PhilipMoore62
Posts: 330 +2
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-12-2016
Ran by Phili (administrator) on DESKTOP-D3QH72K (30-12-2016 15:39:29)
Running from C:\Users\Phili\Downloads
Loaded Profiles: Phili (Available Profiles: defaultuser0 & Phili)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Malwarebytes) C:\Users\Phili\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\consent.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16405744 2015-09-06] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-06] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM\...\Run: [Malwarebytes Anti-Ransomware] => C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe [722896 2016-08-26] (Malwarebytes)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-15] (AVAST Software)
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [6006560 2016-11-01] (IObit)
HKU\S-1-5-21-1403890094-3084518123-2784514409-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9288408 2016-12-06] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-12-15] (AVAST Software)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts-x32: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 216.228.160.4 216.228.160.3
Tcpip\..\Interfaces\{cb18bcaf-31a4-480d-9448-cb7423af1b9a}: [DhcpNameServer] 216.228.160.4 216.228.160.3
Internet Explorer:
==================
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
FireFox:
========
FF DefaultProfile: 3tb87h7n.default
FF ProfilePath: C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default [2016-12-30]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\3tb87h7n.default -> Google
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\3tb87h7n.default -> Bing
FF Homepage: Mozilla\Firefox\Profiles\3tb87h7n.default -> hxxp://www.msn.com/?pc=U270&ocid=U270DHP&osmkt=en-us
hxxp://www.google.com/
FF Keyword.URL: Mozilla\Firefox\Profiles\3tb87h7n.default -> hxxp://www.bing.com/search?FORM=U270DF&PC=U270&q=
FF Extension: (Bing Search) - C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default\Extensions\bingsearch.full@microsoft.com.xpi [2016-12-30]
FF Extension: (iCloud Bookmarks) - C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default\Extensions\firefoxdav@icloud.com [2016-12-15]
FF SearchPlugin: C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default\searchplugins\bing-.xml [2016-12-30]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-12-15]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-12-15]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin HKU\S-1-5-21-1403890094-3084518123-2784514409-1001: SkypePlugin -> C:\Users\Phili\AppData\Local\SkypePlugin\7.29.0.73\npGatewayNpapi.dll [2016-12-08] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-1403890094-3084518123-2784514409-1001: SkypePlugin64 -> C:\Users\Phili\AppData\Local\SkypePlugin\7.29.0.73\npGatewayNpapi-x64.dll [2016-12-08] (Skype Technologies S.A.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-15] (AVAST Software)
S4 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328624 2015-10-07] (Intel Corporation)
S4 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1600800 2016-10-21] (IObit)
S4 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2016-10-28] (IObit)
S4 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
S4 MB3Service; C:\Program Files\Malwarebytes\Anti-Ransomware\MB3Service.exe [3291088 2016-08-26] (Malwarebytes)
S4 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-11-29] (Malwarebytes)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-12-15] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-12-15] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-12-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-12-15] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-12-15] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-12-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-12-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-12-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-12-15] (AVAST Software)
S4 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22208 2016-04-01] (IObit)
R0 MB3SwissArmy; C:\Windows\System32\drivers\MB3SwissArmy.sys [228800 2016-12-30] (Malwarebytes)
S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [110536 2016-12-30] (Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [250816 2016-12-29] (Malwarebytes)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [41464 2015-06-09] (Intel(R) Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2016-07-27] (IObit.com)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-12-28] ()
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [146232 2015-06-26] (Intel Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-03-25 02:48 - 2022-03-25 02:48 - 00000852 _____ C:\Windows\system32\Drivers\RTKHDRC1.dat
2022-03-25 02:48 - 2022-03-25 02:48 - 00000852 _____ C:\Windows\system32\Drivers\RTKHDRC0.dat
2022-03-25 01:22 - 2022-03-25 01:22 - 00000712 _____ C:\Windows\system32\Drivers\RTEQEX1.dat
2022-03-25 01:22 - 2022-03-25 01:22 - 00000712 _____ C:\Windows\system32\Drivers\RTEQEX0.dat
2016-12-30 15:40 - 2016-12-30 15:40 - 00000685 _____ C:\Users\Phili\Desktop\JRT.txt
2016-12-30 13:57 - 2016-12-30 15:02 - 00000000 ____D C:\Program Files (x86)\Security Task Manager
2016-12-30 13:50 - 2016-12-30 13:50 - 00002983 _____ C:\Users\Phili\Downloads\FSS.txt
2016-12-30 11:12 - 2016-12-30 11:15 - 00003426 _____ C:\Users\Phili\Desktop\Rkill.txt
2016-12-30 10:44 - 2016-12-30 10:44 - 00000017 _____ C:\Users\Phili\Desktop\scannow.txt
2016-12-30 10:42 - 2016-12-30 10:42 - 00000017 _____ C:\Users\Phili\Documents\scannow.txt
2016-12-30 09:23 - 2016-12-30 09:23 - 00000000 ____D C:\Users\Phili\AppData\Local\ESET
