 - 00020484 _____ C:\Users\Ioakim\Downloads\melancholia-english-414517.zip
2017-04-18 01:54 - 2017-04-18 01:54 - 00020233 _____ C:\Users\Ioakim\Downloads\melancholia-english-478409.zip
2017-04-18 00:14 - 2017-04-18 00:20 - 00000000 ____D C:\Users\Ioakim\Downloads\Solefald - World Metal. Kosmopolis Sud (2015)
2017-04-18 00:14 - 2017-04-18 00:14 - 00020876 _____ C:\Users\Ioakim\Downloads\[www.seedpeer.eu] Solefald World Metal Kosmopolis Sud 2015.SEEDPEER.torrent
2017-04-18 00:14 - 2017-04-18 00:14 - 00019770 _____ C:\Users\Ioakim\Downloads\D2DEA94DA6F631E54B2B2A4C47A907D6E53E6019.torrent
2017-04-17 21:11 - 2017-04-18 02:01 - 00000000 ____D C:\Users\Ioakim\Downloads\Melancholia.2011.1080p.BluRay.AAC.5.1.HEVC.x265.sharpysword
2017-04-17 21:10 - 2017-04-17 21:10 - 00026669 _____ C:\Users\Ioakim\Downloads\7D74D96AC9C25FE82B6C9D4FF00F0C926F9A9D5C.torrent
2017-04-17 21:10 - 2017-04-17 21:10 - 00025866 _____ C:\Users\Ioakim\Downloads\7D74D96AC9C25FE82B6C9D4FF00F0C926F9A9D5C (2).torrent
2017-04-17 21:10 - 2017-04-17 21:10 - 00025866 _____ C:\Users\Ioakim\Downloads\7D74D96AC9C25FE82B6C9D4FF00F0C926F9A9D5C (1).torrent
2017-04-12 23:19 - 2017-04-12 23:28 - 00000000 ____D C:\Users\Ioakim\Downloads\Louis.C.K.2017.2017.WEBRip.x264-RARBG
2017-04-12 22:59 - 2017-04-12 23:08 - 00000000 ____D C:\Users\Ioakim\Downloads\Toehider - 2014 - What Kind Of Creature Am I [FLAC]
2017-04-09 19:30 - 2017-04-23 23:47 - 00000000 ____D C:\Users\Ioakim\Downloads\Marillion - **** Everyone And Run (2016) [FLAC]
2017-04-08 04:19 - 2017-04-08 04:21 - 00000000 ____D C:\Users\Ioakim\Downloads\Attalla-2017-Glacial Rule
2017-04-06 02:22 - 2017-02-11 16:33 - 00000000 ____D C:\Users\Ioakim\Downloads\Soen - Lykaia (2017) FLAC + scans
2017-04-06 01:55 - 2017-04-06 02:19 - 435624332 _____ C:\Users\Ioakim\Downloads\Soen---Lykaia-(2017)-FLAC-+-scans.rar
2017-04-04 18:05 - 2017-04-04 18:05 - 16207613 _____ C:\Users\Ioakim\Downloads\Paul-Draper---EP-Two-(EP-2016).rar
2017-04-04 03:03 - 2017-04-18 14:09 - 00000000 ____D C:\Users\Ioakim\Downloads\The Contortionist
2017-04-03 01:48 - 2017-04-17 15:45 - 00000000 ____D C:\Users\Ioakim\Downloads\Karmakanic-Wheel Of Life
2017-04-03 01:48 - 2017-04-17 15:45 - 00000000 ____D C:\Users\Ioakim\Downloads\Karmakanic - In A Perfect World (2011)
2017-04-03 01:48 - 2017-04-03 02:05 - 00000000 ____D C:\Users\Ioakim\Downloads\Karmakanic - Entering The Spectra (2002)
2017-04-03 01:32 - 2017-04-03 01:40 - 00000000 ____D C:\Users\Ioakim\Downloads\The Tea Club - Grappling (2015) [FLAC]
2017-04-01 14:58 - 2017-04-01 15:13 - 00000000 ____D C:\Users\Ioakim\Downloads\Mansun - Attack of the Grey Lantern [FLAC]
2017-04-01 14:41 - 2017-04-15 15:06 - 00000000 ____D C:\Users\Ioakim\Downloads\The Neal Morse Band - 2016 - The Similitude of a Dream [FLAC]
2017-03-30 11:51 - 2017-03-30 11:52 - 70938624 _____ C:\Windows\system32\config\software.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00630784 _____ C:\Windows\system32\config\default.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00032768 _____ C:\Windows\system32\config\security.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00032768 _____ C:\Windows\system32\config\sam.iodefrag.bak
2017-03-30 11:51 - 2017-03-30 11:51 - 00000000 ____H C:\asc_rdflag
2017-03-30 02:41 - 2014-10-16 10:27 - 00027424 _____ (IObit) C:\Windows\system32\RegistryDefragBootTime.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-29 14:46 - 2016-06-24 13:02 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\uTorrent
2017-04-29 14:44 - 2009-07-14 07:45 - 00021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-29 14:44 - 2009-07-14 07:45 - 00021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-29 14:35 - 2016-06-27 01:41 - 00000000 ____D C:\Users\Ioakim\AppData\Local\CrashDumps
2017-04-29 14:34 - 2016-06-22 20:29 - 00000000 ____D C:\ProgramData\NVIDIA
2017-04-29 14:33 - 2017-02-16 18:32 - 00002334 ____H C:\Windows\Tasks\{8CE67B9E-3AC8-4ED2-A8EE-28E6FE3D0B51}.job
2017-04-29 14:33 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-29 14:22 - 2016-10-20 14:25 - 00000967 _____ C:\Users\Ioakim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2017-04-29 14:22 - 2016-10-11 14:26 - 00002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-29 04:34 - 2016-06-24 13:17 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\foobar2000
2017-04-28 20:12 - 2016-06-24 14:45 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-28 20:12 - 2016-06-24 14:45 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-27 19:01 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\inf
2017-04-27 17:38 - 2016-09-30 16:21 - 00002068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоmе.lnk
2017-04-27 17:38 - 2016-09-30 16:21 - 00001914 _____ C:\Users\Ioakim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехрlоrеr.lnk
2017-04-27 17:33 - 2017-02-16 20:26 - 00000000 ____D C:\Program Files\Layers of Fear
2017-04-27 14:47 - 2016-06-24 13:06 - 00000000 ____D C:\Users\Ioakim\AppData\Roaming\IObit
2017-04-27 14:38 - 2016-06-24 13:06 - 00000000 ____D C:\ProgramData\IObit
2017-04-27 14:04 - 2016-10-11 18:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-04-27 13:56 - 2016-12-06 17:01 - 00003788 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003838 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003838 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003776 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003600 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-12-06 17:00 - 00003540 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-04-27 13:56 - 2016-06-24 18:58 - 00004456 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-04-27 13:55 - 2017-03-14 14:39 - 00000000 ____D C:\Users\Ioakim\AppData\LocalLow\Mozilla
2017-04-27 13:54 - 2009-07-14 08:13 - 00795674 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-27 04:00 - 2016-06-22 20:09 - 00000000 ____D C:\KMPlayer
2017-04-26 03:26 - 2016-09-22 12:26 - 00000000 ____D C:\Program Files (x86)\Total War Attila
2017-04-25 13:03 - 2016-06-25 17:10 - 00000000 ____D C:\Program Files (x86)\Steam
2017-04-25 12:56 - 2016-06-24 13:06 - 00000000 ____D C:\Users\Ioakim\AppData\LocalLow\IObit
2017-04-25 12:56 - 2016-06-24 13:06 - 00000000 ____D C:\Program Files (x86)\IObit
2017-04-25 12:52 - 2016-06-24 13:06 - 00000000 ____D C:\ProgramData\ProductData
2017-04-24 18:44 - 2002-01-01 00:02 - 00000000 ____D C:\Windows\Minidump
2017-04-24 18:14 - 2016-10-11 18:12 - 00000000 ____D C:\AdwCleaner
2017-04-24 18:12 - 2009-07-14 06:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-04-24 17:56 - 2016-06-24 13:36 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk
2017-04-24 04:56 - 2017-03-08 14:23 - 00000000 ____D C:\Users\Ioakim\AppData\Local\Ubisoft Game Launcher
2017-04-23 14:37 - 2016-06-24 18:58 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-04-13 13:25 - 2009-07-14 08:08 - 00032544 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-12 00:38 - 2017-03-28 19:27 - 00000000 ____D C:\Users\Ioakim\Downloads\The Mute Gods 2016-2017 (Discography)
2017-04-03 01:28 - 2016-06-22 19:47 - 00000000 ____D C:\Users\Ioakim\AppData\Local\ElevatedDiagnostics
2017-04-03 01:27 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\NDF
2017-04-01 02:36 - 2017-03-17 02:58 - 00000000 ____D C:\Users\Ioakim\Downloads\Sun Kil Moon - Benji (Limited Edition) - 2014 (320 kbps)
2017-03-31 01:10 - 2017-03-15 22:32 - 00000000 ____D C:\Users\Ioakim\Downloads\Blackfield - V (2017, Kscope)
==================== Files in the root of some directories =======
2017-04-29 14:04 - 2017-04-29 14:35 - 0007609 _____ () C:\Users\Ioakim\AppData\Local\Resmon.ResmonCfg
2016-11-09 18:58 - 2016-11-09 18:58 - 0000033 _____ () C:\ProgramData\droidcam-settings
2016-11-04 13:11 - 2016-11-07 20:39 - 0001168 _____ () C:\ProgramData\hpzinstall.log
Files to move or delete:
====================
C:\Windows\Tasks\{8CE67B9E-3AC8-4ED2-A8EE-28E6FE3D0B51}.job
Some files in TEMP:
====================
2017-04-24 17:54 - 2017-04-24 17:54 - 0321024 _____ () C:\Users\Ioakim\AppData\Local\Temp\AppHelperV10.exe
2017-04-24 18:11 - 2017-04-24 18:11 - 0340904 _____ (360.cn) C:\Users\Ioakim\AppData\Local\Temp\Inst13__3112295__3f7372633d6c6d266c733d6e37616163383063353938__68616f2e3336302e636e__0c9f.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-04-24 19:47
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-04-2017
Ran by Ioakim (administrator) on IOAKIM-PC (29-04-2017 14:45:27)
Running from C:\Users\Ioakim\Downloads
Loaded Profiles: Ioakim (Available Profiles: Ioakim)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Cuptony\Application\chrome.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\DriveSettings\Sync\SeagateDriveSettingsService.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(BitTorrent Inc.) C:\Users\Ioakim\AppData\Roaming\uTorrent\uTorrent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Users\Ioakim\AppData\Roaming\uTorrent\VirusGuard\BitTorrentAntivirus.exe
(Microsoft Corporation) C:\Windows\System32\perfmon.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Cuptony\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe