Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by user (administrator) on BRONS-PC (12-11-2015 12:07:46)
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available Profiles: user)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [RaidCall] => C:\Program Files (x86)\RaidCall\raidcall.exe [4152984 2015-02-11] (RAIDCALL.COM)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-21-2055689581-48535413-3719112780-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-2055689581-48535413-3719112780-1000\...\Run: [GoogleChromeAutoLaunch_4E874A737D5662A34EBBEADB3A9C4A09] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [811848 2015-11-07] (Google Inc.)
HKU\S-1-5-21-2055689581-48535413-3719112780-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-2055689581-48535413-3719112780-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [48138880 2015-10-14] (Skype Technologies S.A.)
BootExecute: autocheck autochk * bootdelete
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{6E7D7906-54DD-4042-81E5-EB8C7F91EC4A}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8C930C13-1218-40D7-8434-D3180DE42253}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2055689581-48535413-3719112780-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-11-07] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-11-07] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\op8egejq.default-1446260642654
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-09-19] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-09-19] ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-04] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-11-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-11-07] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-06] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-06] (NVIDIA Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\user\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-11-07] (Google Inc.)
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-07]
CHR Extension: (From Dust) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2015-11-07]
CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-07]
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-07]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-07]
CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-07]
CHR Extension: (Dropbox for Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2015-11-07]
CHR Extension: (Google Sheets) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-07]
CHR Extension: (Google Docs Offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-08]
CHR Extension: (AdBlock) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-07]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2015-11-07]
CHR Extension: (Skype Click to Call) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-11-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-07]
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-07]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation)
S4 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2015-09-02] (Hi-Rez Studios) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-03] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-08-01] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-09-13] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-08-20] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-10-03] (NVIDIA Corporation)
S3 RtlWlanu; C:\Windows\System32\DRIVERS\DRTWlanU.sys [3409112 2014-07-30] (Realtek Semiconductor Corporation )
R3 ysusb64; C:\Windows\System32\drivers\ysusb64.sys [132712 2014-07-22] (Yamaha Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-12 12:05 - 2015-11-12 12:07 - 00015276 _____ C:\Users\user\Desktop\FRST.txt
2015-11-12 12:05 - 2015-11-12 12:07 - 00000000 ____D C:\FRST
2015-11-12 12:05 - 2015-11-12 12:05 - 00000000 ____D C:\Users\user\Desktop\FRST-OlderVersion
2015-11-11 16:28 - 2015-11-06 01:41 - 00102704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-11-11 12:29 - 2015-11-06 04:13 - 42914096 _____ C:\Windows\system32\nvcompiler.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 37882488 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 22308656 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 18362160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 17515208 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 16553568 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 15717864 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 14835872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 13527248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 12034248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 11130488 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-11-11 12:29 - 2015-11-06 04:13 - 02870392 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 02490488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 01905272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435891.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 01564792 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435891.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00877360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00861816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00689272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00673912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00500872 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00467912 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00422240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00413816 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00388208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00369272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00177600 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00155792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00151368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-11-11 12:29 - 2015-11-06 04:13 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-11-10 12:23 - 2015-11-10 12:23 - 00000000 ____D C:\Users\user\AppData\Local\Fallout4
2015-11-10 01:25 - 2015-11-10 01:26 - 00000222 _____ C:\Users\user\Desktop\Fallout 4.url
2015-11-09 15:07 - 2015-11-09 15:07 - 00000000 ____D C:\Users\user\Tracing
2015-11-09 15:05 - 2015-11-12 12:03 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2015-11-09 15:05 - 2015-11-09 15:11 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-11-09 15:05 - 2015-11-09 15:05 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
2015-11-09 15:05 - 2015-11-09 15:05 - 00000000 ____D C:\Users\user\AppData\Local\Skype
2015-11-09 15:05 - 2015-11-09 15:05 - 00000000 ____D C:\ProgramData\Skype
2015-11-09 15:05 - 2015-11-09 15:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-11-09 15:03 - 2015-11-09 15:03 - 01503872 _____ (Skype Technologies S.A.) C:\Users\user\Downloads\SkypeSetup.exe
2015-11-09 14:48 - 2015-11-09 14:48 - 00000222 _____ C:\Users\user\Desktop\Rogue Legacy.url
2015-11-09 01:46 - 2015-11-09 01:46 - 00000222 _____ C:\Users\user\Desktop\Warhammer End Times - Vermintide.url
2015-11-09 01:43 - 2015-11-09 01:43 - 00001120 _____ C:\Users\user\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-09 01:41 - 2015-11-12 12:03 - 00000000 ____D C:\Program Files (x86)\Steam
2015-11-09 01:41 - 2015-11-09 01:41 - 00000963 _____ C:\Users\Public\Desktop\Steam.lnk
2015-11-09 01:41 - 2015-11-09 01:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-11-09 01:38 - 2015-11-09 01:38 - 01476720 _____ C:\Users\user\Downloads\SteamSetup (1).exe
2015-11-07 15:08 - 2015-11-11 17:13 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-11-07 15:08 - 2015-11-07 15:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-11-07 15:07 - 2015-11-12 00:12 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-07 15:07 - 2015-11-07 15:07 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-11-07 15:06 - 2015-11-12 11:59 - 00000890 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-07 15:06 - 2015-11-07 15:06 - 00003638 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-11-07 12:10 - 2015-11-07 12:11 - 00001771 _____ C:\DelFix.txt
2015-11-07 12:10 - 2015-11-07 12:10 - 00000000 ____D C:\Windows\ERUNT
2015-11-07 12:02 - 2015-11-07 12:02 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-11-07 12:02 - 2015-11-07 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-07 12:01 - 2015-11-07 12:01 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-07 11:57 - 2015-11-07 11:57 - 00584288 _____ (Oracle Corporation) C:\Users\user\Downloads\jre-8u65-windows-i586-iftw.exe
2015-11-06 18:09 - 2015-11-06 18:09 - 00000000 ____D C:\Users\user\AppData\Local\CrashDumps
2015-11-06 18:00 - 2015-11-06 04:13 - 15121784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-11-06 18:00 - 2015-11-03 09:48 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-11-06 18:00 - 2015-11-03 09:48 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-11-06 18:00 - 2015-11-03 04:10 - 01905456 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435887.dll
2015-11-06 18:00 - 2015-11-03 04:10 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435887.dll
2015-11-05 16:38 - 2015-11-05 16:39 - 00000000 ____D C:\ProgramData\Sophos
2015-11-05 16:37 - 2015-11-05 16:37 - 00002759 _____ C:\Users\user\Desktop\Sophos Virus Removal Tool.lnk
2015-11-05 16:37 - 2015-11-05 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-11-05 16:37 - 2015-11-05 16:37 - 00000000 ____D C:\Program Files (x86)\Sophos
2015-11-05 16:29 - 2015-11-05 16:35 - 137405704 _____ (Sophos Limited) C:\Users\user\Desktop\Sophos Virus Removal Tool.exe
2015-11-05 16:27 - 2015-11-05 16:28 - 00448512 _____ (OldTimer Tools) C:\Users\user\Desktop\TFC.exe
2015-11-05 16:25 - 2015-11-05 16:26 - 00002746 _____ C:\Users\user\Desktop\FSS.txt
2015-11-05 16:25 - 2015-11-05 16:25 - 00899072 _____ (Farbar) C:\Users\user\Desktop\FSS.exe
2015-11-05 16:21 - 2015-11-05 16:21 - 00852720 _____ C:\Users\user\Desktop\SecurityCheck.exe
2015-11-04 15:05 - 2015-11-04 15:15 - 00000000 ____D C:\Windows\erdnt
2015-11-04 15:01 - 2015-11-04 15:02 - 05637361 ____R (Swearware) C:\Users\user\Desktop\ComboFix.exe
2015-11-02 17:49 - 2015-11-02 17:49 - 00001756 _____ C:\Users\user\Desktop\JRT.txt
2015-11-02 17:14 - 2015-11-09 17:24 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-02 17:13 - 2015-11-02 17:13 - 00001102 _____ C:\Users\user\Desktop\Malwarebytes Anti-Malware (2).lnk
2015-11-02 17:13 - 2015-11-02 17:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-02 17:13 - 2015-11-02 17:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-02 17:13 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-11-02 17:13 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-11-02 17:13 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-11-02 16:54 - 2015-11-02 16:55 - 22908888 _____ (Malwarebytes ) C:\Users\user\Downloads\mbam-setup-2.2.0.1024.exe
2015-10-31 18:49 - 2015-11-12 12:05 - 02198528 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2015-10-31 18:41 - 2015-10-31 18:41 - 00000848 _____ C:\Users\user\Desktop\RogueKiller.lnk
2015-10-31 18:41 - 2015-10-31 18:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2015-10-31 18:41 - 2015-10-31 18:41 - 00000000 ____D C:\Program Files\RogueKiller
2015-10-31 18:37 - 2015-10-31 18:41 - 24925400 _____ (Adlice Software ) C:\Users\user\Downloads\setup.exe
2015-10-31 18:28 - 2015-10-31 18:28 - 00003176 _____ C:\Windows\System32\Tasks\{A8EA9BD8-0656-4434-BDB3-191E1EB378C5}
2015-10-31 18:21 - 2015-11-02 16:53 - 00037624 _____ C:\Windows\system32\Drivers\TrueSight.sys
2015-10-31 18:21 - 2015-10-31 18:26 - 00000000 ____D C:\ProgramData\RogueKiller
2015-10-31 15:04 - 2015-10-31 15:04 - 00000000 ____D C:\Users\user\Downloads\backups
2015-10-31 15:02 - 2015-10-31 18:08 - 00000816 _____ C:\Users\user\Documents\hosts.txt
2015-10-31 14:59 - 2015-10-31 14:59 - 06792566 _____ C:\Users\user\Documents\USER-PC.arn
2015-10-31 14:45 - 2015-10-31 14:45 - 00606643 _____ C:\Users\user\Downloads\Autoruns.zip
2015-10-31 13:14 - 2015-10-31 13:14 - 00000621 _____ C:\Users\user\Desktop\windowsk.vbs
2015-10-30 21:46 - 2015-10-30 21:49 - 00000000 ___HD C:\Program Files (x86)\Temp
2015-10-30 21:46 - 2015-05-27 17:38 - 02825944 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2015-10-30 21:45 - 2015-10-30 21:46 - 131494359 _____ (Realtek Semiconductor Corp.) C:\Users\user\Downloads\0006-64bit_Win7_Win8_Win81_Win10_R279.exe
2015-10-30 19:55 - 2015-10-30 19:55 - 00000015 _____ C:\Users\user\Desktop\WIFI.txt
2015-10-25 11:56 - 2015-10-25 12:41 - 00000000 ____D C:\Users\user\AppData\Roaming\Winamp
2015-10-25 11:56 - 2015-10-25 12:02 - 00000000 ____D C:\Program Files (x86)\Winamp
2015-10-25 11:56 - 2015-10-25 11:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
2015-10-25 11:49 - 2015-10-25 11:54 - 10328598 _____ (Nullsoft, Inc.) C:\Users\user\Downloads\winamp5666_full_en-us_redux.exe
2015-10-24 13:13 - 2015-10-24 13:13 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-10-24 13:13 - 2015-10-24 13:13 - 00001945 _____ C:\Windows\epplauncher.mif
2015-10-24 13:13 - 2015-10-24 13:13 - 00000000 ____D C:\Program Files\Microsoft Security Client
2015-10-24 13:13 - 2015-10-24 13:13 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2015-10-24 13:12 - 2015-10-24 13:12 - 14243008 _____ (Microsoft Corporation) C:\Users\user\Downloads\mseinstall.exe
2015-10-24 12:33 - 2015-11-06 04:13 - 12770752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-10-24 12:33 - 2015-11-06 04:13 - 03158736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-10-24 12:33 - 2015-10-03 16:06 - 01905456 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435850.dll
2015-10-24 12:33 - 2015-10-03 16:06 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435850.dll
2015-10-24 12:33 - 2015-10-03 16:06 - 00069416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-10-24 12:33 - 2015-10-03 16:06 - 00050472 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-10-24 12:31 - 2015-10-24 12:31 - 00000000 ____D C:\NVIDIA
2015-10-24 12:13 - 2015-10-24 12:13 - 00000000 ____D C:\Users\user\AppData\Roaming\Sun
2015-10-24 12:13 - 2015-10-24 12:13 - 00000000 ____D C:\Users\user\AppData\LocalLow\Sun
2015-10-24 12:13 - 2015-10-24 12:13 - 00000000 ____D C:\Users\user\.oracle_jre_usage
2015-10-24 12:13 - 2015-10-24 12:13 - 00000000 ____D C:\ProgramData\Oracle
2015-10-24 12:11 - 2015-10-24 12:11 - 00584288 _____ (Oracle Corporation) C:\Users\user\Downloads\chromeinstall-8u65.exe
2015-10-24 12:11 - 2015-10-24 12:11 - 00000000 ____D C:\Users\user\AppData\LocalLow\Oracle
2015-10-24 01:27 - 2015-10-24 01:27 - 00000000 ____D C:\Program Files\Common Files\Steinberg
2015-10-24 01:27 - 2015-10-24 01:27 - 00000000 ____D C:\Program Files (x86)\Yamaha
2015-10-23 23:53 - 2015-10-23 23:53 - 00000000 ____D C:\Windows\{26F3D17D-4FF9-46D5-9255-A1F9FF6BD7E4}
2015-10-23 23:53 - 2015-10-23 23:53 - 00000000 ____D C:\Program Files (x86)\Belkin
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-12 12:06 - 2009-07-14 15:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-12 12:06 - 2009-07-14 15:45 - 00031312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-12 12:05 - 2009-07-14 16:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-12 12:02 - 2015-07-04 18:42 - 01060662 _____ C:\Windows\WindowsUpdate.log
2015-11-12 12:01 - 2015-08-20 23:38 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-11-12 11:59 - 2009-07-14 16:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-12 11:59 - 2009-07-14 15:51 - 00088252 _____ C:\Windows\setupact.log
2015-11-12 11:58 - 2015-07-04 18:58 - 00000000 ____D C:\ProgramData\NVIDIA
2015-11-12 11:58 - 2010-11-21 14:47 - 00640342 _____ C:\Windows\PFRO.log
2015-11-11 16:29 - 2015-07-04 18:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-11-11 16:29 - 2015-07-04 18:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-11-11 11:31 - 2009-07-14 16:32 - 00000000 ____D C:\Windows\addins
2015-11-10 12:23 - 2015-07-05 19:52 - 00000000 ____D C:\Users\user\Documents\My Games
2015-11-09 17:22 - 2009-07-14 14:20 - 00000000 ____D C:\Windows\system32\NDF
2015-11-07 15:08 - 2015-07-05 13:29 - 00000000 ____D C:\Users\user\AppData\Local\Google
2015-11-07 15:08 - 2015-07-05 13:29 - 00000000 ____D C:\Program Files (x86)\Google
2015-11-07 15:06 - 2015-07-05 13:29 - 00000000 ____D C:\Users\user\AppData\Local\Deployment
2015-11-07 12:55 - 2015-10-03 15:13 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-11-06 17:57 - 2015-07-08 20:24 - 00001377 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2015-11-06 17:22 - 2015-07-05 13:29 - 00000000 ____D C:\Users\user\AppData\Local\Apps\2.0
2015-11-06 04:13 - 2015-07-08 19:33 - 00033607 _____ C:\Windows\system32\nvinfo.pb
2015-11-06 04:13 - 2015-07-04 18:52 - 03579000 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-11-06 02:13 - 2015-07-04 18:58 - 00062584 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-11-06 02:13 - 2010-07-31 09:52 - 06358648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-11-06 02:13 - 2010-07-31 09:52 - 02983032 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-11-06 02:13 - 2010-07-31 09:52 - 02554488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-11-06 02:13 - 2010-07-31 09:52 - 00938616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-11-06 02:13 - 2010-07-31 09:52 - 00385328 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-11-04 15:16 - 2009-07-14 14:20 - 00000000 __RHD C:\Users\Default
2015-11-04 15:14 - 2009-07-14 13:34 - 00000215 _____ C:\Windows\system.ini
2015-11-03 09:48 - 2015-07-08 19:42 - 01572496 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-11-02 17:34 - 2009-07-14 14:20 - 00000000 ____D C:\Windows\SchCache
2015-10-31 17:28 - 2015-07-05 14:15 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-10-31 15:01 - 2015-07-04 18:45 - 00000000 ____D C:\Users\user\AppData\Local\VirtualStore
2015-10-31 13:59 - 2015-07-04 18:47 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-30 21:48 - 2015-07-04 18:48 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-10-28 18:42 - 2015-07-05 14:06 - 06027430 _____ C:\Windows\system32\nvcoproc.bin
2015-10-27 12:18 - 2009-07-14 16:08 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-10-24 12:34 - 2015-07-04 18:58 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-10-24 12:01 - 2015-07-08 19:42 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-10-24 11:44 - 2015-07-08 20:24 - 00000000 ____D C:\Users\user\AppData\Local\NVIDIA Corporation
2015-10-24 01:26 - 2015-07-04 18:48 - 00000000 ____D C:\Users\user\AppData\Local\Downloaded Installations
2015-10-24 00:03 - 2015-08-19 22:53 - 00000000 ____D C:\Windows\system32\appmgmt
2015-10-17 20:28 - 2015-10-03 17:02 - 00000000 ____D C:\Users\user\AppData\Roaming\fatshark
2015-10-15 12:50 - 2009-07-14 16:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-10-15 12:25 - 2015-08-18 21:04 - 00022528 ___SH C:\Users\user\Thumbs.db
Some files in TEMP:
====================
C:\Users\user\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\user\AppData\Local\Temp\nvStInst.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-11-10 03:52
==================== End of FRST.txt ============================