FSRT
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-01-2015 03
Ran by olive (administrator) on OLIVE-PC on 04-01-2015 23:19:26
Running from C:\Users\olive\Downloads
Loaded Profile: olive (Available profiles: olive & Administrator & Guest)
Platform: Microsoft Windows 7 Ultimate (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
() C:\ProgramData\DatacardService\HWDeviceService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(AVG) C:\Program Files\AVG\AVG PC Tuneup\BoostSpeed.exe
() C:\Program Files\Garena Plus\ggdllhost.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Razer Inc.) C:\Program Files\Razer\Razer Cortex\RzKLService.exe
() C:\Program Files\ZTE Connection Manager\AssistantServices.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.11\GoogleCrashHandler.exe
() C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
() C:\Program Files\Garena Plus\GarenaMessenger.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Google Inc.) C:\Program Files\Google\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Google\Chrome\Application\chrome.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcfgex.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RazerCortex] => C:\Program Files\Razer\Razer Cortex\RazerCortex.exe [60640 2014-09-11] (Razer Inc.)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\Run: [GarenaPlus] => C:\Program Files\Garena Plus\GarenaMessenger.exe [9974576 2014-10-27] ()
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: F - F:\Autorun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {0d656420-b6e5-11e1-974c-001b38bfc949} - E:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {0d65642d-b6e5-11e1-974c-001b38bfc949} - E:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {16ff6448-0a34-11e3-a362-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {16ff6461-0a34-11e3-a362-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {356cf467-6e2a-11e4-95d4-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {356cf479-6e2a-11e4-95d4-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {47567d4e-4f82-11e3-bf05-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {4eb76fee-4b42-11e3-b09c-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {538fa989-18a1-11e3-b162-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {538fa99c-18a1-11e3-b162-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {7b336ec9-004c-11e4-a8e6-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {8d783105-4f24-11e3-b8e5-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {8d783117-4f24-11e3-b8e5-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {a1566cba-4abe-11e3-bcc3-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {bfe0d345-0832-11e3-aa3a-001b38bfc949} - E:\Autoplay.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {c9408903-632b-11e3-827c-001b38bfc949} - F:\AutoRun.exe
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\...\MountPoints2: {ef230741-0898-11e3-a1f1-001b38bfc949} - F:\autorun.exe
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\olive\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\olive\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\olive\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2864508046-1840752021-4048113893-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://ksa.msn.com/?rd=1&ucc=SA&dcc=SA&opt=0
URLSearchHook: HKU\S-1-5-21-2864508046-1840752021-4048113893-1000 - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn8\yt.dll (Yahoo! Inc.)
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-2864508046-1840752021-4048113893-1000 -> DefaultScope {9B0DF573-F9ED-440B-9A62-49DCDEF15264} URL =
https://ph.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=407453&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2864508046-1840752021-4048113893-1000 -> {492CBCC4-502D-4C79-99C4-9BC09FD8FEE6} URL =
http://ph.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=407453&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2864508046-1840752021-4048113893-1000 -> {9B0DF573-F9ED-440B-9A62-49DCDEF15264} URL =
https://ph.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=407453&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2864508046-1840752021-4048113893-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL =
http://search.yahoo.com/search?p={searchTerms}&fr=mkg028
SearchScopes: HKU\S-1-5-21-2864508046-1840752021-4048113893-1000 -> {E85D6642-6EE8-465F-9ED6-8098FB498B4C} URL =
https://isearch.avg.com/search?cid=...61a18b5d161&lang=en&ds=AVG&pr=fr&d=2012-09-27 12:05:31&v=12.2.5.34&sap=dsp&q={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll No File
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2864508046-1840752021-4048113893-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2E03FDE5-6C32-4085-A19F-F1A01CDE27A0}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{52235E54-F1A5-48F9-8386-7D46220F77A1}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{57BD95B5-B59F-42ED-BA98-50E075A5568D}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{F25ABC70-30A0-4EAB-90F8-502E7806697B}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\olive\AppData\Roaming\Mozilla\Firefox\Profiles\1a3szy42.default
FF DefaultSearchEngine: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Keyword.URL:
https://ph.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=407453&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.1.18 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.1.18 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @t.garena.com/garenatalk -> C:\Program Files\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2864508046-1840752021-4048113893-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\olive\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-2864508046-1840752021-4048113893-1000: @tools.google.com/Google Update;version=3 -> C:\Users\olive\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-2864508046-1840752021-4048113893-1000: @tools.google.com/Google Update;version=9 -> C:\Users\olive\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-2864508046-1840752021-4048113893-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\olive\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-03-26]
FF HKLM\...\Firefox\Extensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: No Name - C:\Users\olive\AppData\Roaming\Mozilla\Firefox\Profiles\1a3szy42.default\extensions\
ffxtlbr@alnaddyToolbar.com [Not Found]
FF Extension: No Name - C:\Users\olive\AppData\Roaming\Mozilla\Firefox\Profiles\1a3szy42.default\extensions\{A88AA718-8AA6-F9FC-95E3-C4CC78077993} [Not Found]
Chrome:
=======
CHR Profile: C:\Users\olive\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\olive\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-14]
CHR Extension: (YouTube) - C:\Users\olive\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-14]
CHR Extension: (Google Search) - C:\Users\olive\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-14]
CHR Extension: (Google Wallet) - C:\Users\olive\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-14]
CHR Extension: (Battlefield Play4Free) - C:\Users\olive\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh [2014-12-13]
CHR Extension: (Gmail) - C:\Users\olive\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-26]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-03-06]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-05-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] ()
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 npggsvc; C:\Windows\system32\GameMon.des [5132656 2013-10-22] (INCA Internet Co., Ltd.)
S4 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2014-12-14] ()
R2 Razer Game Scanner Service; C:\Program Files\Razer\Razer Services\GSS\GameScannerService.exe [183488 2014-11-01] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
R2 RzKLService; C:\Program Files\Razer\Razer Cortex\RzKLService.exe [105448 2014-09-11] (Razer Inc.)
S4 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3289208 2013-05-14] (Skype Technologies S.A.)
S4 Sun_Philippines Wave Modem Device Helper; C:\Program Files\Sun Broadband Wireless\BackgroundService\ServiceManager.exe [49752 2011-06-20] () [File not signed]
R2 UI Assistant Service; C:\Program Files\ZTE Connection Manager\AssistantServices.exe [252784 2010-07-23] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208152 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [200984 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-05-09] (AVG Technologies)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [35560 2012-08-02] (AnchorFree Inc.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [96000 2012-08-20] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27520 2012-08-20] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [205312 2012-12-03] (Huawei Technologies Co., Ltd.)
S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [106112 2011-06-20] (TCT International Mobile Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-04] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R3 mcdbus; C:\Windows\System32\DRIVERS\mcdbus.sys [116736 2009-02-24] (MagicISO, Inc.) [File not signed]
S3 NPPTNT2; C:\Windows\system32\npptNT2.sys [4682 2004-12-31] (INCA Internet Co., Ltd.) [File not signed]
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [20416 2014-11-01] (Razer, Inc.)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [60156 2011-06-15] (PowerISO Computing, Inc.) [File not signed]
R1 StarOpen; C:\Windows\system32\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
R3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [33512 2012-08-02] (AnchorFree Inc)
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [165376 2009-07-23] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [55040 2009-07-23] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2009-07-23] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [293904 2009-07-23] (Microsoft Corporation)
S3 ZSMC303; C:\Windows\System32\Drivers\usbVM303.sys [391300 2006-02-23] (Vimicro Corporation)
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files\Garena Plus\Room\safedrv.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-04 23:19 - 2015-01-04 23:20 - 00021810 _____ () C:\Users\olive\Downloads\FRST.txt
2015-01-04 23:18 - 2015-01-04 23:18 - 00006425 _____ () C:\Users\olive\Downloads\fixlist.txt
2015-01-04 23:17 - 2015-01-04 23:17 - 01115136 _____ (Farbar) C:\Users\olive\Downloads\FRST.exe
2015-01-04 22:57 - 2015-01-04 23:19 - 00000000 ____D () C:\FRST
2015-01-04 22:52 - 2015-01-04 22:52 - 00000076 _____ () C:\Users\olive\Desktop\virus help.txt
2015-01-04 22:10 - 2015-01-04 23:02 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-04 22:07 - 2015-01-04 22:47 - 00000000 ____D () C:\Users\olive\Desktop\mbar
2015-01-04 22:04 - 2015-01-04 22:07 - 16448208 _____ (Malwarebytes Corp.) C:\Users\olive\Downloads\mbar-1.08.2.1001.exe
2015-01-04 21:59 - 2015-01-04 21:59 - 00001122 _____ () C:\Users\olive\Desktop\attach.txt
2015-01-04 21:57 - 2015-01-04 21:57 - 00688992 ____R (Swearware) C:\Users\olive\Downloads\dds.com
2015-01-04 21:50 - 2015-01-04 23:02 - 00007376 _____ () C:\Windows\PFRO.log
2015-01-04 21:07 - 2015-01-04 23:09 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-04 21:06 - 2015-01-04 22:08 - 00079576 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-04 21:06 - 2015-01-04 21:06 - 00001024 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-04 21:06 - 2015-01-04 21:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-04 21:06 - 2015-01-04 21:06 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-01-04 21:06 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-04 21:06 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-04 21:03 - 2015-01-04 22:54 - 00000000 ____D () C:\Users\olive\Desktop\logss
2015-01-04 20:51 - 2015-01-04 21:05 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\olive\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-04 20:16 - 2015-01-04 20:16 - 00144944 _____ () C:\Windows\Minidump\010415-45614-01.dmp
2015-01-04 19:56 - 2015-01-04 22:02 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2015-01-04 19:56 - 2015-01-04 19:56 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-01-04 19:49 - 2015-01-04 19:55 - 15298136 _____ () C:\Users\olive\Downloads\RogueKiller.exe
2015-01-03 16:44 - 2015-01-03 17:10 - 606244774 _____ () C:\Users\olive\Downloads\Halo.rar
2015-01-03 03:25 - 2015-01-03 03:26 - 21273772 _____ () C:\Users\olive\Downloads\AttackOnTitanTributeGame v11212014b [juupzz-creation].rar
2015-01-03 00:08 - 2015-01-04 23:07 - 00000616 _____ () C:\Windows\setupact.log
2015-01-02 19:19 - 2015-01-02 19:19 - 00000000 ____D () C:\Users\olive\AppData\Roaming\AVG2015
2015-01-02 19:18 - 2015-01-02 19:18 - 00000895 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2015-01-02 19:18 - 2015-01-02 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-02 19:17 - 2015-01-04 19:07 - 00000000 ____D () C:\ProgramData\AVG2015
2015-01-02 19:09 - 2015-01-02 19:10 - 04578040 _____ (AVG Technologies) C:\Users\olive\Downloads\avg_free_stb_all_2015_5315_ppc12 (1).exe
2015-01-02 18:58 - 2015-01-02 19:36 - 00000000 ____D () C:\Users\olive\AppData\Roaming\Otbiwag
2015-01-02 09:56 - 2015-01-02 09:56 - 00000000 ____D () C:\Users\olive\Downloads\Modern Combat 3 Fallen Nation v1.1.4g apkmania.com
2015-01-02 09:23 - 2015-01-02 09:31 - 90248213 _____ () C:\Users\olive\Downloads\Modern Combat 3 Fallen Nation v1.1.4g apkmania.com.rar
2015-01-02 09:20 - 2015-01-02 09:22 - 00000000 ____D () C:\Users\olive\Downloads\com.gameloft.android.ANMP.GloftM3HM build.1120 apkmania.com
2015-01-02 07:09 - 2015-01-02 07:09 - 00000000 ____D () C:\Users\olive\Downloads\MC5-110k-Data-Obb
2015-01-02 06:39 - 2015-01-02 06:39 - 00000000 ____D () C:\Users\olive\Downloads\Odin3-v1.85
2015-01-02 06:38 - 2015-01-02 06:38 - 00000000 ____D () C:\Users\olive\Downloads\Samsung Galaxy Tab2 7.0 GT- P3100_CF-Auto-Root-espressor_
2015-01-02 06:35 - 2015-01-02 06:37 - 11131427 _____ () C:\Users\olive\Downloads\Samsung Galaxy Tab2 7.0 GT- P3100_CF-Auto-Root-espressor_.rar
2015-01-02 06:34 - 2015-01-02 06:34 - 00121176 _____ (Company V) C:\Users\olive\Downloads\download
2015-01-02 06:22 - 2015-01-02 06:22 - 00000953 _____ () C:\Users\Public\Desktop\Kingo ROOT.lnk
2015-01-02 06:22 - 2015-01-02 06:22 - 00000000 ____D () C:\Users\olive\AppData\Roaming\Kingosoft
2015-01-02 06:22 - 2015-01-02 06:22 - 00000000 ____D () C:\Users\olive\AppData\Local\Kingosoft
2015-01-02 06:22 - 2015-01-02 06:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT
2015-01-02 06:22 - 2015-01-02 06:22 - 00000000 ____D () C:\Program Files\Kingo ROOT
2015-01-02 01:43 - 2015-01-02 01:43 - 00001474 _____ () C:\Users\olive\Downloads\up09253.zip
2015-01-01 11:12 - 2015-01-01 11:30 - 00000000 ____D () C:\Users\olive\Downloads\War Of Ages
2015-01-01 11:10 - 2015-01-01 11:10 - 00054568 _____ () C:\Users\olive\Downloads\[kat.sitescrack.com]war.of.ages.discography.2005.2012.torrent
2015-01-01 11:08 - 2015-01-01 11:08 - 00017811 _____ () C:\Users\olive\Downloads\[kat.sitescrack.com]war.of.ages.discography.includes.2010.release.jonnybeans.torrent
2015-01-01 06:08 - 2015-01-01 06:08 - 00002688 _____ () C:\Users\olive\Downloads\[kickass.so]modern.combat.5.blackout.mc5.1.0.2f.update.cracked.patched.apk.data.obb.android.download.free.torrent
2015-01-01 05:58 - 2015-01-01 06:13 - 00000000 ____D () C:\Users\olive\Downloads\Exiles v2.18 apkmania.com
2015-01-01 05:50 - 2015-01-02 07:09 - 00000000 ____D () C:\Users\olive\Downloads\Modern Combat 5 - Blackout v1.0.2f apkmania.com
2014-12-31 18:55 - 2015-01-02 19:36 - 00000000 ____D () C:\Users\olive\AppData\Roaming\Woqoasri
2014-12-29 19:52 - 2014-12-29 19:52 - 00001211 _____ () C:\Users\Public\Desktop\YTD Video Downloader.lnk
2014-12-29 19:52 - 2014-12-29 19:52 - 00000000 ____D () C:\Program Files\GreenTree Applications
2014-12-29 18:49 - 2015-01-02 19:36 - 00000000 ____D () C:\Users\olive\AppData\Roaming\Cokuveim
2014-12-29 18:06 - 2014-12-29 18:06 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-12-29 18:06 - 2014-12-29 18:06 - 00000000 ____D () C:\Users\Administrator