2016-12-30 09:22 - 2016-12-30 09:23 - 06771840 _____ (ESET spol. s r.o.) C:\Users\Phili\Downloads\esetonlinescanner_enu.exe
2016-12-30 09:09 - 2016-12-30 09:11 - 00049201 _____ C:\Users\Phili\Downloads\Addition.txt
2016-12-30 09:07 - 2016-12-30 15:40 - 00009660 _____ C:\Users\Phili\Downloads\FRST.txt
2016-12-30 09:07 - 2016-12-30 15:39 - 00000000 ____D C:\FRST
2016-12-30 09:06 - 2016-12-30 09:06 - 02420736 _____ (Farbar) C:\Users\Phili\Downloads\FRST64.exe
2016-12-30 09:02 - 2016-12-30 09:04 - 47675104 _____ (Microsoft Corporation) C:\Users\Phili\Downloads\Windows-KB890830-x64-V5.43.exe
2016-12-30 09:02 - 2016-12-30 09:02 - 02549112 _____ (Microsoft Corporation) C:\Users\Phili\Downloads\DefaultPack.EXE
2016-12-30 08:35 - 2016-12-30 08:37 - 00258244 _____ C:\TDSSKiller.3.1.0.12_30.12.2016_08.35.04_log.txt
2016-12-29 12:37 - 2016-12-29 12:39 - 00258244 _____ C:\TDSSKiller.3.1.0.12_29.12.2016_12.37.25_log.txt
2016-12-29 12:22 - 2016-12-30 14:47 - 00000000 _____ C:\Recovery.txt
2016-12-29 11:29 - 2016-12-29 12:19 - 00000000 ____D C:\ESD
2016-12-29 11:26 - 2016-12-29 11:26 - 00000000 ___HD C:\$Windows.~WS
2016-12-29 11:26 - 2016-12-29 11:26 - 00000000 ____D C:\$WINDOWS.~BT
2016-12-29 11:25 - 2016-12-29 11:25 - 18309328 _____ (Microsoft Corporation) C:\Users\Phili\Downloads\MediaCreationTool.exe
2016-12-29 11:20 - 2016-12-29 11:20 - 01388617 _____ (pendrivelinux.com) C:\Users\Phili\Downloads\Universal-USB-Installer-1.9.7.0.exe
2016-12-29 11:03 - 2016-12-29 11:02 - 00041912 _____ (Uwe Sieber - www.uwe-sieber.de) C:\Windows\system32\DriveCleanup.exe
2016-12-29 10:18 - 2016-12-29 10:35 - 245295376 _____ C:\Users\Phili\Documents\backup.reg
2016-12-29 09:45 - 2016-12-29 09:50 - 00000476 _____ C:\Users\Phili\Documents\fix_registry_permissions.bat
2016-12-29 09:37 - 2016-12-29 09:37 - 00000000 ____D C:\Program Files (x86)\Windows Resource Kits
2016-12-29 09:35 - 2016-12-29 09:35 - 00379392 _____ C:\Users\Phili\Documents\subinacl.msi
2016-12-29 08:53 - 2016-12-30 15:29 - 00228800 _____ (Malwarebytes) C:\Windows\system32\Drivers\MB3SwissArmy.sys
2016-12-29 08:52 - 2016-12-29 08:53 - 00000000 ____D C:\ProgramData\MalwarebytesARW
2016-12-29 08:51 - 2016-12-29 08:52 - 37892136 _____ (Malwarebytes ) C:\Users\Phili\Downloads\MBARW_Setup(1).exe
2016-12-29 08:30 - 2016-12-29 08:30 - 00000000 ____D C:\Users\Phili\Desktop\Important Texts
2016-12-29 08:24 - 2016-12-29 08:24 - 00000000 ____D C:\Users\Phili\AppData\Local\ElevatedDiagnostics
2016-12-29 08:21 - 2016-12-29 08:21 - 00000396 _____ C:\Windows\system32\.crusader
2016-12-29 08:19 - 2016-12-29 08:20 - 00000000 ____D C:\Users\Phili\Documents\Regbackup
2016-12-28 07:26 - 2016-12-28 07:26 - 00000000 ____D C:\Users\Phili\Documents\ProcessExplorer
2016-12-27 14:52 - 2016-12-27 14:52 - 00000000 ____D C:\Users\Phili\Documents\FixWin10
2016-12-27 14:32 - 2016-12-27 14:33 - 00000000 ____D C:\Users\Phili\Documents\CrystalDiskInfo7_0_4
2016-12-27 10:42 - 2016-12-28 12:08 - 00000000 ____D C:\Users\Phili\Documents\TmForever
2016-12-27 10:42 - 2016-12-27 11:29 - 00000000 ____D C:\ProgramData\TmForever
2016-12-27 10:40 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2016-12-27 10:40 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2016-12-27 10:40 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2016-12-27 10:40 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2016-12-27 10:40 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2016-12-27 10:40 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2016-12-27 10:40 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2016-12-27 10:40 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2016-12-27 10:40 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2016-12-27 10:40 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2016-12-27 10:40 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2016-12-27 10:40 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2016-12-27 10:40 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2016-12-27 10:40 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2016-12-27 10:40 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2016-12-27 10:40 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2016-12-27 10:40 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2016-12-27 10:40 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2016-12-27 10:40 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-12-27 10:40 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2016-12-27 10:40 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2016-12-27 10:40 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2016-12-27 10:40 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2016-12-27 10:40 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2016-12-27 10:39 - 2016-12-27 10:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmNationsForever
2016-12-27 10:37 - 2016-12-27 10:39 - 00000000 ____D C:\Program Files (x86)\TmNationsForever
2016-12-27 10:28 - 2016-12-27 10:31 - 530600781 _____ C:\Users\Phili\Downloads\tmnationsforever_setup.exe
2016-12-27 09:50 - 2016-12-27 09:50 - 01663040 _____ (Malwarebytes) C:\Users\Phili\Downloads\JRT.exe
2016-12-27 08:51 - 2016-12-29 12:47 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-12-27 08:41 - 2016-12-27 08:41 - 00002190 _____ C:\Users\Phili\AppData\Roaming\Microsoft\Windows\Start Menu\Complete Internet Repair.lnk
2016-12-27 08:41 - 2016-12-27 08:41 - 00000000 ____D C:\Users\Phili\AppData\Roaming\Rizonesoft
2016-12-27 08:41 - 2016-12-27 08:41 - 00000000 ____D C:\Program Files\Rizonesoft
2016-12-27 08:40 - 2016-12-27 08:40 - 01648664 _____ (Rizonesoft ) C:\Users\Phili\Downloads\ComIntRep_2825_Setup.exe
