Hello, Broni! Hope you are well! And thank you for your efforts!
I only found three steps on <
https://www.techspot.com/community/...lware-removal-preliminary-instructions.58138/>. My "regular" antivirus is Avast! (I am poor). I did a boot-time scan two days ago -- which did not find any malware. The program is up to date.
I ran FRST without incident. The scan results are as follows:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-06-2017 01
Ran by Daniel M. Burkus (administrator) on PC (21-06-2017 17:37:24)
Running from C:\Users\Daniel M. Burkus.PC\Desktop
Loaded Profiles: Daniel M. Burkus (Available Profiles: Daniel M. Burkus)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Foxit Software Inc.) C:\Program Files\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files\Unlocker\UnlockerAssistant.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe
(Kakao Corp. ) C:\Program Files\Kakao\KakaoTalk\KakaoTalk.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-10-19] (NVIDIA Corporation)
HKLM\...\Run: [UnlockerAssistant] => C:\Program Files\Unlocker\UnlockerAssistant.exe [17408 2010-07-05] ()
HKLM\...\Run: [NeroFilterCheck] => C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-30] (AVAST Software)
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6843808 2017-06-21] (SUPERAntiSpyware)
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [7648984 2017-06-13] (Piriform Ltd)
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\Run: [KSS] => C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab)
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\Run: [Kaspersky Software Updater] => C:\Program Files\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe [1565000 2016-11-26] (AO Kaspersky Lab)
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\Run: [KakaoTalk] => C:\Program Files\Kakao\KakaoTalk\KakaoTalk.exe [8315200 2017-06-20] (Kakao Corp. )
HKU\S-1-5-18\...\Run: [KSS] => C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2016-01-29] (Microsoft Corporation)
HKLM\...\Providers\tuyazueu: C:\Program Files\Buqaghghnet Builder\local32spl.dll <===== ATTENTION
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-05-30] (AVAST Software)
BootExecute: autocheck autochk * ROBoot \??\C:\Windows\system32\ASOROSet.bin
GroupPolicy: Restriction ? <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 168.126.63.1 168.126.63.2
Tcpip\..\Interfaces\{66B87001-DA33-470B-9512-77BE9AE4D883}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7E8271E6-6142-41FD-83BE-949EBBBBA13D}: [DhcpNameServer] 168.126.63.1 168.126.63.2
Tcpip\..\Interfaces\{9062A7D0-A780-4AB6-A1B1-967D5C1EB26C}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{B3CE4C30-3C2F-4806-AE63-1892B7E644A5}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D3E6FB35-F97B-4C66-817B-66630537B25B}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2016-07-05] (Internet Download Manager, Tonec Inc.)
BHO: avast! WebRep -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-30] (AVAST Software)
Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-05-30] (AVAST Software)
FireFox:
========
FF ProfilePath: C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008 [2017-06-21]
FF Homepage: Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008 -> hxxps://login.yahoo.com/?.src=ym&.intl=us&.lang=en-US&.done=https%3a//mail.yahoo.com
FF Extension: (Flash Video Downloader - YouTube HD Download [4K]) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\artur.dubovoy@gmail.com [2017-06-15]
FF Extension: (FlashStopper) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\flashstopper@byo.co.il.xpi [2017-03-10]
FF Extension: (Google Search by Image) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\google@hitachi.com.xpi [2017-02-02]
FF Extension: (Markdown Viewer) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\markdownviewer@thiht.fr.xpi [2017-01-07]
FF Extension: (Restart Button) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\restartbutton@strk.jp.xpi [2016-08-16]
FF Extension: (Avast SafePrice) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\sp@avast.com.xpi [2017-06-02]
FF Extension: (Avast Online Security) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\wrc@avast.com.xpi [2017-06-02]
FF Extension: (Bulk Media Downloader) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\{72b2e02b-3a71-4895-886c-fd12ebe36ba3}.xpi [2017-06-15]
FF Extension: (CacheViewer Fx21) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\{81328583-3CA7-4809-B4BA-570A85818FBB} [2017-03-24]
FF Extension: (Video DownloadHelper) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-05-09]
FF Extension: (Adblock Plus) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\9ywgrdrs.default-1471039942008\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-08]
FF HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files\Internet Download Manager\idmmzcc2.xpi [2016-06-08]
FF HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\IDM\idmmzcc5 [2017-06-21] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-18] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-04-06] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-04-06] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-04-06] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-04-06] (Foxit Corporation)
FF Plugin: @Nero.com/KM -> C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2016-02-29] (Nero AG)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-18] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-18] (NVIDIA Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-06-20] <==== ATTENTION
CHR Extension: (Chrome Web Store Payments) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-12]
CHR Extension: (Gmail) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-24]
CHR Extension: (Chrome Media Router) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-23]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2016-06-10]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [143776 2017-02-09] (SUPERAntiSpyware.com)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5732136 2017-05-30] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-30] (AVAST Software)
R2 FoxitReaderService; C:\Program Files\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2017-04-13] (Foxit Software Inc.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [930240 2016-10-19] (NVIDIA Corporation)
R2 kss; C:\Program Files\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab)
R3 ksu; C:\Program Files\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe [1565000 2016-11-26] (AO Kaspersky Lab)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [792944 2016-01-28] (Nero AG)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-10-19] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2904000 2016-10-19] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016704 2016-10-19] (NVIDIA Corporation)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 Bapeward; C:\Program Files\Tersatlaty\DrbCommunity.dll [X]
S2 WSWNDA3100v2; C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 5AF767F5; C:\Windows\System32\drivers\5AF767F5.sys [153784 2016-04-01] (Kaspersky Lab ZAO)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdriverx.sys [258288 2017-05-30] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidshx.sys [148696 2017-05-30] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswblogx.sys [268016 2017-05-30] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbunivx.sys [41664 2017-05-30] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [34136 2017-05-30] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [31064 2017-05-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107928 2017-05-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [90336 2017-05-30] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [62152 2017-05-30] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [764576 2017-05-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [482608 2017-05-30] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [115152 2017-05-30] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [279800 2017-05-30] (AVAST Software)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [392352 2017-05-24] (Symantec Corporation)
R1 epp; C:\EEK\bin32\epp.sys [105248 2016-11-23] (Emsisoft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26048 2016-10-19] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [50744 2016-08-04] (NVIDIA Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX32.sys [134928 2016-02-14] (Ray Hinchliffe)
S3 tatertot.scr; C:\Windows\system32\drivers\tatertot.scr.sys [34816 2017-06-01] () [File not signed]
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
S3 BCMH43XX; system32\DRIVERS\bcmwlhigh6.sys [X]
S3 catchme; \??\C:\Users\DANIEL~1.PC\AppData\Local\Temp\catchme.sys [X]
S1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae.sys [X]
S2 MBAMChameleon; \SystemRoot\system32\drivers\MBAMChameleon.sys [X]
S3 MBAMFarflt; \??\C:\Windows\system32\drivers\farflt.sys [X]
S3 MBAMProtection; \??\C:\Windows\system32\drivers\mbam.sys [X]
S3 MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam32.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard32.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-21 17:37 - 2017-06-21 17:38 - 00020035 _____ C:\Users\Daniel M. Burkus.PC\Desktop\FRST.txt
2017-06-21 17:34 - 2017-06-21 17:35 - 01778176 _____ (Farbar) C:\Users\Daniel M. Burkus.PC\Desktop\FRST.exe
2017-06-21 15:56 - 2017-06-21 15:56 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-06-19 16:46 - 2017-06-19 17:04 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\HTML code
2017-06-19 09:22 - 2017-06-19 09:22 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 11 (Notes).txt
2017-06-19 09:21 - 2017-06-19 09:21 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 9 (Notes).txt
2017-06-19 09:21 - 2017-06-19 09:21 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 8 (Notes).txt
2017-06-19 09:21 - 2017-06-19 09:21 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 10 (Notes).txt
2017-06-19 09:20 - 2017-06-19 09:20 - 00000412 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 11 (Text).txt
2017-06-19 09:20 - 2017-06-19 09:20 - 00000390 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 10 (Text).txt
2017-06-19 09:19 - 2017-06-19 09:19 - 00000388 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 9 (Text).txt
2017-06-19 09:18 - 2017-06-19 09:18 - 00000384 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 8 (Text).txt
2017-06-18 16:35 - 2017-06-18 16:35 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2017-06-18 16:35 - 2017-06-18 16:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2017-06-18 15:48 - 2017-06-18 15:49 - 18609717 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Baby Elephant's Birthday Present.mp4
2017-06-17 20:22 - 2017-06-18 13:40 - 00000000 ____D C:\afd6bb1c0cd15e66d1cca9dae705a300
2017-06-17 17:48 - 2017-06-18 14:35 - 00000000 ____D C:\ProgramData\SMR501
2017-06-17 17:38 - 2017-06-17 17:38 - 00032416 _____ C:\ComboFix.txt
2017-06-17 16:40 - 2017-06-17 17:47 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\uTorrent
2017-06-17 01:47 - 2017-06-17 01:47 - 00000000 ___RD C:\Users\Daniel M. Burkus.PC\Virtual Machines
2017-06-17 00:51 - 2017-06-20 19:38 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-06-16 23:16 - 2017-06-16 23:16 - 00019960 _____ (Wiper Software) C:\Windows\system32\wiperrm.exe
2017-06-16 23:16 - 2017-06-16 23:16 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\CrashRpt
2017-06-16 22:06 - 2017-06-16 22:09 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\Event Logs (June 16)
2017-06-15 13:50 - 2017-06-15 13:50 - 00000384 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 7 (Text).txt
2017-06-15 13:50 - 2017-06-15 13:50 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 7 (Notes).txt
2017-06-15 13:50 - 2017-06-15 13:50 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 6 (Notes).txt
2017-06-15 13:49 - 2017-06-20 01:27 - 00000384 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4, Part 6 (Text).txt
2017-06-14 06:23 - 2017-06-14 06:23 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\THE LETTERS OF WILLIAM ADAMS
2017-06-13 07:46 - 2017-06-13 07:46 - 00000029 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Google Translate.txt
2017-06-12 13:50 - 2017-06-12 13:50 - 00010282 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Book 4.4, Taji (material removed from footnote).txt
2017-06-12 07:44 - 2017-06-12 07:44 - 00000000 ____D C:\$AV_ASW
2017-06-11 19:28 - 2017-06-11 19:28 - 00000007 _____ C:\Users\Daniel M. Burkus.PC\Desktop\covfefe.txt
2017-06-11 10:06 - 2017-06-07 21:49 - 00103665 _____ C:\Windows\system32\Drivers\etc\hosts.20170611-100617.backup
2017-06-08 08:54 - 2017-06-08 08:54 - 00001457 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Little White Duck.txt
2017-06-07 21:50 - 2017-06-07 21:50 - 00000000 ___HD C:\$windows.~bt
2017-06-07 09:56 - 2017-06-07 09:58 - 00000309 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Check Windows Installation for Errors.txt
2017-06-07 09:53 - 2017-06-07 09:53 - 00000101 _____ C:\Users\Daniel M. Burkus.PC\Desktop\shutdown error details.txt
2017-06-04 17:58 - 2017-06-04 17:58 - 00114051 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Remove Necurs (Rootkits).htm
2017-06-04 17:58 - 2017-06-04 17:58 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\Remove Necurs (Rootkits)_files
2017-06-04 13:45 - 2017-06-17 17:39 - 00000000 ____D C:\Qoobox
2017-06-04 13:45 - 2011-06-26 15:45 - 00256000 _____ C:\Windows\PEV.exe
2017-06-04 13:45 - 2010-11-08 02:20 - 00208896 _____ C:\Windows\MBR.exe
2017-06-04 13:45 - 2009-04-20 13:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2017-06-04 13:45 - 2000-08-31 09:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2017-06-04 13:45 - 2000-08-31 09:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2017-06-04 13:45 - 2000-08-31 09:00 - 00098816 _____ C:\Windows\sed.exe
2017-06-04 13:45 - 2000-08-31 09:00 - 00080412 _____ C:\Windows\grep.exe
2017-06-04 13:45 - 2000-08-31 09:00 - 00068096 _____ C:\Windows\zip.exe
2017-06-04 13:37 - 2017-06-16 14:20 - 00000000 ____D C:\AdwCleaner
2017-06-04 13:36 - 2017-06-04 13:36 - 01010146 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Complete List of Latin Phrases.htm
2017-06-04 13:36 - 2017-06-04 13:36 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\Complete List of Latin Phrases_files
2017-06-04 11:17 - 2017-06-21 17:37 - 00000000 ____D C:\FRST
2017-06-04 06:46 - 2017-05-31 23:11 - 00096713 _____ C:\Windows\system32\Drivers\etc\hosts.20170604-064642.backup
2017-06-03 17:32 - 2017-06-03 17:32 - 00001712 _____ C:\Windows\system32\ASOROSet.bin
2017-06-03 17:30 - 2017-06-03 17:32 - 00000000 ____D C:\Windows\system32\config\RCCBakup
2017-06-02 14:04 - 2017-06-02 14:04 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\dll-files.com
2017-06-02 12:57 - 2017-06-02 12:57 - 00056151 _____ C:\Users\Daniel M. Burkus.PC\Desktop\how to turn on hardware virtualization in my bios - Windows 7 Help Forums.htm
2017-06-02 12:57 - 2017-06-02 12:57 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\how to turn on hardware virtualization in my bios - Windows 7 Help Forums_files
2017-06-01 10:07 - 2017-06-01 10:08 - 475850190 _____ C:\Users\Daniel M. Burkus.PC\Desktop\[HigherJourneys] Who is ''the New Human''.mp4
2017-06-01 09:31 - 2017-06-01 09:31 - 00034816 _____ C:\Windows\system32\Drivers\tatertot.scr.sys
2017-05-31 23:38 - 2017-05-31 23:38 - 00000336 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Boot from a Flash Drive.txt
2017-05-31 22:48 - 2011-05-02 15:05 - 00001611 _____ C:\Windows\system32\Drivers\etc\mvps.bat
2017-05-31 08:04 - 2017-05-31 08:04 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\Kakao
2017-05-31 08:02 - 2017-05-31 08:02 - 00000000 ____D C:\Program Files\Kakao
2017-05-30 17:19 - 2017-05-30 17:19 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\AVAST Software
2017-05-30 17:14 - 2017-05-30 17:29 - 00115152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2017-05-30 17:14 - 2017-05-30 17:14 - 00034136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-05-30 17:14 - 2017-05-30 17:13 - 00330768 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-05-30 17:14 - 2017-05-30 17:13 - 00268016 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswblogx.sys
2017-05-30 17:14 - 2017-05-30 17:13 - 00258288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2017-05-30 17:14 - 2017-05-30 17:13 - 00148696 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidshx.sys
2017-05-30 17:14 - 2017-05-30 17:13 - 00041664 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbunivx.sys
2017-05-30 17:14 - 2017-05-30 17:13 - 00031064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-05-30 17:11 - 2017-05-30 17:14 - 00279800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-05-30 17:11 - 2017-05-30 17:14 - 00062152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-05-30 17:05 - 2017-05-30 17:14 - 00482608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-05-30 17:05 - 2017-05-30 17:14 - 00107928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-05-30 17:05 - 2017-05-30 17:14 - 00090336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-05-30 17:05 - 2017-05-30 17:13 - 00764576 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-05-30 17:00 - 2017-05-30 17:13 - 00000000 ____D C:\Program Files\AVAST Software
2017-05-30 16:54 - 2017-05-30 16:54 - 00024963 _____ C:\Windows\system32\servers.def.lkg
2017-05-30 16:54 - 2017-05-30 16:54 - 00024963 _____ C:\Windows\system32\servers.def
2017-05-30 16:54 - 2017-05-30 16:54 - 00002847 _____ C:\Windows\system32\servers.def.vpx
2017-05-30 16:54 - 2017-05-30 16:54 - 00001624 _____ C:\Windows\system32\uat.vpx
2017-05-30 16:54 - 2017-05-30 16:54 - 00000452 _____ C:\Windows\system32\prod-vps.vpx
2017-05-30 16:54 - 2017-05-30 16:54 - 00000446 _____ C:\Windows\system32\prod-pgm.vpx
2017-05-30 16:54 - 2017-05-30 16:54 - 00000039 _____ C:\Windows\system32\Stats.ini
2017-05-30 07:54 - 2017-06-18 14:35 - 00000000 ____D C:\ProgramData\RogueKiller
2017-05-30 07:54 - 2017-06-16 12:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-05-29 19:22 - 2017-05-31 07:44 - 00001364 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Locked Registry Keys.txt
2017-05-28 14:57 - 2017-06-16 18:46 - 00008204 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Feria de San Isidro 2017.txt
2017-05-28 13:24 - 2017-05-27 17:51 - 00096713 _____ C:\Windows\system32\Drivers\etc\hosts.20170528-132455.backup
2017-05-27 10:38 - 2017-05-27 10:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2017-05-24 18:00 - 2017-05-24 18:00 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2017-05-24 17:56 - 2017-05-24 17:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
2017-05-24 17:56 - 2017-05-24 17:56 - 00000000 ____D C:\Windows\system32\Drivers\NSS
2017-05-24 17:56 - 2017-05-24 17:56 - 00000000 ____D C:\ProgramData\NortonInstaller
2017-05-24 17:56 - 2017-05-24 17:56 - 00000000 ____D C:\Program Files\NortonInstaller
2017-05-24 17:56 - 2017-05-24 17:56 - 00000000 ____D C:\Program Files\Norton Security Scan
2017-05-24 11:49 - 2017-06-17 17:51 - 00000000 ____D C:\NPE
2017-05-24 11:42 - 2017-06-18 14:35 - 00000000 ____D C:\ProgramData\Norton
2017-05-24 11:42 - 2017-06-17 18:02 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\NPE
2017-05-23 22:05 - 2017-05-23 22:05 - 00001117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-05-23 22:05 - 2017-05-23 22:05 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2017-05-23 08:36 - 2017-05-23 08:36 - 00001700 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Uninstalling Flash Player.txt
2017-05-23 07:20 - 2017-06-17 00:25 - 00000000 ____D C:\EEK
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-21 15:53 - 2016-11-16 20:55 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\LocalLow\Mozilla
2017-06-21 15:40 - 2009-07-14 13:34 - 00024208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-21 15:40 - 2009-07-14 13:34 - 00024208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-21 15:35 - 2016-01-29 01:50 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-21 15:35 - 2009-07-14 13:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-21 09:53 - 2016-08-06 20:33 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\DMCache
2017-06-21 09:13 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\inf
2017-06-21 09:01 - 2016-03-25 18:43 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-06-20 19:31 - 2016-09-25 20:36 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\IDM
2017-06-19 09:22 - 2016-12-06 09:07 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\Rikyu Chanoyu Sho
2017-06-18 18:03 - 2016-08-18 23:06 - 00000003 _____ C:\Users\Daniel M. Burkus.PC\Desktop\movie time.txt
2017-06-18 16:38 - 2016-03-26 17:13 - 00000000 ____D C:\My Documents
2017-06-18 16:35 - 2016-09-25 20:35 - 00000000 ____D C:\Program Files\Internet Download Manager
2017-06-18 14:36 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\system32\migwiz
2017-06-18 14:36 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-06-18 14:35 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\servicing
2017-06-18 14:35 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\registration
2017-06-18 09:03 - 2016-01-29 05:02 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2017-06-18 09:03 - 2016-01-29 05:02 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2017-06-18 09:03 - 2016-01-29 05:02 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-17 21:37 - 2016-03-24 07:59 - 00000000 ____D C:\Users\Daniel M. Burkus.PC
2017-06-17 18:29 - 2016-02-15 14:58 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-06-17 17:36 - 2009-07-14 11:04 - 00000215 _____ C:\Windows\system.ini
2017-06-17 00:27 - 2016-05-13 13:31 - 129479984 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe
2017-06-17 00:25 - 2016-03-26 19:27 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\CrashDumps
2017-06-16 22:54 - 2016-01-29 16:20 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-16 22:23 - 2016-04-25 09:08 - 00000000 ____D C:\ProgramData\TEMP
2017-06-16 21:34 - 2016-08-03 15:36 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\SCAN TOOLS
2017-06-16 21:15 - 2016-04-13 21:34 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\vlc
2017-06-16 12:24 - 2016-02-15 14:57 - 00000000 ____D C:\Program Files\RogueKiller
2017-06-15 12:35 - 2017-01-02 11:08 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\Blog Photos
2017-06-15 08:21 - 2016-07-17 08:34 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-14 18:45 - 2016-09-17 09:02 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\Convert to PDF
2017-06-13 19:36 - 2016-03-24 19:10 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\Adobe
2017-06-13 12:27 - 2016-12-06 13:45 - 00000343 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Interesting Quotes.txt
2017-06-12 15:48 - 2016-03-24 20:56 - 00001012 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Blog Templates.txt
2017-06-07 01:02 - 2016-06-12 15:27 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\Articles
2017-05-31 18:42 - 2009-07-14 13:53 - 00032564 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-05-31 08:04 - 2016-05-07 19:16 - 00001089 _____ C:\ProgramData\Microsoft\Windows\Start Menu\KakaoTalk.lnk
2017-05-31 07:58 - 2016-06-04 16:56 - 00002335 _____ C:\DelFix.txt
2017-05-30 17:14 - 2016-01-29 16:28 - 00000000 ____D C:\ProgramData\AVAST Software
2017-05-30 17:11 - 2009-07-14 11:04 - 00002577 _____ C:\Windows\system32\config.nt
2017-05-30 17:05 - 2009-07-14 13:52 - 00000000 ____D C:\Program Files\Windows Sidebar
2017-05-30 16:55 - 2016-01-29 04:56 - 00000000 ____D C:\Program Files\Common Files\AV
2017-05-29 23:30 - 2009-07-14 09:18 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\spoolss.dll
2017-05-29 23:29 - 2016-09-12 19:17 - 00290304 _____ (Microsoft Corporation) C:\Windows\system32\subinacl.exe
2017-05-28 15:12 - 2016-06-04 08:12 - 00007635 _____ C:\Users\Daniel M. Burkus.PC\AppData\Local\Resmon.ResmonCfg
2017-05-24 08:38 - 2016-09-21 20:13 - 00001420 _____ C:\Users\Daniel M. Burkus.PC\Desktop\SCAN TOOLS (Download URLs).txt
2017-05-23 22:33 - 2016-06-15 19:12 - 00000000 ____D C:\Program Files\Google
2017-05-23 22:05 - 2016-11-16 16:35 - 00000000 ____D C:\Program Files\Mozilla Firefox
2017-05-23 15:57 - 2016-03-24 13:15 - 00000000 ____D C:\Program Files\Recuva
2017-05-22 06:19 - 2017-05-11 08:44 - 00000128 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Mori-san's Address.txt
==================== Files in the root of some directories =======
2016-03-24 19:18 - 2016-07-09 08:20 - 0000438 _____ () C:\Users\Daniel M. Burkus.PC\AppData\Local\ReclaiMe.config
2016-06-04 08:12 - 2017-05-28 15:12 - 0007635 _____ () C:\Users\Daniel M. Burkus.PC\AppData\Local\Resmon.ResmonCfg
2016-03-24 19:18 - 2016-07-09 08:20 - 0001346 _____ () C:\ProgramData\ReclaiMe.config
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-12 07:06
==================== End of FRST.txt ============================