Thank you.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by NATHAN (administrator) on NATHAN-PC (14-03-2016 22:11:36)
Running from C:\Users\NATHAN\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FVZO540X
Loaded Profiles: NATHAN (Available Profiles: NATHAN)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
() C:\Program Files\Core Temp\Core Temp.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Popcorn Time) C:\Program Files (x86)\Popcorn Time\Updater.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
(BitTorrent Inc.) C:\Users\NATHAN\AppData\Roaming\uTorrent\uTorrent.exe
(Forty One Ltd.) C:\Program Files (x86)\AudioSwitcher\AudioSwitcher.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
() C:\Program Files\AutoHotkey\AutoHotkey.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Unified Intents AB) C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-05-09] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15112312 2016-02-10] (Logitech Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [804168 2016-03-12] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\...\Run: [Unified Remote V3] => C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe [4327120 2016-01-04] (Unified Intents AB)
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\...\Run: [uTorrent] => C:\Users\NATHAN\AppData\Roaming\uTorrent\uTorrent.exe [2094080 2016-03-05] (BitTorrent Inc.)
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\...\Run: [AudioSwitcher] => C:\Program Files (x86)\AudioSwitcher\AudioSwitcher.exe [462848 2016-01-31] (Forty One Ltd.)
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [8641240 2016-02-13] (Piriform Ltd)
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\...\MountPoints2: {1269b879-6413-11e4-a5dd-6cf0490754f5} - "L:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\...\MountPoints2: {7396452f-8f43-11e5-9fc1-6cf0490754f5} - K:\Photokinz.exe
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\...\MountPoints2: {92877c44-8998-11e4-9581-6cf0490754f5} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\KitSetup.exe
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll [2012-04-09] (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll [2012-04-09] (EldoS Corporation)
Startup: C:\Users\NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Advanced Window Snap.ahk [2016-01-31] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{575CC9A1-09CA-4056-8D97-5FB30705E4BC}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{A2CF735A-7D86-4995-83EA-1ABA0C16726A}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{B41CBD71-647D-4A3D-8014-3C2E403B32B9}: [DhcpNameServer] 89.233.43.71 91.239.100.100
Tcpip\..\Interfaces\{E43BAD82-F73A-483C-8058-2F579B303CF9}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://
www.ninemsn.com.au/?ocid=iehp
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://rarbg.to/torrents.php?category=17;44;45;47;42;46;18
HKU\S-1-5-21-2863258378-1141828324-3796875232-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://kat.cr/movies/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2863258378-1141828324-3796875232-1000 -> DefaultScope {5911452A-33E9-4AC9-8472-F61FDF09E154} URL = hxxps://
www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKU\S-1-5-21-2863258378-1141828324-3796875232-1000 -> {5911452A-33E9-4AC9-8472-F61FDF09E154} URL = hxxps://
www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-07-10] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2013-07-13] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-21] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2013-07-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-21] (Oracle Corporation)
Toolbar: HKLM - No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - No File
Toolbar: HKLM-x32 - No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - No File
Toolbar: HKU\S-1-5-21-2863258378-1141828324-3796875232-1000 -> No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - No File
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {784797A8-342D-4072-9486-03C8D0F2F0A1} hxxp://
www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.203.0.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler: WSWSVCUchrome - No CLSID Value
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VLC\npvlc.dll [2015-04-17] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-11] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1221171.dll [2015-10-19] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2013-07-10] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-14] (NVIDIA Corporation)
FF Plugin-x32: @real.com/nppl3260;version=18.0.1.9 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2015-07-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=18.0.1.9 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2015-07-10] (RealTimes)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-19] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2013-07-10] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdwteff => not found
FF HKLM-x32\...\Firefox\Extensions: [bdwteffv20@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2016\antispam32\bdwteff => not found
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.mysites123.com/?type=hp&ts=1451665643&z=d0a57b8bfc9ac1e6f9fb00cg8zew6g8q7q3w2q7z1c&from=amt&uid=wdcxwd1003fzex-00mk2a0_wd-wcc3fanef9y2ef9y2
CHR StartupUrls: Default -> "hxxps://
www.malwarebytes.org/restorebrowser/"
CHR DefaultSearchURL: Default -> hxxp://mysites123.com/web?type=ds&ts=1451665643&z=d0a57b8bfc9ac1e6f9fb00cg8zew6g8q7q3w2q7z1c&from=amt&uid=wdcxwd1003fzex-00mk2a0_wd-wcc3fanef9y2ef9y2&q={searchTerms}
CHR DefaultSearchKeyword: Default -> mysites123
CHR Profile: C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-23]
CHR Extension: (Google Docs) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-23]
CHR Extension: (Google Drive) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-23]
CHR Extension: (YouTube) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-23]
CHR Extension: (Google Search) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-23]
CHR Extension: (Google Sheets) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-23]
CHR Extension: (Google Docs Offline) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-23]
CHR Extension: (Gmail) - C:\Users\NATHAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-23]
CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [948392 2016-03-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [466408 2016-03-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [466408 2016-03-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1417592 2016-03-12] (Avira Operations GmbH & Co. KG)
R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2016-02-10] (Logitech Inc.)