2016-12-26 16:05 - 2016-12-26 16:05 - 01542534 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-12-26 07:10 - 2016-12-26 07:10 - 00000000 ____D C:\Windows\LastGood
2016-12-25 14:00 - 2016-12-25 14:01 - 00014376 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_14.00.35_log.txt
2016-12-25 10:38 - 2016-12-25 10:40 - 00258600 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_10.38.30_log.txt
2016-12-25 09:22 - 2016-12-25 09:23 - 00065088 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_09.22.42_log.txt
2016-12-25 09:21 - 2016-12-25 09:22 - 00007492 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_09.21.46_log.txt
2016-12-25 09:06 - 2016-12-25 09:06 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\11E96BC6.sys
2016-12-25 09:03 - 2016-12-25 09:03 - 54199488 _____ (Malwarebytes ) C:\Users\Phili\Downloads\mb3-setup-consumer-3.0.5.1299(1).exe
2016-12-25 08:56 - 2016-12-25 08:56 - 54199488 _____ (Malwarebytes ) C:\Users\Phili\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2016-12-25 08:51 - 2016-12-30 15:29 - 00110536 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2016-12-25 08:43 - 2016-12-29 08:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2016-12-25 08:33 - 2016-12-30 08:55 - 00000000 ____D C:\Windows\pss
2016-12-24 10:53 - 2016-12-24 10:53 - 00000000 ____D C:\Program Files (x86)\Intel
2016-12-24 10:52 - 2016-12-24 10:52 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-12-24 10:06 - 2016-12-24 10:10 - 00000000 ____D C:\Users\Phili\Downloads\DDU Logs
2016-12-24 10:06 - 2016-12-24 10:06 - 00000000 ____D C:\Users\Phili\Downloads\x64
2016-12-24 10:04 - 2016-12-24 10:10 - 00000000 ____D C:\Users\Phili\Downloads\settings
2016-12-24 10:04 - 2016-12-24 10:04 - 01134528 _____ (Igor Pavlov) C:\Users\Phili\Downloads\DDU v17.0.4.1.exe
2016-12-24 10:04 - 2016-12-15 08:11 - 01441792 _____ C:\Users\Phili\Downloads\Display Driver Uninstaller.exe
2016-12-24 10:04 - 2016-12-15 08:11 - 00554496 _____ C:\Users\Phili\Downloads\Display Driver Uninstaller.pdb
2016-12-24 10:04 - 2015-09-06 03:26 - 00000224 _____ C:\Users\Phili\Downloads\Display Driver Uninstaller.exe.config
2016-12-23 15:10 - 2016-12-23 15:10 - 00000105 _____ C:\Users\Phili\Documents\ChineseDelvery12.23.2016.txt
2016-12-23 14:46 - 2016-12-26 16:11 - 00003656 _____ C:\Windows\System32\Tasks\CreateExplorerShellUnelevatedTask
2016-12-23 14:41 - 2016-12-23 14:42 - 37892136 _____ (Malwarebytes ) C:\Users\Phili\Downloads\MBARW_Setup.exe
2016-12-21 14:38 - 2016-12-21 14:38 - 00000207 _____ C:\Windows\tweaking.com-regbackup-DESKTOP-D3QH72K-Windows-10-Home-(64-bit).dat
2016-12-21 14:38 - 2016-12-21 14:38 - 00000000 ____D C:\RegBackup
2016-12-21 13:16 - 2016-12-21 13:16 - 00003782 _____ C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2016-12-21 13:16 - 2016-12-21 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2016-12-21 13:16 - 2016-12-21 13:16 - 00000000 ____D C:\Program Files (x86)\Tweaking.com
2016-12-21 13:14 - 2016-12-21 13:15 - 32243392 _____ (Tweaking.com) C:\Users\Phili\Downloads\tweaking.com_windows_repair_aio_setup.exe
2016-12-21 12:53 - 2016-12-21 12:53 - 00000000 ____D C:\Users\Phili\Documents\cce_2.5.242177.201_x64
2016-12-21 12:51 - 2016-12-21 12:51 - 00000000 ____D C:\Users\Phili\Documents\cce_2.5.242177.201_x32
2016-12-21 12:41 - 2016-12-21 12:46 - 00258788 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_12.41.27_log.txt
2016-12-21 12:28 - 2016-12-21 12:29 - 00025900 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_12.28.48_log.txt
2016-12-21 11:14 - 2016-12-21 11:14 - 12859464 _____ C:\Users\Phili\Downloads\RogueKillerX64_old.exe
2016-12-21 11:09 - 2016-12-21 11:09 - 03977168 _____ C:\Users\Phili\Downloads\AdwCleaner.exe
2016-12-21 11:04 - 2016-12-21 11:04 - 00057750 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_11.04.05_log.txt
2016-12-21 11:01 - 2016-12-21 11:02 - 00016512 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_11.01.57_log.txt
2016-12-21 11:01 - 2016-12-21 11:01 - 00007492 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_11.01.10_log.txt
2016-12-21 09:21 - 2016-12-21 09:21 - 00000000 ____D C:\Users\Phili\AppData\Local\SkypePlugin
2016-12-21 09:20 - 2016-12-21 09:20 - 13955072 _____ C:\Users\Phili\Downloads\SkypeWebPlugin.msi
2016-12-20 11:57 - 2016-12-20 11:57 - 00000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2016-12-20 11:57 - 2016-12-20 11:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2016-12-20 11:57 - 2016-12-20 11:57 - 00000000 ____D C:\Program Files\Speccy
2016-12-19 11:49 - 2016-12-19 11:49 - 00000376 _____ C:\Windows\ODBC.INI
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Windows\SHELLNEW
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Windows\PCHEALTH
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Program Files (x86)\Microsoft ActiveSync
2016-12-19 11:39 - 2016-12-19 11:39 - 00000000 __RHD C:\MSOCache
2016-12-18 14:45 - 2016-12-18 14:46 - 00258622 _____ C:\TDSSKiller.3.1.0.12_18.12.2016_14.45.19_log.txt
2016-12-18 14:30 - 2016-12-30 14:52 - 00000000 ____D C:\Users\Phili\Documents\mbar
2016-12-18 14:28 - 2016-12-30 11:26 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-12-18 14:27 - 2016-12-18 14:27 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Phili\Downloads\mbar-1.09.3.1001.exe
2016-12-18 14:22 - 2016-12-18 14:22 - 00000000 ____D C:\Users\Phili\Documents\64
2016-12-18 14:21 - 2016-12-18 14:21 - 00011250 ____R C:\Users\Phili\Documents\64.zip
2016-12-18 10:18 - 2016-12-18 10:18 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-12-17 11:47 - 2016-12-17 11:47 - 00000000 ____D C:\Users\Phili\AppData\Roaming\Macromedia
2016-12-17 10:09 - 2016-12-30 15:32 - 00000000 ____D C:\Users\Phili\AppData\Local\CrashDumps
