As the title says. I feel like im being watched.. please help lol
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015
Ran by javonmhawk (administrator) on ZEN on 20-05-2015 15:31:47
Running from C:\Users\javonmhawk\Downloads
Loaded Profiles: javonmhawk & (Available profiles: javonmhawk)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCRTP.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Tenable Network Security, Inc) C:\Program Files\Tenable\Nessus\nessus-service.exe
(Tenable Network Security, Inc) C:\Program Files\Tenable\Nessus\nessusd.exe
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCTray.exe
(vdc) C:\vdc.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\plugins\QMNetMon\QQPCNetFlow.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe
Failed to access process -> explorer.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCRealTimeSpeedup.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\wsqmcons.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506136 2013-12-06] (Realtek Semiconductor)
HKLM\...\Run: [vdc] => c:\vdc.exe [29696 2015-05-16] (vdc)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [134624 2014-07-23] (Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [ QQPCTray] => C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCTray.exe [355296 2015-05-15] (Tencent)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-11-01] (AMD)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-13] (Electronic Arts)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [WTFast Tray] => C:\Program Files (x86)\WTFast\WTFast.exe [4726872 2015-03-18] (AAA Internet Publishing, Inc.)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [Spotify Web Helper] => C:\Users\javonmhawk\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2022968 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [Spotify] => C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe [7298616 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\MountPoints2: {e3faffaa-9b89-11e4-8257-806e6f6e6963} - "D:\Autorun.exe"
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [131072 2013-08-22] (Microsoft Corporation)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-11-01] (AMD)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-13] (Electronic Arts)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WTFast Tray] => C:\Program Files (x86)\WTFast\WTFast.exe [4726872 2015-03-18] (AAA Internet Publishing, Inc.)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\javonmhawk\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2022968 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify] => C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe [7298616 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {e3faffaa-9b89-11e4-8257-806e6f6e6963} - "D:\Autorun.exe"
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [131072 2013-08-22] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-03-26]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QMGCShellExt64.dll [2015-05-15] (Tencent)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-12-30] (Oracle Corporation)
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TSWebMon64.dat [2015-05-15] (Tencent)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-12-30] (Oracle Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: 应用宝一键安装插件 -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-12-30] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-12-30] (Oracle Corporation)
Winsock: Catalog9 01 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 02 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 03 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 04 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 15 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 16 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 17 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 18 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 19 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9-x64 01 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 02 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 03 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 04 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 15 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF ProfilePath: C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default
FF SearchEngineOrder.1: Search By ZoneAlarm
FF SelectedSearchEngine: Search By ZoneAlarm
FF Homepage: https://duckduckgo.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-05-02] ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-12-30] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-05-02] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-12-30] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\npQMExtensionsMozilla.dll [2015-05-15] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.2.37\Bin\npSSOAxCtrlForPTLogin.dll [2013-12-30] (Tencent)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\user.js [2015-03-25]
FF SearchPlugin: C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\searchplugins\zonealarm.xml [2015-03-25]
FF Extension: zonealarm.com - C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\Extensions\ffxtlbr@zonealarm.com [2015-03-25]
FF Extension: Adblock Plus - C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-03-23]
FF HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed]
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2015-03-22] (Microsoft Corporation)
R2 iprip; C:\Windows\System32\iprip.dll [34816 2015-03-22] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910640 2015-03-23] (Electronic Arts)
R2 QQPCRTP; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCRTP.exe [297608 2015-05-15] (Tencent)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc.)
S3 TAOFrame; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TAOFrame.exe [293728 2015-05-15] (Tencent)
R2 Tenable Nessus; C:\Program Files\Tenable\Nessus\nessus-service.exe [17376 2015-03-27] (Tenable Network Security, Inc)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3596240 2014-07-23] (Check Point Software Technologies Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [93712 2014-07-03] (Check Point Software Technologies, Ltd.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2014-06-10] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2014-06-10] (Kaspersky Lab)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [92768 2014-06-10] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [490080 2014-06-10] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MotioninJoyXFilter; C:\Windows\System32\drivers\MijXfilt.sys [115272 2012-03-25] (MotioninJoy) [File not signed]
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc.)