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [38200 2016-01-04] (The OpenVPN Project)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-02-08] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-04-11] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-12] (TeamViewer GmbH)
R2 Update service; C:\Program Files (x86)\Popcorn Time\Updater.exe [339968 2015-10-19] (Popcorn Time) [File not signed]
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162072 2016-03-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [140448 2016-03-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-02-04] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [75472 2016-03-12] (Avira Operations GmbH & Co. KG)
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [352144 2012-04-09] (EldoS Corporation)
R3 dvdfab; C:\Windows\System32\drivers\dvdfab.sys [79232 2011-08-15] (Fengtao Software Inc.)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-22] (Logitech)
R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-11] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [23040 2014-07-15] (Apple Inc.) [File not signed]
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2015-10-14] (NVIDIA Corporation)
S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39592 2014-12-30] (Razer Inc)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-07-28] (Apple, Inc.) [File not signed]
R3 uvhid; C:\Windows\System32\DRIVERS\uvhid.sys [25592 2015-11-05] (Windows (R) Win 7 DDK provider)
R3 ALSysIO; \??\C:\Users\NATHAN\AppData\Local\Temp\ALSysIO64.sys [X]
S3 b06bdrv; \SystemRoot\system32\DRIVERS\bxvbda.sys [X]
S3 GPU-Z; \??\C:\Users\NATHAN\AppData\Local\Temp\GPU-Z.sys [X]
S0 ignis; system32\DRIVERS\ignis.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-14 22:10 - 2016-03-14 22:10 - 02374144 _____ (Farbar) C:\Users\NATHAN\Downloads\FRST64.exe
2016-03-14 22:10 - 2016-03-14 22:10 - 00111912 _____ C:\Users\NATHAN\AppData\Local\GDIPFONTCACHEV1.DAT
2016-03-14 22:09 - 2016-03-14 22:11 - 00000000 ____D C:\FRST
2016-03-13 11:19 - 2016-03-13 11:37 - 649877504 _____ C:\Users\NATHAN\Downloads\GRMWDK_EN_7600_1.ISO
2016-03-12 13:18 - 2016-03-12 13:21 - 00001584 _____ C:\Users\NATHAN\Desktop\Shutdown - ABORT.lnk
2016-03-12 13:04 - 2016-03-12 13:04 - 00002006 _____ C:\Users\Public\Desktop\Avira Antivirus.lnk
2016-03-12 13:04 - 2016-03-12 13:04 - 00002006 _____ C:\ProgramData\Desktop\Avira Antivirus.lnk
2016-03-12 13:04 - 2016-03-12 13:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-03-12 12:51 - 2016-03-12 12:51 - 00097793 _____ C:\ProgramData\1457747343.bdinstall.bin
2016-03-12 12:45 - 2016-03-12 12:45 - 00059430 _____ C:\ProgramData\1457747071.bdinstall.bin
2016-03-12 12:45 - 2016-03-12 12:45 - 00032576 _____ C:\ProgramData\1457747132.bdinstall.bin
2016-03-12 12:44 - 2016-03-12 12:44 - 00037823 _____ C:\ProgramData\1457747063.bdinstall.bin
2016-03-12 12:42 - 2016-03-12 13:05 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\Avira
2016-03-12 12:38 - 2016-03-12 13:01 - 00000000 ____D C:\ProgramData\Avira
2016-03-12 12:38 - 2016-03-12 12:58 - 00162072 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2016-03-12 12:38 - 2016-03-12 12:58 - 00140448 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2016-03-12 12:38 - 2016-03-12 12:58 - 00075472 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2016-03-12 12:38 - 2016-03-12 12:45 - 00000000 ____D C:\Program Files (x86)\Avira
2016-03-12 12:38 - 2015-02-04 17:51 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2016-03-12 11:47 - 2016-03-12 11:47 - 00000000 ____D C:\Users\NATHAN\AppData\Local\ESET
2016-03-12 11:33 - 2016-03-12 11:33 - 00002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2016-03-12 11:33 - 2016-03-12 11:33 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-03-12 11:33 - 2016-03-12 11:33 - 00000822 _____ C:\ProgramData\Desktop\CCleaner.lnk
2016-03-12 11:33 - 2016-03-12 11:33 - 00000000 ____D C:\Program Files\CCleaner
2016-03-11 22:31 - 2016-03-11 22:31 - 00000000 ____D C:\Users\NATHAN\AppData\Local\3delite
2016-03-11 21:44 - 2016-03-11 21:44 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\Hulubulu
2016-03-11 21:05 - 2016-03-11 21:05 - 00001093 _____ C:\Users\NATHAN\Desktop\Tag&Rename.lnk
2016-03-10 16:14 - 2016-03-12 12:05 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-10 16:13 - 2016-03-11 16:44 - 00001100 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-10 16:13 - 2016-03-11 16:44 - 00001100 _____ C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-10 16:13 - 2016-03-10 16:13 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-10 16:13 - 2016-03-10 16:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-10 16:13 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-10 16:13 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-10 16:13 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-10 16:04 - 2016-03-10 16:04 - 00207822 _____ C:\ProgramData\1457586084.bdinstall.bin
2016-03-10 15:49 - 2016-03-10 15:49 - 00096905 _____ C:\ProgramData\1457585330.bdinstall.bin
2016-03-10 15:48 - 2016-03-10 15:48 - 00037817 _____ C:\ProgramData\1457585328.bdinstall.bin
2016-03-10 15:47 - 2016-03-10 15:47 - 00039980 _____ C:\ProgramData\1457585243.bdinstall.bin
2016-03-10 15:47 - 2016-03-10 15:47 - 00037816 _____ C:\ProgramData\1457585242.bdinstall.bin
2016-03-05 13:28 - 2016-03-11 16:43 - 00001350 _____ C:\Users\NATHAN\Desktop\Kodi.lnk
2016-03-05 11:15 - 2016-03-05 13:40 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\Kodi
2016-03-05 10:51 - 2016-03-05 10:51 - 00000487 _____ C:\Users\NATHAN\Desktop\microsoft word - Can I interact with background software - Super User.website
2016-03-02 18:57 - 2016-03-02 19:06 - 00000282 _____ C:\Users\NATHAN\Desktop\New Windows Batch File.bat
2016-03-02 15:49 - 2016-03-02 15:49 - 00003414 _____ C:\Windows\System32\Tasks\steamwebhelper_killer
2016-03-02 14:12 - 2016-03-02 14:12 - 00000000 ____D C:\ProgramData\KillPing
2016-03-02 14:09 - 2016-03-02 14:09 - 00000000 ____D C:\Users\NATHAN\AppData\Local\IsolatedStorage
2016-03-02 14:09 - 2016-03-02 14:09 - 00000000 ____D C:\ProgramData\Kill Ping
2016-03-02 14:01 - 2016-03-02 15:48 - 00000396 _____ C:\Users\NATHAN\Desktop\Steamwebhlp START.bat
2016-03-02 13:58 - 2016-03-02 14:02 - 131494359 _____ (Realtek Semiconductor Corp.) C:\Users\NATHAN\Downloads\64bit_Win7_Win8_Win81_Win10_R279.exe
2016-03-02 13:06 - 2016-03-02 15:46 - 00002814 _____ C:\Users\NATHAN\Desktop\Steamwebhlp STOP.bat
2016-02-21 22:13 - 2016-02-21 22:13 - 00000000 ____D C:\Users\NATHAN\Documents\Unpark-CPU-App