2016-12-17 10:09 - 2016-12-17 10:10 - 00021744 _____ C:\TDSSKiller.3.1.0.12_17.12.2016_10.09.55_log.txt
2016-12-17 10:09 - 2016-12-17 10:09 - 00007472 _____ C:\TDSSKiller.3.1.0.12_17.12.2016_10.09.19_log.txt
2016-12-16 14:52 - 2016-12-16 14:52 - 00000000 ____D C:\Users\Phili\AppData\Roaming\Goodsol
2016-12-16 14:51 - 2016-12-16 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pretty Good Solitaire
2016-12-16 14:51 - 2016-12-16 14:51 - 00000000 ____D C:\Program Files (x86)\goodsol
2016-12-16 14:51 - 2012-05-02 11:17 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2016-12-16 14:51 - 2010-02-16 14:22 - 00258880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msflxgrd.ocx
2016-12-16 14:51 - 2010-02-16 14:22 - 00155984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2016-12-16 14:50 - 2016-12-16 14:51 - 17915136 _____ (Goodsol Development Inc. ) C:\Users\Phili\Downloads\gdsol(1).exe
2016-12-16 14:50 - 2016-12-16 14:50 - 17915136 _____ (Goodsol Development Inc. ) C:\Users\Phili\Downloads\gdsol.exe
2016-12-16 14:21 - 2016-12-28 11:22 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-12-16 14:17 - 2016-12-30 15:02 - 00000000 ____D C:\ProgramData\RogueKiller
2016-12-16 13:52 - 2016-12-16 13:53 - 00005876 _____ C:\TDSSKiller.3.1.0.12_16.12.2016_13.52.55_log.txt
2016-12-16 13:48 - 2016-12-16 13:49 - 00006866 _____ C:\TDSSKiller.3.1.0.12_16.12.2016_13.48.11_log.txt
2016-12-16 13:46 - 2016-12-16 13:47 - 00007472 _____ C:\TDSSKiller.3.1.0.12_16.12.2016_13.46.18_log.txt
2016-12-16 13:45 - 2016-12-16 13:45 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Phili\Downloads\tdsskiller.exe
2016-12-16 13:38 - 2016-12-16 13:38 - 00548774 _____ C:\Users\Phili\Downloads\winupdatefix_1.3.exe
2016-12-16 13:36 - 2016-12-27 09:36 - 00000000 ____D C:\AdwCleaner
2016-12-16 13:35 - 2016-12-16 13:35 - 03977168 _____ C:\Users\Phili\Downloads\adwcleaner_6.041.exe
2016-12-16 10:52 - 2016-12-16 10:52 - 01106888 _____ (Bleeping Computer, LLC) C:\Users\Phili\Downloads\rkill64.exe
2016-12-16 10:31 - 2016-12-16 10:31 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Phili\Downloads\rkill.exe
2016-12-16 10:20 - 2016-12-16 10:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2016-12-16 10:16 - 2016-12-16 10:17 - 45738072 _____ (IObit ) C:\Users\Phili\Downloads\IObit-Malware-Fighter-Setup.exe
2016-12-16 06:58 - 2016-12-17 10:27 - 00000000 ____D C:\Program Files\MyDefrag v4.3.1
2016-12-16 06:58 - 2016-12-16 06:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyDefrag v4.3.1
2016-12-16 06:58 - 2010-05-21 12:11 - 01147392 _____ (J.C. Kessels) C:\Windows\system32\MyDefragScreenSaver_v4.3.1.exe
2016-12-16 06:58 - 2010-05-21 12:11 - 00485376 _____ (J.C. Kessels) C:\Windows\system32\MyDefragScreenSaver_v4.3.1.scr
2016-12-16 06:55 - 2016-12-16 06:56 - 02082630 _____ (J.C. Kessels ) C:\Users\Phili\Downloads\MyDefrag-v4.3.1.exe
2016-12-16 06:45 - 2016-12-16 06:45 - 00485032 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-12-15 16:12 - 2016-12-30 09:04 - 135632432 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-12-15 16:12 - 2016-12-15 16:16 - 00000000 ____D C:\Windows\system32\MRT
2016-12-15 16:08 - 2016-12-09 02:32 - 07816032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-12-15 16:08 - 2016-12-09 02:29 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll
2016-12-15 16:08 - 2016-12-09 02:19 - 01293152 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2016-12-15 16:08 - 2016-12-09 02:18 - 01100128 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2016-12-15 16:08 - 2016-12-09 02:18 - 00989024 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2016-12-15 16:08 - 2016-12-09 02:18 - 00947552 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
2016-12-15 16:08 - 2016-12-09 02:18 - 00811872 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
2016-12-15 16:08 - 2016-12-09 02:15 - 08168000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2016-12-15 16:08 - 2016-12-09 02:15 - 01988560 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2016-12-15 16:08 - 2016-12-09 02:14 - 01274712 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-12-15 16:08 - 2016-12-09 02:01 - 02323728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2016-12-15 16:08 - 2016-12-09 01:57 - 01852720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2016-12-15 16:08 - 2016-12-09 01:41 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WordBreakers.dll
2016-12-15 16:08 - 2016-12-09 01:38 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2016-12-15 16:08 - 2016-12-09 01:36 - 06285312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-12-15 16:08 - 2016-12-09 01:36 - 03059200 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-12-15 16:08 - 2016-12-09 01:36 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-12-15 16:08 - 2016-12-09 01:33 - 03777536 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-12-15 16:08 - 2016-12-09 01:33 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2016-12-15 16:08 - 2016-12-09 01:31 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2016-12-15 16:08 - 2016-12-09 01:30 - 04612608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2016-12-15 16:08 - 2016-12-09 01:28 - 03306496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2016-12-15 16:08 - 2016-12-09 01:24 - 02275840 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-12-15 16:08 - 2016-12-09 01:22 - 02688512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-12-15 16:08 - 2016-12-09 01:18 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2016-12-15 16:08 - 2016-12-09 01:16 - 00353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2016-12-15 16:08 - 2016-12-09 01:15 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
Ran by Phili (administrator) on DESKTOP-D3QH72K (30-12-2016 15:39:29)