2014-12-29 18:06 - 2009-07-14 12:42 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-29 18:06 - 2009-07-14 12:37 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-29 02:17 - 2014-12-29 02:17 - 00020681 _____ () C:\Users\olive\Downloads\[ZenSub] Mangaka-san to Assistant-san - OVA (BDRip 1280x720 x264 FLAC).mkv.torrent
2014-12-28 04:39 - 2014-12-28 06:49 - 00000000 ____D () C:\Program Files\Steam
2014-12-28 04:39 - 2014-12-28 05:04 - 00000000 ____D () C:\Program Files\Common Files\Steam
2014-12-28 04:39 - 2014-12-28 04:39 - 01142392 _____ () C:\Users\olive\Downloads\SteamSetup.exe
2014-12-28 04:39 - 2014-12-28 04:39 - 01142392 _____ () C:\Users\olive\Downloads\SteamSetup (1).exe
2014-12-28 04:39 - 2014-12-28 04:39 - 00000885 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-12-28 04:39 - 2014-12-28 04:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-27 20:33 - 2014-12-27 20:33 - 00000009 _____ () C:\Users\olive\Desktop\stalk.txt
2014-12-27 19:33 - 2015-01-02 19:27 - 00000000 ____D () C:\Users\olive\AppData\Roaming\Aksolai
2014-12-27 18:40 - 2015-01-02 19:36 - 00000000 ____D () C:\Users\olive\AppData\Roaming\Oqtaovi
2014-12-27 03:27 - 2014-12-27 03:27 - 00000000 ____D () C:\Users\olive\Downloads\Halo 2 Activation
2014-12-27 03:26 - 2014-12-27 03:26 - 00168211 _____ () C:\Users\olive\Downloads\Halo 2 Activation.rar
2014-12-27 03:20 - 2014-12-27 03:20 - 00000000 ____D () C:\Users\olive\Downloads\rzr-hal2
2014-12-27 03:19 - 2014-12-27 03:19 - 00003773 ____R () C:\Users\olive\Downloads\rzr-hal2.rar
2014-12-27 03:18 - 2014-12-27 03:18 - 00000559 _____ () C:\Users\olive\Downloads\[kickass.so]halo.2.crack.only.torrent
2014-12-27 03:12 - 2014-12-27 03:12 - 00000000 ____D () C:\Users\olive\AppData\Roaming\Microsoft Game Studios
2014-12-27 02:19 - 2014-12-27 02:19 - 00000000 ____D () C:\Windows\system32\original
2014-12-27 01:47 - 2014-12-27 01:47 - 00000000 ____D () C:\Users\olive\Downloads\[PC] Halo 2 XP + VISTA [RIP] [dopeman]
2014-12-25 11:00 - 2014-12-25 11:00 - 00013554 _____ () C:\Users\olive\Downloads\[kickass.so]pc.halo.2.xp.vista.rip.dopeman.zip.torrent
2014-12-24 04:36 - 2014-12-24 04:44 - 00000000 ____D () C:\Users\olive\Downloads\Cabin Fever (2002)
2014-12-24 04:35 - 2014-12-24 04:35 - 00015852 _____ () C:\Users\olive\Downloads\Cabin_Fever_2002_720p.torrent
2014-12-24 04:31 - 2014-12-24 04:31 - 00015403 _____ () C:\Users\olive\Downloads\The_Signal_2014_1080p_1080p.torrent
2014-12-23 18:34 - 2015-01-04 21:34 - 00000000 ____D () C:\Users\olive\AppData\Local\Owpics
2014-12-23 14:21 - 2014-12-23 14:21 - 00000106 _____ () C:\Users\olive\Desktop\galleon shop location.txt
2014-12-21 17:55 - 2015-01-04 21:33 - 00000000 ____D () C:\Users\olive\AppData\Local\Awrdworks
2014-12-21 14:33 - 2014-12-21 14:33 - 00004286 _____ () C:\Windows\system32\jupdate-1.7.0_71-b14.log
2014-12-21 14:33 - 2014-12-21 14:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-12-21 14:33 - 2014-09-26 18:42 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-12-21 14:33 - 2014-09-26 18:36 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-12-21 14:33 - 2014-09-26 18:36 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-12-21 14:33 - 2014-09-26 18:35 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-12-17 20:23 - 2014-12-17 20:23 - 00000000 ____D () C:\Users\olive\AppData\Local\Razer_Inc
2014-12-17 20:22 - 2014-12-17 20:22 - 00000000 ____D () C:\Users\olive\Documents\Razer
2014-12-17 20:18 - 2014-12-17 20:18 - 00001956 _____ () C:\Users\Public\Desktop\Razer Cortex.lnk
2014-12-17 20:18 - 2014-12-17 20:18 - 00000000 ____D () C:\Users\olive\AppData\Local\Razer
2014-12-17 20:18 - 2014-12-17 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2014-12-17 20:17 - 2014-12-17 20:18 - 00000000 ____D () C:\ProgramData\Razer
2014-12-17 20:17 - 2014-12-17 20:18 - 00000000 ____D () C:\Program Files\Razer
2014-12-17 20:17 - 2014-12-17 20:17 - 00000000 ____D () C:\Users\olive\AppData\Roaming\AVG
2014-12-17 20:17 - 2014-11-01 06:27 - 00020416 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpmgrk.sys
2014-12-17 20:09 - 2009-11-25 11:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-12-17 20:09 - 2009-11-25 11:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2014-12-17 20:09 - 2009-11-25 11:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2014-12-17 20:09 - 2009-11-25 11:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2014-12-17 20:09 - 2009-11-25 11:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2014-12-17 19:56 - 2015-01-04 19:35 - 00000000 ____D () C:\Users\olive\AppData\Local\Avg2015
2014-12-17 19:56 - 2014-12-17 19:56 - 04578040 _____ (AVG Technologies) C:\Users\olive\Downloads\avg_free_stb_all_2015_5315_ppc12.exe
2014-12-15 18:09 - 2014-12-15 18:09 - 00101072 _____ (GreenTree Applications SRL) C:\Users\olive\Downloads\YTDSetup (1).exe
2014-12-15 17:43 - 2014-12-15 17:43 - 00101072 _____ (GreenTree Applications SRL) C:\Users\olive\Downloads\YTDSetup.exe
2014-12-15 06:11 - 2014-12-15 06:11 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2014-12-14 05:55 - 2014-12-14 05:56 - 00000000 ____D () C:\Users\olive\Downloads\Big Hero 6 2014 HDCAM NEW SOURCE XviD AC3 ACAB
2014-12-14 05:54 - 2015-01-01 22:38 - 00000761 _____ () C:\Windows\system32\Drivers\etc\hosts.txt
2014-12-14 05:50 - 2014-12-25 10:53 - 00000000 ____D () C:\Program Files\GarenaPBPH
2014-12-14 02:48 - 2014-12-14 05:46 - 1249654704 _____ () C:\PointBlank_GarenaPlus_Install_1034.exe
2014-12-14 02:34 - 2014-12-14 02:40 - 00234768 _____ () C:\Windows\system32\PnkBstrB.xtr
2014-12-14 02:34 - 2014-12-14 02:34 - 00000000 ____D () C:\Users\olive\AppData\Local\PunkBuster
2014-12-14 01:50 - 2014-12-14 02:35 - 00138264 _____ () C:\Windows\system32\Drivers\PnkBstrK.sys
2014-12-14 01:50 - 2014-12-14 02:33 - 00000000 ____D () C:\Users\olive\Documents\Battlefield Play4Free
2014-12-14 01:50 - 2014-12-14 01:50 - 00138056 _____ () C:\Users\olive\AppData\Roaming\PnkBstrK.sys
2014-12-14 01:49 - 2014-12-14 02:40 - 00234768 _____ () C:\Windows\system32\PnkBstrB.exe
2014-12-14 01:49 - 2014-12-14 01:49 - 00075136 _____ () C:\Windows\system32\PnkBstrA.exe
2014-12-14 01:49 - 2014-12-14 01:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games
2014-12-14 00:19 - 2014-12-14 00:40 - 137678830 _____ () C:\Users\olive\Downloads\Big Hero 6.rar
2014-12-08 21:25 - 2014-12-08 21:25 - 00208152 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys
2014-12-05 18:15 - 2014-12-05 18:29 - 18409608 _____ () C:\Users\olive\Downloads\TouchPal X Keyboard apk 5.5.0.3 apkdock.com.zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-04 23:20 - 2012-08-15 18:01 - 00000000 ____D () C:\ProgramData\TEMP
2015-01-04 23:19 - 2013-11-18 22:10 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2864508046-1840752021-4048113893-1000UA.job
2015-01-04 23:13 - 2009-07-14 12:34 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-04 23:13 - 2009-07-14 12:34 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-04 23:11 - 2013-12-27 04:58 - 00000000 ____D () C:\Users\olive\AppData\Roaming\GarenaPlus
2015-01-04 23:11 - 2013-12-27 04:46 - 00000000 ____D () C:\ProgramData\GarenaMessenger
2015-01-04 23:11 - 2012-05-03 00:33 - 02060227 _____ () C:\Windows\WindowsUpdate.log
2015-01-04 23:07 - 2013-08-24 18:28 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-04 23:07 - 2009-07-14 12:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-04 22:54 - 2012-08-15 17:08 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-04 22:49 - 2009-07-14 12:52 - 00000000 ____D () C:\Windows\addins
2015-01-04 22:47 - 2013-08-19 12:02 - 00000000 ____D () C:\Users\olive\Desktop\games
2015-01-04 22:35 - 2013-08-24 18:28 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-04 22:31 - 2012-06-14 01:54 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-04 22:24 - 2012-06-14 02:11 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2864508046-1840752021-4048113893-1000UA.job