2016-02-21 22:13 - 2016-02-21 22:13 - 00000000 ____D C:\Program Files (x86)\CPU Core Unparker
2016-02-21 22:03 - 2016-02-21 22:02 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-02-20 20:44 - 2016-03-11 16:43 - 00006139 _____ C:\Users\NATHAN\Desktop\Toggle file extension & hidden files.lnk
2016-02-19 20:09 - 2016-02-19 20:09 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\java
2016-02-19 20:07 - 2016-03-11 16:43 - 00002086 _____ C:\Users\NATHAN\Desktop\FileBot.lnk
2016-02-19 20:07 - 2016-02-19 21:19 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\FileBot
2016-02-19 20:07 - 2016-02-19 20:07 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileBot
2016-02-19 20:06 - 2016-02-19 20:07 - 00000000 ____D C:\Program Files\FileBot
2016-02-17 18:05 - 2016-02-17 18:05 - 00001330 _____ C:\Users\NATHAN\Desktop\Control in Focus in Other Processes - CodeProject.url
2016-02-16 18:24 - 2016-02-16 18:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-14 22:11 - 2016-01-22 17:41 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\uTorrent
2016-03-14 22:05 - 2014-09-29 20:08 - 00000000 ____D C:\Users\NATHAN\Documents\Torrents
2016-03-14 22:01 - 2015-07-10 13:39 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\vlc
2016-03-14 22:01 - 2014-09-27 20:06 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F7C351A0-836F-4A1B-8D62-14BE1D2564EC}
2016-03-14 21:49 - 2015-11-23 22:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-14 21:41 - 2014-09-27 20:16 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-14 19:23 - 2009-07-14 15:45 - 00023584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-14 19:23 - 2009-07-14 15:45 - 00023584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-14 18:57 - 2009-07-14 14:20 - 00000000 ____D C:\Windows\inf
2016-03-14 18:54 - 2016-01-11 19:18 - 00000000 ____D C:\ProgramData\Unified Remote
2016-03-14 18:53 - 2015-12-31 14:37 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-14 18:53 - 2015-11-23 22:33 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-14 18:53 - 2009-07-14 16:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-13 11:08 - 2014-10-05 13:16 - 00000000 ____D C:\Users\NATHAN\Documents\Visual Studio 2013
2016-03-12 21:55 - 2014-11-23 00:05 - 00000000 ____D C:\Users\NATHAN\Documents\ACID Pro 7.0 Projects
2016-03-12 11:49 - 2015-01-11 21:05 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\TS3Client
2016-03-12 11:49 - 2014-11-17 10:35 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-03-12 11:49 - 2014-11-12 18:02 - 00000000 ____D C:\Program Files (x86)\Steam
2016-03-12 11:49 - 2014-09-28 13:49 - 00000000 ____D C:\Windows\Panther
2016-03-12 10:36 - 2014-12-31 21:56 - 00000000 ____D C:\Program Files (x86)\TagRename
2016-03-11 22:24 - 2015-01-11 21:55 - 00001134 _____ C:\Users\NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo.lnk
2016-03-11 21:25 - 2016-01-30 17:50 - 00000000 ____D C:\Users\NATHAN\Desktop\Video
2016-03-11 21:24 - 2015-04-08 23:31 - 00000000 ____D C:\Program Files\MKVToolNix
2016-03-11 21:13 - 2015-04-08 23:31 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\mkvtoolnix
2016-03-11 21:05 - 2014-12-31 21:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tag&Rename
2016-03-11 18:55 - 2014-09-27 20:16 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-03-11 18:55 - 2014-09-27 20:16 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-11 18:55 - 2014-09-27 20:16 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-03-11 17:22 - 2015-11-23 22:34 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-11 16:44 - 2016-01-17 18:22 - 00000946 _____ C:\Users\Public\Desktop\OpenVPN GUI.lnk
2016-03-11 16:44 - 2016-01-17 18:22 - 00000946 _____ C:\ProgramData\Desktop\OpenVPN GUI.lnk
2016-03-11 16:44 - 2016-01-09 18:00 - 00001153 _____ C:\Users\NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2016-03-11 16:44 - 2016-01-09 16:24 - 00001040 _____ C:\Users\Public\Desktop\IntelliJ IDEA Community Edition 15.0.2.lnk
2016-03-11 16:44 - 2016-01-09 16:24 - 00001040 _____ C:\ProgramData\Desktop\IntelliJ IDEA Community Edition 15.0.2.lnk
2016-03-11 16:44 - 2015-12-28 19:28 - 00001329 _____ C:\Users\Public\Desktop\Smartphone Recovery PRO for Android.lnk
2016-03-11 16:44 - 2015-12-28 19:28 - 00001329 _____ C:\ProgramData\Desktop\Smartphone Recovery PRO for Android.lnk
2016-03-11 16:44 - 2015-12-28 19:10 - 00001233 _____ C:\Users\Public\Desktop\FoneLab for Android.lnk
2016-03-11 16:44 - 2015-12-28 19:10 - 00001233 _____ C:\ProgramData\Desktop\FoneLab for Android.lnk
2016-03-11 16:44 - 2015-12-23 18:38 - 00002121 _____ C:\Users\Public\Desktop\Smart Switch.lnk
2016-03-11 16:44 - 2015-12-23 18:38 - 00002121 _____ C:\ProgramData\Desktop\Smart Switch.lnk
2016-03-11 16:44 - 2015-12-06 14:00 - 00001176 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2016-03-11 16:44 - 2015-12-06 14:00 - 00001170 _____ C:\Users\Public\Desktop\paint.net.lnk
2016-03-11 16:44 - 2015-12-06 14:00 - 00001170 _____ C:\ProgramData\Desktop\paint.net.lnk
2016-03-11 16:44 - 2015-11-08 17:19 - 00001096 _____ C:\Users\Public\Desktop\Unified Remote.lnk
2016-03-11 16:44 - 2015-11-08 17:19 - 00001096 _____ C:\ProgramData\Desktop\Unified Remote.lnk
2016-03-11 16:44 - 2015-11-01 12:36 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-11 16:44 - 2015-10-17 09:43 - 00001029 _____ C:\Users\Public\Desktop\AusLogics BoostSpeed.lnk
2016-03-11 16:44 - 2015-10-17 09:43 - 00001029 _____ C:\ProgramData\Desktop\AusLogics BoostSpeed.lnk
2016-03-11 16:44 - 2015-07-13 10:58 - 00001982 _____ C:\Users\NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2.lnk
2016-03-11 16:44 - 2015-07-11 08:10 - 00001353 _____ C:\Users\Public\Desktop\Renegade X.lnk
2016-03-11 16:44 - 2015-07-11 08:10 - 00001353 _____ C:\ProgramData\Desktop\Renegade X.lnk
2016-03-11 16:44 - 2015-07-10 13:39 - 00000891 _____ C:\Users\Public\Desktop\VLC.lnk
2016-03-11 16:44 - 2015-07-10 13:39 - 00000891 _____ C:\ProgramData\Desktop\VLC.lnk
2016-03-11 16:44 - 2015-06-08 19:32 - 00000971 _____ C:\Users\Public\Desktop\Fraps.lnk
2016-03-11 16:44 - 2015-06-08 19:32 - 00000971 _____ C:\ProgramData\Desktop\Fraps.lnk
2016-03-11 16:44 - 2015-01-11 21:05 - 00001005 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-03-11 16:44 - 2015-01-11 21:05 - 00001005 _____ C:\ProgramData\Desktop\TeamSpeak 3 Client.lnk
2016-03-11 16:44 - 2014-12-23 09:04 - 00001068 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk
2016-03-11 16:44 - 2014-12-23 09:04 - 00001068 _____ C:\ProgramData\Desktop\Virtual CloneDrive.lnk