Running from C:\Users\Phili\Downloads
Loaded Profiles: Phili (Available Profiles: defaultuser0 & Phili)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.145.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Malwarebytes) C:\Users\Phili\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\consent.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16405744 2015-09-06] (Realtek Semiconductor)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-06] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes)
HKLM\...\Run: [Malwarebytes Anti-Ransomware] => C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe [722896 2016-08-26] (Malwarebytes)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-15] (AVAST Software)
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [6006560 2016-11-01] (IObit)
HKU\S-1-5-21-1403890094-3084518123-2784514409-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9288408 2016-12-06] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-12-15] (AVAST Software)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts-x32: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 216.228.160.4 216.228.160.3
Tcpip\..\Interfaces\{cb18bcaf-31a4-480d-9448-cb7423af1b9a}: [DhcpNameServer] 216.228.160.4 216.228.160.3
Internet Explorer:
==================
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
FireFox:
========
FF DefaultProfile: 3tb87h7n.default
FF ProfilePath: C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default [2016-12-30]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\3tb87h7n.default -> Google
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\3tb87h7n.default -> Bing
FF Homepage: Mozilla\Firefox\Profiles\3tb87h7n.default -> hxxp://www.msn.com/?pc=U270&ocid=U270DHP&osmkt=en-us
hxxp://www.google.com/
FF Keyword.URL: Mozilla\Firefox\Profiles\3tb87h7n.default -> hxxp://www.bing.com/search?FORM=U270DF&PC=U270&q=
FF Extension: (Bing Search) - C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default\Extensions\bingsearch.full@microsoft.com.xpi [2016-12-30]
FF Extension: (iCloud Bookmarks) - C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default\Extensions\firefoxdav@icloud.com [2016-12-15]
FF SearchPlugin: C:\Users\Phili\AppData\Roaming\Mozilla\Firefox\Profiles\3tb87h7n.default\searchplugins\bing-.xml [2016-12-30]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-12-15]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-12-15]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin HKU\S-1-5-21-1403890094-3084518123-2784514409-1001: SkypePlugin -> C:\Users\Phili\AppData\Local\SkypePlugin\7.29.0.73\npGatewayNpapi.dll [2016-12-08] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-1403890094-3084518123-2784514409-1001: SkypePlugin64 -> C:\Users\Phili\AppData\Local\SkypePlugin\7.29.0.73\npGatewayNpapi-x64.dll [2016-12-08] (Skype Technologies S.A.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-15] (AVAST Software)
S4 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328624 2015-10-07] (Intel Corporation)
S4 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1600800 2016-10-21] (IObit)
S4 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [360736 2016-10-28] (IObit)
S4 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
S4 MB3Service; C:\Program Files\Malwarebytes\Anti-Ransomware\MB3Service.exe [3291088 2016-08-26] (Malwarebytes)
S4 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-11-29] (Malwarebytes)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-12-15] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-12-15] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-12-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-12-15] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-12-15] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-12-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-12-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-12-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-12-15] (AVAST Software)
S4 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22208 2016-04-01] (IObit)
R0 MB3SwissArmy; C:\Windows\System32\drivers\MB3SwissArmy.sys [228800 2016-12-30] (Malwarebytes)
S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [110536 2016-12-30] (Malwarebytes)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [250816 2016-12-29] (Malwarebytes)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [41464 2015-06-09] (Intel(R) Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2016-07-27] (IObit.com)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-12-28] ()
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [146232 2015-06-26] (Intel Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2022-03-25 02:48 - 2022-03-25 02:48 - 00000852 _____ C:\Windows\system32\Drivers\RTKHDRC1.dat
2022-03-25 02:48 - 2022-03-25 02:48 - 00000852 _____ C:\Windows\system32\Drivers\RTKHDRC0.dat
2022-03-25 01:22 - 2022-03-25 01:22 - 00000712 _____ C:\Windows\system32\Drivers\RTEQEX1.dat
2022-03-25 01:22 - 2022-03-25 01:22 - 00000712 _____ C:\Windows\system32\Drivers\RTEQEX0.dat
2016-12-30 15:40 - 2016-12-30 15:40 - 00000685 _____ C:\Users\Phili\Desktop\JRT.txt
2016-12-30 13:57 - 2016-12-30 15:02 - 00000000 ____D C:\Program Files (x86)\Security Task Manager
2016-12-30 13:50 - 2016-12-30 13:50 - 00002983 _____ C:\Users\Phili\Downloads\FSS.txt
2016-12-30 11:12 - 2016-12-30 11:15 - 00003426 _____ C:\Users\Phili\Desktop\Rkill.txt
2016-12-30 10:44 - 2016-12-30 10:44 - 00000017 _____ C:\Users\Phili\Desktop\scannow.txt
2016-12-30 10:42 - 2016-12-30 10:42 - 00000017 _____ C:\Users\Phili\Documents\scannow.txt
2016-12-30 09:23 - 2016-12-30 09:23 - 00000000 ____D C:\Users\Phili\AppData\Local\ESET