2015-01-04 22:24 - 2012-06-14 02:11 - 00000856 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2864508046-1840752021-4048113893-1000Core.job
2015-01-04 21:43 - 2012-08-15 23:06 - 00000000 ____D () C:\Users\olive\AppData\Local\CRE
2015-01-04 21:43 - 2012-05-03 01:33 - 00000000 ____D () C:\Users\olive\AppData\Roaming\vlc
2015-01-04 21:06 - 2012-10-04 19:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-04 20:32 - 2013-09-21 02:02 - 00007594 _____ () C:\Users\olive\AppData\Local\resmon.resmoncfg
2015-01-04 20:21 - 2012-06-16 19:56 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-01-04 20:16 - 2014-01-27 06:40 - 00000000 ____D () C:\Windows\Minidump
2015-01-04 19:42 - 2014-05-04 23:58 - 00000000 ____D () C:\AdwCleaner
2015-01-04 19:26 - 2013-12-27 06:42 - 00000000 ____D () C:\Users\olive\Desktop\melancholy
2015-01-04 11:19 - 2013-11-18 22:10 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2864508046-1840752021-4048113893-1000Core.job
2015-01-03 16:16 - 2014-04-17 14:21 - 00000000 ____D () C:\Users\olive\Desktop\d
2015-01-03 16:04 - 2012-05-03 00:45 - 00800548 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-03 06:28 - 2014-06-03 13:54 - 00000000 ____D () C:\Users\olive\AppData\Roaming\uTorrent
2015-01-02 19:52 - 2014-10-06 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II
2015-01-02 19:52 - 2014-08-13 20:02 - 00000000 ____D () C:\Users\olive\Desktop\misc
2015-01-02 19:52 - 2014-04-10 02:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sigma Team
2015-01-02 19:52 - 2013-09-09 00:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Bro
2015-01-02 19:52 - 2013-08-21 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Master of Defense
2015-01-02 19:52 - 2012-05-03 01:20 - 00000000 ____D () C:\Users\olive\Desktop\PALARO
2015-01-02 19:52 - 2009-07-14 12:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-02 19:17 - 2012-08-15 17:13 - 00000000 ___HD () C:\$AVG
2015-01-02 19:16 - 2012-08-15 17:12 - 00000000 ____D () C:\Program Files\AVG
2015-01-02 07:16 - 2014-09-09 04:13 - 00000000 ____D () C:\Users\olive\Desktop\com.gameloft.android.ANMP.GloftM5HM apkmania.com
2015-01-01 18:15 - 2014-02-17 11:26 - 00000000 ____D () C:\Users\olive\Desktop\Gravity 2013 1080p WEBDL x264 Pimp4003
2014-12-30 18:17 - 2013-12-27 04:47 - 00000000 ____D () C:\Program Files\Garena Plus
2014-12-30 05:18 - 2013-11-19 21:17 - 00000000 ____D () C:\Users\olive\AppData\Roaming\.minecraft
2014-12-29 19:42 - 2009-07-14 12:53 - 00032612 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-27 02:27 - 2013-08-19 05:00 - 00000000 ____D () C:\Users\olive\Documents\My Games
2014-12-25 10:53 - 2013-12-27 04:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garena
2014-12-24 21:21 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\rescache
2014-12-21 14:33 - 2013-06-22 15:38 - 00000000 ____D () C:\Program Files\Java
2014-12-18 22:02 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-12-17 20:09 - 2012-05-03 01:27 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-12-17 17:29 - 2009-07-14 12:33 - 00412432 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-17 06:06 - 2012-05-03 01:00 - 00108824 _____ () C:\Users\olive\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-15 18:21 - 2013-12-24 21:41 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-12-15 15:17 - 2012-12-20 19:00 - 00000000 ____D () C:\ProgramData\InstallMate
2014-12-15 06:22 - 2009-07-14 10:04 - 00000580 _____ () C:\Windows\win.ini
2014-12-15 06:17 - 2013-12-26 17:47 - 00000983 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-14 06:42 - 2014-08-08 19:10 - 00000000 ____D () C:\Users\olive\AppData\Roaming\CDisplayEx
2014-12-14 02:45 - 2014-05-13 00:32 - 00000000 ____D () C:\Program Files\EA Games
2014-12-14 01:49 - 2009-07-14 10:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-12-13 19:44 - 2014-06-08 22:54 - 00000000 ____D () C:\Dev-Cpp
Some content of TEMP:
====================
C:\Users\olive\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-04 12:51
==================== End Of Log ============================