2016-03-11 16:44 - 2014-11-29 16:03 - 00000856 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VidCoder.lnk
2016-03-11 16:44 - 2014-11-17 10:35 - 00000959 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2016-03-11 16:44 - 2014-11-17 10:35 - 00000953 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2016-03-11 16:44 - 2014-11-17 10:35 - 00000953 _____ C:\ProgramData\Desktop\TeamViewer 10.lnk
2016-03-11 16:44 - 2014-11-12 18:02 - 00000961 _____ C:\Users\Public\Desktop\Steam.lnk
2016-03-11 16:44 - 2014-11-12 18:02 - 00000961 _____ C:\ProgramData\Desktop\Steam.lnk
2016-03-11 16:44 - 2014-10-05 12:46 - 00002047 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
2016-03-11 16:44 - 2014-09-27 20:05 - 00001393 _____ C:\Users\NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-11 16:44 - 2014-09-27 19:53 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-03-11 16:44 - 2009-07-14 15:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
2016-03-11 16:44 - 2009-07-14 15:57 - 00001318 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-03-11 16:44 - 2009-07-14 15:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-03-11 16:44 - 2009-07-14 15:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-03-11 16:43 - 2016-02-10 21:17 - 00001945 _____ C:\Users\NATHAN\Desktop\Loudness EQ - Off.lnk
2016-03-11 16:43 - 2016-02-10 21:17 - 00001940 _____ C:\Users\NATHAN\Desktop\Loudness EQ - On.lnk
2016-03-11 16:43 - 2016-02-01 20:58 - 00001049 _____ C:\Users\NATHAN\Desktop\Clipdiary.lnk
2016-03-11 16:43 - 2016-01-31 19:55 - 00000885 _____ C:\Users\NATHAN\Desktop\Template.ahk.lnk
2016-03-11 16:43 - 2016-01-30 18:13 - 00002571 _____ C:\Users\NATHAN\Desktop\Restart Core Temp.lnk
2016-03-11 16:43 - 2016-01-30 18:09 - 00002648 _____ C:\Users\NATHAN\Desktop\Restart Audio Switcher.lnk
2016-03-11 16:43 - 2016-01-30 17:49 - 00001728 _____ C:\Users\NATHAN\Desktop\# FIXES.lnk
2016-03-11 16:43 - 2016-01-30 17:01 - 00001513 _____ C:\Users\NATHAN\Desktop\LCore.lnk
2016-03-11 16:43 - 2016-01-30 16:59 - 00001825 _____ C:\Users\NATHAN\Desktop\End CSGO, Steam, start uTorrent).lnk
2016-03-11 16:43 - 2016-01-27 22:43 - 00001228 _____ C:\Users\NATHAN\Desktop\Local.lnk
2016-03-11 16:43 - 2016-01-27 22:12 - 00013053 _____ C:\Users\NATHAN\Desktop\Volume.lnk
2016-03-11 16:43 - 2016-01-19 12:44 - 00001610 _____ C:\Users\NATHAN\Desktop\Kill AutoHotKey.lnk
2016-03-11 16:43 - 2016-01-19 12:15 - 00004267 _____ C:\Users\NATHAN\Desktop\Change Case.lnk
2016-03-11 16:43 - 2016-01-19 11:58 - 00001435 _____ C:\Users\NATHAN\Desktop\AutoHotkeyU64.lnk
2016-03-11 16:43 - 2016-01-19 11:56 - 00001379 _____ C:\Users\NATHAN\Desktop\AU3_Spy.lnk
2016-03-11 16:43 - 2016-01-18 15:44 - 00002057 _____ C:\Users\NATHAN\Desktop\Display Switch.lnk
2016-03-11 16:43 - 2016-01-09 18:00 - 00001147 _____ C:\Users\NATHAN\Desktop\Start Tor Browser.lnk
2016-03-11 16:43 - 2015-12-26 23:13 - 00001212 _____ C:\Users\NATHAN\Desktop\Calculator.lnk
2016-03-11 16:43 - 2015-12-22 19:06 - 00001484 _____ C:\Users\NATHAN\Desktop\Examples.lnk
2016-03-11 16:43 - 2015-12-08 23:15 - 00001573 _____ C:\Users\NATHAN\Desktop\A1.lnk
2016-03-11 16:43 - 2015-12-03 21:28 - 00001720 _____ C:\Users\NATHAN\Desktop\autoexec.cfg.lnk
2016-03-11 16:43 - 2015-10-12 21:29 - 00002737 _____ C:\Users\NATHAN\Desktop\CSGO (Batch - Kill uTorrent, start CSGO).lnk
2016-03-11 16:43 - 2015-07-25 19:50 - 00001776 _____ C:\Users\NATHAN\Desktop\RegJump (registry path direct access).lnk
2016-03-11 16:43 - 2015-07-25 18:09 - 00013171 _____ C:\Users\NATHAN\Desktop\IExpress.lnk
2016-03-11 16:43 - 2015-07-25 16:41 - 00001042 _____ C:\Users\NATHAN\Desktop\Folder Size.lnk
2016-03-11 16:43 - 2015-07-13 10:58 - 00001976 _____ C:\Users\NATHAN\Desktop\PlanetSide 2.lnk
2016-03-11 16:43 - 2015-06-25 16:32 - 00001134 _____ C:\Users\NATHAN\Desktop\Documents.lnk
2016-03-11 16:43 - 2015-05-09 15:16 - 00002599 _____ C:\Users\NATHAN\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-03-11 16:43 - 2015-05-06 16:39 - 00001154 _____ C:\Users\NATHAN\Desktop\Doomsday Engine.lnk
2016-03-11 16:43 - 2015-05-06 16:39 - 00001123 _____ C:\Users\NATHAN\Desktop\Doomsday Shell.lnk
2016-03-11 16:43 - 2015-03-29 10:31 - 00001784 _____ C:\Users\NATHAN\Desktop\Restart Ethernet Driver.lnk
2016-03-11 16:43 - 2015-02-01 16:17 - 00001249 _____ C:\Users\NATHAN\Desktop\Task Manager.lnk
2016-03-11 16:43 - 2014-12-31 21:56 - 00001093 _____ C:\Users\NATHAN\Desktop\Tag & Rename.lnk
2016-03-11 16:43 - 2014-12-27 14:42 - 00001251 _____ C:\Users\NATHAN\Desktop\Clear Clipboard.lnk
2016-03-11 16:43 - 2014-12-23 10:42 - 00001616 _____ C:\Users\NATHAN\Desktop\WINWORD.lnk
2016-03-11 16:43 - 2014-12-23 10:42 - 00001596 _____ C:\Users\NATHAN\Desktop\EXCEL.lnk
2016-03-11 16:43 - 2014-11-29 12:26 - 00000940 _____ C:\Users\NATHAN\Desktop\complete.lnk
2016-03-11 16:43 - 2014-10-21 17:35 - 00001337 _____ C:\Users\NATHAN\Desktop\SoulseekQt.lnk
2016-03-11 16:43 - 2014-10-17 17:42 - 00002172 _____ C:\Users\NATHAN\Desktop\Lock (Win+L).lnk
2016-03-11 16:43 - 2014-10-14 07:32 - 00001792 _____ C:\Users\NATHAN\Desktop\Torrents.lnk
2016-03-11 16:43 - 2014-10-04 22:52 - 00001783 _____ C:\Users\NATHAN\Desktop\MFR.lnk
2016-03-11 16:43 - 2014-10-03 18:09 - 00001089 _____ C:\Users\NATHAN\Desktop\Cheat Engine.lnk
2016-03-11 16:43 - 2014-09-28 12:46 - 00001224 _____ C:\Users\NATHAN\Desktop\Paint.lnk
2016-03-11 16:43 - 2014-09-27 20:05 - 00000853 _____ C:\Users\NATHAN\Desktop\Downloads.lnk
2016-03-11 16:43 - 2009-07-14 16:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-03-11 16:43 - 2009-07-14 15:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-03-10 17:22 - 2016-01-02 03:40 - 00000000 ____D C:\Users\NATHAN\AppData\LocalLow\Company
2016-03-10 16:06 - 2009-07-14 16:08 - 00032586 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-03-10 16:02 - 2014-09-29 21:20 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\QuickScan
2016-03-06 19:36 - 2009-07-14 16:13 - 00786598 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-05 12:05 - 2016-01-08 23:34 - 00000232 _____ C:\Windows\SysWOW64\RfmDat2.dat
2016-03-05 11:15 - 2014-10-05 12:48 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-05 11:14 - 2015-12-06 16:21 - 00000000 ____D C:\Program Files (x86)\Kodi
2016-03-02 17:17 - 2015-06-09 16:22 - 00000000 ____D C:\Users\NATHAN\AppData\Local\Steam
2016-03-02 13:55 - 2014-09-28 15:11 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-02 13:55 - 2014-09-28 15:11 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-02 13:55 - 2014-09-28 15:10 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-02 13:54 - 2016-01-01 14:24 - 00000000 ____D C:\Users\NATHAN\AppData\Local\NVIDIA Corporation
2016-03-02 13:54 - 2015-12-31 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-02-24 16:36 - 2015-06-08 19:32 - 00000000 ____D C:\Program Files (x86)\Fraps
2016-02-21 22:06 - 2016-01-09 16:33 - 00000000 ____D C:\Program Files\Java
2016-02-21 22:06 - 2015-07-18 19:57 - 00000000 ____D C:\ProgramData\Oracle
2016-02-21 22:05 - 2016-01-09 16:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-02-21 22:05 - 2015-10-31 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-21 22:05 - 2015-07-18 19:57 - 00000000 ____D C:\Program Files (x86)\Java
2016-02-21 22:03 - 2015-08-31 12:06 - 00000000 ____D C:\Users\NATHAN\.oracle_jre_usage
2016-02-20 21:19 - 2015-06-25 06:19 - 00000000 ____D C:\Users\NATHAN\AppData\Roaming\Skype
2016-02-16 18:27 - 2015-02-10 20:06 - 00000000 ____D C:\Program Files\Logitech Gaming Software
==================== Files in the root of some directories =======
2016-01-18 15:24 - 2016-01-18 15:46 - 0013819 _____ () C:\Users\NATHAN\AppData\Roaming\PStrip.ini
2015-10-16 15:45 - 2015-10-16 15:45 - 0007604 _____ () C:\Users\NATHAN\AppData\Local\Resmon.ResmonCfg
2016-01-06 19:33 - 2016-01-06 19:33 - 0447324 _____ () C:\ProgramData\1452068835.bdinstall.bin
2016-01-06 20:03 - 2016-01-06 20:03 - 0025194 _____ () C:\ProgramData\1452070893.bdinstall.bin
2016-01-08 22:20 - 2016-01-08 22:20 - 0019272 _____ () C:\ProgramData\1452251995.bdinstall.bin
2016-01-08 22:24 - 2016-01-08 22:24 - 0019272 _____ () C:\ProgramData\1452252264.bdinstall.bin
2016-01-08 22:53 - 2016-01-08 22:53 - 0220356 _____ () C:\ProgramData\1452253623.bdinstall.bin
2016-01-18 14:51 - 2016-01-18 14:51 - 0037823 _____ () C:\ProgramData\1453089098.bdinstall.bin
2016-01-18 14:52 - 2016-01-18 14:52 - 0175479 _____ () C:\ProgramData\1453089101.bdinstall.bin
2016-01-18 17:24 - 2016-01-18 17:24 - 0037839 _____ () C:\ProgramData\1453098254.bdinstall.bin
2016-01-18 17:24 - 2016-01-18 17:24 - 0174283 _____ () C:\ProgramData\1453098260.bdinstall.bin
2016-03-10 15:47 - 2016-03-10 15:47 - 0037816 _____ () C:\ProgramData\1457585242.bdinstall.bin
2016-03-10 15:47 - 2016-03-10 15:47 - 0039980 _____ () C:\ProgramData\1457585243.bdinstall.bin
2016-03-10 15:48 - 2016-03-10 15:48 - 0037817 _____ () C:\ProgramData\1457585328.bdinstall.bin
2016-03-10 15:49 - 2016-03-10 15:49 - 0096905 _____ () C:\ProgramData\1457585330.bdinstall.bin
2016-03-10 16:04 - 2016-03-10 16:04 - 0207822 _____ () C:\ProgramData\1457586084.bdinstall.bin
2016-03-12 12:44 - 2016-03-12 12:44 - 0037823 _____ () C:\ProgramData\1457747063.bdinstall.bin
2016-03-12 12:45 - 2016-03-12 12:45 - 0059430 _____ () C:\ProgramData\1457747071.bdinstall.bin
2016-03-12 12:45 - 2016-03-12 12:45 - 0032576 _____ () C:\ProgramData\1457747132.bdinstall.bin
2016-03-12 12:51 - 2016-03-12 12:51 - 0097793 _____ () C:\ProgramData\1457747343.bdinstall.bin
2014-12-23 19:25 - 2014-12-23 19:25 - 0000000 _____ () C:\ProgramData\New Text Document.txt
Some files in TEMP:
====================
C:\Users\NATHAN\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-09 00:53
==================== End of FRST.txt ============================