2016-12-30 09:22 - 2016-12-30 09:23 - 06771840 _____ (ESET spol. s r.o.) C:\Users\Phili\Downloads\esetonlinescanner_enu.exe
2016-12-30 09:09 - 2016-12-30 09:11 - 00049201 _____ C:\Users\Phili\Downloads\Addition.txt
2016-12-30 09:07 - 2016-12-30 15:40 - 00009660 _____ C:\Users\Phili\Downloads\FRST.txt
2016-12-30 09:07 - 2016-12-30 15:39 - 00000000 ____D C:\FRST
2016-12-30 09:06 - 2016-12-30 09:06 - 02420736 _____ (Farbar) C:\Users\Phili\Downloads\FRST64.exe
2016-12-30 09:02 - 2016-12-30 09:04 - 47675104 _____ (Microsoft Corporation) C:\Users\Phili\Downloads\Windows-KB890830-x64-V5.43.exe
2016-12-30 09:02 - 2016-12-30 09:02 - 02549112 _____ (Microsoft Corporation) C:\Users\Phili\Downloads\DefaultPack.EXE
2016-12-30 08:35 - 2016-12-30 08:37 - 00258244 _____ C:\TDSSKiller.3.1.0.12_30.12.2016_08.35.04_log.txt
2016-12-29 12:37 - 2016-12-29 12:39 - 00258244 _____ C:\TDSSKiller.3.1.0.12_29.12.2016_12.37.25_log.txt
2016-12-29 12:22 - 2016-12-30 14:47 - 00000000 _____ C:\Recovery.txt
2016-12-29 11:29 - 2016-12-29 12:19 - 00000000 ____D C:\ESD
2016-12-29 11:26 - 2016-12-29 11:26 - 00000000 ___HD C:\$Windows.~WS
2016-12-29 11:26 - 2016-12-29 11:26 - 00000000 ____D C:\$WINDOWS.~BT
2016-12-29 11:25 - 2016-12-29 11:25 - 18309328 _____ (Microsoft Corporation) C:\Users\Phili\Downloads\MediaCreationTool.exe
2016-12-29 11:20 - 2016-12-29 11:20 - 01388617 _____ (pendrivelinux.com) C:\Users\Phili\Downloads\Universal-USB-Installer-1.9.7.0.exe
2016-12-29 11:03 - 2016-12-29 11:02 - 00041912 _____ (Uwe Sieber - www.uwe-sieber.de) C:\Windows\system32\DriveCleanup.exe
2016-12-29 10:18 - 2016-12-29 10:35 - 245295376 _____ C:\Users\Phili\Documents\backup.reg
2016-12-29 09:45 - 2016-12-29 09:50 - 00000476 _____ C:\Users\Phili\Documents\fix_registry_permissions.bat
2016-12-29 09:37 - 2016-12-29 09:37 - 00000000 ____D C:\Program Files (x86)\Windows Resource Kits
2016-12-29 09:35 - 2016-12-29 09:35 - 00379392 _____ C:\Users\Phili\Documents\subinacl.msi
2016-12-29 08:53 - 2016-12-30 15:29 - 00228800 _____ (Malwarebytes) C:\Windows\system32\Drivers\MB3SwissArmy.sys
2016-12-29 08:52 - 2016-12-29 08:53 - 00000000 ____D C:\ProgramData\MalwarebytesARW
2016-12-29 08:51 - 2016-12-29 08:52 - 37892136 _____ (Malwarebytes ) C:\Users\Phili\Downloads\MBARW_Setup(1).exe
2016-12-29 08:30 - 2016-12-29 08:30 - 00000000 ____D C:\Users\Phili\Desktop\Important Texts
2016-12-29 08:24 - 2016-12-29 08:24 - 00000000 ____D C:\Users\Phili\AppData\Local\ElevatedDiagnostics
2016-12-29 08:21 - 2016-12-29 08:21 - 00000396 _____ C:\Windows\system32\.crusader
2016-12-29 08:19 - 2016-12-29 08:20 - 00000000 ____D C:\Users\Phili\Documents\Regbackup
2016-12-28 07:26 - 2016-12-28 07:26 - 00000000 ____D C:\Users\Phili\Documents\ProcessExplorer
2016-12-27 14:52 - 2016-12-27 14:52 - 00000000 ____D C:\Users\Phili\Documents\FixWin10
2016-12-27 14:32 - 2016-12-27 14:33 - 00000000 ____D C:\Users\Phili\Documents\CrystalDiskInfo7_0_4
2016-12-27 10:42 - 2016-12-28 12:08 - 00000000 ____D C:\Users\Phili\Documents\TmForever
2016-12-27 10:42 - 2016-12-27 11:29 - 00000000 ____D C:\ProgramData\TmForever
2016-12-27 10:40 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2016-12-27 10:40 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2016-12-27 10:40 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2016-12-27 10:40 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2016-12-27 10:40 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2016-12-27 10:40 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2016-12-27 10:40 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2016-12-27 10:40 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2016-12-27 10:40 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2016-12-27 10:40 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2016-12-27 10:40 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2016-12-27 10:40 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2016-12-27 10:40 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2016-12-27 10:40 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2016-12-27 10:40 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2016-12-27 10:40 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2016-12-27 10:40 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2016-12-27 10:40 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2016-12-27 10:40 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-12-27 10:40 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2016-12-27 10:40 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2016-12-27 10:40 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2016-12-27 10:40 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2016-12-27 10:40 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2016-12-27 10:39 - 2016-12-27 10:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TmNationsForever
2016-12-27 10:37 - 2016-12-27 10:39 - 00000000 ____D C:\Program Files (x86)\TmNationsForever
2016-12-27 10:28 - 2016-12-27 10:31 - 530600781 _____ C:\Users\Phili\Downloads\tmnationsforever_setup.exe
2016-12-27 09:50 - 2016-12-27 09:50 - 01663040 _____ (Malwarebytes) C:\Users\Phili\Downloads\JRT.exe
2016-12-27 08:51 - 2016-12-29 12:47 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-12-27 08:41 - 2016-12-27 08:41 - 00002190 _____ C:\Users\Phili\AppData\Roaming\Microsoft\Windows\Start Menu\Complete Internet Repair.lnk
2016-12-27 08:41 - 2016-12-27 08:41 - 00000000 ____D C:\Users\Phili\AppData\Roaming\Rizonesoft
2016-12-27 08:41 - 2016-12-27 08:41 - 00000000 ____D C:\Program Files\Rizonesoft
2016-12-27 08:40 - 2016-12-27 08:40 - 01648664 _____ (Rizonesoft ) C:\Users\Phili\Downloads\ComIntRep_2825_Setup.exe
