TechSpot

Virus stops IE, Opera and Safari connecting to web

By ppiper
Mar 31, 2016
  1. Hi,
    only firefox connects to the internet, I have done a virus check but none found. I think that registry is problem.
    (Windows 7 64 all latest browsers)
    Any help really welcome
    Thanks
    Peter
     
  2. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Welcome aboard [​IMG]

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     
  3. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi,
    I Had to disable AVG so FARBAR would work.
    have been getting cannot connect to update server from both AVG and flash player.
    here is FRST.txt
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
    Ran by a (administrator) on A-PC (01-04-2016 12:59:07)
    Running from C:\Users\a\Downloads
    Loaded Profiles: a (Available Profiles: a)
    Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
    (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
    (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
    (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
    (Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
    (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2730616 2015-09-28] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] => C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
    HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1136552 2015-11-12] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3855272 2015-11-20] (AVG Technologies CZ, s.r.o.)
    Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation)
    ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
    ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
    ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
    ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2010-02-10] (Autodesk, Inc.)
    ShellIconOverlayIdentifiers-x32: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\SysWOW64\AcSignIcon.dll [2007-02-13] (Autodesk, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EasySetPackage.lnk [2015-08-25]
    ShortcutTarget: EasySetPackage.lnk -> C:\Program Files (x86)\LG Soft India\EasySetPackage\bin\EasySetPackage.exe ()

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Winsock: Catalog5-x64 01 C:\Windows\System32\mswsock.dll [327168 2013-09-08] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{5F96EEFF-043E-470A-85AA-1D0C59A2263E}: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{8B3C0D3D-5D5F-4D8A-BB9A-18A93E642CB3}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{A66457FB-76D7-44A4-BFA0-D4C23D5733A4}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
    BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll [2010-04-28] (Microsoft Corporation)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
    BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
    BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
    BHO-x32: ContributeBHO Class -> {074C1DC5-9320-4A9A-947D-C042949C6216} -> C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27] (Adobe Systems, Inc.)
    BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-08] (Oracle Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
    BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-08] (Oracle Corporation)
    BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
    Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27] (Adobe Systems, Inc.)
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
    Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
    Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

    FireFox:
    ========
    FF ProfilePath: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\ijupd536.default-1430291221738
    FF DefaultSearchEngine: DuckDuckGo
    FF Homepage: about:home
    FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-29] ()
    FF Plugin: @microsoft.com/GENUINE -> C:\windows\system32\Wat\npWatWeb.dll [2010-12-26] (Microsoft Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-11-05] (Adobe Systems)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-29] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
    FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-08] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-08] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> C:\windows\system32\Wat\npWatWeb.dll [2010-12-26] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
    FF Plugin-x32: @rooms.hp.com -> C:\Program Files (x86)\Hewlett-Packard\HP Virutal Rooms Client Launcher Plugin\nphpvrl.dll [2011-03-29] ( )
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
    FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.5 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2010-09-02] (Wacom, Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-09-12] (Adobe Systems Inc.)
    FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-11-05] (Adobe Systems)
    FF Plugin-x32: nuance.com/DragonRIAPlugin -> C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\npDgnRia.dll [2012-07-18] (Nuance Communications Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll [2010-03-27] (Adobe Systems, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2013-05-18] (Apple Inc.)
    FF Extension: Adblock Plus - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\ijupd536.default-1430291221738\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-03-09]
    FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-03-06] [not signed]
    FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-03-06] [not signed]
    FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} [2016-03-06] [not signed]
    FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-19] [not signed]
    FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-03-06] [not signed]
    FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
    FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-06] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
    FF Extension: Adobe Contribute Toolbar - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2008-09-06] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi
    FF Extension: Dragon NaturallySpeaking Rich Internet Application Support - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi [2012-07-18] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
    FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-02-17] [not signed]

    Chrome:
    =======
    CHR HKU\S-1-5-21-522234228-4192544273-3428825822-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
    CHR HKLM-x32\...\Chrome\Extension: [mikhcaiakabeeokmenglcdebplfdjicn] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\chromeShim.crx [2012-07-18]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [85096 2011-02-07] (Autodesk)
    S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3857272 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1046952 2015-11-12] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [579776 2015-11-20] (AVG Technologies CZ, s.r.o.)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
    S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2010-12-26] (Macrovision Europe Ltd.) [File not signed]
    R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-09-28] (NVIDIA Corporation)
    S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
    R2 nlsX86cc; C:\windows\SysWOW64\nlssrv32.exe [66560 2011-12-19] (Nalpeiron Ltd.) [File not signed]
    R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-09-28] (NVIDIA Corporation)
    R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568632 2015-09-28] (NVIDIA Corporation)
    R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2266160 2016-03-03] (IBM Corp.)
    S4 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] () [File not signed]
    S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
    R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2015-01-06] (Samsung Electronics CO., LTD.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313776 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [256432 2015-11-06] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-08-10] (AVG Technologies CZ, s.r.o.)
    S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    S3 LGDDCDevice; C:\windows\SysWOW64\LGI2CDriver.sys [16384 2009-12-22] (LG Soft India) [File not signed]
    S3 LGII2CDevice; C:\windows\SysWOW64\LGPII2CDriver.sys [19456 2009-12-22] (LG Soft India) [File not signed]
    S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [40904 2010-02-17] (McAfee, Inc.)
    S3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [49480 2010-02-17] (McAfee, Inc.)
    R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-09-28] (NVIDIA Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
    R1 RapportCerberus_1507082; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys [972896 2016-03-07] (IBM Corp.)
    R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [514336 2016-03-03] (IBM Corp.)
    R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [152320 2016-03-03] (IBM Corp.)
    R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [407168 2016-03-03] (IBM Corp.)
    R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [507424 2016-03-03] (IBM Corp.)
    S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-09-17] (Windows (R) 2003 DDK 3790 provider)
    U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2015-05-25] (Seiko Epson Corporation)
    R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [X]
    S4 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S4 tsusbhub; system32\drivers\tsusbhub.sys [X]
    S4 VGPU; System32\drivers\rdvgkmd.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-04-01 12:59 - 2016-04-01 13:05 - 00024586 _____ C:\Users\a\Downloads\FRST.txt
    2016-04-01 12:48 - 2016-04-01 12:59 - 00000000 ____D C:\FRST
    2016-04-01 11:11 - 2016-04-01 11:11 - 00000000 ____D C:\Program Files\Common Files\AV
    2016-04-01 11:10 - 2016-04-01 11:10 - 00000936 _____ C:\Users\Public\Desktop\AVG Protection.lnk
    2016-04-01 11:10 - 2016-04-01 11:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2016-04-01 11:06 - 2016-04-01 11:06 - 00000000 ___HD C:\$AVG
    2016-04-01 10:32 - 2016-04-01 10:32 - 02374144 _____ (Farbar) C:\Users\a\Downloads\FRST64.exe
    2016-04-01 10:29 - 2016-04-01 10:57 - 240607256 _____ (AVG Technologies CZ, s.r.o.) C:\Users\a\Downloads\AVG_Internet_Security_x64_696.exe
    2016-03-31 16:31 - 2016-03-31 16:31 - 00024136 _____ C:\ComboFix.txt
    2016-03-31 15:32 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe
    2016-03-31 15:32 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe
    2016-03-31 15:32 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe
    2016-03-31 15:31 - 2016-03-31 16:32 - 00000000 ____D C:\Qoobox
    2016-03-31 15:29 - 2016-03-31 16:22 - 00000000 ____D C:\windows\erdnt
    2016-03-31 14:47 - 2016-03-31 14:47 - 00002060 _____ C:\Users\a\Desktop\aswMBR.txt
    2016-03-31 14:47 - 2016-03-31 14:47 - 00000512 _____ C:\Users\a\Desktop\MBR.dat
    2016-03-31 14:41 - 2016-03-31 14:56 - 05659241 ____R (Swearware) C:\Users\a\Desktop\ComboFix.exe
    2016-03-31 14:40 - 2016-03-31 14:42 - 05198336 _____ (AVAST Software) C:\Users\a\Desktop\aswMBR.exe
    2016-03-31 14:27 - 2016-03-31 14:36 - 00000000 ____D C:\Users\a\Desktop\destop_shortcuts
    2016-03-31 14:26 - 2016-03-31 14:26 - 00000000 ____D C:\Users\a\Desktop\cards_etc
    2016-03-31 12:45 - 2016-03-31 12:32 - 00688992 _____ (Swearware) C:\Users\a\Desktop\dds.scr
    2016-03-31 12:32 - 2016-03-31 12:32 - 00688992 _____ (Swearware) C:\Users\a\Downloads\dds.scr
    2016-03-29 22:43 - 2016-03-29 22:43 - 00000000 ____D C:\Users\a\Downloads\backups
    2016-03-29 22:24 - 2016-03-29 22:25 - 00388608 _____ (Trend Micro Inc.) C:\Users\a\Downloads\HijackThis.exe
    2016-03-29 21:58 - 2016-03-29 21:58 - 00003820 _____ C:\windows\System32\Tasks\Opera scheduled Autoupdate 1459285081
    2016-03-29 21:58 - 2016-03-29 21:58 - 00001135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
    2016-03-29 21:58 - 2016-03-29 21:58 - 00000000 ____D C:\Users\a\AppData\Roaming\Opera Software
    2016-03-29 21:58 - 2016-03-29 21:58 - 00000000 ____D C:\Users\a\AppData\Local\Opera Software
    2016-03-29 21:57 - 2016-03-31 21:58 - 00000000 ____D C:\Program Files (x86)\Opera
    2016-03-29 21:47 - 2016-03-29 21:56 - 37696232 _____ (Opera Software) C:\Users\a\Downloads\Opera_36.0.2130.32_Setup.exe
    2016-03-29 21:45 - 2016-03-29 21:46 - 00724888 _____ (Opera Software) C:\Users\a\Downloads\OperaSetup.exe
    2016-03-29 20:43 - 2016-03-29 20:53 - 19904704 _____ (Adobe Systems Incorporated) C:\Users\a\Downloads\install_flash_player(2).exe
    2016-03-21 11:31 - 2016-03-30 02:21 - 00000000 ____D C:\Program Files (x86)\EPUB File Reader
    2016-03-21 11:31 - 2016-03-21 11:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPUB File Reader
    2016-03-20 11:17 - 2016-03-20 12:23 - 00000000 ____D C:\Users\Public\Downloads\Badens
    2016-03-17 19:08 - 2016-03-17 19:09 - 02606578 _____ C:\Users\a\Downloads\DDLValley.cool_G-e-n-I-u-s-_-I-n-t-e-l-l-I-g-e-n-c-e-.pdf
    2016-03-13 11:49 - 2016-03-13 12:02 - 29312924 _____ C:\Users\a\Downloads\DDLValley.cool_N.Sc-12.M.2016.pdf
    2016-03-10 20:03 - 2016-03-10 20:03 - 00574158 _____ C:\Users\Public\Downloads\iexplorer.reg
    2016-03-10 00:01 - 2016-03-10 00:01 - 00001413 _____ C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2016-03-09 23:30 - 2016-03-09 23:46 - 55915216 _____ (Microsoft Corporation) C:\Users\a\Downloads\IE11-Windows6.1-x64-en-us.exe
    2016-03-09 23:28 - 2016-03-09 23:29 - 02077392 _____ (Microsoft Corporation) C:\Users\a\Downloads\IE11-Windows6.1.exe
    2016-03-09 21:45 - 2016-03-09 22:47 - 00000000 ____D C:\windows\Panther
    2016-03-08 20:44 - 2016-04-01 03:50 - 00000000 ____D C:\Program Files\Mozilla Firefox
    2016-03-08 18:55 - 2016-03-08 18:55 - 00328409 _____ C:\Users\a\AppData\Local\census.cache
    2016-03-08 18:55 - 2016-03-08 18:55 - 00185089 _____ C:\Users\a\AppData\Local\ars.cache
    2016-03-08 17:44 - 2016-03-08 17:45 - 02405672 _____ (Trend Micro Inc.) C:\Users\a\Downloads\HousecallLauncher64(1).exe
    2016-03-08 17:30 - 2016-03-08 17:37 - 47521472 _____ C:\Users\Public\Downloads\Firefox Setup 43.0.1.exe
    2016-03-08 16:58 - 2016-03-08 16:58 - 00987728 _____ (Google Inc.) C:\Users\Public\Downloads\ChromeSetup.exe
    2016-03-08 16:30 - 2016-03-08 16:34 - 58082952 _____ (Microsoft Corporation) C:\Users\Public\Downloads\EIE11_EN-US_MCM_WIN764.EXE
    2016-03-08 14:22 - 2016-03-08 16:00 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
    2016-03-08 14:20 - 2016-03-08 14:21 - 01524224 _____ C:\Users\a\Downloads\adwcleaner_5.101.exe
    2016-03-08 13:54 - 2016-03-08 16:00 - 00000000 ____D C:\Users\a\AppData\LocalLow\Adblock Plus for IE
    2016-03-08 13:54 - 2016-03-08 16:00 - 00000000 ____D C:\Program Files\Adblock Plus for IE
    2016-03-08 13:50 - 2016-03-08 13:52 - 06468104 _____ ( ) C:\Users\a\Downloads\adblockplusie-1.5.exe
    2016-03-07 17:17 - 2016-03-07 17:17 - 00000000 ____D C:\Users\Public\Downloads\FL studio tutorial by lynda.com
    2016-03-07 17:10 - 2016-03-07 17:11 - 00000000 ____D C:\Users\Public\Downloads\melodyne_tut
    2016-03-06 22:09 - 2016-03-07 12:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2016-03-06 11:15 - 2016-03-06 11:24 - 28623077 _____ C:\Users\a\Downloads\DDLValley.cool_New_Scientist_-_5_March_2016-P2P.pdf

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-04-01 12:45 - 2013-02-09 19:08 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    2016-04-01 12:19 - 2012-03-15 21:09 - 00000000 ____D C:\ProgramData\MFAData
    2016-04-01 11:12 - 2015-06-02 13:27 - 00000000 ____D C:\Users\a\AppData\Local\Avg
    2016-04-01 11:06 - 2015-07-14 18:24 - 00000000 ____D C:\ProgramData\AVG
    2016-04-01 11:01 - 2015-10-23 14:02 - 00000000 ____D C:\Users\a\AppData\Local\AvgSetupLog
    2016-04-01 11:01 - 2012-03-15 21:19 - 00000000 ____D C:\Program Files (x86)\AVG
    2016-04-01 08:57 - 2009-07-14 05:45 - 00029264 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-04-01 08:57 - 2009-07-14 05:45 - 00029264 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-03-31 19:44 - 2013-02-09 19:08 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    2016-03-31 16:31 - 2013-01-09 17:46 - 00000000 ____D C:\Users\systemprofile
    2016-03-31 16:19 - 2009-07-14 06:13 - 00801128 _____ C:\windows\system32\PerfStringBackup.INI
    2016-03-31 16:19 - 2009-07-14 04:20 - 00000000 ____D C:\windows\inf
    2016-03-31 16:16 - 2009-07-14 03:34 - 00000215 _____ C:\windows\system.ini
    2016-03-31 16:15 - 2015-06-20 16:54 - 00000419 _____ C:\windows\BRWMARK.INI
    2016-03-31 16:15 - 2015-06-20 16:54 - 00000027 _____ C:\windows\BRPP2KA.INI
    2016-03-31 16:11 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
    2016-03-31 14:25 - 2013-02-10 13:05 - 00000000 ____D C:\Users\a\Desktop\desktop_folders
    2016-03-30 02:21 - 2015-04-07 10:00 - 00000000 ___SD C:\windows\system32\GWX
    2016-03-30 02:21 - 2013-10-11 12:33 - 00000000 ____D C:\Users\a\AppData\Roaming\Azureus
    2016-03-30 02:21 - 2012-07-17 16:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2016-03-30 02:21 - 2009-07-14 04:20 - 00000000 ____D C:\windows\registration
    2016-03-29 22:44 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\NDF
    2016-03-29 22:07 - 2011-03-20 08:38 - 00000000 ____D C:\Users\a\AppData\Local\ElevatedDiagnostics
    2016-03-29 21:38 - 2015-07-14 19:47 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
    2016-03-29 20:54 - 2015-07-14 19:47 - 00003770 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
    2016-03-29 20:54 - 2015-04-03 16:26 - 00797376 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
    2016-03-29 20:54 - 2015-04-03 16:26 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-03-29 18:43 - 2015-03-12 19:28 - 00000000 ____D C:\Users\a\AppData\Local\CrashDumps
    2016-03-29 18:27 - 2010-12-24 20:53 - 00000000 ____D C:\Users\a
    2016-03-13 11:27 - 2015-03-01 16:41 - 00000000 ____D C:\Users\a\AppData\Roaming\tox
    2016-03-09 21:36 - 2013-02-09 19:08 - 00000000 ____D C:\Program Files (x86)\Google
    2016-03-09 21:36 - 2013-01-21 18:07 - 00000000 ____D C:\Users\a\AppData\Local\Google
    2016-03-09 20:04 - 2013-10-11 12:33 - 00000000 ____D C:\Users\a\Documents\Vuze Downloads
    2016-03-09 15:19 - 2010-12-28 02:31 - 00000000 ____D C:\Users\a\AppData\Roaming\vlc
    2016-03-08 17:43 - 2012-07-17 16:53 - 00000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2016-03-08 16:00 - 2014-12-30 22:49 - 00000000 ____D C:\windows\system32\appraiser
    2016-03-08 16:00 - 2014-05-03 10:10 - 00000000 ___SD C:\windows\system32\CompatTel
    2016-03-08 16:00 - 2010-08-04 03:40 - 00000000 ____D C:\ProgramData\WinClon
    2016-03-07 18:31 - 2010-12-24 20:54 - 00000000 ____D C:\Users\a\AppData\Local\Adobe
    2016-03-07 14:40 - 2013-09-13 17:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
    2016-03-03 12:19 - 2015-06-11 19:33 - 00152320 _____ (IBM Corp.) C:\windows\system32\Drivers\RapportHades64.sys
    2016-03-03 12:19 - 2012-02-04 17:08 - 00407168 _____ (IBM Corp.) C:\windows\system32\Drivers\RapportKE64.sys
    2016-03-02 15:55 - 2016-01-29 11:45 - 00000000 ____D C:\Users\a\Desktop\melodyne_tut

    ==================== Files in the root of some directories =======

    2011-12-14 18:29 - 2011-12-14 18:29 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe BMP Format CS5 Prefs
    2011-02-28 18:07 - 2013-05-22 16:30 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2013-02-27 15:46 - 2016-01-06 13:34 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe PNG Format CS6 Prefs
    2011-08-06 16:13 - 2011-08-06 16:17 - 7140618 _____ () C:\Users\a\AppData\Roaming\bppenu11.log
    2011-04-08 14:32 - 2011-04-08 14:32 - 0000000 _____ () C:\Users\a\AppData\Roaming\chrtmp
    2013-03-17 12:53 - 2013-04-20 17:02 - 0000268 ___RH () C:\Users\a\AppData\Roaming\Image Manipulation
    2010-12-27 20:47 - 2013-01-18 11:43 - 0002315 _____ () C:\Users\a\AppData\Roaming\SAS7_000.DAT
    2009-02-15 01:25 - 2009-02-15 01:25 - 0690176 _____ (Tensons Corporation) C:\Users\a\AppData\Roaming\Website Ripper Copier.exe
    2011-06-02 13:23 - 2011-09-05 15:33 - 0001456 _____ () C:\Users\a\AppData\Local\Adobe Save for Web 12.0 Prefs
    2016-03-08 18:55 - 2016-03-08 18:55 - 0185089 _____ () C:\Users\a\AppData\Local\ars.cache
    2016-03-08 18:55 - 2016-03-08 18:55 - 0328409 _____ () C:\Users\a\AppData\Local\census.cache
    2010-12-28 21:50 - 2010-12-28 21:50 - 0003584 _____ () C:\Users\a\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2008-09-03 16:10 - 2008-09-03 16:10 - 0000036 _____ () C:\Users\a\AppData\Local\housecall.guid.cache
    2015-08-14 15:44 - 2015-08-14 15:49 - 0000528 _____ () C:\Users\a\AppData\Local\Player.ini
    2015-02-11 10:31 - 2015-08-15 12:01 - 0007634 _____ () C:\Users\a\AppData\Local\Resmon.ResmonCfg
    2011-09-15 16:17 - 2011-09-15 16:17 - 0000096 ____H () C:\Users\a\AppData\Local\vwr_lic_p.dat
    2010-12-24 20:55 - 2010-01-16 08:18 - 0131368 _____ () C:\ProgramData\FullRemove.exe
    2013-03-17 12:53 - 2013-04-20 17:02 - 0000268 ___RH () C:\ProgramData\InkjetPrinter
    2013-03-17 12:53 - 2013-04-20 17:02 - 0000012 ___RH () C:\ProgramData\Keyboard Layouts
    2010-12-27 00:59 - 2013-12-06 17:42 - 0000020 ____H () C:\ProgramData\PKP_DLdy.DAT
    2010-12-26 19:18 - 2015-02-15 12:05 - 0000020 ____H () C:\ProgramData\PKP_DLea.DAT
    2013-03-17 14:39 - 2013-03-17 15:05 - 0000000 ____H () C:\ProgramData\PKP_DLeh.DAT
    2010-08-04 03:37 - 2010-08-04 03:37 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
    2010-08-04 03:35 - 2010-08-04 03:36 - 0000106 _____ () C:\ProgramData\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.log
    2010-08-04 03:32 - 2010-08-04 03:33 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2010-08-04 03:36 - 2010-08-04 03:37 - 0000110 _____ () C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log
    2010-08-04 03:31 - 2010-08-04 03:32 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
    2010-08-04 03:33 - 2010-08-04 03:35 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\SysWOW64\wininit.exe => File is digitally signed
    C:\windows\explorer.exe => File is digitally signed
    C:\windows\SysWOW64\explorer.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\SysWOW64\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\SysWOW64\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\SysWOW64\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\dnsapi.dll => File is digitally signed
    C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2016-03-29 00:57

    ==================== End of FRST.txt ============================
    Thanks Peter
     
  4. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Here is Addition.txt part1
    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by a (2016-04-01 13:13:43)
    Running from C:\Users\a\Downloads
    Windows 7 Ultimate Service Pack 1 (X64) (2010-12-24 19:53:29)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    a (S-1-5-21-522234228-4192544273-3428825822-1000 - Administrator - Enabled) => C:\Users\a
    Administrator (S-1-5-21-522234228-4192544273-3428825822-500 - Administrator - Disabled)
    ASPNET (S-1-5-21-522234228-4192544273-3428825822-1003 - Limited - Enabled)
    Guest (S-1-5-21-522234228-4192544273-3428825822-501 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: AVG Internet Security (Enabled - Out of date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG Internet Security (Enabled - Out of date) {F620D48B-1497-73CC-F290-58052563BEAE}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    A4DeskPro v5.80 (HKLM-x32\...\a4deskpro_webunion_is1) (Version: - WebUnion Media Ltd.)
    ACAD DWG to Image Converter v7.9.2 (HKLM-x32\...\ACAD DWG to Image Converter_is1) (Version: - Copyright(C) 2005-2014 AcroCAD Inc.)
    Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{0F347A49-E36C-4639-8D2E-003AD408B8B2}) (Version: 1.5 - Eyeo GmbH)
    Adobe After Effects CS5 Third Party Content (HKLM-x32\...\{2AF31A97-817A-4D06-8210-4F789A0FF908}) (Version: 10.0.2 - Adobe Systems Incorporated)
    Adobe After Effects CS5 Third Party Royalty Content (HKLM-x32\...\{8A5387E2-7F1A-4FDD-883F-511DC8AA2295}) (Version: 10.0.2 - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
    Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
    Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.2.1.260 - Adobe Systems Incorporated)
    Adobe Creative Suite 5 Master Collection (HKLM-x32\...\{FBB02B04-C034-4382-A3F6-57416E2752C4}) (Version: 5.0 - Adobe Systems Incorporated)
    Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.6 - Adobe Systems Incorporated)
    Adobe Edge Animate (HKLM-x32\...\{181241DD-2FC2-4CF9-94CE-97F3E37D6F0B}) (Version: 1.5 - Adobe Systems Incorporated)
    Adobe Edge Inspect (HKLM-x32\...\{D830EE30-BF0C-42B7-A13C-927A379353ED}) (Version: 1.0.388 - Adobe Systems Incorporated)
    Adobe Edge Reflow Preview (HKLM-x32\...\{4932BCEA-E142-4A41-B3D2-0934EBE24CB4}) (Version: 0.12.9232 - Adobe Systems Incorporated)
    Adobe Flash Builder 4.6 (HKLM-x32\...\{0802B79F-257C-4F91-9A1E-7A94588C636A}) (Version: 4.6 - Adobe Systems Incorporated)
    Adobe Flash Catalyst CS5.5 (HKLM-x32\...\{D8CCCF4C-C227-427C-B4BE-736657D2AB7E}) (Version: 1.5 - Adobe Systems Incorporated)
    Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated)
    Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
    Adobe Flash Professional CS5.5 (HKLM-x32\...\{23E445D5-FD83-4C50-A211-EB26A2975317}) (Version: 11.5 - Adobe Systems Incorporated)
    Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
    Adobe Photoshop CS6 (HKLM-x32\...\{D586BF67-0A61-4572-BE25-07B40C4CEDA1}) (Version: 13.0 - Adobe Systems Incorporated)
    Adobe Photoshop Lightroom 2.6 (HKLM-x32\...\{81CB77FF-9789-4337-A46E-185F7876AC40}) (Version: 2.6.1 - Adobe)
    Adobe Pixel Bender Toolkit 2 (HKLM-x32\...\{D5CC77BE-BC5B-424E-8E45-DF60AFF7BE9C}) (Version: 2.0 - Adobe Systems Incorporated)
    Adobe Premiere Pro CS5 Third Party Royalty Content (HKLM-x32\...\{4BD0D94C-C5CA-41CA-879B-928E55ADA18F}) (Version: 5.0.3 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
    Adobe Visual Communicator 3 (HKLM-x32\...\InstallShield_{A5335A43-C886-4447-9885-013E62796E7C}) (Version: 3.0.3129.0 - Adobe Systems Incorporated)
    Advanced Uninstaller PRO - Version 10 (HKLM-x32\...\AU10_is1) (Version: 10 - Innovative Solutions)
    Akamai NetSession Interface (HKU\S-1-5-21-522234228-4192544273-3428825822-1000\...\Akamai) (Version: - Akamai Technologies, Inc)
    Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach)
    Atheros Client Installation Program (HKLM-x32\...\{D1434266-0486-4469-B338-A60082CC04E1}) (Version: 1.0.5.0621 - Atheros)
    Auction Alert 2.1.0 (HKLM-x32\...\Auction Alert_is1) (Version: - Auction Alert)
    AutoCAD Architecture 2008 (HKLM-x32\...\AutoCAD Architecture 2008) (Version: 5.5.235.0 - Autodesk)
    AutoCAD Architecture 2008 (x32 Version: 5.5.235.0 - Autodesk) Hidden
    AutoCAD Architecture 2011 - English (HKLM\...\AutoCAD Architecture 2011 - English) (Version: 6.5.49.0 - Autodesk)
    AutoCAD Architecture 2011 - English (Version: 6.5.49.0 - Autodesk) Hidden
    AutoCAD Architecture 2011 Language Pack - English (Version: 18.1.49.0 - Autodesk) Hidden
    Autodesk DWF Viewer 7 (HKLM-x32\...\{9A346205-EA92-4406-B1AB-50379DA3F057}) (Version: 7.2.0 - Autodesk, Inc.)
    Autodesk Material Library 2011 (HKLM-x32\...\{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}) (Version: 2.0.0.49 - Autodesk)
    Autodesk Material Library 2011 Base Image library (HKLM-x32\...\{CD1E078C-A6B9-47DA-B035-6365C85C7832}) (Version: 2.0.0.49 - Autodesk)
    Autodesk Stitcher Unlimited 2009 (HKLM-x32\...\{AACCA3ED-9F2F-4336-8A80-B09D90DBB91B}) (Version: - )
    AVG (Version: 16.12.7294 - AVG Technologies) Hidden
    AVG 2016 (Version: 16.0.4477 - AVG Technologies) Hidden
    AVG Protection (HKLM\...\AVG) (Version: 2016.12.7294 - AVG Technologies)
    Barra di ricerca di Encarta (64 bit) (HKLM\...\{08244040-959A-4B0D-8825-2C533F0DDB19}) (Version: 1.0.0 - Microsoft)
    BatteryLifeExtender (HKLM-x32\...\{74A579FB-EB06-497D-B194-01590D6FE51A}) (Version: 1.0.5 - Samsung)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Business Plan Pro 11.0 (HKLM-x32\...\{7E0E01E6-8F0B-428B-9A06-668104DA6872}) (Version: 11.14.0002 - Palo Alto Software, Inc.)
    Camera Control Pro 2 (HKLM-x32\...\{FE96C49B-DB90-405E-A00E-09E38372F880}) (Version: 2.14.0 - Nikon)
    ControlMyNikon version 3.0 (HKLM-x32\...\{C851A57F-0745-4B2D-9F64-950A53CC77C0}_is1) (Version: 3.0 - Tetherscript Technology Corp.)
    DirectWave VSTi (HKLM-x32\...\DirectWave VSTi) (Version: - Image-Line)
    DMG Extractor (HKU\S-1-5-21-522234228-4192544273-3428825822-1000\...\DMG Extractor) (Version: 1.2.1.0 - Reincubate Ltd)
    Dragon NaturallySpeaking 12 (HKLM-x32\...\{D5D422B9-6976-4E98-8DDF-9632CB515D7E}) (Version: 12.00.100 - Nuance Communications Inc.)
    Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.)
    Easy Network Manager (HKLM-x32\...\{F9557866-B4C8-4CE5-8508-0E386BDC20B2}) (Version: 4.3.3 - Samsung)
    Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 3.0.0.5 - Samsung Electronics Co.,Ltd.)
    EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung)
    EasySetPackage (HKLM-x32\...\{266725C1-716F-43AC-BBFB-4201131ED656}) (Version: 2.4 - LG Soft India)
    EpsonNet Config V4 (HKLM-x32\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.6.0 - Seiko Epson Corporation)
    eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
    FaceFilter v3.02 SE (HKLM-x32\...\{6020758E-57A9-41E3-AF20-8EE311EA6156}) (Version: 3.02.1720.1 - Reallusion Inc.)
    FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production)
    FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse)
    Filter Forge 3.006 (HKLM-x32\...\Filter Forge 3_is1) (Version: - Filter Forge, Inc.)
    FL Studio 12 (HKLM-x32\...\FL Studio 12) (Version: - Image-Line)
    FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line)
    Flash Decompiler Trillix (HKLM-x32\...\Flash Decompiler Trillix_is1) (Version: 4.1 - Eltima Software)
    FlashDevelop 4.0.0 (HKLM-x32\...\FlashDevelop) (Version: 4.0.0-RC3 - FlashDevelop.org)
    Flashificator (HKLM-x32\...\com.Flashificator) (Version: 2.086 - UNKNOWN)
    Flashificator (x32 Version: 2.086 - UNKNOWN) Hidden
    FMW 1 (Version: 1.32.2 - AVG Technologies) Hidden
    FonePaw iOS Transfer 1.2.0 (HKLM-x32\...\{548859D3-48CF-4fcb-8E03-E7F488ADF2EA}_is1) (Version: 1.2.0 - FonePaw)
    GARDEN ORGANIZER DELUXE (S) (HKLM-x32\...\{C9F0AAB9-41D6-420A-8B41-0859BE4E960B}) (Version: 3.5 - PRIMASOFT PC, INC.)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
    Google Web Designer (HKLM-x32\...\{811767F4-C586-4673-A41F-E9D767497222}) (Version: 1.2.4.0 - Google Inc.)
    Helicon Focus 5.3.7 (HKLM-x32\...\Helicon Focus_is1) (Version: - Helicon Soft Ltd.)
    HP Virtual Rooms Client Launcher Plugin (HKLM-x32\...\{C0847D30-4B8A-11E0-98C0-80E2DED72085}) (Version: 1.0.0.1 - Hewlett-Packard)
    iClone v5.4 PRO (HKLM-x32\...\{E8EB9130-8C34-4DCE-A6C4-B1C5A399F616}) (Version: 5.4.2706.1 - Reallusion Inc.)
    IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
    IL Minihost Modular (HKLM-x32\...\IL Minihost Modular) (Version: - Image-Line)
    IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version: - Image-Line)
    InPixio Photo Maximizer Pro (HKLM-x32\...\{33DB8C17-40C9-4629-B6D4-05A4C7E8AA86}) (Version: 1.20.25799 - Micro Application)
    Instant Wire Cleaner 1.0 (HKLM-x32\...\{94F29B90-CED3-4DA5-9255-96E2BE4C38A3}_is1) (Version: - CPSSoftware)
    Intel A/V Codecs V2.0 (HKLM-x32\...\CodInstl) (Version: - )
    Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{1A8BA6CE-822D-4888-89E2-ACBF4308F271}) (Version: 13.02.0000 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.3.1001 - Intel Corporation)
    Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 - Intel Corporation)
    IsoBuster 2.7 (HKLM-x32\...\IsoBuster_is1) (Version: 2.7 - Smart Projects)
    iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
    iZotope Nectar 2 Production Suite (HKLM-x32\...\iZotope Nectar 2 Production Suite_is1) (Version: 2.03 - iZotope, Inc.)
    Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
    Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
    Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
    Kodak DIGITAL GEM Airbrush Professional Plug-In (HKLM-x32\...\{AD871377-A1A3-4D7B-AA5E-EB163E1202C6}) (Version: 2.1.0 - Eastman Kodak Company)
    Kodak DIGITAL GEM Professional Plug-In (HKLM-x32\...\{6B18F58C-6AAD-42D4-97A2-0EB12E949539}) (Version: 2.1.0 - Kodak's Austin Development Center)
    Kodak DIGITAL ROC Professional Plug-In (HKLM-x32\...\{47786DE3-7FCA-4F5D-B3D5-D15BFE3ABCD8}) (Version: 2.1.0 - Kodak's Austin Development Center)
    Kodak DIGITAL SHO Professional Plug-In (HKLM-x32\...\{E8EC6F5D-A8A0-44AB-A238-5D6047F725FC}) (Version: 2.1.0 - Kodak's Austin Development Center)
    Kolor Panotour Pro 1.8 (HKLM-x32\...\Panotour Pro 1.8) (Version: V1.8.0 - Kolor)
    KoolMoves Demo 8.1.0 (HKLM-x32\...\KoolMoves Demo_is1) (Version: 8.1.0 - Lucky Monkey Designs LLC)
    Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
    Marvell Miniport Driver (HKLM-x32\...\Marvell Miniport Driver) (Version: 11.45.4.3 - Marvell)
    Melodyne 3.1 (HKLM-x32\...\{A1F143D1-1F0D-44FB-A44B-71D4367D16DE}) (Version: 3.1.0200 - Celemony Software GmbH)
    Melodyne 3.1 (x32 Version: 3.1.0200 - Celemony Software GmbH) Hidden
    MFC80 (x32 Version: 1.00.0000 - Your Company Name) Hidden
    Microsoft - Math (HKLM-x32\...\{07243840-959A-4B0D-8825-2C533F0DDB19}) (Version: 2007 - Microsoft Corporation)
    Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
    Microsoft Expression Blend 3 (HKLM-x32\...\Blend_3.0.1927.0) (Version: 3.0.1927.0 - Microsoft Corporation)
    Microsoft Expression Blend 3 SDK (HKLM-x32\...\{0E837AF0-4C92-4077-83F0-D022073F17C0}) (Version: 1.0.1327.0 - Microsoft Corporation)
    Microsoft Expression Design 3 (HKLM-x32\...\Design_6.0.1739.0) (Version: 6.0.1739.0 - Microsoft Corporation)
    Microsoft Expression Encoder 3 (HKLM-x32\...\Encoder_3.0.1332.0) (Version: 3.0.1332.0 - Microsoft Corporation)
    Microsoft Expression Studio 3 (HKLM-x32\...\ExpressionStudio_3.0.1061.0) (Version: 3.0.1061.0 - Microsoft Corporation)
    Microsoft Expression Web 3 (HKLM-x32\...\Web_3.0.3813.0) (Version: 3.0.3813.0 - Microsoft Corporation)
    Microsoft Expression Web 3 SP1 (HKLM-x32\...\{752E90AC-3F11-4EA3-88EA-96441047EC31}) (Version: - Microsoft Corporation)
    Microsoft HealthVault Connection Center (HKLM-x32\...\HealthVault Connection Center) (Version: 4.1.3438.8024 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
    Microsoft Silverlight 3 SDK (HKLM-x32\...\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40624.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP1 English (HKLM-x32\...\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}) (Version: 3.5.5692.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
    Mozilla Firefox 44.0.2 (x64 en-US) (HKLM\...\Mozilla Firefox 44.0.2 (x64 en-US)) (Version: 44.0.2 - Mozilla)
    Mozilla Firefox 45.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 45.0 (x86 en-US)) (Version: 45.0 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1 - Mozilla)
    MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
    MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
    MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
    MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
    msvcrt_installer (HKLM-x32\...\{6068A42A-C1CF-45F2-9859-5DB16287FE5D}) (Version: 1.0.0 - SAH)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: - Native Instruments)
    Native Instruments Guitar Rig 5 (HKLM-x32\...\Native Instruments Guitar Rig 5) (Version: - Native Instruments)
    Native Instruments Guitar Rig Mobile I/O (HKLM-x32\...\Native Instruments Guitar Rig Mobile I/O) (Version: - Native Instruments)
    Native Instruments Guitar Rig Session I/O (HKLM-x32\...\Native Instruments Guitar Rig Session I/O) (Version: - Native Instruments)
    Native Instruments Rig Kontrol 3 (HKLM-x32\...\Native Instruments Rig Kontrol 3) (Version: - Native Instruments)
    Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments)
    Nikon Message Center (HKLM-x32\...\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.92.000 - Nikon)
    Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
    NikonCapture (HKLM-x32\...\{21DDC579-834B-4C14-8122-853994FA2214}) (Version: 4.0 - )
    NKRemote (HKLM-x32\...\{18F7C517-4870-4b6a-93E0-09CB4AC4FFB7}) (Version: v2.2.3 - Breeze Systems Ltd)
    Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia)
    NVIDIA GeForce Experience 2.6.1.10 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.6.1.10 - NVIDIA Corporation)
    NVIDIA Graphics Driver 341.81 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.81 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
    Omron Drivers for HealthVault (HKLM\...\{2C62BD6D-7937-406C-A8B9-C0B0CB2FFF1D}) (Version: 1.8.1.0 - Omron)
    Omron Health Management Software (HKLM-x32\...\{F6BA8EF2-A9F8-45B7-BD59-0A15DA9F7D68}) (Version: 1.31.0007 - Omron Healthcare)
    Opera Mobile Emulator (HKLM-x32\...\{1826D0CA-F479-4430-9EFE-86E8E783505B}_is1) (Version: - Opera Software ASA)
    Opera Stable 36.0.2130.32 (HKLM-x32\...\Opera 36.0.2130.32) (Version: 36.0.2130.32 - Opera Software)
    OSC Third Party Libraries (Version: 1.1 - NVIDIA Corporation) Hidden
    Oxygen XML Editor 10.0 (HKLM-x32\...\Oxygen XML Editor 10.0) (Version: - SyncRO Soft)
    Pano2VR - Garden Gnome Software (HKLM-x32\...\Pano2VR) (Version: - )
    Panoweaver 9.1 Professional Edition (HKLM-x32\...\Panoweaver910_pro_is1) (Version: - Easypano Holdings Inc.)
    PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
    PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
    PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
    Perfect Resize 7 (HKLM-x32\...\{FCADA4FF-142C-42A8-B73C-0A54A7F83345}) (Version: 7.0.6 - onOne Software)
    Photomatix Pro version 3.2.7 (HKLM\...\PhotomatixPro3x32_is1) (Version: 3.2.7 - HDRsoft Sarl)
    PhysicsEditor (HKLM-x32\...\PhysicsEditor) (Version: 1.0.5 - Andreas Loew)
    PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden
    QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
    RapidTyping (HKLM-x32\...\RapidTyping) (Version: 4.6.6 - RapidTyping Software)
    Rapport (Version: 3.5.1205.20 - Trusteer) Hidden
    Rapport (x32 Version: 3.5.1507.113 - Trusteer) Hidden
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6378 - Realtek Semiconductor Corp.)
    REALTEK Wireless LAN Software (HKLM-x32\...\{0F796312-289C-40CA-856C-9FBCF5E83342}) (Version: 0133.09.1202 - REALTEK Semiconductor Corp.)
    Room Arranger (HKLM-x32\...\Room Arranger) (Version: 7.2.1 - Jan Adamec)
    S Agent (Version: 1.1.51 - Samsung Electronics CO., LTD.) Hidden
    Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
    Samsung Recovery Solution 4 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 4.0.0.6 - Samsung)
    Samsung R-Series (HKLM-x32\...\{3EED7541-55F8-4DC6-B9CD-28762D71310E}) (Version: 1.0 - Samsung)
    Samsung Support Center (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.0.2 - Samsung)
    Samsung Update Plus (HKLM-x32\...\{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}) (Version: 2.0 - Samsung Electronics Co., Ltd.)
    SamsungMovie (HKLM-x32\...\{EFA6EF6A-9E0D-4CF0-91DD-B55D8632F65A}) (Version: 1.0.0 - Samsung)
    SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden
    SHIELD Wireless Controller Driver (Version: 2.6.1.10 - NVIDIA Corporation) Hidden
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
    Skype™ 7.2 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
    SMPlayer 16.1.0 (x64) (HKLM\...\SMPlayer) (Version: 16.1.0 - Ricardo Villalba)
    Snappixx for Windows 95/98/ME/NT/2K/XP (HKLM-x32\...\ST6UNST #1) (Version: - )
    Sothink SWF Decompiler (HKLM-x32\...\{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1) (Version: 5.3 - SourceTec Software Co., LTD)
    Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
    StitcherUnlimited2009 AdLM (HKLM-x32\...\{891BB3F0-F157-4C82-8882-F920D7E9D42F}) (Version: 1.0.0 - Autodesk)
    Strumenti e modelli didattici per Microsoft Office (HKLM-x32\...\{75F3A4B2-F6E8-434D-A2EF-DBBC016C6CB2}) (Version: 2.0 - Microsoft)
    Style Studio v3.8 (HKLM-x32\...\Style Studio 3.8_is1) (Version: 3.8.107 - OverZone Software)
    SW Update (HKLM-x32\...\{1687FC01-135F-4ADE-B828-B461CC74BD8A}) (Version: 2.2.4 - Samsung Electronics CO., LTD.)
    Sweet Home 3D version 4.4 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.10.0 - Synaptics Incorporated)
    TetherProLite (HKLM-x32\...\{7235F547-FB89-4836-BB1B-CD73DA400064}) (Version: 1.0.3 - Todd Gibbs)
    ToonIt! (HKLM\...\ToonIt PS) (Version: 2.6.3 - Digital Anarchy, Inc.)
    TourDeFlex (HKLM-x32\...\TourDeFlex.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 2.0 - Adobe Systems Incorporated)
    TourDeFlex (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
    Tourweaver 7.50 Professional Edition (HKLM-x32\...\tw750_pro_is1) (Version: - Easypano Holdings Inc.)
    Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1507.113 - Trusteer)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - )
    VBA (2627.01) (x32 Version: 6.03.00.9402 - Microsoft Corporation) Hidden
    Vegas Pro 11.0 (HKLM-x32\...\{E6F012B0-E930-11E0-A67A-F04DA23A5C58}) (Version: 11.0.370 - Sony)
    Vegas Pro 12.0 (64-bit) (HKLM\...\{87CEB7C0-1D35-11E2-8F19-F04DA23A5C58}) (Version: 12.0.394 - Sony)
    Vertus Fluid Mask 3 3.0.10 (HKLM-x32\...\VertusFluidMask3) (Version: 3.0.10 - )
    Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) (HKLM\...\{4A5A427F-BA39-4BF0-7777-9A47FBE60C9F}) (Version: 11.0.0 - Nuance Communications Inc.)
    Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
    Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
    Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 5.7.0.0 - Azureus Software, Inc.)
    Vuze Remote Toolbar v10.0 (HKLM-x32\...\{2A567123-6435-476E-9529-54F5F9A9F4E0}) (Version: 10.0 - Spigot, Inc.) <==== ATTENTION
    Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.1.6-7 - Wacom Technology Corp.)
    WebAcappella4 (HKLM-x32\...\WebAcappella4_is1) (Version: - Intuisphere)
    WebTablet IE Plugin (HKLM-x32\...\Wacom WebTabletPlugin for IE) (Version: 1.1.0.7 - Wacom Technology Corp.)
    WebTablet Netscape Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Netscape) (Version: 1.1.0.5 - Wacom Technology Corp.)
    Windows 7 Manager (HKLM\...\{BB3C56DF-41B1-4D06-8699-2D5004173CDA}) (Version: 4.3.2 - Yamicsoft)
    Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
    Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
    Windows Live Sync (HKLM-x32\...\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
    Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
    WinRAR 4.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
    WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - )
    WinZip 15.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240C3}) (Version: 15.5.9510 - WinZip Computing, S.L. )
    Wocarson Windows Genuine Advantage Validation v1.9.40.0 Cracked V2 (HKLM-x32\...\{E108ADB5-8B3E-427D-A945-EAA2FCE68913}) (Version: 1.9.40.0 - Wocarson)
    Wondershare Dr.Fone for iOS(Build 4.5.1.6) (HKLM-x32\...\{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1) (Version: 4.5.1.6 - Wondershare Software Co.,Ltd.)
    Wondershare MobileTrans ( Version 3.3.0 ) (HKLM-x32\...\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 3.3.0 - Wondershare)
    WOW Slider (HKLM-x32\...\WOW Slider_is1) (Version: - )
    WPF Toolkit June 2009 (Version 3.5.40619.1) (HKLM-x32\...\{5EE6E987-1B79-4A93-832B-27472C7D1579}) (Version: 3.5.40619.1 - Microsoft Corporation)
    Youtube Downloader HD v. 2.2 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com)
    Zerene Stacker 1.04 (HKLM\...\{3C69B65F-770A-444B-8F31-F1ABDAA9D000}_is1) (Version: - Zerene Systems, LLC)
     
  5. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Here is Addition.txt part2
    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acadficn.dll (Autodesk, Inc.)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {0127EA8B-67CF-4E2C-AC60-11726F54AA09} - System32\Tasks\{F930C33E-CF57-454C-84FF-4E2AE5DE640C} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {05FACB47-A91F-420D-BCEC-FF600F302C99} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
    Task: {0727640F-EA5E-4D76-A83E-48C70E8738EC} - System32\Tasks\{D7680B2A-5E5C-4BC1-BD28-2CE2BB765740} => C:\Users\a\Desktop\Keygen.exe
    Task: {09331EFC-5DDF-4BB5-A086-711AF5448AFE} - System32\Tasks\{8293165A-D20F-4A29-83CF-FA23EE90B85B} => pcalua.exe -a C:\windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Nikon\NCapture4\Control\NControl.exe"
    Task: {0B7DFB6C-E4D1-48B8-898B-4C7912F97612} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-03-29] (SAMSUNG Electronics co., LTD.)
    Task: {0D973559-B5D9-4A3B-9A99-700976520DC7} - System32\Tasks\{B83D9BF1-9546-4DA9-800A-812A63002A30} => pcalua.exe -a "C:\Users\a\Desktop\Applications\Style Studio v3.8.107\Setup.exe" -d "C:\Users\a\Desktop\Applications\Style Studio v3.8.107"
    Task: {0E67D412-ADC3-4BF0-803D-0D8E23CF6082} - System32\Tasks\{08AC1D05-8E1A-42B7-9F82-BED8F09379EF} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {1191BA75-10D4-4D2F-9480-FB3E9F728F97} - System32\Tasks\{1F1A212B-9EEC-4A15-9842-EEA4B414F258} => C:\Program Files (x86)\Autodesk Architectural Desktop 2006\acad.exe
    Task: {12559310-DFAC-4989-8F23-709667D73793} - System32\Tasks\{EA31EA1B-6090-4E6E-B76A-0B87964436B4} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {1529E60A-F86A-464E-B522-633F3137244F} - System32\Tasks\{1832152F-7EE1-4947-82E5-92F74D61BE6C} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {19F41D0E-4D44-4094-9067-8771BC428826} - System32\Tasks\{312B2E96-4F98-4C2C-A9CD-2C511B5CA939} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {226CBEF3-C14B-4D3E-9085-AAEF8FF18D69} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-06-01] (Samsung Electronics. Co. Ltd.)
    Task: {2463E3F1-1E53-4021-87C1-ABD8FE4BB6B7} - System32\Tasks\{5813487C-E03B-4DAC-88A7-657E06658248} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {247E448E-79CC-495A-B96F-FF33CADC8148} - System32\Tasks\{93BDAF7B-F319-416D-8160-A42252DC4199} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {26439328-BD31-40D6-B5D6-80BD526FB36D} - System32\Tasks\{1B5B4BD5-EF27-4BCF-B6DE-6E29A7A7A93E} => C:\Users\a\Desktop\Keygen.exe
    Task: {2994F999-8B1E-4BD0-A37D-33BC499AF46F} - System32\Tasks\{FE4DDDC1-1C4A-482E-A4B7-7724E474A1E3} => C:\Users\a\Desktop\Keygen.exe
    Task: {2C0AFDDB-043B-493D-A40E-1AEDF70E8209} - System32\Tasks\{C865ABC5-D606-479D-9260-F2C2A25614DC} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {33761319-5E1B-41BB-BEAF-14DCAD251D5E} - System32\Tasks\{C8FA6773-6131-413D-8875-AA5A92A9E959} => C:\Users\a\Desktop\Keygen.exe
    Task: {37DA715B-647F-4B7C-BC78-9B5337DE7080} - System32\Tasks\{93B0144A-7C22-4C52-8375-DF3910EED519} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {396B9B80-C632-43CC-B773-1CF937F1D80E} - System32\Tasks\{2C57BE53-1797-42CD-B89E-69EDA7FF7308} => C:\Users\a\Desktop\p440\Setup.exe
    Task: {3B586B7B-2918-4716-82BE-CBD2AE501135} - System32\Tasks\{B5F3E929-9A2B-4167-A5EE-F64AE6C1047C} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {4A2CF537-170B-4B87-9548-F1BDE9DDD4D8} - System32\Tasks\{1D535599-E6D0-49D8-9099-AAB3D95A144D} => C:\Users\a\Desktop\Keygen.exe
    Task: {4D69C9FC-A99E-4581-9EA7-BA42AE89B50E} - System32\Tasks\{2714325B-674E-4675-8433-556CB869CE64} => C:\Users\a\Desktop\Keygen.exe
    Task: {4E68656A-4B65-4361-BF20-137AB2ECB12B} - System32\Tasks\{DC79ECF4-3436-4A42-A6F3-406896695BE3} => C:\Users\a\Desktop\Keygen.exe
    Task: {5BD0D3F6-C777-4E6E-A7A6-24A8B0E66898} - System32\Tasks\{CB807FBF-6F50-4AC5-90B8-AB54AB3D2084} => C:\Program Files (x86)\Autodesk Architectural Desktop 2006\acad.exe
    Task: {5C4CBC5D-A9B8-4B1F-8D8D-9209D0EF3CEB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
    Task: {5D106342-51E3-422E-9CA1-F24EBF2C4B15} - System32\Tasks\{C948908D-3929-47B3-BD6C-56FB52F36E2A} => C:\Users\a\Desktop\Keygen.exe
    Task: {653FEC7F-8ED0-41BD-AB56-2AF118229ACE} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
    Task: {684E9ECC-37E4-40FC-A3C9-25869923B6A9} - System32\Tasks\{48BED7A2-A7FF-4406-9457-1C1EE60CB4FC} => F:\Adobe Photoshop Elements\Setup.exe
    Task: {6BB5F843-E71E-490E-8E0F-F653F2B2B2AE} - System32\Tasks\{7DB39A53-2CD0-4339-A4BE-B6C0627918A1} => pcalua.exe -a C:\Users\a\Desktop\ADT2008\Setup.exe -d C:\Users\a\Desktop\ADT2008
    Task: {72167699-3690-432E-AF18-1768EE7BCF95} - System32\Tasks\{BEBBF18B-E535-4FA6-B51A-37223352D6FD} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {723CB7EC-A285-42A8-9E2D-9893D371B7FF} - System32\Tasks\{AB890F67-DA91-456E-BA7D-34F06BFBFC04} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {7E131182-19E8-4D00-93D1-E2FCA7A42F7C} - System32\Tasks\{0076CCF1-F738-41A9-BE62-ECD612473443} => C:\Users\a\Desktop\Keygen.exe
    Task: {7FB8C834-06FC-4611-B503-8215B3C34B15} - System32\Tasks\AdobeAAMUpdater-1.0-a-PC-a => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-09-25] (Adobe Systems Incorporated)
    Task: {808D0385-1AA0-48B9-BC4A-A86EF313DA51} - System32\Tasks\{BA6787A1-24FB-4F97-A76F-A3D16F3A612F} => C:\Program Files (x86)\BreezeSys\NKRemote\NKRemote.exe [2009-08-05] (Breeze Systems Ltd)
    Task: {826CAABD-7A69-47EE-9CC7-25D639392929} - System32\Tasks\{7C1CC536-1A8F-4A26-8873-71FAE52B8827} => pcalua.exe -a C:\Users\a\Downloads\iv5setup(1).exe -d C:\Users\a\Downloads
    Task: {83D71393-7B48-44EC-83D4-8355533AED6A} - System32\Tasks\{EC43FA6C-741F-4E15-A018-78DD0BCC1D12} => pcalua.exe -a "C:\Users\a\Desktop\nk4\Nikon Capture 4.2.1 Full + 4.3 update + serial\Nikon Capture 4.2.1\Disk1\setup.exe" -d "C:\Users\a\Desktop\nk4\Nikon Capture 4.2.1 Full + 4.3 update + serial\Nikon Capture 4.2.1\Disk1"
    Task: {886F123B-D25A-4AEB-A115-32CE07A5D0F9} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2009-10-13] (Samsung Electronics Co., Ltd.)
    Task: {89CADC1C-BF1E-45DE-924B-68DBC59D91B0} - System32\Tasks\{E74B7EA6-7027-428A-A6EE-28152804FC60} => C:\Users\a\Desktop\Keygen.exe
    Task: {8A713A54-2E1E-4B75-924A-1BEB24554958} - System32\Tasks\{9ABBECC3-8B9F-4E8D-B591-89F26F1E2751} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {8CD32D5D-2EC2-40E1-8FBD-134BC8F471D2} - System32\Tasks\{C8101388-0FE2-489C-9737-FF4A6D43E0E8} => C:\Program Files (x86)\BreezeSys\NKRemote\NKRemote.exe [2009-08-05] (Breeze Systems Ltd)
    Task: {914380EF-A337-4C25-AA28-001AC56552CA} - System32\Tasks\{C227EB27-B362-40C8-9C38-4FDC4CCD5776} => C:\Program Files (x86)\BreezeSys\NKRemote\NKRemote.exe [2009-08-05] (Breeze Systems Ltd)
    Task: {95F1EA6F-C43F-417C-9FA3-943D0EB642D0} - System32\Tasks\{90FCBAFE-A676-43E5-883C-D59E26FA36B6} => pcalua.exe -a C:\Users\a\Desktop\sound\SETUP.EXE -d C:\Users\a\Desktop\sound
    Task: {9AD23A4F-E20E-4CA6-84DE-521C226E7B25} - System32\Tasks\{C9135D17-281C-484D-AED4-CBCBF7018C33} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {9AF1ABEA-82D2-4C32-9D5E-A7406B582C86} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-10-29] (Samsung Electronics CO., LTD.)
    Task: {A39A2C68-98D2-48ED-A813-FABB1844BCB4} - System32\Tasks\{FCC73AFA-6A1B-45BB-B3EF-76FBF16964D7} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {AD0D814A-7AB4-4ABF-8B75-81F7340BFC2E} - System32\Tasks\{097E86C3-9DCE-4D61-B720-EAB3655C52D3} => pcalua.exe -a "C:\Users\a\Desktop\Install Lightroom 2.4.exe" -d C:\Users\a\Desktop
    Task: {AECD8FB5-B082-413A-9923-4E6BB096E77F} - System32\Tasks\{9B0C9148-E605-4492-A3EC-9951A4486127} => E:\setup.exe
    Task: {B55C47EE-9383-4C1A-A352-7FB9852998D0} - System32\Tasks\{43671627-D6C3-4C1E-AB11-55D013FE69D2} => pcalua.exe -a "C:\Users\a\Desktop\nk4\Nikon Capture 4.4 官方简体中文版\Nikon_Capture_4.4.1_Updater_CN\S-NC____-440WU-INTCN.exe" -d "C:\Users\a\Desktop\nk4\Nikon Capture 4.4 官方简体中文版\Nikon_Capture_4.4.1_Updater_CN"
    Task: {BBFD0CE6-6870-43B6-86FC-BFCF19D836DA} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-29] (Adobe Systems Incorporated)
    Task: {BC1D6023-12FC-4A90-A181-6D379B61C831} - System32\Tasks\{24192CF8-07C4-4A4D-A8DF-9FD555ADA992} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {C018816C-82F9-4FCA-B0BA-E82C217B3653} - System32\Tasks\{B201E666-1A42-4649-87E3-C334064E76E7} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {C7485C50-4F50-46E1-87E5-C80C669FE914} - System32\Tasks\{D5E02ED5-566C-4A14-9698-67883B57AAB0} => C:\Users\a\Desktop\p440\Setup.exe
    Task: {C86D1B6D-C500-4A3C-901D-7AEDA40AE402} - System32\Tasks\{AD49533E-B97A-4ACF-B20F-C514CF8B9A21} => pcalua.exe -a C:\Users\a\Desktop\NV625_up\Disk1\Setup.exe -d C:\Users\a\Desktop\NV625_up\Disk1
    Task: {DBD12B99-9916-4057-9ECC-9180FCEE1D19} - System32\Tasks\{5E4C098B-A82F-4FD4-8B25-0E9A792A4397} => pcalua.exe -a "C:\Users\a\Desktop\Photoshop Lightroom 2.6\Install Lightroom 2.6.exe" -d "C:\Users\a\Desktop\Photoshop Lightroom 2.6"
    Task: {E171AD44-9B85-4821-B8B8-4DFFC6814957} - System32\Tasks\{BAB62250-0056-4E9A-9DD5-F6A2578E2D4C} => C:\Users\a\Desktop\Keygen.exe
    Task: {E2B45D9D-9C3C-49E2-A200-735284FE0BF0} - System32\Tasks\{160EDAB2-7F43-4EBF-8E5B-B21F5A0D5C9E} => pcalua.exe -a C:\Users\a\Desktop\p440\Setup.exe -d C:\Users\a\Desktop\p440
    Task: {E4E99033-4D2D-4778-B942-A9E954A1F77F} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21] (Adobe Systems Incorporated)
    Task: {E53A0F0A-404A-4A72-B060-B362656BCCB1} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-05053A92\EPM.exe
    Task: {EA6170C3-5994-48CF-89DE-DEDB7C5AF71B} - System32\Tasks\{14C80B1B-9E21-4155-91FE-4F83FBDA3740} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {EAAD2705-A24C-4892-BB47-D19CBB3ED01A} - System32\Tasks\Opera scheduled Autoupdate 1459285081 => C:\Program Files (x86)\Opera\launcher.exe [2016-03-14] (Opera Software)
    Task: {EB502C84-0AC6-43B4-97A0-2EDBBDF6E6FC} - System32\Tasks\{8E704D9C-B141-4B07-8F42-D51E781F5582} => pcalua.exe -a "C:\Users\a\Documents\Vuze Downloads\Micro Expression\iv5setup.exe" -d "C:\Users\a\Documents\Vuze Downloads\Micro Expression"
    Task: {EE90E3C3-B0A3-4B52-954A-42DF3B32C966} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
    Task: {F337FCB2-3827-451A-99A2-EF949959EF9A} - System32\Tasks\{7C040EE6-4D80-4C21-886D-86BB0779C232} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {F61F6EF1-4B7D-4235-A63E-9D1A37BD484D} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-06-08] (Samsung Electronics Co., Ltd.)
    Task: {F6C06100-B3EE-4C44-8A7F-E3F8682D24CE} - System32\Tasks\{20B35A6A-E43F-4504-98FB-6C259D2DD408} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {F73307E1-C9A5-4CA2-9740-A0990B5D2BA5} - System32\Tasks\{FDF90E5D-4995-4897-A4DC-EA9193D0571B} => C:\Users\a\Downloads\photopc.exe
    Task: {F82155C6-29C3-42D4-82DE-64FFE99E1E81} - System32\Tasks\{0642A9A7-51C3-425A-BAF6-A316E099EFA1} => C:\Users\a\Desktop\Keygen.exe
    Task: {FA5B689E-6F93-465F-B34E-23911AC2B62B} - System32\Tasks\{06DDEC3B-81C0-417B-BFEC-6679078C3D5D} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {FC8801BB-D0C9-48A7-B692-FE243C37E441} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-05-06] (SAMSUNG Electronics)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-11 19:25 - 2015-08-18 01:07 - 00115376 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2008-01-04 17:56 - 2010-11-15 12:08 - 01182576 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
    2015-10-16 11:02 - 2015-10-16 11:02 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
    2011-02-03 14:39 - 2011-02-03 14:39 - 02870784 _____ () C:\Windows\System32\drivers\UMDF\Omron\OmronWpdDriver.dll
    2013-10-16 19:02 - 2013-10-16 19:02 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
    2016-03-29 20:54 - 2016-03-29 20:54 - 26727616 _____ () C:\windows\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll
    2015-07-21 17:02 - 2015-07-21 17:02 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll
    2015-10-11 18:32 - 2015-09-28 23:05 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
    2016-04-01 11:01 - 2015-04-07 14:34 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Windows:nlsPreferences [0]
    AlternateDataStreams: C:\Users\a\Cookies:pCcyTPEdyM46RMzTfp48lq [2430]
    AlternateDataStreams: C:\Users\a\AppData\Local\desktop.ini:3a96398c0f384e4adf5faa1736aeaf96 [802]
    AlternateDataStreams: C:\Users\a\AppData\Local\Temporary Internet Files:5Se5QwcRmq1ayglFYLV0gH8qKz8 [1950]
    AlternateDataStreams: C:\ProgramData\Microsoft:5PJuBaesDyapndf8Ut50s7g1c [2022]
    AlternateDataStreams: C:\ProgramData\Microsoft:dhEatTyVPHSPSDRP1cQln04OWUn6W [2360]
    AlternateDataStreams: C:\ProgramData\Microsoft:GUaGESdiIiSVeGzg5H2EC [2350]
    AlternateDataStreams: C:\ProgramData\Microsoft:m0z7NBO9GMLEoMy4XO7p [2136]
    AlternateDataStreams: C:\ProgramData\Microsoft:uHj3MQsPeHwZblwQ6pUWZ5 [2012]
    AlternateDataStreams: C:\ProgramData\Temp:0FF263E8 [140]
    AlternateDataStreams: C:\ProgramData\Temp:F4CA4D70 [458]
    AlternateDataStreams: C:\ProgramData\Temp:FD268286 [190]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 03:34 - 2016-03-31 16:15 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts

    127.0.0.1 localhost

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\a\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
    Windows Firewall is disabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\Services: McMPFSvc => 2
    MSCONFIG\Services: mcmscsvc => 2
    MSCONFIG\Services: McNaiAnn => 2
    MSCONFIG\Services: McNASvc => 2
    MSCONFIG\Services: McODS => 3
    MSCONFIG\Services: McProxy => 2
    MSCONFIG\Services: mfefire => 2
    MSCONFIG\startupreg: (default) =>
    MSCONFIG\startupreg: AdobeCS5.5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
    MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
    MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
    MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    MSCONFIG\startupreg: mcui_exe =>
    MSCONFIG\startupreg: NvCplDaemon => RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
    MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
    MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    MSCONFIG\startupreg: SynTPEnh => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{42A0F55B-06A4-4D05-AB14-92C8424357DA}C:\program files (x86)\vuze\azureus.exe] => (Allow) C:\program files (x86)\vuze\azureus.exe
    FirewallRules: [UDP Query User{C96B2DD6-F633-4483-AB31-B59EC18C16F7}C:\program files (x86)\vuze\azureus.exe] => (Allow) C:\program files (x86)\vuze\azureus.exe
    FirewallRules: [{E2030FD0-3CF2-4374-A048-50C612F837AB}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
    FirewallRules: [{98550D4F-7C4E-411A-ACE2-5F5484CAAF1B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
    FirewallRules: [{4F5753A7-F03D-48A9-82DF-82349D288CDE}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{E801E9BD-00B5-4EF7-8A87-675160AA09A8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
    FirewallRules: [{06818514-E985-4B4B-A98A-5CDD75E83E94}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{1385384C-39CB-4A06-9C78-41765B311DB3}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe

    ==================== Restore Points =========================

    18-03-2016 01:00:01 Scheduled Checkpoint
    25-03-2016 01:00:02 Scheduled Checkpoint
    31-03-2016 14:59:34 Removed AVG
    31-03-2016 15:04:49 Removed AVG 2016
    01-04-2016 11:03:09 Installed AVG 2016
    01-04-2016 11:04:51 Installed AVG

    ==================== Faulty Device Manager Devices =============

    Name: Microsoft ISATAP Adapter
    Description: Microsoft ISATAP Adapter
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: tunnel
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name: Microsoft ISATAP Adapter #2
    Description: Microsoft ISATAP Adapter
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: tunnel
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (04/01/2016 12:03:28 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:03:28 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:03:28 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:03:28 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:03:28 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:03:28 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:03:28 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:03:27 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:02:53 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/01/2016 12:02:53 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.


    System errors:
    =============
    Error: (03/31/2016 04:09:58 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (03/31/2016 04:07:46 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

    Error: (03/31/2016 03:55:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (03/31/2016 03:29:41 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The SW Update Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (03/31/2016 12:54:19 PM) (Source: BROWSER) (EventID: 8032) (User: )
    Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{A66457FB-76D7-44A4-BFA0-D4C23D5733A4}.
    The backup browser is stopping.

    Error: (03/29/2016 09:54:23 PM) (Source: BROWSER) (EventID: 8032) (User: )
    Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{A66457FB-76D7-44A4-BFA0-D4C23D5733A4}.
    The backup browser is stopping.

    Error: (03/29/2016 09:38:43 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 21:00:33 on ‎29/‎03/‎2016 was unexpected.

    Error: (03/29/2016 08:26:58 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 20:24:53 on ‎29/‎03/‎2016 was unexpected.

    Error: (03/29/2016 08:05:14 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 20:00:46 on ‎29/‎03/‎2016 was unexpected.

    Error: (03/21/2016 10:52:32 AM) (Source: BROWSER) (EventID: 8032) (User: )
    Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{A66457FB-76D7-44A4-BFA0-D4C23D5733A4}.
    The backup browser is stopping.


    CodeIntegrity:
    ===================================
    Date: 2016-03-31 16:07:46.944
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-03-31 16:07:46.834
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:42.946
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidFilt.Sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:42.855
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidFilt.Sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:39.580
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidFilt.Sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:39.492
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidFilt.Sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:35.453
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidEqd.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:35.393
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidEqd.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:35.326
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidEqd.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-02-17 15:38:35.266
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\LHidEqd.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
    Percentage of memory in use: 78%
    Total physical RAM: 3956.55 MB
    Available physical RAM: 849.45 MB
    Total Virtual: 7911.31 MB
    Available Virtual: 4463.04 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:371 GB) (Free:62.02 GB) NTFS
    Drive d: () (Fixed) (Total:74.66 GB) (Free:74.56 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 465.8 GB) (Disk ID: 8C0FBFDC)
    Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=371 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=74.7 GB) - (Type=OF Extended)

    ==================== End of Addition.txt ============================
     
  6. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi Broni,
    reposted as Virus removal for Peter.
    Thanks
    Peter
     
  7. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    [​IMG] Please do NOT create multiple topics.

    [​IMG] Uninstall following unwanted program: Vuze Remote Toolbar.

    [​IMG] Download RogueKiller from one of the following links and save it to your Desktop:

    Link 1
    Link 2
    • Close all the running programs
    • Windows Vista/7/8 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
    [​IMG] Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
    NOTE. If you already have MBAM 2.0 installed scroll down.
    • Double-click mbam-setup-2.0.0.1000.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
    • Click Finish.
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.
    If you already have MBAM 2.0 installed:
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.
    How to get logs:
    (Export log to save as txt)
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • Attach that saved log to your next reply.
    (Copy to clipboard for pasting into forum replies or tickets)
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Copy to Clipboard'
    • Paste the contents of the clipboard into your reply.
    [​IMG] Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Scan button.
    • When the scan has finished click on Clean button.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
  8. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi I cannot delete Vuze Remote Toolbar v10.0
    I get "error the path 1 cannot be found. Insert the Vuze Remote Toolbar v10.0 disk "
     
  9. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Leave it alone then.
     
  10. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi,
    here are txt files.
    On malwarebytes I got unable to access update server message.
    On JRT I got unable to ping, skipping update check message.
    Rogue Killer1
    RogueKiller V12.0.3.0 [Mar 21 2016] (Free) by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/software/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : a [Administrator]
    Started from : C:\Users\a\Desktop\RogueKiller.exe
    Mode : Delete -- Date : 04/03/2016 10:09:52

    ¤¤¤ Processes : 2 ¤¤¤
    [Suspicious.Path] Advanced_Uninstaller11.tmp(9024) -- C:\Users\a\AppData\Local\Temp\is-7KLM7.tmp\Advanced_Uninstaller11.tmp[x] -> Found
    [Suspicious.Path] (SVC) RapportCerberus_1507082 -- \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys[x] -> Found

    ¤¤¤ Registry : 9 ¤¤¤
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RapportCerberus_1507082 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys) -> Not selected
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RapportCerberus_1507082 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys) -> Not selected
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RapportCerberus_1507082 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys) -> Not selected
    [PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Not selected
    [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Not selected

    ¤¤¤ Tasks : 1 ¤¤¤
    [Suspicious.Path] \Microsoft\Windows\Media Center\PeriodicScanRetry -- %windir%\ehome\MCUpdate.exe (-pscn 0) -> Not selected

    ¤¤¤ Files : 0 ¤¤¤

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: WDC WD5000BEVT-35A0RT0 +++++
    --- User ---
    [MBR] 9fa1c4fec72fad182e740f60158b40a8
    [BSP] ede565d532ec6e69be3bf69522f567b3 : Kiwi MBR Code
    Partition table:
    0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 20480 MB
    1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 41945088 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 42149888 | Size: 379904 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 820193280 | Size: 76454 MB
    User = LL1 ... OK
    User = LL2 ... OK
    Rogue killer 2
    RogueKiller V12.0.3.0 [Mar 21 2016] (Free) by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/software/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : a [Administrator]
    Started from : C:\Users\a\Desktop\RogueKiller.exe
    Mode : Delete -- Date : 04/03/2016 10:09:52

    ¤¤¤ Processes : 2 ¤¤¤
    [Suspicious.Path] Advanced_Uninstaller11.tmp(9024) -- C:\Users\a\AppData\Local\Temp\is-7KLM7.tmp\Advanced_Uninstaller11.tmp[x] -> Found
    [Suspicious.Path] (SVC) RapportCerberus_1507082 -- \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys[x] -> Found

    ¤¤¤ Registry : 9 ¤¤¤
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RapportCerberus_1507082 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys) -> Not selected
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RapportCerberus_1507082 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys) -> Not selected
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RapportCerberus_1507082 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys) -> Not selected
    [PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://samsung.msn.com -> Not selected
    [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Not selected
    [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Not selected

    ¤¤¤ Tasks : 1 ¤¤¤
    [Suspicious.Path] \Microsoft\Windows\Media Center\PeriodicScanRetry -- %windir%\ehome\MCUpdate.exe (-pscn 0) -> Not selected

    ¤¤¤ Files : 0 ¤¤¤

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: WDC WD5000BEVT-35A0RT0 +++++
    --- User ---
    [MBR] 9fa1c4fec72fad182e740f60158b40a8
    [BSP] ede565d532ec6e69be3bf69522f567b3 : Kiwi MBR Code
    Partition table:
    0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 20480 MB
    1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 41945088 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 42149888 | Size: 379904 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 820193280 | Size: 76454 MB
    User = LL1 ... OK
    User = LL2 ... OK
     
  11. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Here are other txt files
    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 03/04/2016
    Scan Time: 10:14
    Logfile: mbam03042016.txt
    Administrator: Yes

    Version: 2.2.1.1043
    Malware Database: v2016.02.16.06
    Rootkit Database: v2016.02.08.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled

    OS: Windows 7 Service Pack 1
    CPU: x64
    File System: NTFS
    User: a

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 439729
    Time Elapsed: 43 min, 38 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Disabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 1
    CrackTool.Agent, C:\Users\a\Downloads\amtlib_pour_Adobe_CS6_UpByBastinouForWawa_Mania.rar, , [2e38a4bd2f6a15218299c28bab577c84],

    Physical Sectors: 0
    (No malicious items detected)


    (end)

    # AdwCleaner v5.108 - Logfile created 03/04/2016 at 11:08:47
    # Updated 30/03/2016 by Xplode
    # Database : 1984.9 [Local]
    # Operating system : Windows 7 Ultimate Service Pack 1 (x64)
    # Username : a - A-PC
    # Running from : C:\Users\a\Desktop\adwcleaner_5.108.exe
    # Option : Clean
    # Support : http://toolslib.net/forum

    ***** [ Services ] *****


    ***** [ Folders ] *****

    [-] Folder Deleted : C:\Program Files (x86)\Innovative Solutions
    [-] Folder Deleted : C:\Program Files (x86)\Common Files\Innovative Solutions
    [-] Folder Deleted : C:\ProgramData\Innovative Solutions
    [-] Folder Deleted : C:\Users\a\appData\Local\Innovative Solutions

    ***** [ Files ] *****


    ***** [ DLLs ] *****


    ***** [ Shortcuts ] *****


    ***** [ Scheduled tasks ] *****


    ***** [ Registry ] *****

    [-] Key Deleted : HKCU\Software\AVG Web TuneUp

    ***** [ Web browsers ] *****


    *************************

    :: "Tracing" keys deleted
    :: Winsock settings cleared

    *************************

    C:\AdwCleaner\AdwCleaner[C1].txt - [1004 bytes] - [03/04/2016 11:08:47]
    C:\AdwCleaner\AdwCleaner[S1].txt - [1123 bytes] - [03/04/2016 11:01:26]

    ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1150 bytes] ##########

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.0.4 (03.14.2016)
    Operating System: Windows 7 Ultimate x64
    Ran by a (Administrator) on 03/04/2016 at 11:18:30.77
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    File System: 26

    Successfully deleted: C:\Users\a\AppData\Roaming\new version available (Folder)
    Successfully deleted: C:\windows\system32\Tasks\EasySpeedUpManager (Task)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RXN05HX (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5922IQB7 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C0GKP8QP (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FBKHTI8F (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IC98NZQA (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PJL41CC3 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PX9Q961D (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\a\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W81LRQCN (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RXN05HX (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5922IQB7 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C0GKP8QP (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FBKHTI8F (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IC98NZQA (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PJL41CC3 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PX9Q961D (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W81LRQCN (Temporary Internet Files Folder)



    Registry: 0





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 03/04/2016 at 11:38:37.26
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
  12. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Very Important! Temporarily disable your anti-virus and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error Illegal operation attempted on a registery key that has been marked for deletion, restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     
  13. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi,
    here is combofix txt.
    ComboFix 16-04-01.01 - a 04/04/2016 10:56:21.2.4 - x64
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.3957.1460 [GMT 1:00]
    Running from: c:\users\a\Desktop\ComboFix.exe
    SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ADS - windows: deleted 0 bytes in 1 streams.
    /wow section - STAGE 33
    Access is denied.
    .
    .
    ((((((((((((((((((((((((( Files Created from 2016-03-04 to 2016-04-04 )))))))))))))))))))))))))))))))
    .
    .
    2016-04-04 10:24 . 2016-04-04 10:24 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
    2016-04-04 10:24 . 2016-04-04 10:24 -------- d-----w- c:\users\Default\AppData\Local\temp
    2016-04-04 09:58 . 2016-04-04 09:58 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FB5D3479-195C-446B-845F-86065C96281E}\offreg.2752.dll
    2016-04-04 09:14 . 2016-04-04 09:14 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\MFAData
    2016-04-04 09:13 . 2016-04-04 09:13 28464 ----a-w- c:\windows\system32\drivers\libwasys.sys
    2016-04-04 09:13 . 2016-04-04 09:13 15664 ----a-w- c:\windows\system32\drivers\libwamf.sys
    2016-04-03 10:01 . 2016-04-03 10:08 -------- d-----w- C:\AdwCleaner
    2016-04-03 09:13 . 2016-04-03 09:13 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
    2016-04-03 09:12 . 2016-04-03 09:13 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
    2016-04-03 09:12 . 2016-03-10 13:09 64896 ----a-w- c:\windows\system32\drivers\mwac.sys
    2016-04-03 09:12 . 2016-03-10 13:08 140672 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2016-04-03 09:12 . 2016-03-10 13:08 27008 ----a-w- c:\windows\system32\drivers\mbam.sys
    2016-04-03 08:24 . 2016-04-03 08:27 24688 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2016-04-03 08:23 . 2016-04-03 08:26 -------- d-----w- c:\programdata\RogueKiller
    2016-04-02 17:55 . 2016-04-02 17:55 -------- d-----w- C:\zoek
    2016-04-01 11:48 . 2016-04-01 12:37 -------- d-----w- C:\FRST
    2016-04-01 10:06 . 2016-04-04 09:21 -------- d-----w- C:\$AVG
    2016-04-01 02:50 . 2016-04-01 15:30 -------- d-----w- c:\program files\Mozilla Firefox
    2016-03-31 14:46 . 2016-03-31 14:46 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FB5D3479-195C-446B-845F-86065C96281E}\offreg.4736.dll
    2016-03-29 20:58 . 2016-03-29 20:58 -------- d-----w- c:\users\a\AppData\Local\Opera Software
    2016-03-29 20:58 . 2016-03-29 20:58 -------- d-----w- c:\users\a\AppData\Roaming\Opera Software
    2016-03-29 20:57 . 2016-04-04 09:45 -------- d-----w- c:\program files (x86)\Opera
    2016-03-21 10:31 . 2016-03-30 01:21 -------- d-----w- c:\program files (x86)\EPUB File Reader
    2016-03-09 21:49 . 2016-03-09 21:49 -------- d--h--w- c:\program files\Uninstall Information
    2016-03-09 20:45 . 2016-03-09 21:47 -------- d-----w- c:\windows\Panther
    2016-03-08 13:22 . 2016-03-08 15:00 -------- d-----w- c:\program files (x86)\AdwCleaner
    2016-03-08 12:54 . 2016-03-08 15:00 -------- d-----w- c:\program files\Adblock Plus for IE
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2016-03-29 19:54 . 2015-04-03 15:26 797376 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2016-03-29 19:54 . 2015-04-03 15:26 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2016-03-03 11:19 . 2015-06-11 18:33 152320 ----a-w- c:\windows\system32\drivers\RapportHades64.sys
    2016-03-03 11:19 . 2012-02-04 16:08 407168 ----a-w- c:\windows\system32\drivers\RapportKE64.sys
    2016-02-17 15:37 . 2013-11-23 13:44 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
    2016-02-08 10:20 . 2014-10-30 10:36 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-01-29 594992]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    EasySetPackage.lnk - c:\program files (x86)\LG Soft India\EasySetPackage\bin\EasySetPackage.exe -startup [2015-8-25 159744]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
    "DNS7reminder"="c:\program files (x86)\Nuance\NaturallySpeaking12\Ereg\Ereg.exe" -r "c:\programdata\Nuance\NaturallySpeaking12\Ereg.ini"
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R2 SWUpdateService;SW Update Service;c:\programdata\Samsung\SW Update Service\SWMAgent.exe;c:\programdata\Samsung\SW Update Service\SWMAgent.exe [x]
    R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
    R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
    R3 LGDDCDevice;LGDDCDevice;c:\windows\system32\LGI2CDriver.sys;c:\windows\SYSNATIVE\LGI2CDriver.sys [x]
    R3 LGII2CDevice;LGII2CDevice;c:\windows\system32\LGPII2CDriver.sys;c:\windows\SYSNATIVE\LGPII2CDriver.sys [x]
    R3 libwamf;libwamf;c:\windows\system32\DRIVERS\libwamf.sys;c:\windows\SYSNATIVE\DRIVERS\libwamf.sys [x]
    R3 libwasys;libwasys;c:\windows\system32\DRIVERS\libwasys.sys;c:\windows\SYSNATIVE\DRIVERS\libwasys.sys [x]
    R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
    R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
    R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys;c:\windows\SYSNATIVE\DRIVERS\wacmoumonitor.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    R4 DragonSvc;Dragon Service;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe [x]
    R4 Rezip;Rezip;c:\windows\SysWOW64\Rezip.exe;c:\windows\SysWOW64\Rezip.exe [x]
    R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
    R4 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
    R4 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
    R4 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
    S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
    S0 RapportHades64;RapportHades64;c:\windows\System32\Drivers\RapportHades64.sys;c:\windows\SYSNATIVE\Drivers\RapportHades64.sys [x]
    S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys;c:\windows\SYSNATIVE\Drivers\RapportKE64.sys [x]
    S1 RapportCerberus_1507082;RapportCerberus_1507082;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys [x]
    S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [x]
    S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [x]
    S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys;c:\windows\SYSNATIVE\Drivers\SABI.sys [x]
    S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
    S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
    S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
    S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
    S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
    S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [x]
    S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe;c:\windows\SysWOW64\nlssrv32.exe [x]
    S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
    S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
    S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [x]
    S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
    S2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [x]
    S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x]
    S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x]
    S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
    S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
    S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
    S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
    S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
    S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
    S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2016-03-29 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-03 19:54]
    .
    2016-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-09 17:46]
    .
    2016-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-09 17:46]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
    @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
    [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
    2013-10-16 18:02 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
    @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
    [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
    2013-10-16 18:02 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
    @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
    [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
    2013-10-16 18:02 3358064 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-09-28 2730616]
    "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-09-28 1793480]
    "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2015-08-26 3113592]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = <-loopback>;<local>
    TCP: DhcpNameServer = 192.168.1.1
    FF - ProfilePath - c:\users\a\AppData\Roaming\Mozilla\Firefox\Profiles\ijupd536.default-1430291221738\
    FF - prefs.js: browser.startup.homepage - about:home
    FF - ExtSQL: 2016-03-09 20:32; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\a\AppData\Roaming\Mozilla\Firefox\Profiles\ijupd536.default-1430291221738\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Wow6432Node-HKLM-Run-<NO NAME> - (no file)
    AddRemove-AU11_is1 - c:\program files (x86)\Innovative Solutions\Advanced Uninstaller PRO\unins000.exe
    AddRemove-CodInstl - c:\windows\system32\CDUninst.isu
    AddRemove-Native Instruments Controller Editor - c:\programdata\{30FA7941-4170-4C83-A9A8-FDF01C431704}\Controller Editor Setup PC.exe
    AddRemove-Native Instruments Guitar Rig 5 - c:\programdata\{B7072B15-6E80-42FF-A9AE-4E62AF2B2418}\Guitar Rig 5 Setup PC.exe
    AddRemove-O - c:\programdata\{B0CAD5CC-867E-473E-B55F-339F9635A45D}\Guitar Rig Mobile IO Setup PC.exe
    AddRemove-O - c:\programdata\{CB28D9D3-6B5D-4AFA-BA37-B4AFAAAF71B9}\Guitar Rig Session IO Setup PC.exe
    AddRemove-Native Instruments Rig Kontrol 3 - c:\programdata\{5A23829C-A66E-47B0-AD50-21A3FFE6C325}\Rig Kontrol 3 Setup PC.exe
    AddRemove-Native Instruments Service Center - c:\programdata\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14}\Service Center Setup PC.exe
    AddRemove-{01D57CF6-B5BC-4D03-AFF5-7960CFBD05A9} - c:\programdata\{B7072B15-6E80-42FF-A9AE-4E62AF2B2418}\Guitar Rig 5 Setup PC.exe
    AddRemove-{0886900B-B2F3-452C-B580-60F1253F7F80} - c:\programdata\{30FA7941-4170-4C83-A9A8-FDF01C431704}\Controller Editor Setup PC.exe
    AddRemove-{0B8565BA-BAD5-4732-B122-5FD78EFC50A9} - c:\programdata\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14}\Service Center Setup PC.exe
    AddRemove-{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1 - c:\program files (x86)\Wondershare\MobileTrans\unins000.exe
    AddRemove-{2930FB47-6452-4476-BF16-D77F748646DB} - c:\programdata\{B0CAD5CC-867E-473E-B55F-339F9635A45D}\Guitar Rig Mobile IO Setup PC.exe
    AddRemove-{7930FB47-6452-4476-BF16-D77F748646DB} - c:\programdata\{CB28D9D3-6B5D-4AFA-BA37-B4AFAAAF71B9}\Guitar Rig Session IO Setup PC.exe
    AddRemove-{7f51bdb9-ee21-49ee-94d6-90afc321780e} - c:\programdata\Package Cache\{7f51bdb9-ee21-49ee-94d6-90afc321780e}\vcredist_x64.exe
    AddRemove-{8B370339-DB24-449E-A675-930650D421CF} - c:\progra~3\INSTAL~1\{8B370~1\Setup.exe
    AddRemove-{933C74FA-EAD1-46A9-A442-A2F348DF560C} - c:\progra~3\INSTAL~1\{933C7~1\Setup.exe
    AddRemove-{95716cce-fc71-413f-8ad5-56c2892d4b3a} - c:\programdata\Package Cache\{95716cce-fc71-413f-8ad5-56c2892d4b3a}\vcredist_x86.exe
    AddRemove-{a1909659-0a08-4554-8af1-2175904903a1} - c:\programdata\Package Cache\{a1909659-0a08-4554-8af1-2175904903a1}\vcredist_x64.exe
    AddRemove-{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1 - c:\program files (x86)\Wondershare\Dr.Fone for iOS\unins000.exe
    AddRemove-{B962AD08-335F-46f7-A182-257D37672E5C} - c:\programdata\{5A23829C-A66E-47B0-AD50-21A3FFE6C325}\Rig Kontrol 3 Setup PC.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{767DFF67-0300-6B6A-87D5-805BCC7961AE}*]
    "haipnigdmcfjeinn"=hex:6a,61,67,6a,66,64,69,6d,66,67,6e,67,64,6b,6c,68,6a,6e,
    6a,65,00,01
    "iacadjjaaaklgookgh"=hex:6a,61,67,6a,66,64,69,6d,66,67,6e,67,64,6b,6c,68,6a,6e,
    6a,65,00,ff
    "habpipldcopghfbp"=hex:70,62,62,65,66,6b,67,6f,63,67,66,6d,61,67,68,68,61,69,
    64,6f,6b,6b,69,62,69,61,6a,6a,67,62,6e,61,62,69,6d,70,69,6a,6e,62,65,61,68,\
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_20_0_0_306_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_20_0_0_306_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
    "Version"=hex:65,a0,6f,f8,2d,14,41,16,36,d9,c1,fe,ec,d5,da,cd,35,50,54,ef,17,
    80,fa,54,0a,67,d8,94,cd,4c,fc,e3,9e,24,7c,61,01,f2,98,88,09,97,b6,c0,69,87,\
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{767DFF67-0300-6B6A-87D5-805BCC7961AE}\InProcServer32*]
    "jaeanobnfcclaeaodnkl"=hex:6a,61,67,6a,66,64,69,6d,66,67,6e,67,64,6b,6c,68,6a,
    6e,6a,65,00,ff
    "iaeahodoaodnfajlag"=hex:6a,61,67,6a,66,64,69,6d,66,67,6e,67,64,6b,6c,68,6a,6e,
    6a,65,00,ff
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_20_0_0_306_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_20_0_0_306_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.20"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,4f,00,46,00,\
    .
    [HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
    "Version"=hex:65,a0,6f,f8,2d,14,41,16,36,d9,c1,fe,ec,d5,da,cd,35,50,54,ef,17,
    80,fa,54,0a,67,d8,94,cd,4c,fc,e3,9e,24,7c,61,01,f2,98,88,09,97,b6,c0,69,87,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2016-04-04 11:33:59
    ComboFix-quarantined-files.txt 2016-04-04 10:33
    ComboFix2.txt 2016-03-31 15:31
    .
    Pre-Run: 67,610,030,080 bytes free
    Post-Run: 67,122,221,056 bytes free
    .
    - - End Of File - - E374CA6B7FAFC7FDC6B8469636C98F8A
     
  14. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

    • Double click to run it.
    • Make sure you checkmark Addition.txt box.
    • Press Scan button.
    • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
     
  15. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi here is FRST.txt
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
    Ran by a (administrator) on A-PC (05-04-2016 07:11:56)
    Running from C:\Users\a\Desktop
    Loaded Profiles: a (Available Profiles: a)
    Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: FF)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
    (Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
    (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
    (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
    (Microsoft Corporation) C:\Windows\System32\wisptis.exe
    (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
    (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
    (IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
    (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
    (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
    (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2730616 2015-09-28] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] => C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
    Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation)
    ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
    ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
    ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
    ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2010-02-10] (Autodesk, Inc.)
    ShellIconOverlayIdentifiers-x32: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\SysWOW64\AcSignIcon.dll [2007-02-13] (Autodesk, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EasySetPackage.lnk [2015-08-25]
    ShortcutTarget: EasySetPackage.lnk -> C:\Program Files (x86)\LG Soft India\EasySetPackage\bin\EasySetPackage.exe ()

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Winsock: Catalog5-x64 01 C:\Windows\System32\mswsock.dll [327168 2013-09-08] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{5F96EEFF-043E-470A-85AA-1D0C59A2263E}: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{8B3C0D3D-5D5F-4D8A-BB9A-18A93E642CB3}: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{A66457FB-76D7-44A4-BFA0-D4C23D5733A4}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-522234228-4192544273-3428825822-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
    BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll [2010-04-28] (Microsoft Corporation)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
    BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
    BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
    BHO-x32: ContributeBHO Class -> {074C1DC5-9320-4A9A-947D-C042949C6216} -> C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27] (Adobe Systems, Inc.)
    BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-08] (Oracle Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
    BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-08] (Oracle Corporation)
    BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)
    Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27] (Adobe Systems, Inc.)
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
    Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
    Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

    FireFox:
    ========
    FF ProfilePath: C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\ijupd536.default-1430291221738
    FF DefaultSearchEngine: DuckDuckGo
    FF Homepage: about:home
    FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-29] ()
    FF Plugin: @microsoft.com/GENUINE -> C:\windows\system32\Wat\npWatWeb.dll [2010-12-26] (Microsoft Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-11-05] (Adobe Systems)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-29] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
    FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-08] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-08] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> C:\windows\system32\Wat\npWatWeb.dll [2010-12-26] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
    FF Plugin-x32: @rooms.hp.com -> C:\Program Files (x86)\Hewlett-Packard\HP Virutal Rooms Client Launcher Plugin\nphpvrl.dll [2011-03-29] ( )
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
    FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.5 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2010-09-02] (Wacom, Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-09-12] (Adobe Systems Inc.)
    FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-11-05] (Adobe Systems)
    FF Plugin-x32: nuance.com/DragonRIAPlugin -> C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\npDgnRia.dll [2012-07-18] (Nuance Communications Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll [2010-03-27] (Adobe Systems, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2013-05-18] (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2013-05-18] (Apple Inc.)
    FF Extension: Adblock Plus - C:\Users\a\AppData\Roaming\Mozilla\Firefox\Profiles\ijupd536.default-1430291221738\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-03-09]
    FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-03-06] [not signed]
    FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-03-06] [not signed]
    FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} [2016-03-06] [not signed]
    FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-04-01] [not signed]
    FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2016-03-06] [not signed]
    FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
    FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-06] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
    FF Extension: Adobe Contribute Toolbar - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2008-09-06] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi
    FF Extension: Dragon NaturallySpeaking Rich Internet Application Support - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\ffShim.xpi [2012-07-18] [not signed]
    FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
    FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-02-17] [not signed]

    Chrome:
    =======
    CHR HKU\S-1-5-21-522234228-4192544273-3428825822-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
    CHR HKLM-x32\...\Chrome\Extension: [mikhcaiakabeeokmenglcdebplfdjicn] - C:\Program Files (x86)\Nuance\NaturallySpeaking12\Program\chromeShim.crx [2012-07-18]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [85096 2011-02-07] (Autodesk)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
    S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2010-12-26] (Macrovision Europe Ltd.) [File not signed]
    R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-09-28] (NVIDIA Corporation)
    S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
    R2 nlsX86cc; C:\windows\SysWOW64\nlssrv32.exe [66560 2011-12-19] (Nalpeiron Ltd.) [File not signed]
    R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-09-28] (NVIDIA Corporation)
    R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568632 2015-09-28] (NVIDIA Corporation)
    R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2266160 2016-03-03] (IBM Corp.)
    S4 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] () [File not signed]
    S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
    S2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3000664 2015-01-06] (Samsung Electronics CO., LTD.)
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    S3 LGDDCDevice; C:\windows\SysWOW64\LGI2CDriver.sys [16384 2009-12-22] (LG Soft India) [File not signed]
    S3 LGII2CDevice; C:\windows\SysWOW64\LGPII2CDriver.sys [19456 2009-12-22] (LG Soft India) [File not signed]
    S3 libwamf; C:\Windows\System32\DRIVERS\libwamf.sys [15664 2016-04-04] (Windows (R) Win 7 DDK provider)
    S3 libwasys; C:\Windows\System32\DRIVERS\libwasys.sys [28464 2016-04-04] ()
    S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [40904 2010-02-17] (McAfee, Inc.)
    S3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [49480 2010-02-17] (McAfee, Inc.)
    R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-09-28] (NVIDIA Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
    R1 RapportCerberus_1507082; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507082.sys [972896 2016-03-07] (IBM Corp.)
    R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [514336 2016-03-03] (IBM Corp.)
    R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [152320 2016-03-03] (IBM Corp.)
    R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [407168 2016-03-03] (IBM Corp.)
    R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [507424 2016-03-03] (IBM Corp.)
    S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2010-09-17] (Windows (R) 2003 DDK 3790 provider)
    U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2015-05-25] (Seiko Epson Corporation)
    U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-04-03] ()
    R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S4 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S4 tsusbhub; system32\drivers\tsusbhub.sys [X]
    S4 VGPU; System32\drivers\rdvgkmd.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-04-05 07:11 - 2016-04-05 07:12 - 00022931 _____ C:\Users\a\Desktop\FRST.txt
    2016-04-05 07:11 - 2016-04-05 07:11 - 02374144 _____ (Farbar) C:\Users\a\Downloads\FRST64.exe
    2016-04-05 07:11 - 2016-04-05 07:11 - 02374144 _____ (Farbar) C:\Users\a\Desktop\FRST64.exe
    2016-04-04 11:34 - 2016-04-04 11:34 - 00025072 _____ C:\ComboFix.txt
    2016-04-04 10:13 - 2016-04-04 10:13 - 00028464 _____ C:\windows\system32\Drivers\libwasys.sys
    2016-04-04 10:13 - 2016-04-04 10:13 - 00015664 _____ (Windows (R) Win 7 DDK provider) C:\windows\system32\Drivers\libwamf.sys
    2016-04-04 10:12 - 2016-04-04 10:12 - 07029896 _____ () C:\Users\a\Downloads\OESISEndpointAssessmentTool.exe
    2016-04-03 13:23 - 2016-04-03 13:27 - 00287224 _____ C:\windows\ntbtlog.txt
    2016-04-03 12:39 - 2016-04-03 12:39 - 00347816 _____ (Microsoft Corporation) C:\Users\a\Downloads\MicrosoftFixit.IEPerformance.RNP.Run.exe
    2016-04-03 11:38 - 2016-04-03 11:39 - 00004592 _____ C:\Users\a\Desktop\JRT.txt
    2016-04-03 11:16 - 2016-04-03 11:16 - 00001229 _____ C:\Users\a\Desktop\AdwCleaner[C1].txt
    2016-04-03 11:01 - 2016-04-03 11:08 - 00000000 ____D C:\AdwCleaner
    2016-04-03 11:00 - 2016-04-03 11:00 - 00001157 _____ C:\Users\a\Desktop\mbam03042016.txt
    2016-04-03 10:15 - 2016-04-03 10:15 - 00006600 _____ C:\Users\a\Desktop\rk_F307.tmp.txt
    2016-04-03 10:15 - 2016-04-03 10:15 - 00006600 _____ C:\Users\a\Desktop\rk_F25B.tmp.txt
    2016-04-03 10:13 - 2016-04-03 10:13 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
    2016-04-03 10:13 - 2016-04-03 10:13 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2016-04-03 10:13 - 2016-04-03 10:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2016-04-03 10:12 - 2016-04-03 10:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-04-03 10:12 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
    2016-04-03 10:12 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
    2016-04-03 10:12 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
    2016-04-03 09:24 - 2016-04-03 09:27 - 00024688 _____ C:\windows\system32\Drivers\TrueSight.sys
    2016-04-03 09:23 - 2016-04-03 09:26 - 00000000 ____D C:\ProgramData\RogueKiller
    2016-04-03 09:00 - 2016-04-03 09:00 - 00003438 _____ C:\windows\System32\Tasks\UninstallMonitor
    2016-04-03 08:59 - 2016-04-03 08:59 - 00001641 _____ C:\Users\a\Desktop\Advanced Uninstaller PRO 11.lnk
    2016-04-03 08:59 - 2016-04-03 08:59 - 00001525 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO 11.lnk
    2016-04-02 20:28 - 2016-04-02 20:35 - 19311728 _____ (Innovative Solutions ) C:\Users\a\Downloads\Advanced_Uninstaller11.exe
    2016-04-02 18:55 - 2016-04-02 18:55 - 00000000 ____D C:\zoek
    2016-04-02 17:31 - 2016-04-02 17:31 - 00000458 _____ C:\Local Disk (D) - Shortcut.lnk
    2016-04-02 12:42 - 2016-04-02 12:44 - 22851472 _____ (Malwarebytes ) C:\Users\a\Desktop\mbam-setup-2.2.1.1043.exe
    2016-04-02 12:42 - 2016-04-02 12:42 - 03102720 _____ C:\Users\a\Desktop\adwcleaner_5.108.exe
    2016-04-02 12:41 - 2016-04-02 12:41 - 01610352 _____ (Malwarebytes) C:\Users\a\Desktop\JRT.exe
    2016-04-02 12:40 - 2016-04-02 12:42 - 19655240 _____ C:\Users\a\Desktop\RogueKiller.exe
    2016-04-02 11:10 - 2016-04-02 18:58 - 00003032 _____ C:\runcheck.txt
    2016-04-02 11:10 - 2016-04-02 12:06 - 00000000 ____D C:\zoek_backup
    2016-04-02 11:09 - 2016-04-02 11:09 - 01309184 _____ C:\Users\a\Desktop\zoek.exe
    2016-04-01 13:13 - 2016-04-01 13:37 - 00062609 _____ C:\Users\a\Downloads\Addition.txt
    2016-04-01 12:59 - 2016-04-01 13:37 - 00039123 _____ C:\Users\a\Downloads\FRST.txt
    2016-04-01 12:48 - 2016-04-05 07:11 - 00000000 ____D C:\FRST
    2016-04-01 11:06 - 2016-04-04 10:21 - 00000000 ____D C:\$AVG
    2016-04-01 10:29 - 2016-04-01 10:57 - 240607256 _____ (AVG Technologies CZ, s.r.o.) C:\Users\a\Downloads\AVG_Internet_Security_x64_696.exe
    2016-04-01 03:50 - 2016-04-01 16:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
    2016-03-31 15:32 - 2011-06-26 07:45 - 00256000 _____ C:\windows\PEV.exe
    2016-03-31 15:32 - 2010-11-07 18:20 - 00208896 _____ C:\windows\MBR.exe
    2016-03-31 15:32 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00098816 _____ C:\windows\sed.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00080412 _____ C:\windows\grep.exe
    2016-03-31 15:32 - 2000-08-31 01:00 - 00068096 _____ C:\windows\zip.exe
    2016-03-31 15:31 - 2016-04-04 11:34 - 00000000 ____D C:\Qoobox
    2016-03-31 15:29 - 2016-03-31 16:22 - 00000000 ____D C:\windows\erdnt
    2016-03-31 14:47 - 2016-03-31 14:47 - 00002060 _____ C:\Users\a\Desktop\aswMBR.txt
    2016-03-31 14:47 - 2016-03-31 14:47 - 00000512 _____ C:\Users\a\Desktop\MBR.dat
    2016-03-31 14:41 - 2016-04-04 10:50 - 05658312 ____R (Swearware) C:\Users\a\Desktop\ComboFix.exe
    2016-03-31 14:40 - 2016-03-31 14:42 - 05198336 _____ (AVAST Software) C:\Users\a\Desktop\aswMBR.exe
    2016-03-31 14:27 - 2016-03-31 14:36 - 00000000 ____D C:\Users\a\Desktop\destop_shortcuts
    2016-03-31 14:26 - 2016-03-31 14:26 - 00000000 ____D C:\Users\a\Desktop\cards_etc
    2016-03-31 12:45 - 2016-03-31 12:32 - 00688992 _____ (Swearware) C:\Users\a\Desktop\dds.scr
    2016-03-31 12:32 - 2016-03-31 12:32 - 00688992 _____ (Swearware) C:\Users\a\Downloads\dds.scr
    2016-03-29 22:43 - 2016-03-29 22:43 - 00000000 ____D C:\Users\a\Downloads\backups
    2016-03-29 22:24 - 2016-03-29 22:25 - 00388608 _____ (Trend Micro Inc.) C:\Users\a\Downloads\HijackThis.exe
    2016-03-29 21:58 - 2016-03-29 21:58 - 00003820 _____ C:\windows\System32\Tasks\Opera scheduled Autoupdate 1459285081
    2016-03-29 21:58 - 2016-03-29 21:58 - 00001135 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
    2016-03-29 21:58 - 2016-03-29 21:58 - 00000000 ____D C:\Users\a\AppData\Roaming\Opera Software
    2016-03-29 21:58 - 2016-03-29 21:58 - 00000000 ____D C:\Users\a\AppData\Local\Opera Software
    2016-03-29 21:57 - 2016-04-04 21:58 - 00000000 ____D C:\Program Files (x86)\Opera
    2016-03-29 21:47 - 2016-03-29 21:56 - 37696232 _____ (Opera Software) C:\Users\a\Downloads\Opera_36.0.2130.32_Setup.exe
    2016-03-29 21:45 - 2016-03-29 21:46 - 00724888 _____ (Opera Software) C:\Users\a\Downloads\OperaSetup.exe
    2016-03-29 20:43 - 2016-03-29 20:53 - 19904704 _____ (Adobe Systems Incorporated) C:\Users\a\Downloads\install_flash_player(2).exe
    2016-03-21 11:31 - 2016-03-30 02:21 - 00000000 ____D C:\Program Files (x86)\EPUB File Reader
    2016-03-21 11:31 - 2016-03-21 11:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPUB File Reader
    2016-03-20 11:17 - 2016-03-20 12:23 - 00000000 ____D C:\Users\Public\Downloads\Badens
    2016-03-17 19:08 - 2016-03-17 19:09 - 02606578 _____ C:\Users\a\Downloads\DDLValley.cool_G-e-n-I-u-s-_-I-n-t-e-l-l-I-g-e-n-c-e-.pdf
    2016-03-13 11:49 - 2016-03-13 12:02 - 29312924 _____ C:\Users\a\Downloads\DDLValley.cool_N.Sc-12.M.2016.pdf
    2016-03-10 20:03 - 2016-03-10 20:03 - 00574158 _____ C:\Users\Public\Downloads\iexplorer.reg
    2016-03-10 00:01 - 2016-03-10 00:01 - 00001413 _____ C:\Users\a\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2016-03-09 23:30 - 2016-03-09 23:46 - 55915216 _____ (Microsoft Corporation) C:\Users\a\Downloads\IE11-Windows6.1-x64-en-us.exe
    2016-03-09 23:28 - 2016-03-09 23:29 - 02077392 _____ (Microsoft Corporation) C:\Users\a\Downloads\IE11-Windows6.1.exe
    2016-03-09 21:45 - 2016-03-09 22:47 - 00000000 ____D C:\windows\Panther
    2016-03-08 18:55 - 2016-03-08 18:55 - 00328409 _____ C:\Users\a\AppData\Local\census.cache
    2016-03-08 18:55 - 2016-03-08 18:55 - 00185089 _____ C:\Users\a\AppData\Local\ars.cache
    2016-03-08 17:44 - 2016-03-08 17:45 - 02405672 _____ (Trend Micro Inc.) C:\Users\a\Downloads\HousecallLauncher64(1).exe
    2016-03-08 17:30 - 2016-03-08 17:37 - 47521472 _____ C:\Users\Public\Downloads\Firefox Setup 43.0.1.exe
    2016-03-08 16:58 - 2016-03-08 16:58 - 00987728 _____ (Google Inc.) C:\Users\Public\Downloads\ChromeSetup.exe
    2016-03-08 16:30 - 2016-03-08 16:34 - 58082952 _____ (Microsoft Corporation) C:\Users\Public\Downloads\EIE11_EN-US_MCM_WIN764.EXE
    2016-03-08 14:22 - 2016-03-08 16:00 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
    2016-03-08 14:20 - 2016-03-08 14:21 - 01524224 _____ C:\Users\a\Downloads\adwcleaner_5.101.exe
    2016-03-08 13:54 - 2016-03-08 16:00 - 00000000 ____D C:\Users\a\AppData\LocalLow\Adblock Plus for IE
    2016-03-08 13:54 - 2016-03-08 16:00 - 00000000 ____D C:\Program Files\Adblock Plus for IE
    2016-03-08 13:50 - 2016-03-08 13:52 - 06468104 _____ ( ) C:\Users\a\Downloads\adblockplusie-1.5.exe
    2016-03-07 17:17 - 2016-03-07 17:17 - 00000000 ____D C:\Users\Public\Downloads\FL studio tutorial by lynda.com
    2016-03-07 17:10 - 2016-03-07 17:11 - 00000000 ____D C:\Users\Public\Downloads\melodyne_tut
    2016-03-06 22:09 - 2016-03-07 12:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2016-03-06 11:15 - 2016-03-06 11:24 - 28623077 _____ C:\Users\a\Downloads\DDLValley.cool_New_Scientist_-_5_March_2016-P2P.pdf

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-04-05 07:11 - 2009-07-14 05:45 - 00029264 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-04-05 07:11 - 2009-07-14 05:45 - 00029264 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-04-05 06:45 - 2013-02-09 19:08 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    2016-04-04 19:44 - 2013-02-09 19:08 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    2016-04-04 11:42 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\NDF
    2016-04-04 11:25 - 2009-07-14 03:34 - 00000215 _____ C:\windows\system.ini
    2016-04-04 10:46 - 2015-06-20 16:54 - 00000419 _____ C:\windows\BRWMARK.INI
    2016-04-04 10:46 - 2015-06-20 16:54 - 00000027 _____ C:\windows\BRPP2KA.INI
    2016-04-04 10:40 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
    2016-04-04 10:39 - 2015-06-02 13:27 - 00000000 ____D C:\Users\a\AppData\Local\Avg
    2016-04-04 10:39 - 2012-03-15 21:09 - 00000000 ____D C:\ProgramData\MFAData
    2016-04-04 10:28 - 2012-03-15 21:19 - 00000000 ____D C:\Program Files (x86)\AVG
    2016-04-04 10:22 - 2015-10-23 14:02 - 00000000 ____D C:\Users\a\AppData\Local\AvgSetupLog
    2016-04-03 12:51 - 2009-07-14 04:20 - 00000000 ____D C:\PerfLogs
    2016-04-03 12:41 - 2011-03-20 08:38 - 00000000 ____D C:\Users\a\AppData\Local\ElevatedDiagnostics
    2016-04-03 08:59 - 2010-12-29 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO
    2016-04-02 17:25 - 2015-03-12 19:28 - 00000000 ____D C:\Users\a\AppData\Local\CrashDumps
    2016-04-02 17:18 - 2012-07-17 16:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2016-04-02 17:05 - 2015-02-11 10:31 - 00007634 _____ C:\Users\a\AppData\Local\Resmon.ResmonCfg
    2016-04-02 12:06 - 2010-12-24 20:53 - 00000000 ____D C:\Users\a
    2016-04-01 11:06 - 2015-07-14 18:24 - 00000000 ____D C:\ProgramData\AVG
    2016-03-31 16:31 - 2013-01-09 17:46 - 00000000 ____D C:\Users\systemprofile
    2016-03-31 16:19 - 2009-07-14 06:13 - 00801128 _____ C:\windows\system32\PerfStringBackup.INI
    2016-03-31 16:19 - 2009-07-14 04:20 - 00000000 ____D C:\windows\inf
    2016-03-31 14:25 - 2013-02-10 13:05 - 00000000 ____D C:\Users\a\Desktop\desktop_folders
    2016-03-30 02:21 - 2015-04-07 10:00 - 00000000 ___SD C:\windows\system32\GWX
    2016-03-30 02:21 - 2013-10-11 12:33 - 00000000 ____D C:\Users\a\AppData\Roaming\Azureus
    2016-03-30 02:21 - 2009-07-14 04:20 - 00000000 ____D C:\windows\registration
    2016-03-29 21:38 - 2015-07-14 19:47 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
    2016-03-29 20:54 - 2015-07-14 19:47 - 00003770 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
    2016-03-29 20:54 - 2015-04-03 16:26 - 00797376 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
    2016-03-29 20:54 - 2015-04-03 16:26 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-03-13 11:27 - 2015-03-01 16:41 - 00000000 ____D C:\Users\a\AppData\Roaming\tox
    2016-03-09 21:36 - 2013-02-09 19:08 - 00000000 ____D C:\Program Files (x86)\Google
    2016-03-09 21:36 - 2013-01-21 18:07 - 00000000 ____D C:\Users\a\AppData\Local\Google
    2016-03-09 20:04 - 2013-10-11 12:33 - 00000000 ____D C:\Users\a\Documents\Vuze Downloads
    2016-03-09 15:19 - 2010-12-28 02:31 - 00000000 ____D C:\Users\a\AppData\Roaming\vlc
    2016-03-08 17:43 - 2012-07-17 16:53 - 00000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2016-03-08 16:00 - 2014-12-30 22:49 - 00000000 ____D C:\windows\system32\appraiser
    2016-03-08 16:00 - 2014-05-03 10:10 - 00000000 ___SD C:\windows\system32\CompatTel
    2016-03-08 16:00 - 2010-08-04 03:40 - 00000000 ____D C:\ProgramData\WinClon
    2016-03-07 18:31 - 2010-12-24 20:54 - 00000000 ____D C:\Users\a\AppData\Local\Adobe
    2016-03-07 14:40 - 2013-09-13 17:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection

    ==================== Files in the root of some directories =======

    2011-12-14 18:29 - 2011-12-14 18:29 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe BMP Format CS5 Prefs
    2011-02-28 18:07 - 2013-05-22 16:30 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2013-02-27 15:46 - 2016-01-06 13:34 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe PNG Format CS6 Prefs
    2010-12-27 20:47 - 2013-01-18 11:43 - 0002315 _____ () C:\Users\a\AppData\Roaming\SAS7_000.DAT
    2011-06-02 13:23 - 2011-09-05 15:33 - 0001456 _____ () C:\Users\a\AppData\Local\Adobe Save for Web 12.0 Prefs
    2016-03-08 18:55 - 2016-03-08 18:55 - 0185089 _____ () C:\Users\a\AppData\Local\ars.cache
    2016-03-08 18:55 - 2016-03-08 18:55 - 0328409 _____ () C:\Users\a\AppData\Local\census.cache
    2010-12-28 21:50 - 2010-12-28 21:50 - 0003584 _____ () C:\Users\a\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2008-09-03 16:10 - 2008-09-03 16:10 - 0000036 _____ () C:\Users\a\AppData\Local\housecall.guid.cache
    2016-04-04 10:13 - 2016-04-04 10:17 - 0001071 _____ () C:\Users\a\AppData\Local\infection.log
    2015-08-14 15:44 - 2015-08-14 15:49 - 0000528 _____ () C:\Users\a\AppData\Local\Player.ini
    2015-02-11 10:31 - 2016-04-02 17:05 - 0007634 _____ () C:\Users\a\AppData\Local\Resmon.ResmonCfg
    2011-09-15 16:17 - 2011-09-15 16:17 - 0000096 ____H () C:\Users\a\AppData\Local\vwr_lic_p.dat
    2010-12-24 20:55 - 2010-01-16 08:18 - 0131368 _____ () C:\ProgramData\FullRemove.exe
    2010-12-27 00:59 - 2013-12-06 17:42 - 0000020 ____H () C:\ProgramData\PKP_DLdy.DAT
    2010-12-26 19:18 - 2015-02-15 12:05 - 0000020 ____H () C:\ProgramData\PKP_DLea.DAT
    2013-03-17 14:39 - 2013-03-17 15:05 - 0000000 ____H () C:\ProgramData\PKP_DLeh.DAT
    2010-08-04 03:37 - 2010-08-04 03:37 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
    2010-08-04 03:35 - 2010-08-04 03:36 - 0000106 _____ () C:\ProgramData\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.log
    2010-08-04 03:32 - 2010-08-04 03:33 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2010-08-04 03:36 - 2010-08-04 03:37 - 0000110 _____ () C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log
    2010-08-04 03:31 - 2010-08-04 03:32 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
    2010-08-04 03:33 - 2010-08-04 03:35 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\SysWOW64\wininit.exe => File is digitally signed
    C:\windows\explorer.exe => File is digitally signed
    C:\windows\SysWOW64\explorer.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\SysWOW64\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\SysWOW64\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\SysWOW64\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\dnsapi.dll => File is digitally signed
    C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


    ATTENTION: ==> Could not access BCD.


    LastRegBack: 2016-03-29 00:57

    ==================== End of FRST.txt ============================

    Thanks
     
  16. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    I still need Addition.txt log.
     
  17. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Sorry part1
    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by a (2016-04-05 07:12:59)
    Running from C:\Users\a\Desktop
    Windows 7 Ultimate Service Pack 1 (X64) (2010-12-24 19:53:29)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    a (S-1-5-21-522234228-4192544273-3428825822-1000 - Administrator - Enabled) => C:\Users\a
    Administrator (S-1-5-21-522234228-4192544273-3428825822-500 - Administrator - Disabled)
    ASPNET (S-1-5-21-522234228-4192544273-3428825822-1003 - Limited - Enabled)
    Guest (S-1-5-21-522234228-4192544273-3428825822-501 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    A4DeskPro v5.80 (HKLM-x32\...\a4deskpro_webunion_is1) (Version: - WebUnion Media Ltd.)
    ACAD DWG to Image Converter v7.9.2 (HKLM-x32\...\ACAD DWG to Image Converter_is1) (Version: - Copyright(C) 2005-2014 AcroCAD Inc.)
    Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{0F347A49-E36C-4639-8D2E-003AD408B8B2}) (Version: 1.5 - Eyeo GmbH)
    Adobe After Effects CS5 Third Party Content (HKLM-x32\...\{2AF31A97-817A-4D06-8210-4F789A0FF908}) (Version: 10.0.2 - Adobe Systems Incorporated)
    Adobe After Effects CS5 Third Party Royalty Content (HKLM-x32\...\{8A5387E2-7F1A-4FDD-883F-511DC8AA2295}) (Version: 10.0.2 - Adobe Systems Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
    Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
    Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.2.1.260 - Adobe Systems Incorporated)
    Adobe Creative Suite 5 Master Collection (HKLM-x32\...\{FBB02B04-C034-4382-A3F6-57416E2752C4}) (Version: 5.0 - Adobe Systems Incorporated)
    Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.6 - Adobe Systems Incorporated)
    Adobe Edge Animate (HKLM-x32\...\{181241DD-2FC2-4CF9-94CE-97F3E37D6F0B}) (Version: 1.5 - Adobe Systems Incorporated)
    Adobe Edge Inspect (HKLM-x32\...\{D830EE30-BF0C-42B7-A13C-927A379353ED}) (Version: 1.0.388 - Adobe Systems Incorporated)
    Adobe Edge Reflow Preview (HKLM-x32\...\{4932BCEA-E142-4A41-B3D2-0934EBE24CB4}) (Version: 0.12.9232 - Adobe Systems Incorporated)
    Adobe Flash Builder 4.6 (HKLM-x32\...\{0802B79F-257C-4F91-9A1E-7A94588C636A}) (Version: 4.6 - Adobe Systems Incorporated)
    Adobe Flash Catalyst CS5.5 (HKLM-x32\...\{D8CCCF4C-C227-427C-B4BE-736657D2AB7E}) (Version: 1.5 - Adobe Systems Incorporated)
    Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated)
    Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
    Adobe Flash Professional CS5.5 (HKLM-x32\...\{23E445D5-FD83-4C50-A211-EB26A2975317}) (Version: 11.5 - Adobe Systems Incorporated)
    Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
    Adobe Photoshop CS6 (HKLM-x32\...\{D586BF67-0A61-4572-BE25-07B40C4CEDA1}) (Version: 13.0 - Adobe Systems Incorporated)
    Adobe Photoshop Lightroom 2.6 (HKLM-x32\...\{81CB77FF-9789-4337-A46E-185F7876AC40}) (Version: 2.6.1 - Adobe)
    Adobe Pixel Bender Toolkit 2 (HKLM-x32\...\{D5CC77BE-BC5B-424E-8E45-DF60AFF7BE9C}) (Version: 2.0 - Adobe Systems Incorporated)
    Adobe Premiere Pro CS5 Third Party Royalty Content (HKLM-x32\...\{4BD0D94C-C5CA-41CA-879B-928E55ADA18F}) (Version: 5.0.3 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
    Adobe Visual Communicator 3 (HKLM-x32\...\InstallShield_{A5335A43-C886-4447-9885-013E62796E7C}) (Version: 3.0.3129.0 - Adobe Systems Incorporated)
    Advanced Uninstaller PRO - Version 10 (HKLM-x32\...\AU10_is1) (Version: 10 - Innovative Solutions)
    Advanced Uninstaller PRO - Version 11 (HKLM-x32\...\AU11_is1) (Version: 11.71.0.334 - Innovative Solutions)
    Akamai NetSession Interface (HKU\S-1-5-21-522234228-4192544273-3428825822-1000\...\Akamai) (Version: - Akamai Technologies, Inc)
    Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach)
    Atheros Client Installation Program (HKLM-x32\...\{D1434266-0486-4469-B338-A60082CC04E1}) (Version: 1.0.5.0621 - Atheros)
    Auction Alert 2.1.0 (HKLM-x32\...\Auction Alert_is1) (Version: - Auction Alert)
    AutoCAD Architecture 2008 (HKLM-x32\...\AutoCAD Architecture 2008) (Version: 5.5.235.0 - Autodesk)
    AutoCAD Architecture 2008 (x32 Version: 5.5.235.0 - Autodesk) Hidden
    AutoCAD Architecture 2011 - English (HKLM\...\AutoCAD Architecture 2011 - English) (Version: 6.5.49.0 - Autodesk)
    AutoCAD Architecture 2011 - English (Version: 6.5.49.0 - Autodesk) Hidden
    AutoCAD Architecture 2011 Language Pack - English (Version: 18.1.49.0 - Autodesk) Hidden
    Autodesk DWF Viewer 7 (HKLM-x32\...\{9A346205-EA92-4406-B1AB-50379DA3F057}) (Version: 7.2.0 - Autodesk, Inc.)
    Autodesk Material Library 2011 (HKLM-x32\...\{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}) (Version: 2.0.0.49 - Autodesk)
    Autodesk Material Library 2011 Base Image library (HKLM-x32\...\{CD1E078C-A6B9-47DA-B035-6365C85C7832}) (Version: 2.0.0.49 - Autodesk)
    Autodesk Stitcher Unlimited 2009 (HKLM-x32\...\{AACCA3ED-9F2F-4336-8A80-B09D90DBB91B}) (Version: - )
    Barra di ricerca di Encarta (64 bit) (HKLM\...\{08244040-959A-4B0D-8825-2C533F0DDB19}) (Version: 1.0.0 - Microsoft)
    BatteryLifeExtender (HKLM-x32\...\{74A579FB-EB06-497D-B194-01590D6FE51A}) (Version: 1.0.5 - Samsung)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Business Plan Pro 11.0 (HKLM-x32\...\{7E0E01E6-8F0B-428B-9A06-668104DA6872}) (Version: 11.14.0002 - Palo Alto Software, Inc.)
    Camera Control Pro 2 (HKLM-x32\...\{FE96C49B-DB90-405E-A00E-09E38372F880}) (Version: 2.14.0 - Nikon)
    ControlMyNikon version 3.0 (HKLM-x32\...\{C851A57F-0745-4B2D-9F64-950A53CC77C0}_is1) (Version: 3.0 - Tetherscript Technology Corp.)
    DirectWave VSTi (HKLM-x32\...\DirectWave VSTi) (Version: - Image-Line)
    DMG Extractor (HKU\S-1-5-21-522234228-4192544273-3428825822-1000\...\DMG Extractor) (Version: 1.2.1.0 - Reincubate Ltd)
    Dragon NaturallySpeaking 12 (HKLM-x32\...\{D5D422B9-6976-4E98-8DDF-9632CB515D7E}) (Version: 12.00.100 - Nuance Communications Inc.)
    Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.)
    Easy Network Manager (HKLM-x32\...\{F9557866-B4C8-4CE5-8508-0E386BDC20B2}) (Version: 4.3.3 - Samsung)
    Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 3.0.0.5 - Samsung Electronics Co.,Ltd.)
    EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung)
    EasySetPackage (HKLM-x32\...\{266725C1-716F-43AC-BBFB-4201131ED656}) (Version: 2.4 - LG Soft India)
    EpsonNet Config V4 (HKLM-x32\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.6.0 - Seiko Epson Corporation)
    eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
    FaceFilter v3.02 SE (HKLM-x32\...\{6020758E-57A9-41E3-AF20-8EE311EA6156}) (Version: 3.02.1720.1 - Reallusion Inc.)
    FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production)
    FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse)
    Filter Forge 3.006 (HKLM-x32\...\Filter Forge 3_is1) (Version: - Filter Forge, Inc.)
    FL Studio 12 (HKLM-x32\...\FL Studio 12) (Version: - Image-Line)
    FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version: - Image-Line)
    Flash Decompiler Trillix (HKLM-x32\...\Flash Decompiler Trillix_is1) (Version: 4.1 - Eltima Software)
    FlashDevelop 4.0.0 (HKLM-x32\...\FlashDevelop) (Version: 4.0.0-RC3 - FlashDevelop.org)
    Flashificator (HKLM-x32\...\com.Flashificator) (Version: 2.086 - UNKNOWN)
    Flashificator (x32 Version: 2.086 - UNKNOWN) Hidden
    FonePaw iOS Transfer 1.2.0 (HKLM-x32\...\{548859D3-48CF-4fcb-8E03-E7F488ADF2EA}_is1) (Version: 1.2.0 - FonePaw)
    GARDEN ORGANIZER DELUXE (S) (HKLM-x32\...\{C9F0AAB9-41D6-420A-8B41-0859BE4E960B}) (Version: 3.5 - PRIMASOFT PC, INC.)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
    Google Web Designer (HKLM-x32\...\{811767F4-C586-4673-A41F-E9D767497222}) (Version: 1.2.4.0 - Google Inc.)
    Helicon Focus 5.3.7 (HKLM-x32\...\Helicon Focus_is1) (Version: - Helicon Soft Ltd.)
    HP Virtual Rooms Client Launcher Plugin (HKLM-x32\...\{C0847D30-4B8A-11E0-98C0-80E2DED72085}) (Version: 1.0.0.1 - Hewlett-Packard)
    iClone v5.4 PRO (HKLM-x32\...\{E8EB9130-8C34-4DCE-A6C4-B1C5A399F616}) (Version: 5.4.2706.1 - Reallusion Inc.)
    IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
    IL Minihost Modular (HKLM-x32\...\IL Minihost Modular) (Version: - Image-Line)
    IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version: - Image-Line)
    InPixio Photo Maximizer Pro (HKLM-x32\...\{33DB8C17-40C9-4629-B6D4-05A4C7E8AA86}) (Version: 1.20.25799 - Micro Application)
    Instant Wire Cleaner 1.0 (HKLM-x32\...\{94F29B90-CED3-4DA5-9255-96E2BE4C38A3}_is1) (Version: - CPSSoftware)
    Intel A/V Codecs V2.0 (HKLM-x32\...\CodInstl) (Version: - )
    Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{1A8BA6CE-822D-4888-89E2-ACBF4308F271}) (Version: 13.02.0000 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.3.1001 - Intel Corporation)
    Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 - Intel Corporation)
    IsoBuster 2.7 (HKLM-x32\...\IsoBuster_is1) (Version: 2.7 - Smart Projects)
    iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
    iZotope Nectar 2 Production Suite (HKLM-x32\...\iZotope Nectar 2 Production Suite_is1) (Version: 2.03 - iZotope, Inc.)
    Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
    Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
    Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
    Kodak DIGITAL GEM Airbrush Professional Plug-In (HKLM-x32\...\{AD871377-A1A3-4D7B-AA5E-EB163E1202C6}) (Version: 2.1.0 - Eastman Kodak Company)
    Kodak DIGITAL GEM Professional Plug-In (HKLM-x32\...\{6B18F58C-6AAD-42D4-97A2-0EB12E949539}) (Version: 2.1.0 - Kodak's Austin Development Center)
    Kodak DIGITAL ROC Professional Plug-In (HKLM-x32\...\{47786DE3-7FCA-4F5D-B3D5-D15BFE3ABCD8}) (Version: 2.1.0 - Kodak's Austin Development Center)
    Kodak DIGITAL SHO Professional Plug-In (HKLM-x32\...\{E8EC6F5D-A8A0-44AB-A238-5D6047F725FC}) (Version: 2.1.0 - Kodak's Austin Development Center)
    Kolor Panotour Pro 1.8 (HKLM-x32\...\Panotour Pro 1.8) (Version: V1.8.0 - Kolor)
    KoolMoves Demo 8.1.0 (HKLM-x32\...\KoolMoves Demo_is1) (Version: 8.1.0 - Lucky Monkey Designs LLC)
    Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
    Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
    Marvell Miniport Driver (HKLM-x32\...\Marvell Miniport Driver) (Version: 11.45.4.3 - Marvell)
    Melodyne 3.1 (HKLM-x32\...\{A1F143D1-1F0D-44FB-A44B-71D4367D16DE}) (Version: 3.1.0200 - Celemony Software GmbH)
    Melodyne 3.1 (x32 Version: 3.1.0200 - Celemony Software GmbH) Hidden
    MFC80 (x32 Version: 1.00.0000 - Your Company Name) Hidden
    Microsoft - Math (HKLM-x32\...\{07243840-959A-4B0D-8825-2C533F0DDB19}) (Version: 2007 - Microsoft Corporation)
    Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
    Microsoft Expression Blend 3 (HKLM-x32\...\Blend_3.0.1927.0) (Version: 3.0.1927.0 - Microsoft Corporation)
    Microsoft Expression Blend 3 SDK (HKLM-x32\...\{0E837AF0-4C92-4077-83F0-D022073F17C0}) (Version: 1.0.1327.0 - Microsoft Corporation)
    Microsoft Expression Design 3 (HKLM-x32\...\Design_6.0.1739.0) (Version: 6.0.1739.0 - Microsoft Corporation)
    Microsoft Expression Encoder 3 (HKLM-x32\...\Encoder_3.0.1332.0) (Version: 3.0.1332.0 - Microsoft Corporation)
    Microsoft Expression Studio 3 (HKLM-x32\...\ExpressionStudio_3.0.1061.0) (Version: 3.0.1061.0 - Microsoft Corporation)
    Microsoft Expression Web 3 (HKLM-x32\...\Web_3.0.3813.0) (Version: 3.0.3813.0 - Microsoft Corporation)
    Microsoft Expression Web 3 SP1 (HKLM-x32\...\{752E90AC-3F11-4EA3-88EA-96441047EC31}) (Version: - Microsoft Corporation)
    Microsoft HealthVault Connection Center (HKLM-x32\...\HealthVault Connection Center) (Version: 4.1.3438.8024 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
    Microsoft Silverlight 3 SDK (HKLM-x32\...\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40624.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP1 English (HKLM-x32\...\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}) (Version: 3.5.5692.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
    Mozilla Firefox 45.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 45.0 (x86 en-US)) (Version: 45.0 - Mozilla)
    Mozilla Firefox 45.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 45.0.1 (x64 en-US)) (Version: 45.0.1 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.1.5918 - Mozilla)
    MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
    MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
    MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
    MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
    msvcrt_installer (HKLM-x32\...\{6068A42A-C1CF-45F2-9859-5DB16287FE5D}) (Version: 1.0.0 - SAH)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: - Native Instruments)
    Native Instruments Guitar Rig 5 (HKLM-x32\...\Native Instruments Guitar Rig 5) (Version: - Native Instruments)
    Native Instruments Guitar Rig Mobile I/O (HKLM-x32\...\Native Instruments Guitar Rig Mobile I/O) (Version: - Native Instruments)
    Native Instruments Guitar Rig Session I/O (HKLM-x32\...\Native Instruments Guitar Rig Session I/O) (Version: - Native Instruments)
    Native Instruments Rig Kontrol 3 (HKLM-x32\...\Native Instruments Rig Kontrol 3) (Version: - Native Instruments)
    Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments)
    Nikon Message Center (HKLM-x32\...\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.92.000 - Nikon)
    Nikon Message Center 2 (HKLM-x32\...\{B014EE44-9197-4513-9613-71E6EB1B514E}) (Version: 2.1.0 - Nikon)
    NikonCapture (HKLM-x32\...\{21DDC579-834B-4C14-8122-853994FA2214}) (Version: 4.0 - )
    NKRemote (HKLM-x32\...\{18F7C517-4870-4b6a-93E0-09CB4AC4FFB7}) (Version: v2.2.3 - Breeze Systems Ltd)
    Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia)
    NVIDIA GeForce Experience 2.6.1.10 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.6.1.10 - NVIDIA Corporation)
    NVIDIA Graphics Driver 341.81 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.81 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
    Omron Drivers for HealthVault (HKLM\...\{2C62BD6D-7937-406C-A8B9-C0B0CB2FFF1D}) (Version: 1.8.1.0 - Omron)
    Omron Health Management Software (HKLM-x32\...\{F6BA8EF2-A9F8-45B7-BD59-0A15DA9F7D68}) (Version: 1.31.0007 - Omron Healthcare)
    Opera Mobile Emulator (HKLM-x32\...\{1826D0CA-F479-4430-9EFE-86E8E783505B}_is1) (Version: - Opera Software ASA)
    Opera Stable 36.0.2130.32 (HKLM-x32\...\Opera 36.0.2130.32) (Version: 36.0.2130.32 - Opera Software)
    OSC Third Party Libraries (Version: 1.1 - NVIDIA Corporation) Hidden
    Oxygen XML Editor 10.0 (HKLM-x32\...\Oxygen XML Editor 10.0) (Version: - SyncRO Soft)
    Pano2VR - Garden Gnome Software (HKLM-x32\...\Pano2VR) (Version: - )
    Panoweaver 9.1 Professional Edition (HKLM-x32\...\Panoweaver910_pro_is1) (Version: - Easypano Holdings Inc.)
    PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
    PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
    PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
    Perfect Resize 7 (HKLM-x32\...\{FCADA4FF-142C-42A8-B73C-0A54A7F83345}) (Version: 7.0.6 - onOne Software)
    Photomatix Pro version 3.2.7 (HKLM\...\PhotomatixPro3x32_is1) (Version: 3.2.7 - HDRsoft Sarl)
    PhysicsEditor (HKLM-x32\...\PhysicsEditor) (Version: 1.0.5 - Andreas Loew)
    PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden
    QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
    RapidTyping (HKLM-x32\...\RapidTyping) (Version: 4.6.6 - RapidTyping Software)
    Rapport (Version: 3.5.1205.20 - Trusteer) Hidden
    Rapport (x32 Version: 3.5.1507.113 - Trusteer) Hidden
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6378 - Realtek Semiconductor Corp.)
    REALTEK Wireless LAN Software (HKLM-x32\...\{0F796312-289C-40CA-856C-9FBCF5E83342}) (Version: 0133.09.1202 - REALTEK Semiconductor Corp.)
    Room Arranger (HKLM-x32\...\Room Arranger) (Version: 7.2.1 - Jan Adamec)
    S Agent (Version: 1.1.51 - Samsung Electronics CO., LTD.) Hidden
    Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
    Samsung Recovery Solution 4 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 4.0.0.6 - Samsung)
    Samsung R-Series (HKLM-x32\...\{3EED7541-55F8-4DC6-B9CD-28762D71310E}) (Version: 1.0 - Samsung)
    Samsung Support Center (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.0.2 - Samsung)
    Samsung Update Plus (HKLM-x32\...\{D3F2FAA5-FEC4-42AA-9ABA-1F763919A2B5}) (Version: 2.0 - Samsung Electronics Co., Ltd.)
    SamsungMovie (HKLM-x32\...\{EFA6EF6A-9E0D-4CF0-91DD-B55D8632F65A}) (Version: 1.0.0 - Samsung)
    SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden
    SHIELD Wireless Controller Driver (Version: 2.6.1.10 - NVIDIA Corporation) Hidden
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
    Skype™ 7.2 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
    SMPlayer 16.1.0 (x64) (HKLM\...\SMPlayer) (Version: 16.1.0 - Ricardo Villalba)
    Snappixx for Windows 95/98/ME/NT/2K/XP (HKLM-x32\...\ST6UNST #1) (Version: - )
    Sothink SWF Decompiler (HKLM-x32\...\{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1) (Version: 5.3 - SourceTec Software Co., LTD)
    Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
    StitcherUnlimited2009 AdLM (HKLM-x32\...\{891BB3F0-F157-4C82-8882-F920D7E9D42F}) (Version: 1.0.0 - Autodesk)
    Strumenti e modelli didattici per Microsoft Office (HKLM-x32\...\{75F3A4B2-F6E8-434D-A2EF-DBBC016C6CB2}) (Version: 2.0 - Microsoft)
    Style Studio v3.8 (HKLM-x32\...\Style Studio 3.8_is1) (Version: 3.8.107 - OverZone Software)
    SW Update (HKLM-x32\...\{1687FC01-135F-4ADE-B828-B461CC74BD8A}) (Version: 2.2.4 - Samsung Electronics CO., LTD.)
    Sweet Home 3D version 4.4 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.10.0 - Synaptics Incorporated)
    TetherProLite (HKLM-x32\...\{7235F547-FB89-4836-BB1B-CD73DA400064}) (Version: 1.0.3 - Todd Gibbs)
    ToonIt! (HKLM\...\ToonIt PS) (Version: 2.6.3 - Digital Anarchy, Inc.)
    TourDeFlex (HKLM-x32\...\TourDeFlex.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 2.0 - Adobe Systems Incorporated)
    TourDeFlex (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
    Tourweaver 7.50 Professional Edition (HKLM-x32\...\tw750_pro_is1) (Version: - Easypano Holdings Inc.)
    Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1507.113 - Trusteer)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - )
    VBA (2627.01) (x32 Version: 6.03.00.9402 - Microsoft Corporation) Hidden
    Vegas Pro 11.0 (HKLM-x32\...\{E6F012B0-E930-11E0-A67A-F04DA23A5C58}) (Version: 11.0.370 - Sony)
    Vegas Pro 12.0 (64-bit) (HKLM\...\{87CEB7C0-1D35-11E2-8F19-F04DA23A5C58}) (Version: 12.0.394 - Sony)
    Vertus Fluid Mask 3 3.0.10 (HKLM-x32\...\VertusFluidMask3) (Version: 3.0.10 - )
    Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) (HKLM\...\{4A5A427F-BA39-4BF0-7777-9A47FBE60C9F}) (Version: 11.0.0 - Nuance Communications Inc.)
    Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
    Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
    Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 5.7.0.0 - Azureus Software, Inc.)
    Vuze Remote Toolbar v10.0 (HKLM-x32\...\{2A567123-6435-476E-9529-54F5F9A9F4E0}) (Version: 10.0 - Spigot, Inc.) <==== ATTENTION
    Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.1.6-7 - Wacom Technology Corp.)
    WebAcappella4 (HKLM-x32\...\WebAcappella4_is1) (Version: - Intuisphere)
    WebTablet IE Plugin (HKLM-x32\...\Wacom WebTabletPlugin for IE) (Version: 1.1.0.7 - Wacom Technology Corp.)
    WebTablet Netscape Plugin (HKLM-x32\...\Wacom WebTabletPlugin for Netscape) (Version: 1.1.0.5 - Wacom Technology Corp.)
    Windows 7 Manager (HKLM\...\{BB3C56DF-41B1-4D06-8699-2D5004173CDA}) (Version: 4.3.2 - Yamicsoft)
    Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
    Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
    Windows Live Sync (HKLM-x32\...\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
    Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
    WinRAR 4.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
    WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - )
    WinZip 15.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240C3}) (Version: 15.5.9510 - WinZip Computing, S.L. )
    Wocarson Windows Genuine Advantage Validation v1.9.40.0 Cracked V2 (HKLM-x32\...\{E108ADB5-8B3E-427D-A945-EAA2FCE68913}) (Version: 1.9.40.0 - Wocarson)
    Wondershare Dr.Fone for iOS(Build 4.5.1.6) (HKLM-x32\...\{A26F8BBD-EC10-4bdc-8AD8-F146825A8A63}_is1) (Version: 4.5.1.6 - Wondershare Software Co.,Ltd.)
    Wondershare MobileTrans ( Version 3.3.0 ) (HKLM-x32\...\{18CDCEAA-A9E4-4A4C-AC0E-C15E87C30EA5}_is1) (Version: 3.3.0 - Wondershare)
    WOW Slider (HKLM-x32\...\WOW Slider_is1) (Version: - )
    WPF Toolkit June 2009 (Version 3.5.40619.1) (HKLM-x32\...\{5EE6E987-1B79-4A93-832B-27472C7D1579}) (Version: 3.5.40619.1 - Microsoft Corporation)
    Youtube Downloader HD v. 2.2 (HKLM-x32\...\Youtube Downloader HD_is1) (Version: - YoutubeDownloaderHD.com)
    Zerene Stacker 1.04 (HKLM\...\{3C69B65F-770A-444B-8F31-F1ABDAA9D000}_is1) (Version: - Zerene Systems, LLC)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acadficn.dll (Autodesk, Inc.)
     
  18. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Addition.txt part2

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acad.exe (Autodesk, Inc.)
    CustomCLSID: HKU\S-1-5-21-522234228-4192544273-3428825822-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD Architecture 2011\acadficn.dll (Autodesk, Inc.)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {0127EA8B-67CF-4E2C-AC60-11726F54AA09} - System32\Tasks\{F930C33E-CF57-454C-84FF-4E2AE5DE640C} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {05FACB47-A91F-420D-BCEC-FF600F302C99} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
    Task: {0727640F-EA5E-4D76-A83E-48C70E8738EC} - System32\Tasks\{D7680B2A-5E5C-4BC1-BD28-2CE2BB765740} => C:\Users\a\Desktop\Keygen.exe
    Task: {09331EFC-5DDF-4BB5-A086-711AF5448AFE} - System32\Tasks\{8293165A-D20F-4A29-83CF-FA23EE90B85B} => pcalua.exe -a C:\windows\system32\pcwrun.exe -c "C:\Program Files (x86)\Nikon\NCapture4\Control\NControl.exe"
    Task: {0B7DFB6C-E4D1-48B8-898B-4C7912F97612} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-03-29] (SAMSUNG Electronics co., LTD.)
    Task: {0D973559-B5D9-4A3B-9A99-700976520DC7} - System32\Tasks\{B83D9BF1-9546-4DA9-800A-812A63002A30} => pcalua.exe -a "C:\Users\a\Desktop\Applications\Style Studio v3.8.107\Setup.exe" -d "C:\Users\a\Desktop\Applications\Style Studio v3.8.107"
    Task: {0E67D412-ADC3-4BF0-803D-0D8E23CF6082} - System32\Tasks\{08AC1D05-8E1A-42B7-9F82-BED8F09379EF} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {1191BA75-10D4-4D2F-9480-FB3E9F728F97} - System32\Tasks\{1F1A212B-9EEC-4A15-9842-EEA4B414F258} => C:\Program Files (x86)\Autodesk Architectural Desktop 2006\acad.exe
    Task: {12559310-DFAC-4989-8F23-709667D73793} - System32\Tasks\{EA31EA1B-6090-4E6E-B76A-0B87964436B4} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {1529E60A-F86A-464E-B522-633F3137244F} - System32\Tasks\{1832152F-7EE1-4947-82E5-92F74D61BE6C} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {19F41D0E-4D44-4094-9067-8771BC428826} - System32\Tasks\{312B2E96-4F98-4C2C-A9CD-2C511B5CA939} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {226CBEF3-C14B-4D3E-9085-AAEF8FF18D69} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-06-01] (Samsung Electronics. Co. Ltd.)
    Task: {2463E3F1-1E53-4021-87C1-ABD8FE4BB6B7} - System32\Tasks\{5813487C-E03B-4DAC-88A7-657E06658248} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {247E448E-79CC-495A-B96F-FF33CADC8148} - System32\Tasks\{93BDAF7B-F319-416D-8160-A42252DC4199} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {26439328-BD31-40D6-B5D6-80BD526FB36D} - System32\Tasks\{1B5B4BD5-EF27-4BCF-B6DE-6E29A7A7A93E} => C:\Users\a\Desktop\Keygen.exe
    Task: {2994F999-8B1E-4BD0-A37D-33BC499AF46F} - System32\Tasks\{FE4DDDC1-1C4A-482E-A4B7-7724E474A1E3} => C:\Users\a\Desktop\Keygen.exe
    Task: {2C0AFDDB-043B-493D-A40E-1AEDF70E8209} - System32\Tasks\{C865ABC5-D606-479D-9260-F2C2A25614DC} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {33761319-5E1B-41BB-BEAF-14DCAD251D5E} - System32\Tasks\{C8FA6773-6131-413D-8875-AA5A92A9E959} => C:\Users\a\Desktop\Keygen.exe
    Task: {37DA715B-647F-4B7C-BC78-9B5337DE7080} - System32\Tasks\{93B0144A-7C22-4C52-8375-DF3910EED519} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {396B9B80-C632-43CC-B773-1CF937F1D80E} - System32\Tasks\{2C57BE53-1797-42CD-B89E-69EDA7FF7308} => C:\Users\a\Desktop\p440\Setup.exe
    Task: {3B586B7B-2918-4716-82BE-CBD2AE501135} - System32\Tasks\{B5F3E929-9A2B-4167-A5EE-F64AE6C1047C} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {43DB88D8-7AF9-4FAF-B0B2-A7BF5BE256BB} - System32\Tasks\UninstallMonitor => C:\Program Files (x86)\Innovative Solutions\Advanced Uninstaller PRO\Uninstaller.exe
    Task: {4A2CF537-170B-4B87-9548-F1BDE9DDD4D8} - System32\Tasks\{1D535599-E6D0-49D8-9099-AAB3D95A144D} => C:\Users\a\Desktop\Keygen.exe
    Task: {4D69C9FC-A99E-4581-9EA7-BA42AE89B50E} - System32\Tasks\{2714325B-674E-4675-8433-556CB869CE64} => C:\Users\a\Desktop\Keygen.exe
    Task: {4E68656A-4B65-4361-BF20-137AB2ECB12B} - System32\Tasks\{DC79ECF4-3436-4A42-A6F3-406896695BE3} => C:\Users\a\Desktop\Keygen.exe
    Task: {5BD0D3F6-C777-4E6E-A7A6-24A8B0E66898} - System32\Tasks\{CB807FBF-6F50-4AC5-90B8-AB54AB3D2084} => C:\Program Files (x86)\Autodesk Architectural Desktop 2006\acad.exe
    Task: {5C4CBC5D-A9B8-4B1F-8D8D-9209D0EF3CEB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
    Task: {5D106342-51E3-422E-9CA1-F24EBF2C4B15} - System32\Tasks\{C948908D-3929-47B3-BD6C-56FB52F36E2A} => C:\Users\a\Desktop\Keygen.exe
    Task: {653FEC7F-8ED0-41BD-AB56-2AF118229ACE} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
    Task: {684E9ECC-37E4-40FC-A3C9-25869923B6A9} - System32\Tasks\{48BED7A2-A7FF-4406-9457-1C1EE60CB4FC} => F:\Adobe Photoshop Elements\Setup.exe
    Task: {6BB5F843-E71E-490E-8E0F-F653F2B2B2AE} - System32\Tasks\{7DB39A53-2CD0-4339-A4BE-B6C0627918A1} => pcalua.exe -a C:\Users\a\Desktop\ADT2008\Setup.exe -d C:\Users\a\Desktop\ADT2008
    Task: {72167699-3690-432E-AF18-1768EE7BCF95} - System32\Tasks\{BEBBF18B-E535-4FA6-B51A-37223352D6FD} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {723CB7EC-A285-42A8-9E2D-9893D371B7FF} - System32\Tasks\{AB890F67-DA91-456E-BA7D-34F06BFBFC04} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {7E131182-19E8-4D00-93D1-E2FCA7A42F7C} - System32\Tasks\{0076CCF1-F738-41A9-BE62-ECD612473443} => C:\Users\a\Desktop\Keygen.exe
    Task: {7FB8C834-06FC-4611-B503-8215B3C34B15} - System32\Tasks\AdobeAAMUpdater-1.0-a-PC-a => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-09-25] (Adobe Systems Incorporated)
    Task: {808D0385-1AA0-48B9-BC4A-A86EF313DA51} - System32\Tasks\{BA6787A1-24FB-4F97-A76F-A3D16F3A612F} => C:\Program Files (x86)\BreezeSys\NKRemote\NKRemote.exe [2009-08-05] (Breeze Systems Ltd)
    Task: {826CAABD-7A69-47EE-9CC7-25D639392929} - System32\Tasks\{7C1CC536-1A8F-4A26-8873-71FAE52B8827} => pcalua.exe -a C:\Users\a\Downloads\iv5setup(1).exe -d C:\Users\a\Downloads
    Task: {83D71393-7B48-44EC-83D4-8355533AED6A} - System32\Tasks\{EC43FA6C-741F-4E15-A018-78DD0BCC1D12} => pcalua.exe -a "C:\Users\a\Desktop\nk4\Nikon Capture 4.2.1 Full + 4.3 update + serial\Nikon Capture 4.2.1\Disk1\setup.exe" -d "C:\Users\a\Desktop\nk4\Nikon Capture 4.2.1 Full + 4.3 update + serial\Nikon Capture 4.2.1\Disk1"
    Task: {89CADC1C-BF1E-45DE-924B-68DBC59D91B0} - System32\Tasks\{E74B7EA6-7027-428A-A6EE-28152804FC60} => C:\Users\a\Desktop\Keygen.exe
    Task: {8A713A54-2E1E-4B75-924A-1BEB24554958} - System32\Tasks\{9ABBECC3-8B9F-4E8D-B591-89F26F1E2751} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {8CD32D5D-2EC2-40E1-8FBD-134BC8F471D2} - System32\Tasks\{C8101388-0FE2-489C-9737-FF4A6D43E0E8} => C:\Program Files (x86)\BreezeSys\NKRemote\NKRemote.exe [2009-08-05] (Breeze Systems Ltd)
    Task: {914380EF-A337-4C25-AA28-001AC56552CA} - System32\Tasks\{C227EB27-B362-40C8-9C38-4FDC4CCD5776} => C:\Program Files (x86)\BreezeSys\NKRemote\NKRemote.exe [2009-08-05] (Breeze Systems Ltd)
    Task: {95F1EA6F-C43F-417C-9FA3-943D0EB642D0} - System32\Tasks\{90FCBAFE-A676-43E5-883C-D59E26FA36B6} => pcalua.exe -a C:\Users\a\Desktop\sound\SETUP.EXE -d C:\Users\a\Desktop\sound
    Task: {9AD23A4F-E20E-4CA6-84DE-521C226E7B25} - System32\Tasks\{C9135D17-281C-484D-AED4-CBCBF7018C33} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {9AF1ABEA-82D2-4C32-9D5E-A7406B582C86} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-10-29] (Samsung Electronics CO., LTD.)
    Task: {A39A2C68-98D2-48ED-A813-FABB1844BCB4} - System32\Tasks\{FCC73AFA-6A1B-45BB-B3EF-76FBF16964D7} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {AD0D814A-7AB4-4ABF-8B75-81F7340BFC2E} - System32\Tasks\{097E86C3-9DCE-4D61-B720-EAB3655C52D3} => pcalua.exe -a "C:\Users\a\Desktop\Install Lightroom 2.4.exe" -d C:\Users\a\Desktop
    Task: {AECD8FB5-B082-413A-9923-4E6BB096E77F} - System32\Tasks\{9B0C9148-E605-4492-A3EC-9951A4486127} => E:\setup.exe
    Task: {B55C47EE-9383-4C1A-A352-7FB9852998D0} - System32\Tasks\{43671627-D6C3-4C1E-AB11-55D013FE69D2} => pcalua.exe -a "C:\Users\a\Desktop\nk4\Nikon Capture 4.4 官方简体中文版\Nikon_Capture_4.4.1_Updater_CN\S-NC____-440WU-INTCN.exe" -d "C:\Users\a\Desktop\nk4\Nikon Capture 4.4 官方简体中文版\Nikon_Capture_4.4.1_Updater_CN"
    Task: {BBFD0CE6-6870-43B6-86FC-BFCF19D836DA} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-29] (Adobe Systems Incorporated)
    Task: {BC1D6023-12FC-4A90-A181-6D379B61C831} - System32\Tasks\{24192CF8-07C4-4A4D-A8DF-9FD555ADA992} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {C018816C-82F9-4FCA-B0BA-E82C217B3653} - System32\Tasks\{B201E666-1A42-4649-87E3-C334064E76E7} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {C7485C50-4F50-46E1-87E5-C80C669FE914} - System32\Tasks\{D5E02ED5-566C-4A14-9698-67883B57AAB0} => C:\Users\a\Desktop\p440\Setup.exe
    Task: {C86D1B6D-C500-4A3C-901D-7AEDA40AE402} - System32\Tasks\{AD49533E-B97A-4ACF-B20F-C514CF8B9A21} => pcalua.exe -a C:\Users\a\Desktop\NV625_up\Disk1\Setup.exe -d C:\Users\a\Desktop\NV625_up\Disk1
    Task: {DBD12B99-9916-4057-9ECC-9180FCEE1D19} - System32\Tasks\{5E4C098B-A82F-4FD4-8B25-0E9A792A4397} => pcalua.exe -a "C:\Users\a\Desktop\Photoshop Lightroom 2.6\Install Lightroom 2.6.exe" -d "C:\Users\a\Desktop\Photoshop Lightroom 2.6"
    Task: {E171AD44-9B85-4821-B8B8-4DFFC6814957} - System32\Tasks\{BAB62250-0056-4E9A-9DD5-F6A2578E2D4C} => C:\Users\a\Desktop\Keygen.exe
    Task: {E2B45D9D-9C3C-49E2-A200-735284FE0BF0} - System32\Tasks\{160EDAB2-7F43-4EBF-8E5B-B21F5A0D5C9E} => pcalua.exe -a C:\Users\a\Desktop\p440\Setup.exe -d C:\Users\a\Desktop\p440
    Task: {E4E99033-4D2D-4778-B942-A9E954A1F77F} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21] (Adobe Systems Incorporated)
    Task: {E53A0F0A-404A-4A72-B060-B362656BCCB1} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-05053A92\EPM.exe
    Task: {EA6170C3-5994-48CF-89DE-DEDB7C5AF71B} - System32\Tasks\{14C80B1B-9E21-4155-91FE-4F83FBDA3740} => C:\Program Files (x86)\ControlMyNikon v30\ControlMyNikon.exe [2011-08-19] (TetherScript Technology Corporation)
    Task: {EAAD2705-A24C-4892-BB47-D19CBB3ED01A} - System32\Tasks\Opera scheduled Autoupdate 1459285081 => C:\Program Files (x86)\Opera\launcher.exe [2016-03-14] (Opera Software)
    Task: {EB502C84-0AC6-43B4-97A0-2EDBBDF6E6FC} - System32\Tasks\{8E704D9C-B141-4B07-8F42-D51E781F5582} => pcalua.exe -a "C:\Users\a\Documents\Vuze Downloads\Micro Expression\iv5setup.exe" -d "C:\Users\a\Documents\Vuze Downloads\Micro Expression"
    Task: {EE90E3C3-B0A3-4B52-954A-42DF3B32C966} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
    Task: {F337FCB2-3827-451A-99A2-EF949959EF9A} - System32\Tasks\{7C040EE6-4D80-4C21-886D-86BB0779C232} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {F61F6EF1-4B7D-4235-A63E-9D1A37BD484D} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-06-08] (Samsung Electronics Co., Ltd.)
    Task: {F6C06100-B3EE-4C44-8A7F-E3F8682D24CE} - System32\Tasks\{20B35A6A-E43F-4504-98FB-6C259D2DD408} => C:\Program Files (x86)\Nikon\Camera Control Pro 2\NControlPro.exe [2013-02-18] (Nikon Corporation)
    Task: {F73307E1-C9A5-4CA2-9740-A0990B5D2BA5} - System32\Tasks\{FDF90E5D-4995-4897-A4DC-EA9193D0571B} => C:\Users\a\Downloads\photopc.exe
    Task: {F82155C6-29C3-42D4-82DE-64FFE99E1E81} - System32\Tasks\{0642A9A7-51C3-425A-BAF6-A316E099EFA1} => C:\Users\a\Desktop\Keygen.exe
    Task: {FA5B689E-6F93-465F-B34E-23911AC2B62B} - System32\Tasks\{06DDEC3B-81C0-417B-BFEC-6679078C3D5D} => C:\Users\a\Desktop\ADT2008\Setup.exe
    Task: {FC8801BB-D0C9-48A7-B692-FE243C37E441} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2010-05-06] (SAMSUNG Electronics)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-11 19:25 - 2015-08-18 01:07 - 00115376 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2008-01-04 17:56 - 2010-11-15 12:08 - 01182576 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
    2015-10-16 11:02 - 2015-10-16 11:02 - 00043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
    2011-02-03 14:39 - 2011-02-03 14:39 - 02870784 _____ () C:\Windows\System32\drivers\UMDF\Omron\OmronWpdDriver.dll
    2015-08-25 16:46 - 2009-12-04 17:15 - 00062976 _____ () C:\Program Files (x86)\LG Soft India\EasySetPackage\bin\HOOK64.dll
    2013-10-16 19:02 - 2013-10-16 19:02 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
    2016-03-29 20:54 - 2016-03-29 20:54 - 26727616 _____ () C:\windows\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll
    2015-10-11 18:32 - 2015-09-28 23:05 - 00011896 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
    2015-07-21 17:02 - 2015-07-21 17:02 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Users\a\Cookies:pCcyTPEdyM46RMzTfp48lq [2430]
    AlternateDataStreams: C:\Users\a\AppData\Local\desktop.ini:3a96398c0f384e4adf5faa1736aeaf96 [802]
    AlternateDataStreams: C:\Users\a\AppData\Local\Temporary Internet Files:5Se5QwcRmq1ayglFYLV0gH8qKz8 [1950]
    AlternateDataStreams: C:\ProgramData\Microsoft:5PJuBaesDyapndf8Ut50s7g1c [2022]
    AlternateDataStreams: C:\ProgramData\Microsoft:dhEatTyVPHSPSDRP1cQln04OWUn6W [2360]
    AlternateDataStreams: C:\ProgramData\Microsoft:GUaGESdiIiSVeGzg5H2EC [2350]
    AlternateDataStreams: C:\ProgramData\Microsoft:m0z7NBO9GMLEoMy4XO7p [2136]
    AlternateDataStreams: C:\ProgramData\Microsoft:uHj3MQsPeHwZblwQ6pUWZ5 [2012]
    AlternateDataStreams: C:\ProgramData\Temp:0FF263E8 [140]
    AlternateDataStreams: C:\ProgramData\Temp:F4CA4D70 [458]
    AlternateDataStreams: C:\ProgramData\Temp:FD268286 [190]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 03:34 - 2016-03-31 16:15 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts

    127.0.0.1 localhost

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\a\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
    Windows Firewall is disabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\Services: McMPFSvc => 2
    MSCONFIG\Services: mcmscsvc => 2
    MSCONFIG\Services: McNaiAnn => 2
    MSCONFIG\Services: McNASvc => 2
    MSCONFIG\Services: McODS => 3
    MSCONFIG\Services: McProxy => 2
    MSCONFIG\Services: mfefire => 2
    MSCONFIG\startupreg: (default) =>
    MSCONFIG\startupreg: AdobeCS5.5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
    MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
    MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
    MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    MSCONFIG\startupreg: mcui_exe =>
    MSCONFIG\startupreg: NvCplDaemon => RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
    MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
    MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    MSCONFIG\startupreg: SynTPEnh => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{42A0F55B-06A4-4D05-AB14-92C8424357DA}C:\program files (x86)\vuze\azureus.exe] => (Allow) C:\program files (x86)\vuze\azureus.exe
    FirewallRules: [UDP Query User{C96B2DD6-F633-4483-AB31-B59EC18C16F7}C:\program files (x86)\vuze\azureus.exe] => (Allow) C:\program files (x86)\vuze\azureus.exe
    FirewallRules: [{E2030FD0-3CF2-4374-A048-50C612F837AB}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
    FirewallRules: [{98550D4F-7C4E-411A-ACE2-5F5484CAAF1B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
    FirewallRules: [{06818514-E985-4B4B-A98A-5CDD75E83E94}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
    FirewallRules: [{1385384C-39CB-4A06-9C78-41765B311DB3}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe

    ==================== Restore Points =========================

    01-04-2016 11:03:09 Installed AVG 2016
    01-04-2016 11:04:51 Installed AVG
    02-04-2016 11:16:49 zoek.exe restore point
    02-04-2016 17:40:35 zoek.exe restore point
    03-04-2016 09:00:16 After installing Advanced Uninstaller PRO
    03-04-2016 11:18:39 JRT Pre-Junkware Removal
    04-04-2016 10:18:24 Removed AVG
    04-04-2016 10:21:54 Removed AVG 2016

    ==================== Faulty Device Manager Devices =============

    Name: Microsoft ISATAP Adapter
    Description: Microsoft ISATAP Adapter
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: tunnel
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name: Microsoft ISATAP Adapter #2
    Description: Microsoft ISATAP Adapter
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: tunnel
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (04/05/2016 01:37:13 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AitStatic.exe, version: 10.0.10004.0, time stamp: 0x54c65a8b
    Faulting module name: KERNELBASE.dll, version: 6.1.7601.18869, time stamp: 0x556366fd
    Exception code: 0xc000000d
    Fault offset: 0x000000000000b3dd
    Faulting process id: 0x1af0
    Faulting application start time: 0xAitStatic.exe0
    Faulting application path: AitStatic.exe1
    Faulting module path: AitStatic.exe2
    Report Id: AitStatic.exe3

    Error: (04/05/2016 01:37:12 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AitStatic.exe, version: 10.0.10004.0, time stamp: 0x54c65a8b
    Faulting module name: KERNELBASE.dll, version: 6.1.7601.18869, time stamp: 0x556366fd
    Exception code: 0xc000000d
    Fault offset: 0x000000000000b3dd
    Faulting process id: 0x14d4
    Faulting application start time: 0xAitStatic.exe0
    Faulting application path: AitStatic.exe1
    Faulting module path: AitStatic.exe2
    Report Id: AitStatic.exe3

    Error: (04/05/2016 01:37:08 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: AitStatic.exe, version: 10.0.10004.0, time stamp: 0x54c65a8b
    Faulting module name: KERNELBASE.dll, version: 6.1.7601.18869, time stamp: 0x556366fd
    Exception code: 0xc000000d
    Fault offset: 0x000000000000b3dd
    Faulting process id: 0xc08
    Faulting application start time: 0xAitStatic.exe0
    Faulting application path: AitStatic.exe1
    Faulting module path: AitStatic.exe2
    Report Id: AitStatic.exe3

    Error: (04/05/2016 01:24:36 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/05/2016 01:24:36 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/05/2016 01:24:36 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/05/2016 01:24:36 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/05/2016 01:24:35 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/05/2016 01:24:35 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.

    Error: (04/05/2016 01:24:35 AM) (Source: SideBySide) (EventID: 33) (User: )
    Description: Activation context generation failed for "Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1"1".
    Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="x86",type="win32",version="9.0.30729.1" could not be found.
    Please use sxstrace.exe for detailed diagnosis.


    System errors:
    =============
    Error: (04/04/2016 11:24:51 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (04/04/2016 11:11:25 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (04/04/2016 10:47:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The SW Update Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (04/03/2016 02:17:55 PM) (Source: BROWSER) (EventID: 8032) (User: )
    Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{A66457FB-76D7-44A4-BFA0-D4C23D5733A4}.
    The backup browser is stopping.

    Error: (04/03/2016 01:59:03 PM) (Source: DCOM) (EventID: 10005) (User: )
    Description: 1068fdPHost{D3DCB472-7261-43CE-924B-0704BD730D5F}

    Error: (04/03/2016 01:59:03 PM) (Source: DCOM) (EventID: 10005) (User: )
    Description: 1068fdPHost{145B4335-FE2A-4927-A040-7C35AD3180EF}

    Error: (04/03/2016 01:59:03 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    %%1068

    Error: (04/03/2016 01:25:33 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    %%1068

    Error: (04/03/2016 01:25:33 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    %%1068

    Error: (04/03/2016 01:25:33 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    %%1068


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
    Percentage of memory in use: 57%
    Total physical RAM: 3956.55 MB
    Available physical RAM: 1694.87 MB
    Total Virtual: 7911.31 MB
    Available Virtual: 4942.35 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:371 GB) (Free:60.64 GB) NTFS
    Drive d: () (Fixed) (Total:74.66 GB) (Free:74.56 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 465.8 GB) (Disk ID: 8C0FBFDC)
    Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=371 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=74.7 GB) - (Type=OF Extended)

    ==================== End of Addition.txt ============================
     
  19. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
     

    Attached Files:

  20. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi,
    here is Fixlog.txt
    Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by a (2016-04-07 08:21:03) Run:1
    Running from C:\Users\a\Desktop
    Loaded Profiles: a (Available Profiles: a)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKLM-x32\...\Run: [] => [X]
    Winsock: Catalog5-x64 01 C:\Windows\System32\mswsock.dll [327168 2013-09-08] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-522234228-4192544273-3428825822-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S4 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S4 tsusbhub; system32\drivers\tsusbhub.sys [X]
    S4 VGPU; System32\drivers\rdvgkmd.sys [X]
    2011-12-14 18:29 - 2011-12-14 18:29 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe BMP Format CS5 Prefs
    2011-02-28 18:07 - 2013-05-22 16:30 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2013-02-27 15:46 - 2016-01-06 13:34 - 0000132 _____ () C:\Users\a\AppData\Roaming\Adobe PNG Format CS6 Prefs
    2010-12-27 20:47 - 2013-01-18 11:43 - 0002315 _____ () C:\Users\a\AppData\Roaming\SAS7_000.DAT
    2011-06-02 13:23 - 2011-09-05 15:33 - 0001456 _____ () C:\Users\a\AppData\Local\Adobe Save for Web 12.0 Prefs
    2016-03-08 18:55 - 2016-03-08 18:55 - 0185089 _____ () C:\Users\a\AppData\Local\ars.cache
    2016-03-08 18:55 - 2016-03-08 18:55 - 0328409 _____ () C:\Users\a\AppData\Local\census.cache
    2010-12-28 21:50 - 2010-12-28 21:50 - 0003584 _____ () C:\Users\a\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2008-09-03 16:10 - 2008-09-03 16:10 - 0000036 _____ () C:\Users\a\AppData\Local\housecall.guid.cache
    2016-04-04 10:13 - 2016-04-04 10:17 - 0001071 _____ () C:\Users\a\AppData\Local\infection.log
    2015-08-14 15:44 - 2015-08-14 15:49 - 0000528 _____ () C:\Users\a\AppData\Local\Player.ini
    2015-02-11 10:31 - 2016-04-02 17:05 - 0007634 _____ () C:\Users\a\AppData\Local\Resmon.ResmonCfg
    2011-09-15 16:17 - 2011-09-15 16:17 - 0000096 ____H () C:\Users\a\AppData\Local\vwr_lic_p.dat
    2010-12-24 20:55 - 2010-01-16 08:18 - 0131368 _____ () C:\ProgramData\FullRemove.exe
    2010-12-27 00:59 - 2013-12-06 17:42 - 0000020 ____H () C:\ProgramData\PKP_DLdy.DAT
    2010-12-26 19:18 - 2015-02-15 12:05 - 0000020 ____H () C:\ProgramData\PKP_DLea.DAT
    2013-03-17 14:39 - 2013-03-17 15:05 - 0000000 ____H () C:\ProgramData\PKP_DLeh.DAT
    2010-08-04 03:37 - 2010-08-04 03:37 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
    2010-08-04 03:35 - 2010-08-04 03:36 - 0000106 _____ () C:\ProgramData\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.log
    2010-08-04 03:32 - 2010-08-04 03:33 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2010-08-04 03:36 - 2010-08-04 03:37 - 0000110 _____ () C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log
    2010-08-04 03:31 - 2010-08-04 03:32 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
    2010-08-04 03:33 - 2010-08-04 03:35 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
    AlternateDataStreams: C:\Users\a\Cookies:pCcyTPEdyM46RMzTfp48lq [2430]
    AlternateDataStreams: C:\Users\a\AppData\Local\desktop.ini:3a96398c0f384e4adf5faa1736aeaf96 [802]
    AlternateDataStreams: C:\Users\a\AppData\Local\Temporary Internet Files:5Se5QwcRmq1ayglFYLV0gH8qKz8 [1950]
    AlternateDataStreams: C:\ProgramData\Microsoft:5PJuBaesDyapndf8Ut50s7g1c [2022]
    AlternateDataStreams: C:\ProgramData\Microsoft:dhEatTyVPHSPSDRP1cQln04OWUn6W [2360]
    AlternateDataStreams: C:\ProgramData\Microsoft:GUaGESdiIiSVeGzg5H2EC [2350]
    AlternateDataStreams: C:\ProgramData\Microsoft:m0z7NBO9GMLEoMy4XO7p [2136]
    AlternateDataStreams: C:\ProgramData\Microsoft:uHj3MQsPeHwZblwQ6pUWZ5 [2012]
    AlternateDataStreams: C:\ProgramData\Temp:0FF263E8 [140]
    AlternateDataStreams: C:\ProgramData\Temp:F4CA4D70 [458]
    AlternateDataStreams: C:\ProgramData\Temp:FD268286 [190]

    *****************

    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
    Winsock: Catalog5-x64 000000000001\\LibraryPath => restored successfully (%SystemRoot%\system32\NLAapi.dll)
    "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
    "HKU\S-1-5-21-522234228-4192544273-3428825822-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
    "HKCR\PROTOCOLS\Handler\linkscanner" => key removed successfully
    HKCR\CLSID\{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} => key not found.
    catchme => service removed successfully
    Synth3dVsc => service removed successfully
    tsusbhub => service removed successfully
    VGPU => service removed successfully
    C:\Users\a\AppData\Roaming\Adobe BMP Format CS5 Prefs => moved successfully
    C:\Users\a\AppData\Roaming\Adobe PNG Format CS5 Prefs => moved successfully
    C:\Users\a\AppData\Roaming\Adobe PNG Format CS6 Prefs => moved successfully
    C:\Users\a\AppData\Roaming\SAS7_000.DAT => moved successfully
    C:\Users\a\AppData\Local\Adobe Save for Web 12.0 Prefs => moved successfully
    C:\Users\a\AppData\Local\ars.cache => moved successfully
    C:\Users\a\AppData\Local\census.cache => moved successfully
    C:\Users\a\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
    C:\Users\a\AppData\Local\housecall.guid.cache => moved successfully
    C:\Users\a\AppData\Local\infection.log => moved successfully
    C:\Users\a\AppData\Local\Player.ini => moved successfully
    C:\Users\a\AppData\Local\Resmon.ResmonCfg => moved successfully
    C:\Users\a\AppData\Local\vwr_lic_p.dat => moved successfully
    C:\ProgramData\FullRemove.exe => moved successfully
    C:\ProgramData\PKP_DLdy.DAT => moved successfully
    C:\ProgramData\PKP_DLea.DAT => moved successfully
    C:\ProgramData\PKP_DLeh.DAT => moved successfully
    C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log => moved successfully
    C:\ProgramData\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.log => moved successfully
    C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log => moved successfully
    C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log => moved successfully
    C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log => moved successfully
    C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log => moved successfully
    "C:\Users\a\Cookies" => ":pCcyTPEdyM46RMzTfp48lq" ADS not found.
    C:\Users\a\AppData\Local\desktop.ini => ":3a96398c0f384e4adf5faa1736aeaf96" ADS removed successfully.
    "C:\Users\a\AppData\Local\Temporary Internet Files" => ":5Se5QwcRmq1ayglFYLV0gH8qKz8" ADS not found.
    C:\ProgramData\Microsoft => ":5PJuBaesDyapndf8Ut50s7g1c" ADS removed successfully.
    C:\ProgramData\Microsoft => ":dhEatTyVPHSPSDRP1cQln04OWUn6W" ADS removed successfully.
    C:\ProgramData\Microsoft => ":GUaGESdiIiSVeGzg5H2EC" ADS removed successfully.
    C:\ProgramData\Microsoft => ":m0z7NBO9GMLEoMy4XO7p" ADS removed successfully.
    C:\ProgramData\Microsoft => ":uHj3MQsPeHwZblwQ6pUWZ5" ADS removed successfully.
    C:\ProgramData\Temp => ":0FF263E8" ADS removed successfully.
    C:\ProgramData\Temp => ":F4CA4D70" ADS removed successfully.
    C:\ProgramData\Temp => ":FD268286" ADS removed successfully.

    ==== End of Fixlog 08:21:05 ====
     
  21. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services

    Press "Scan".
    It will create a log (FSS.txt) in the same directory the tool is run.
    Please copy and paste the log to your reply.


    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    [​IMG] Download Sophos Free Virus Removal Tool and save it to your desktop.
    • Double click the icon and select Run
    • Click Next
    • Select I accept the terms in this license agreement, then click Next twice
    • Click Install
    • Click Finish to launch the program
    • Once the virus database has been updated click Start Scanning
    • If any threats are found click Details, then View log file... (bottom left hand corner)
    • Copy and paste the results in your reply
    • Close the Notepad document, close the Threat Details screen, then click Start cleanup
    • Click Exit to close the program
     
  22. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Hi here is checkup.txt
    Results of screen317's Security Check version 1.014 --- 12/23/15
    Windows 7 Service Pack 1 x64 (UAC is disabled!)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Windows Firewall Disabled!
    WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````
    Instant Wire Cleaner 1.0
    Java 7 Update 71
    Java 8 Update 45
    Java 8 Update 73
    Java version 32-bit out of Date!
    Adobe Flash Player 21.0.0.197
    Adobe Reader XI
    Mozilla Firefox (45.0)
    ````````Process Check: objlist.exe by Laurent````````
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````
    Here is FSS.txt
    Farbar Service Scanner Version: 27-01-2016
    Ran by a (administrator) on 08-04-2016 at 11:20:37
    Running from "C:\Users\a\Desktop"
    Microsoft Windows 7 Ultimate Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Attempt to access Local Host IP returned error: Localhost is blocked: Other errors
    LAN connected.
    Attempt to access Google IP returned error. Other errors
    Attempt to access Google.com returned error: Other errors
    Attempt to access Yahoo.com returned error: Other errors


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall"=DWORD:0


    System Restore:
    ============

    System Restore Policy:
    ========================


    Action Center:
    ============

    Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================
    Here is Sophos.txt
    2016-04-08 11:33:14.848 Sophos Virus Removal Tool version 2.5.5
    2016-04-08 11:33:14.848 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

    2016-04-08 11:33:14.848 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

    2016-04-08 11:33:14.848 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
    2016-04-08 11:33:14.864 Checking for updates...
    2016-04-08 11:33:17.667 Update progress: proxy server not available
    2016-04-08 11:33:17.677 Update error: failed to read remote metadata (error 4)
    Cannot locate server for http://dci.sophosupd.com/update/a/87/a877f89ddd87d4e45fbc809f2cd95531.xml
    2016-04-08 11:33:27.257 Option all = no
    2016-04-08 11:33:27.257 Option recurse = yes
    2016-04-08 11:33:27.257 Option archive = no
    2016-04-08 11:33:27.257 Option service = yes
    2016-04-08 11:33:27.257 Option confirm = yes
    2016-04-08 11:33:27.257 Option sxl = yes
    2016-04-08 11:33:27.257 Option max-data-age = 35
    2016-04-08 11:33:27.257 Option EnableSafeClean = yes
    2016-04-08 11:33:28.599 Option vdl-logging = yes
    2016-04-08 11:33:28.614 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2016-04-08 11:33:28.614 Machine ID: 5e088206d36b49f88068ec2680b2ec4d
    2016-04-08 11:33:28.614 Component SVRTcli.exe version 2.5.5
    2016-04-08 11:33:28.614 Component control.dll version 2.5.5
    2016-04-08 11:33:28.614 Component SVRTservice.exe version 2.5.5
    2016-04-08 11:33:28.614 Component engine\osdp.dll version 1.44.1.2240
    2016-04-08 11:33:28.614 Component engine\veex.dll version 3.64.0.2240
    2016-04-08 11:33:28.614 Component engine\savi.dll version 9.0.0.2240
    2016-04-08 11:33:28.614 Component rkdisk.dll version 1.5.30.0
    2016-04-08 11:33:28.614 Version info: Product version 2.5.5
    2016-04-08 11:33:28.630 Version info: Detection engine 3.64.0
    2016-04-08 11:33:28.630 Version info: Detection data 5.25
    2016-04-08 11:33:28.630 Version info: Build date 08/03/2016
    2016-04-08 11:33:28.630 Version info: Data files added 312
    2016-04-08 11:33:28.630 Version info: Last successful update (not yet updated)
    2016-04-08 11:51:54.781 Error level 1

    2016-04-08 11:51:54.781 Scan completed.
    2016-04-08 11:51:54.781

    ------------------------------------------------------------

    2016-04-08 11:53:10.614 Sophos Virus Removal Tool version 2.5.5
    2016-04-08 11:53:10.614 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

    2016-04-08 11:53:10.614 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

    2016-04-08 11:53:10.614 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
    2016-04-08 11:53:10.614 Checking for updates...
    2016-04-08 11:53:13.266 Update progress: proxy server not available
    2016-04-08 11:53:13.266 Update error: failed to read remote metadata (error 4)
    Cannot locate server for http://dci.sophosupd.com/update/a/87/a877f89ddd87d4e45fbc809f2cd95531.xml
    2016-04-08 11:53:23.156 Option all = no
    2016-04-08 11:53:23.156 Option recurse = yes
    2016-04-08 11:53:23.156 Option archive = no
    2016-04-08 11:53:23.156 Option service = yes
    2016-04-08 11:53:23.156 Option confirm = yes
    2016-04-08 11:53:23.156 Option sxl = yes
    2016-04-08 11:53:23.156 Option max-data-age = 35
    2016-04-08 11:53:23.156 Option EnableSafeClean = yes
    2016-04-08 11:53:23.234 Option vdl-logging = yes
    2016-04-08 11:53:23.250 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2016-04-08 11:53:23.250 Machine ID: 5e088206d36b49f88068ec2680b2ec4d
    2016-04-08 11:53:23.250 Component SVRTcli.exe version 2.5.5
    2016-04-08 11:53:23.250 Component control.dll version 2.5.5
    2016-04-08 11:53:23.250 Component SVRTservice.exe version 2.5.5
    2016-04-08 11:53:23.250 Component engine\osdp.dll version 1.44.1.2240
    2016-04-08 11:53:23.250 Component engine\veex.dll version 3.64.0.2240
    2016-04-08 11:53:23.250 Component engine\savi.dll version 9.0.0.2240
    2016-04-08 11:53:23.250 Component rkdisk.dll version 1.5.30.0
    2016-04-08 11:53:23.250 Version info: Product version 2.5.5
    2016-04-08 11:53:23.250 Version info: Detection engine 3.64.0
    2016-04-08 11:53:23.250 Version info: Detection data 5.25
    2016-04-08 11:53:23.250 Version info: Build date 08/03/2016
    2016-04-08 11:53:23.250 Version info: Data files added 312
    2016-04-08 11:53:23.250 Version info: Last successful update (not yet updated)

    2016-04-08 11:55:44.149 Warning: rootkit scan failed to open volume "\\?\Volume{5c2133be-5272-11e0-81de-002454c7efd8}" (5)
    2016-04-08 12:38:22.046 Could not open C:\hiberfil.sys
    2016-04-08 12:38:26.601 Could not open C:\pagefile.sys
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file C:\Program Files (x86)\Kolor\Panotour Pro 1.8\PanotourPro_win32.exe
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103
    2016-04-08 13:55:23.589 >>> Virus 'Mal/Sinowa-A' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103
    2016-04-08 13:55:23.605 >>> Virus 'Mal/Sinowa-A' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208
    2016-04-08 13:55:23.605 >>> Virus 'Mal/Sinowa-A' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208
    2016-04-08 13:55:23.605 >>> Virus 'Mal/Sinowa-A' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 14:17:03.413 Could not open C:\System Volume Information\{1f2065b4-f901-11e5-afdf-002454c7efd8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:17:03.429 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:17:03.429 Could not open C:\System Volume Information\{42dff6f6-f99c-11e5-be31-002454c7efd8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:17:03.429 Could not open C:\System Volume Information\{42dff710-f99c-11e5-be31-002454c7efd8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:17:03.444 Could not open C:\System Volume Information\{5a12e896-f984-11e5-aee7-002454c7efd8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:17:03.444 Could not open C:\System Volume Information\{e6185af8-fce8-11e5-b5b1-002454c7efd8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:17:03.444 Could not open C:\System Volume Information\{e6185b69-fce8-11e5-b5b1-002454c7efd8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:17:03.460 Could not open C:\System Volume Information\{e6185b71-fce8-11e5-b5b1-002454c7efd8}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file C:\Users\a\Desktop\desktop_folders\HeliconSoft.HeliconFocus.v5.3.7.1.Incl.Keygen.And.Patch-MAZE\Keygen.exe
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208
    2016-04-08 14:27:49.207 >>> Virus 'Mal/Packer' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file C:\Users\a\Documents\Vuze Downloads\Native Instruments Guitar Rig 5 Pro v5.1.1-FULL\Guitar Rig 5 Setup.exe
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file C:\Users\a\Documents\Vuze Downloads\Native Instruments Guitar Rig 5 Pro v5.1.1-FULL\Guitar Rig 5 Setup.exe
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-522234228-4192544273-3428825822-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208
    2016-04-08 14:47:38.745 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2016-04-08 15:04:25.402 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
    2016-04-08 15:04:25.417 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
    2016-04-08 15:04:36.556 Could not open C:\Windows\System32\config\RegBack\DEFAULT
    2016-04-08 15:04:36.571 Could not open C:\Windows\System32\config\RegBack\SAM
    2016-04-08 15:04:36.602 Could not open C:\Windows\System32\config\RegBack\SECURITY
    2016-04-08 15:04:36.618 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
    2016-04-08 15:04:36.665 Could not open C:\Windows\System32\config\RegBack\SYSTEM
    2016-04-08 15:48:37.392 Could not open LOGICAL:0010:00000000
    2016-04-08 15:48:37.392 Could not open Q:\
    2016-04-08 15:48:37.813 The following items will be cleaned up:
    2016-04-08 15:48:37.813 Mal/Sinowa-A
    2016-04-08 15:48:37.813 Mal/Packer
    2016-04-08 15:48:37.813 Mal/Generic-S
     
  23. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    FSS log is incomplete.
    Please post entire log.
     
  24. ppiper

    ppiper TS Rookie Topic Starter Posts: 20

    Here is FSSlog
    Farbar Service Scanner Version: 27-01-2016
    Ran by a (administrator) on 08-04-2016 at 11:20:37
    Running from "C:\Users\a\Desktop"
    Microsoft Windows 7 Ultimate Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Attempt to access Local Host IP returned error: Localhost is blocked: Other errors
    LAN connected.
    Attempt to access Google IP returned error. Other errors
    Attempt to access Google.com returned error: Other errors
    Attempt to access Yahoo.com returned error: Other errors


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall"=DWORD:0


    System Restore:
    ============

    System Restore Policy:
    ========================


    Action Center:
    ============

    Action Center Notification Icon =====> Unable to open HKLM\...\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist.


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============

    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => File is digitally signed
    C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
    C:\Windows\System32\dhcpcore.dll => File is digitally signed
    C:\Windows\System32\drivers\afd.sys => File is digitally signed
    C:\Windows\System32\drivers\tdx.sys => File is digitally signed
    C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
    C:\Windows\System32\dnsrslvr.dll => File is digitally signed
    C:\Windows\System32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\System32\mpssvc.dll => File is digitally signed
    C:\Windows\System32\bfe.dll => File is digitally signed
    C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
    C:\Windows\System32\SDRSVC.dll => File is digitally signed
    C:\Windows\System32\vssvc.exe => File is digitally signed
    C:\Windows\System32\wscsvc.dll => File is digitally signed
    C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
    C:\Windows\System32\wuaueng.dll => File is digitally signed
    C:\Windows\System32\qmgr.dll => File is digitally signed
    C:\Windows\System32\es.dll => File is digitally signed
    C:\Windows\System32\cryptsvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
    C:\Windows\System32\ipnathlp.dll => File is digitally signed
    C:\Windows\System32\iphlpsvc.dll => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed


    **** End of log ****
     
  25. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    [​IMG]Update your Java version here: http://www.java.com/en/download/manual.jsp
    Alternate download: http://www.filehippo.com/search?q=java

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
    Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

    [​IMG] We have one registry issue.
    Following steps involve registry editing. Please create new restore point before proceeding!!!
    How to: http://www.smartestcomputing.us.com/topic/63983-how-to-create-new-restore-point-all-windows/

    Download win-7-8-action-center-notification-icon-missing.reg from here: http://www.bleepstatic.com/fhost/uploads/1/win-7-8-action-center-notification-icon-missing.reg
    Double-click on downloaded file and confirm the prompt.
    Restart computer.
    Post new FSS log.
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...