R1 QMUdisk; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QMUdisk64.sys [62264 2015-04-17] (Tencent)
R1 QqGameMasterControl; C:\Windows\system32\drivers\QMTgpNetflow764.sys [47928 2013-12-13] (tencent)
R1 QqGameMasterControl; C:\Windows\SysWOW64\drivers\QMTgpNetflow764.sys [47928 2013-12-13] (tencent)
R2 QQSysMonX64; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQSysMonX64.sys [129336 2015-05-15] (电脑管家)
S3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation )
R2 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys [99640 2015-05-15] (Tencent)
R1 TAOKernelDriver; C:\Windows\System32\Drivers\TAOKernel64.sys [174392 2015-05-15] (Tencent Technology(Shenzhen) Company Limited)
S3 TesSafe; C:\Windows\system32\TesSafe.sys [910992 2015-04-12] (TENCENT)
R1 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [87864 2015-05-15] (电脑管家)
R3 TS888x64; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TS888x64.sys [28984 2015-05-20] (Tencent)
R1 TSCPM; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\tscpm64.sys [42296 2015-05-15] (电脑管家)
S1 TSDefenseBt; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TSDefenseBT64.sys [28472 2015-05-15] (Tencent)
R1 TSSysKit; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TSSysKit64.sys [87352 2015-05-15] (电脑管家)
R1 Vsdatant; C:\Windows\System32\drivers\vsdatant.sys [450456 2014-07-23] (Check Point Software Technologies Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 15:31 - 2015-05-20 15:31 - 02107904 _____ (Farbar) C:\Users\javonmhawk\Downloads\FRST64.exe
2015-05-20 15:31 - 2015-05-20 15:31 - 00019232 _____ () C:\Users\javonmhawk\Downloads\FRST.txt
2015-05-20 15:31 - 2015-05-20 15:31 - 00000000 ____D () C:\FRST
2015-05-20 15:30 - 2015-05-20 15:30 - 01146880 _____ (Farbar) C:\Users\javonmhawk\Downloads\FRST.exe
2015-05-18 17:07 - 2015-05-20 15:26 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-18 16:00 - 2015-05-18 16:00 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-18 16:00 - 2015-05-18 16:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-18 16:00 - 2015-05-18 16:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-18 16:00 - 2015-05-18 16:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-18 16:00 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-18 16:00 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-18 16:00 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-18 14:46 - 2015-05-18 14:47 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\javonmhawk\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-16 11:54 - 2015-05-16 11:54 - 00029696 _____ (vdc) C:\vdc.exe
2015-05-15 16:55 - 2015-05-15 16:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
2015-05-15 15:54 - 2015-05-15 15:53 - 00174392 _____ (Tencent Technology(Shenzhen) Company Limited) C:\Windows\system32\Drivers\TAOKernel64.sys
2015-05-15 15:54 - 2015-05-15 15:53 - 00099640 _____ (Tencent) C:\Windows\system32\Drivers\TAOAccelerator64.sys
2015-05-13 01:24 - 2015-04-21 12:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 01:24 - 2015-04-21 11:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 01:24 - 2015-04-21 11:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 01:24 - 2015-04-21 11:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 01:24 - 2015-04-21 11:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 01:24 - 2015-04-21 11:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 01:24 - 2015-04-21 11:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 01:24 - 2015-04-21 11:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 01:24 - 2015-04-21 11:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-13 01:24 - 2015-04-21 11:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 01:24 - 2015-04-21 11:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 01:24 - 2015-04-21 11:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 01:24 - 2015-04-21 11:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-13 01:24 - 2015-04-21 11:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 01:24 - 2015-04-21 11:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 01:24 - 2015-04-21 10:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-13 01:24 - 2015-04-21 10:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 01:24 - 2015-04-21 10:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-13 01:24 - 2015-04-21 10:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 01:24 - 2015-04-21 10:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 01:24 - 2015-04-21 10:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 01:24 - 2015-04-21 10:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 01:24 - 2015-04-21 10:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 01:24 - 2015-04-21 10:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 01:24 - 2015-04-21 10:37 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-05-13 01:24 - 2015-04-21 10:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 01:24 - 2015-04-21 10:32 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-05-13 01:24 - 2015-04-21 10:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 01:24 - 2015-04-21 10:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-13 01:24 - 2015-04-21 10:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 01:24 - 2015-04-21 10:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 01:24 - 2015-04-21 10:26 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-13 01:24 - 2015-04-21 10:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 01:24 - 2015-04-21 10:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 01:24 - 2015-04-21 10:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 01:24 - 2015-04-21 10:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 01:24 - 2015-04-21 10:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 01:24 - 2015-04-21 09:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 01:24 - 2015-04-21 09:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-13 01:22 - 2015-04-30 15:35 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 01:22 - 2015-04-30 15:35 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 18:05 - 2015-04-13 17:48 - 04180480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-12 18:05 - 2015-04-09 20:00 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-12 18:05 - 2015-04-09 19:50 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-12 18:05 - 2015-04-09 19:26 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-12 18:05 - 2015-03-30 00:47 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-12 18:05 - 2015-03-26 22:27 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-12 18:05 - 2015-03-26 21:50 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-12 18:05 - 2015-03-26 21:48 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-12 18:05 - 2014-10-28 21:42 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-12 18:05 - 2014-10-28 20:19 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-12 18:05 - 2014-10-28 19:59 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-05-12 18:04 - 2015-04-30 18:05 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-12 18:04 - 2015-04-30 17:48 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-12 18:03 - 2015-04-08 17:55 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-08 17:10 - 2015-05-08 17:13 - 78683444 _____ () C:\Users\javonmhawk\Downloads\preservation__september_1200.zip
2015-05-02 12:57 - 2015-05-02 12:57 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Macromedia
2015-04-24 15:53 - 2015-04-24 15:54 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\yspkg5eua0il
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 15:31 - 2014-12-30 11:49 - 01236270 _____ () C:\Windows\WindowsUpdate.log
2015-05-20 15:28 - 2015-04-03 21:58 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\Spotify
2015-05-20 15:24 - 2015-04-03 22:00 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Spotify
2015-05-20 15:23 - 2015-03-24 10:00 - 00028984 _____ (Tencent) C:\Windows\SysWOW64\Drivers\TS888x64.sys
2015-05-20 15:19 - 2015-04-12 15:24 - 00001024 _____ () C:\.rnd
2015-05-20 15:19 - 2014-03-18 04:54 - 00065416 _____ () C:\Windows\PFRO.log
2015-05-20 15:19 - 2013-08-22 09:46 - 00064717 _____ () C:\Windows\setupact.log
2015-05-20 15:19 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-19 23:00 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sru
2015-05-19 22:17 - 2015-03-23 20:37 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Warframe
2015-05-19 20:05 - 2015-03-20 19:06 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7A46DFE9-4646-4D03-92DD-360A27E6859E}
2015-05-18 19:09 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\Branding
2015-05-18 17:48 - 2015-03-20 18:59 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1748747307-3260626592-723431498-1002
2015-05-17 19:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-17 08:53 - 2015-03-24 03:00 - 00435308 _____ () C:\Windows\system32\prfh0804.dat
2015-05-17 08:53 - 2015-03-24 03:00 - 00135332 _____ () C:\Windows\system32\prfc0804.dat
2015-05-17 08:53 - 2014-03-18 05:03 - 01434808 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-16 04:48 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-05-15 16:15 - 2015-03-23 20:00 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\Tencent
2015-05-15 15:54 - 2015-03-24 07:37 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2015-05-15 15:53 - 2015-03-24 07:37 - 00087864 _____ (电脑管家) C:\Windows\system32\Drivers\TFsFltX64.sys
2015-05-15 11:33 - 2014-12-30 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-14 20:24 - 2015-03-23 22:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-13 17:11 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\rescache
2015-05-13 16:12 - 2013-08-22 09:44 - 00337616 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 01:26 - 2013-08-22 10:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-05-12 18:06 - 2014-03-18 04:45 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-04 00:21 - 2015-03-20 18:53 - 00000000 ____D () C:\Users\javonmhawk
2015-05-02 00:51 - 2015-03-26 12:30 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Adobe
2015-04-28 17:06 - 2015-03-25 19:20 - 00004489 ____H () C:\Windows\SysWOW64\BTImages.dat
==================== Files in the root of some directories =======
2014-12-30 11:55 - 2014-12-30 11:55 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-03-24 11:49 - 2015-04-12 14:02 - 0000040 _____ () C:\ProgramData\DT0001.dat
2015-03-24 11:29 - 2015-04-12 14:02 - 0000040 _____ () C:\ProgramData\DT0006.dat
Files to move or delete:
====================
C:\ProgramData\DT0001.dat
C:\ProgramData\DT0006.dat
Some content of TEMP:
====================
C:\Users\javonmhawk\AppData\Local\Temp\i4jdel0.exe
C:\Users\javonmhawk\AppData\Local\Temp\PCMgr_AndroidServer.exe
C:\Users\javonmhawk\AppData\Local\Temp\PCMgr_Setup_10_7_16066_216.exe
C:\Users\javonmhawk\AppData\Local\Temp\PCMgr_Setup_10_9_16349_225.exe
C:\Users\javonmhawk\AppData\Local\Temp\TENCENTDOWNLOAD.EXE
C:\Users\javonmhawk\AppData\Local\Temp\TXPltSafeInit.dll
C:\Users\javonmhawk\AppData\Local\Temp\uninst.exe
C:\Users\javonmhawk\AppData\Local\Temp\uninstall_complete.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-15 13:28
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-05-2015
Ran by javonmhawk (administrator) on ZEN on 20-05-2015 15:31:47
Running from C:\Users\javonmhawk\Downloads
Loaded Profiles: javonmhawk & (Available profiles: javonmhawk)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCRTP.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Tenable Network Security, Inc) C:\Program Files\Tenable\Nessus\nessus-service.exe
(Tenable Network Security, Inc) C:\Program Files\Tenable\Nessus\nessusd.exe
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCTray.exe
(vdc) C:\vdc.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\plugins\QMNetMon\QQPCNetFlow.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe
Failed to access process -> explorer.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Tencent) C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCRealTimeSpeedup.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\wsqmcons.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506136 2013-12-06] (Realtek Semiconductor)
HKLM\...\Run: [vdc] => c:\vdc.exe [29696 2015-05-16] (vdc)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [134624 2014-07-23] (Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [ QQPCTray] => C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCTray.exe [355296 2015-05-15] (Tencent)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-11-01] (AMD)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-13] (Electronic Arts)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [WTFast Tray] => C:\Program Files (x86)\WTFast\WTFast.exe [4726872 2015-03-18] (AAA Internet Publishing, Inc.)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [Spotify Web Helper] => C:\Users\javonmhawk\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2022968 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Run: [Spotify] => C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe [7298616 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\MountPoints2: {e3faffaa-9b89-11e4-8257-806e6f6e6963} - "D:\Autorun.exe"
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [131072 2013-08-22] (Microsoft Corporation)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-11-01] (AMD)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-13] (Electronic Arts)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WTFast Tray] => C:\Program Files (x86)\WTFast\WTFast.exe [4726872 2015-03-18] (AAA Internet Publishing, Inc.)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\javonmhawk\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2022968 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify] => C:\Users\javonmhawk\AppData\Roaming\Spotify\Spotify.exe [7298616 2015-05-18] (Spotify Ltd)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {e3faffaa-9b89-11e4-8257-806e6f6e6963} - "D:\Autorun.exe"
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [131072 2013-08-22] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-03-26]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QMGCShellExt64.dll [2015-05-15] (Tencent)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1748747307-3260626592-723431498-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-12-30] (Oracle Corporation)
BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TSWebMon64.dat [2015-05-15] (Tencent)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-12-30] (Oracle Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: 应用宝一键安装插件 -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-12-30] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-12-30] (Oracle Corporation)
Winsock: Catalog9 01 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 02 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 03 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 04 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9 15 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 16 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 17 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 18 C:\Windows\SysWOW64\ierd_tgp_lsp.dll [1348152 2015-03-24] (Tencent)
Winsock: Catalog9 19 C:\Windows\SysWOW64\WTFastDrv.dll [72296 2015-03-24] (Initex)
Winsock: Catalog9-x64 01 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 02 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 03 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 04 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Winsock: Catalog9-x64 15 C:\Windows\system32\WTFastDrv.dll [79464 2015-03-24] (Initex)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF ProfilePath: C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default
FF SearchEngineOrder.1: Search By ZoneAlarm
FF SelectedSearchEngine: Search By ZoneAlarm
FF Homepage: https://duckduckgo.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-05-02] ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-12-30] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-05-02] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-12-30] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\npQMExtensionsMozilla.dll [2015-05-15] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.2.37\Bin\npSSOAxCtrlForPTLogin.dll [2013-12-30] (Tencent)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\user.js [2015-03-25]
FF SearchPlugin: C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\searchplugins\zonealarm.xml [2015-03-25]
FF Extension: zonealarm.com - C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\Extensions\ffxtlbr@zonealarm.com [2015-03-25]
FF Extension: Adblock Plus - C:\Users\javonmhawk\AppData\Roaming\Mozilla\Firefox\Profiles\jxxtznra.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-03-23]
FF HKU\S-1-5-21-1748747307-3260626592-723431498-1002\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKU\S-1-5-21-1748747307-3260626592-723431498-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed]
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2015-03-22] (Microsoft Corporation)
R2 iprip; C:\Windows\System32\iprip.dll [34816 2015-03-22] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910640 2015-03-23] (Electronic Arts)
R2 QQPCRTP; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQPCRTP.exe [297608 2015-05-15] (Tencent)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc.)
S3 TAOFrame; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TAOFrame.exe [293728 2015-05-15] (Tencent)
R2 Tenable Nessus; C:\Program Files\Tenable\Nessus\nessus-service.exe [17376 2015-03-27] (Tenable Network Security, Inc)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3596240 2014-07-23] (Check Point Software Technologies Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [93712 2014-07-03] (Check Point Software Technologies, Ltd.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2014-06-10] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2014-06-10] (Kaspersky Lab)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [92768 2014-06-10] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [490080 2014-06-10] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MotioninJoyXFilter; C:\Windows\System32\drivers\MijXfilt.sys [115272 2012-03-25] (MotioninJoy) [File not signed]
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc.)
R1 QMUdisk; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QMUdisk64.sys [62264 2015-04-17] (Tencent)
R1 QqGameMasterControl; C:\Windows\system32\drivers\QMTgpNetflow764.sys [47928 2013-12-13] (tencent)
R1 QqGameMasterControl; C:\Windows\SysWOW64\drivers\QMTgpNetflow764.sys [47928 2013-12-13] (tencent)
R2 QQSysMonX64; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\QQSysMonX64.sys [129336 2015-05-15] (电脑管家)
S3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation )
R2 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator64.sys [99640 2015-05-15] (Tencent)
R1 TAOKernelDriver; C:\Windows\System32\Drivers\TAOKernel64.sys [174392 2015-05-15] (Tencent Technology(Shenzhen) Company Limited)
S3 TesSafe; C:\Windows\system32\TesSafe.sys [910992 2015-04-12] (TENCENT)
R1 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [87864 2015-05-15] (电脑管家)
R3 TS888x64; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TS888x64.sys [28984 2015-05-20] (Tencent)
R1 TSCPM; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\tscpm64.sys [42296 2015-05-15] (电脑管家)
S1 TSDefenseBt; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TSDefenseBT64.sys [28472 2015-05-15] (Tencent)
R1 TSSysKit; C:\Program Files\腾讯游戏\QQPCMgr\10.9.16349.225\TSSysKit64.sys [87352 2015-05-15] (电脑管家)
R1 Vsdatant; C:\Windows\System32\drivers\vsdatant.sys [450456 2014-07-23] (Check Point Software Technologies Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 15:31 - 2015-05-20 15:31 - 02107904 _____ (Farbar) C:\Users\javonmhawk\Downloads\FRST64.exe
2015-05-20 15:31 - 2015-05-20 15:31 - 00019232 _____ () C:\Users\javonmhawk\Downloads\FRST.txt
2015-05-20 15:31 - 2015-05-20 15:31 - 00000000 ____D () C:\FRST
2015-05-20 15:30 - 2015-05-20 15:30 - 01146880 _____ (Farbar) C:\Users\javonmhawk\Downloads\FRST.exe
2015-05-18 17:07 - 2015-05-20 15:26 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-18 16:00 - 2015-05-18 16:00 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-18 16:00 - 2015-05-18 16:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-18 16:00 - 2015-05-18 16:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-18 16:00 - 2015-05-18 16:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-18 16:00 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-18 16:00 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-18 16:00 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-18 14:46 - 2015-05-18 14:47 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\javonmhawk\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-16 11:54 - 2015-05-16 11:54 - 00029696 _____ (vdc) C:\vdc.exe
2015-05-15 16:55 - 2015-05-15 16:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
2015-05-15 15:54 - 2015-05-15 15:53 - 00174392 _____ (Tencent Technology(Shenzhen) Company Limited) C:\Windows\system32\Drivers\TAOKernel64.sys
2015-05-15 15:54 - 2015-05-15 15:53 - 00099640 _____ (Tencent) C:\Windows\system32\Drivers\TAOAccelerator64.sys
2015-05-13 01:24 - 2015-04-21 12:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 01:24 - 2015-04-21 11:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 01:24 - 2015-04-21 11:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 01:24 - 2015-04-21 11:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 01:24 - 2015-04-21 11:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 01:24 - 2015-04-21 11:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 01:24 - 2015-04-21 11:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 01:24 - 2015-04-21 11:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 01:24 - 2015-04-21 11:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-13 01:24 - 2015-04-21 11:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 01:24 - 2015-04-21 11:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 01:24 - 2015-04-21 11:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 01:24 - 2015-04-21 11:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-13 01:24 - 2015-04-21 11:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 01:24 - 2015-04-21 11:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 01:24 - 2015-04-21 10:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-13 01:24 - 2015-04-21 10:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 01:24 - 2015-04-21 10:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-13 01:24 - 2015-04-21 10:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 01:24 - 2015-04-21 10:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 01:24 - 2015-04-21 10:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 01:24 - 2015-04-21 10:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 01:24 - 2015-04-21 10:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 01:24 - 2015-04-21 10:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 01:24 - 2015-04-21 10:37 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-05-13 01:24 - 2015-04-21 10:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 01:24 - 2015-04-21 10:32 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-05-13 01:24 - 2015-04-21 10:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 01:24 - 2015-04-21 10:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-13 01:24 - 2015-04-21 10:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 01:24 - 2015-04-21 10:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 01:24 - 2015-04-21 10:26 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-13 01:24 - 2015-04-21 10:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 01:24 - 2015-04-21 10:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 01:24 - 2015-04-21 10:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 01:24 - 2015-04-21 10:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 01:24 - 2015-04-21 10:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 01:24 - 2015-04-21 09:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 01:24 - 2015-04-21 09:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-13 01:22 - 2015-04-30 15:35 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 01:22 - 2015-04-30 15:35 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 18:05 - 2015-04-13 17:48 - 04180480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-12 18:05 - 2015-04-09 20:00 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-12 18:05 - 2015-04-09 19:50 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-12 18:05 - 2015-04-09 19:26 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-12 18:05 - 2015-03-30 00:47 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-12 18:05 - 2015-03-26 22:27 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-12 18:05 - 2015-03-26 21:50 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-12 18:05 - 2015-03-26 21:48 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-12 18:05 - 2014-10-28 21:42 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-12 18:05 - 2014-10-28 20:19 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-12 18:05 - 2014-10-28 19:59 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-05-12 18:04 - 2015-04-30 18:05 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-12 18:04 - 2015-04-30 17:48 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-12 18:03 - 2015-04-08 17:55 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-08 17:10 - 2015-05-08 17:13 - 78683444 _____ () C:\Users\javonmhawk\Downloads\preservation__september_1200.zip
2015-05-02 12:57 - 2015-05-02 12:57 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Macromedia
2015-04-24 15:53 - 2015-04-24 15:54 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\yspkg5eua0il
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-20 15:31 - 2014-12-30 11:49 - 01236270 _____ () C:\Windows\WindowsUpdate.log
2015-05-20 15:28 - 2015-04-03 21:58 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\Spotify
2015-05-20 15:24 - 2015-04-03 22:00 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Spotify
2015-05-20 15:23 - 2015-03-24 10:00 - 00028984 _____ (Tencent) C:\Windows\SysWOW64\Drivers\TS888x64.sys
2015-05-20 15:19 - 2015-04-12 15:24 - 00001024 _____ () C:\.rnd
2015-05-20 15:19 - 2014-03-18 04:54 - 00065416 _____ () C:\Windows\PFRO.log
2015-05-20 15:19 - 2013-08-22 09:46 - 00064717 _____ () C:\Windows\setupact.log
2015-05-20 15:19 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-19 23:00 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sru
2015-05-19 22:17 - 2015-03-23 20:37 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Warframe
2015-05-19 20:05 - 2015-03-20 19:06 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7A46DFE9-4646-4D03-92DD-360A27E6859E}
2015-05-18 19:09 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\Branding
2015-05-18 17:48 - 2015-03-20 18:59 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1748747307-3260626592-723431498-1002
2015-05-17 19:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-17 08:53 - 2015-03-24 03:00 - 00435308 _____ () C:\Windows\system32\prfh0804.dat
2015-05-17 08:53 - 2015-03-24 03:00 - 00135332 _____ () C:\Windows\system32\prfc0804.dat
2015-05-17 08:53 - 2014-03-18 05:03 - 01434808 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-16 04:48 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-05-15 16:15 - 2015-03-23 20:00 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\Tencent
2015-05-15 15:54 - 2015-03-24 07:37 - 00000000 ____D () C:\Users\javonmhawk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2015-05-15 15:53 - 2015-03-24 07:37 - 00087864 _____ (电脑管家) C:\Windows\system32\Drivers\TFsFltX64.sys
2015-05-15 11:33 - 2014-12-30 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-14 20:24 - 2015-03-23 22:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-13 17:11 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\rescache
2015-05-13 16:12 - 2013-08-22 09:44 - 00337616 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 01:26 - 2013-08-22 10:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-05-12 18:06 - 2014-03-18 04:45 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-04 00:21 - 2015-03-20 18:53 - 00000000 ____D () C:\Users\javonmhawk
2015-05-02 00:51 - 2015-03-26 12:30 - 00000000 ____D () C:\Users\javonmhawk\AppData\Local\Adobe
2015-04-28 17:06 - 2015-03-25 19:20 - 00004489 ____H () C:\Windows\SysWOW64\BTImages.dat
==================== Files in the root of some directories =======
2014-12-30 11:55 - 2014-12-30 11:55 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-03-24 11:49 - 2015-04-12 14:02 - 0000040 _____ () C:\ProgramData\DT0001.dat
2015-03-24 11:29 - 2015-04-12 14:02 - 0000040 _____ () C:\ProgramData\DT0006.dat
Files to move or delete:
====================
C:\ProgramData\DT0001.dat
C:\ProgramData\DT0006.dat
Some content of TEMP:
====================
C:\Users\javonmhawk\AppData\Local\Temp\i4jdel0.exe
C:\Users\javonmhawk\AppData\Local\Temp\PCMgr_AndroidServer.exe
C:\Users\javonmhawk\AppData\Local\Temp\PCMgr_Setup_10_7_16066_216.exe
C:\Users\javonmhawk\AppData\Local\Temp\PCMgr_Setup_10_9_16349_225.exe
C:\Users\javonmhawk\AppData\Local\Temp\TENCENTDOWNLOAD.EXE
C:\Users\javonmhawk\AppData\Local\Temp\TXPltSafeInit.dll
C:\Users\javonmhawk\AppData\Local\Temp\uninst.exe
C:\Users\javonmhawk\AppData\Local\Temp\uninstall_complete.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-15 13:28
==================== End Of Log ============================