2016-12-26 16:05 - 2016-12-26 16:05 - 01542534 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-12-26 07:10 - 2016-12-26 07:10 - 00000000 ____D C:\Windows\LastGood
2016-12-25 14:00 - 2016-12-25 14:01 - 00014376 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_14.00.35_log.txt
2016-12-25 10:38 - 2016-12-25 10:40 - 00258600 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_10.38.30_log.txt
2016-12-25 09:22 - 2016-12-25 09:23 - 00065088 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_09.22.42_log.txt
2016-12-25 09:21 - 2016-12-25 09:22 - 00007492 _____ C:\TDSSKiller.3.1.0.12_25.12.2016_09.21.46_log.txt
2016-12-25 09:06 - 2016-12-25 09:06 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\11E96BC6.sys
2016-12-25 09:03 - 2016-12-25 09:03 - 54199488 _____ (Malwarebytes ) C:\Users\Phili\Downloads\mb3-setup-consumer-3.0.5.1299(1).exe
2016-12-25 08:56 - 2016-12-25 08:56 - 54199488 _____ (Malwarebytes ) C:\Users\Phili\Downloads\mb3-setup-consumer-3.0.5.1299.exe
2016-12-25 08:51 - 2016-12-30 15:29 - 00110536 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2016-12-25 08:43 - 2016-12-29 08:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2016-12-25 08:33 - 2016-12-30 08:55 - 00000000 ____D C:\Windows\pss
2016-12-24 10:53 - 2016-12-24 10:53 - 00000000 ____D C:\Program Files (x86)\Intel
2016-12-24 10:52 - 2016-12-24 10:52 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-12-24 10:06 - 2016-12-24 10:10 - 00000000 ____D C:\Users\Phili\Downloads\DDU Logs
2016-12-24 10:06 - 2016-12-24 10:06 - 00000000 ____D C:\Users\Phili\Downloads\x64
2016-12-24 10:04 - 2016-12-24 10:10 - 00000000 ____D C:\Users\Phili\Downloads\settings
2016-12-24 10:04 - 2016-12-24 10:04 - 01134528 _____ (Igor Pavlov) C:\Users\Phili\Downloads\DDU v17.0.4.1.exe
2016-12-24 10:04 - 2016-12-15 08:11 - 01441792 _____ C:\Users\Phili\Downloads\Display Driver Uninstaller.exe
2016-12-24 10:04 - 2016-12-15 08:11 - 00554496 _____ C:\Users\Phili\Downloads\Display Driver Uninstaller.pdb
2016-12-24 10:04 - 2015-09-06 03:26 - 00000224 _____ C:\Users\Phili\Downloads\Display Driver Uninstaller.exe.config
2016-12-23 15:10 - 2016-12-23 15:10 - 00000105 _____ C:\Users\Phili\Documents\ChineseDelvery12.23.2016.txt
2016-12-23 14:46 - 2016-12-26 16:11 - 00003656 _____ C:\Windows\System32\Tasks\CreateExplorerShellUnelevatedTask
2016-12-23 14:41 - 2016-12-23 14:42 - 37892136 _____ (Malwarebytes ) C:\Users\Phili\Downloads\MBARW_Setup.exe
2016-12-21 14:38 - 2016-12-21 14:38 - 00000207 _____ C:\Windows\tweaking.com-regbackup-DESKTOP-D3QH72K-Windows-10-Home-(64-bit).dat
2016-12-21 14:38 - 2016-12-21 14:38 - 00000000 ____D C:\RegBackup
2016-12-21 13:16 - 2016-12-21 13:16 - 00003782 _____ C:\Windows\System32\Tasks\Tweaking.com - Windows Repair Tray Icon
2016-12-21 13:16 - 2016-12-21 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2016-12-21 13:16 - 2016-12-21 13:16 - 00000000 ____D C:\Program Files (x86)\Tweaking.com
2016-12-21 13:14 - 2016-12-21 13:15 - 32243392 _____ (Tweaking.com) C:\Users\Phili\Downloads\tweaking.com_windows_repair_aio_setup.exe
2016-12-21 12:53 - 2016-12-21 12:53 - 00000000 ____D C:\Users\Phili\Documents\cce_2.5.242177.201_x64
2016-12-21 12:51 - 2016-12-21 12:51 - 00000000 ____D C:\Users\Phili\Documents\cce_2.5.242177.201_x32
2016-12-21 12:41 - 2016-12-21 12:46 - 00258788 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_12.41.27_log.txt
2016-12-21 12:28 - 2016-12-21 12:29 - 00025900 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_12.28.48_log.txt
2016-12-21 11:14 - 2016-12-21 11:14 - 12859464 _____ C:\Users\Phili\Downloads\RogueKillerX64_old.exe
2016-12-21 11:09 - 2016-12-21 11:09 - 03977168 _____ C:\Users\Phili\Downloads\AdwCleaner.exe
2016-12-21 11:04 - 2016-12-21 11:04 - 00057750 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_11.04.05_log.txt
2016-12-21 11:01 - 2016-12-21 11:02 - 00016512 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_11.01.57_log.txt
2016-12-21 11:01 - 2016-12-21 11:01 - 00007492 _____ C:\TDSSKiller.3.1.0.12_21.12.2016_11.01.10_log.txt
2016-12-21 09:21 - 2016-12-21 09:21 - 00000000 ____D C:\Users\Phili\AppData\Local\SkypePlugin
2016-12-21 09:20 - 2016-12-21 09:20 - 13955072 _____ C:\Users\Phili\Downloads\SkypeWebPlugin.msi
2016-12-20 11:57 - 2016-12-20 11:57 - 00000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2016-12-20 11:57 - 2016-12-20 11:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2016-12-20 11:57 - 2016-12-20 11:57 - 00000000 ____D C:\Program Files\Speccy
2016-12-19 11:49 - 2016-12-19 11:49 - 00000376 _____ C:\Windows\ODBC.INI
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Windows\SHELLNEW
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Windows\PCHEALTH
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-12-19 11:48 - 2016-12-19 11:48 - 00000000 ____D C:\Program Files (x86)\Microsoft ActiveSync
2016-12-19 11:39 - 2016-12-19 11:39 - 00000000 __RHD C:\MSOCache
2016-12-18 14:45 - 2016-12-18 14:46 - 00258622 _____ C:\TDSSKiller.3.1.0.12_18.12.2016_14.45.19_log.txt
2016-12-18 14:30 - 2016-12-30 14:52 - 00000000 ____D C:\Users\Phili\Documents\mbar
2016-12-18 14:28 - 2016-12-30 11:26 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-12-18 14:27 - 2016-12-18 14:27 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Phili\Downloads\mbar-1.09.3.1001.exe
2016-12-18 14:22 - 2016-12-18 14:22 - 00000000 ____D C:\Users\Phili\Documents\64
2016-12-18 14:21 - 2016-12-18 14:21 - 00011250 ____R C:\Users\Phili\Documents\64.zip
2016-12-18 10:18 - 2016-12-18 10:18 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-12-17 11:47 - 2016-12-17 11:47 - 00000000 ____D C:\Users\Phili\AppData\Roaming\Macromedia
2016-12-17 10:09 - 2016-12-30 15:32 - 00000000 ____D C:\Users\Phili\AppData\Local\CrashDumps
2016-12-17 10:09 - 2016-12-17 10:10 - 00021744 _____ C:\TDSSKiller.3.1.0.12_17.12.2016_10.09.55_log.txt
2016-12-17 10:09 - 2016-12-17 10:09 - 00007472 _____ C:\TDSSKiller.3.1.0.12_17.12.2016_10.09.19_log.txt
2016-12-16 14:52 - 2016-12-16 14:52 - 00000000 ____D C:\Users\Phili\AppData\Roaming\Goodsol
2016-12-16 14:51 - 2016-12-16 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pretty Good Solitaire
2016-12-16 14:51 - 2016-12-16 14:51 - 00000000 ____D C:\Program Files (x86)\goodsol
2016-12-16 14:51 - 2012-05-02 11:17 - 01070152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2016-12-16 14:51 - 2010-02-16 14:22 - 00258880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msflxgrd.ocx
2016-12-16 14:51 - 2010-02-16 14:22 - 00155984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2016-12-16 14:50 - 2016-12-16 14:51 - 17915136 _____ (Goodsol Development Inc. ) C:\Users\Phili\Downloads\gdsol(1).exe
2016-12-16 14:50 - 2016-12-16 14:50 - 17915136 _____ (Goodsol Development Inc. ) C:\Users\Phili\Downloads\gdsol.exe
2016-12-16 14:21 - 2016-12-28 11:22 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-12-16 14:17 - 2016-12-30 15:02 - 00000000 ____D C:\ProgramData\RogueKiller
2016-12-16 13:52 - 2016-12-16 13:53 - 00005876 _____ C:\TDSSKiller.3.1.0.12_16.12.2016_13.52.55_log.txt
2016-12-16 13:48 - 2016-12-16 13:49 - 00006866 _____ C:\TDSSKiller.3.1.0.12_16.12.2016_13.48.11_log.txt
2016-12-16 13:46 - 2016-12-16 13:47 - 00007472 _____ C:\TDSSKiller.3.1.0.12_16.12.2016_13.46.18_log.txt
2016-12-16 13:45 - 2016-12-16 13:45 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Phili\Downloads\tdsskiller.exe
2016-12-16 13:38 - 2016-12-16 13:38 - 00548774 _____ C:\Users\Phili\Downloads\winupdatefix_1.3.exe
2016-12-16 13:36 - 2016-12-27 09:36 - 00000000 ____D C:\AdwCleaner
2016-12-16 13:35 - 2016-12-16 13:35 - 03977168 _____ C:\Users\Phili\Downloads\adwcleaner_6.041.exe
2016-12-16 10:52 - 2016-12-16 10:52 - 01106888 _____ (Bleeping Computer, LLC) C:\Users\Phili\Downloads\rkill64.exe
2016-12-16 10:31 - 2016-12-16 10:31 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Phili\Downloads\rkill.exe
2016-12-16 10:20 - 2016-12-16 10:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2016-12-16 10:16 - 2016-12-16 10:17 - 45738072 _____ (IObit ) C:\Users\Phili\Downloads\IObit-Malware-Fighter-Setup.exe
2016-12-16 06:58 - 2016-12-17 10:27 - 00000000 ____D C:\Program Files\MyDefrag v4.3.1
2016-12-16 06:58 - 2016-12-16 06:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyDefrag v4.3.1
2016-12-16 06:58 - 2010-05-21 12:11 - 01147392 _____ (J.C. Kessels) C:\Windows\system32\MyDefragScreenSaver_v4.3.1.exe
2016-12-16 06:58 - 2010-05-21 12:11 - 00485376 _____ (J.C. Kessels) C:\Windows\system32\MyDefragScreenSaver_v4.3.1.scr
2016-12-16 06:55 - 2016-12-16 06:56 - 02082630 _____ (J.C. Kessels ) C:\Users\Phili\Downloads\MyDefrag-v4.3.1.exe
2016-12-16 06:45 - 2016-12-16 06:45 - 00485032 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-12-15 16:12 - 2016-12-30 09:04 - 135632432 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-12-15 16:12 - 2016-12-15 16:16 - 00000000 ____D C:\Windows\system32\MRT
2016-12-15 16:08 - 2016-12-09 02:32 - 07816032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-12-15 16:08 - 2016-12-09 02:29 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll
2016-12-15 16:08 - 2016-12-09 02:19 - 01293152 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2016-12-15 16:08 - 2016-12-09 02:18 - 01100128 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2016-12-15 16:08 - 2016-12-09 02:18 - 00989024 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2016-12-15 16:08 - 2016-12-09 02:18 - 00947552 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
2016-12-15 16:08 - 2016-12-09 02:18 - 00811872 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
2016-12-15 16:08 - 2016-12-09 02:15 - 08168000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2016-12-15 16:08 - 2016-12-09 02:15 - 01988560 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2016-12-15 16:08 - 2016-12-09 02:14 - 01274712 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-12-15 16:08 - 2016-12-09 02:01 - 02323728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2016-12-15 16:08 - 2016-12-09 01:57 - 01852720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2016-12-15 16:08 - 2016-12-09 01:41 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WordBreakers.dll
2016-12-15 16:08 - 2016-12-09 01:38 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2016-12-15 16:08 - 2016-12-09 01:36 - 06285312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-12-15 16:08 - 2016-12-09 01:36 - 03059200 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-12-15 16:08 - 2016-12-09 01:36 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-12-15 16:08 - 2016-12-09 01:33 - 03777536 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-12-15 16:08 - 2016-12-09 01:33 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2016-12-15 16:08 - 2016-12-09 01:31 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2016-12-15 16:08 - 2016-12-09 01:30 - 04612608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2016-12-15 16:08 - 2016-12-09 01:28 - 03306496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2016-12-15 16:08 - 2016-12-09 01:24 - 02275840 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-12-15 16:08 - 2016-12-09 01:22 - 02688512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-12-15 16:08 - 2016-12-09 01:18 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2016-12-15 16:08 - 2016-12-09 01:16 - 00353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
2016-12-15 16:08 - 2016-12-09 01:15 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll