Is it okay if we can pause this for the moment, I uninstalled a VPN that might have been the culprit.
heres my logs just in case
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-07-2017
Ran by Nick (administrator) on NICK (07-07-2017 13:49:24)
Running from C:\Users\Nick\Downloads
Loaded Profiles: Nick (Available Profiles: Nick & Banana)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Mr. John aka japamd) C:\Users\Nick\Desktop\RadeonPro\RadeonProSupport.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\SndVol.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunes.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Picorover3) C:\Xlide\Xlideit.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
() C:\Program Files\PureRef\PureRef.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-11-02] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8911872 2016-10-15] (Realtek Semiconductor)
HKLM\...\Run: [TabletDriver] => C:\PenTabletDriver\TabletDriver.exe [655368 2017-04-19] (Graphic Tablet Company Shenzhen)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [58584 2016-09-28] (Raptr, Inc)
HKLM-x32\...\Run: [PlaysTV] => C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [71440 2016-06-06] (Plays.tv, LLC)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157456 2015-09-12] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2404952 2017-03-27] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [ForceActiveDesktopOn] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoRecentDocsHistory] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoFolderOptions] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoDrives] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoControlPanel] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoDriveTypeAutoRun] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoFind] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoFile] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoRun] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [HideClock] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoSetFolders] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoClose] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoDFSTab] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoLogoff] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [StartMenuLogoff] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoResolveSearch] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoResolveTrack] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoSaveSettings] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoHardwareTab] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoDesktop] 0 [67688 2017-07-06] ()
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 0 [67688 2017-07-06] ()
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Run: [Discord] => C:\Users\Nick\AppData\Local\Discord\app-0.0.297\Discord.exe [64290304 2017-01-04] (Hammer & Chisel, Inc.)
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27742168 2017-06-07] (Skype Technologies S.A.)
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
AppInit_DLLs: prio.dll => No File
AppInit_DLLs-x32: prio32.dll => No File
Startup: C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2016-07-22]
ShortcutTarget: Curse.lnk -> C:\Users\Nick\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
Startup: C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk [2017-06-24]
ShortcutTarget: ShareX.lnk -> C:\ShareX\ShareX.exe (ShareX Team)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{0176a071-34bd-487e-91ba-0ad426176add}: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{d08b08d9-9e90-44de-9d15-3d140b96ca49}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\S-1-5-21-1919207557-622674961-3464858116-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
SearchScopes: HKLM-x32 -> {8E663C5B-B546-41B9-BD2D-6727090C6731} URL = hxxp://
www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
FireFox:
========
FF DefaultProfile: tbp5edt3.default
FF ProfilePath: C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\tbp5edt3.default [2017-06-23]
FF Extension: (Imagus) - C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\tbp5edt3.default\Extensions\{00000f2a-7cde-4f20-83ed-434fcb420d71}.xpi [2017-04-27]
FF Extension: (Adblock Plus) - C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\tbp5edt3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-04-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-04-09] ()
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-03-27] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-04-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-09-04] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2016-04-18] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-03-27] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1919207557-622674961-3464858116-1002: @nsroblox.roblox.com/launcher -> C:\Users\Nick\AppData\Local\Roblox\Versions\version-6da8969024ca4410\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-1919207557-622674961-3464858116-1002: @nsroblox.roblox.com/launcher64 -> C:\Users\Nick\AppData\Local\Roblox\Versions\version-6da8969024ca4410\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-1919207557-622674961-3464858116-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Nick\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-07-14] (Unity Technologies ApS)
Chrome:
=======
CHR Profile: C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default [2017-07-07]
CHR Extension: (Google Drive) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-27]
CHR Extension: (YouTube) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-27]
CHR Extension: (uBlock Origin) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-06-21]
CHR Extension: (Betternet Unlimited Free VPN Proxy) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjknjjomckknofjidppipffbpoekiipm [2017-07-07]
CHR Extension: (Imagus) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\immpkjjlgappgfkkfieppnmlhakdmaab [2017-05-30]
CHR Extension: (GaiaUpgrade) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\njdjoeklfbahijdoadnlpagipchldkea [2017-07-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-27]
CHR Extension: (Fullscreen Anything) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\olcfgpmjldkkjdclidhcbonieibfhhdh [2017-05-08]
CHR Extension: (Gmail) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-27]
CHR Extension: (Chrome Media Router) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-11]
CHR Extension: (Save Image Router) - C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkimacjjcahflldkhofmdjlelllacbil [2017-07-03]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
Opera:
=======
OPR Extension: (Adguard AdBlocker) - C:\Users\Nick\AppData\Roaming\Opera Software\Opera Stable\Extensions\bopfaehpakahokaelnomggbohfbimcia [2017-02-15]
OPR Extension: (Imagus) - C:\Users\Nick\AppData\Roaming\Opera Software\Opera Stable\Extensions\immpkjjlgappgfkkfieppnmlhakdmaab [2017-06-13]
OPR Extension: (Download Chrome Extension) - C:\Users\Nick\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2017-02-14]
OPR Extension: (Fullscreen Anything) - C:\Users\Nick\AppData\Roaming\Opera Software\Opera Stable\Extensions\olcfgpmjldkkjdclidhcbonieibfhhdh [2017-02-14]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [771672 2017-03-14] (Adobe Systems Incorporated)
S3 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
S3 EasyAntiCheat; C:\windows\SysWOW64\EasyAntiCheat.exe [238376 2016-04-27] (EasyAntiCheat Ltd)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [143872 2014-10-24] (Microsoft Corporation) [File not signed]
S4 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [350064 2016-04-18] (WildTangent)
S3 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-09-23] (Hi-Rez Studios) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321056 2017-06-01] (HP Inc.)
S4 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [608520 2015-02-17] (Hewlett-Packard Development Company, L.P.)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [4362656 2016-02-24] (INCA Internet Co., Ltd.) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2122248 2016-07-10] (Electronic Arts)
S3 PAExec; C:\windows\PAExec.exe [189112 2016-10-12] (Power Admin LLC)
S4 PlaysService; C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe [32528 2016-06-06] (Plays.tv, LLC)
R2 RadeonPro Support Service; C:\Users\Nick\Desktop\RadeonPro\RadeonProSupport.exe [20608 2013-11-04] (Mr. John aka japamd) [File not signed]
S4 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [326656 2016-10-15] (Realtek Semiconductor)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [269400 2016-10-05] (Synaptics Incorporated)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [122368 2015-02-26] (Microsoft Corporation) [File not signed]
S3 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10884848 2017-05-23] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-03-04] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AmdAS4; C:\WINDOWS\System32\drivers\AmdAS4.sys [27376 2016-08-12] (Advanced Micro Devices, INC.)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0313745.inf_amd64_133311ca362c9cc6\atikmdag.sys [36558232 2017-05-03] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0313745.inf_amd64_133311ca362c9cc6\atikmpag.sys [528792 2017-05-03] (Advanced Micro Devices, Inc.)
R2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [101376 2016-12-08] (Advanced Micro Devices)
R3 clwvd6; C:\WINDOWS\system32\DRIVERS\clwvd6.sys [41400 2015-08-31] (CyberLink Corporation)
S3 DFX11_1; C:\WINDOWS\system32\drivers\dfx11_1x64.sys [28008 2017-06-19] (Windows (R) Win 7 DDK provider)
S3 DFX12; C:\WINDOWS\system32\drivers\dfx12x64.sys [39048 2017-06-19] (Windows (R) Win 7 DDK provider)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [109272 2017-07-04] (Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-07-04] (Malwarebytes)
R1 MpKsl60eaeca7; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{BAFFCFFE-3FEF-45D3-A25F-3C89B3290A83}\MpKsl60eaeca7.sys [44928 2017-07-07] (Microsoft Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [936192 2016-04-29] (Realtek )
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [411712 2015-05-21] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\WINDOWS\system32\DRIVERS\rtwlane.sys [6294016 2017-02-01] (Realtek Semiconductor Corporation )
R3 SmbDrv; C:\WINDOWS\system32\DRIVERS\Smb_driver_AMDASF.sys [76376 2016-10-05] (Synaptics Incorporated)
S3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [33960 2015-07-13] (Synaptics Incorporated)
R3 vmulti; C:\WINDOWS\System32\drivers\vmulti.sys [10752 2014-09-17] (Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [30544 2015-08-13] (HP)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [36832 2017-03-20] (Wellbia.com Co., Ltd.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-07 13:49 - 2017-07-07 13:58 - 00024626 _____ C:\Users\Nick\Downloads\FRST.txt
2017-07-07 13:48 - 2017-07-07 13:49 - 00000000 ____D C:\FRST
2017-07-07 13:48 - 2017-07-07 13:48 - 02436608 _____ (Farbar) C:\Users\Nick\Downloads\FRST64.exe
2017-07-07 13:48 - 2017-07-07 13:48 - 01782272 _____ (Farbar) C:\Users\Nick\Downloads\FRST.exe
2017-07-07 00:05 - 2017-07-07 00:05 - 00001145 _____ C:\Users\Nick\AppData\Roaming\PureRef.ini
2017-07-06 22:00 - 2017-07-06 22:00 - 00000719 _____ C:\Users\Public\Desktop\PenTabletDriver.lnk
2017-07-06 22:00 - 2017-07-06 22:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PenTabletDriver
2017-07-06 22:00 - 2017-04-18 17:09 - 00062984 _____ (Graphics Tablet) C:\WINDOWS\system32\wintab32.dll
2017-07-06 22:00 - 2017-04-18 17:09 - 00057864 _____ (Graphics Tablet) C:\WINDOWS\SysWOW64\wintab32.dll
2017-07-06 21:59 - 2017-07-06 22:04 - 00000000 ____D C:\PenTabletDriver
2017-07-06 21:47 - 2017-07-06 21:48 - 21159334 _____ C:\Users\Nick\Downloads\WIN_1060pro_H610pro_H610_Driver12.3.7.zip
2017-07-06 21:41 - 2014-09-17 10:47 - 00010752 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\vmulti.sys
2017-07-06 21:41 - 2014-09-17 10:47 - 00007680 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\hidkmdf.sys
2017-07-06 21:31 - 2017-07-06 21:32 - 08099476 _____ C:\Users\Nick\Downloads\HUION_WIN_G10T_GT156HD_v13.6.2.161226.zip
2017-07-06 20:15 - 2017-07-06 20:15 - 00033332 _____ C:\Users\Nick\Downloads\0 (1)
2017-07-06 20:13 - 2017-07-06 20:13 - 00067688 _____ C:\Users\Nick\Downloads\0
2017-07-06 16:25 - 2017-07-06 16:25 - 00000000 ____D C:\Users\Nick\AppData\LocalLow\Abrakam
2017-07-06 15:14 - 2017-07-06 15:16 - 07306358 _____ C:\Users\Nick\Downloads\xvideos.com_aebbac161063537bf697b0169d91c02a.mp4
2017-07-06 11:59 - 2017-07-06 12:00 - 00420420 _____ C:\WINDOWS\Minidump\070617-26812-01.dmp
2017-07-05 16:11 - 2017-07-05 16:11 - 00000000 ____D C:\Users\Nick\AppData\LocalLow\SmashGames
2017-07-05 16:09 - 2017-07-05 16:09 - 00000222 _____ C:\Users\Nick\Desktop\Warframe.url
2017-07-05 04:42 - 2017-07-05 04:42 - 00000000 ____D C:\Users\Nick\AppData\LocalLow\uTorrent
2017-07-04 21:52 - 2017-07-04 21:52 - 02558935 _____ C:\Users\Nick\Downloads\win10-10.0.0.341-whql.zip
2017-07-04 19:40 - 2016-01-13 13:35 - 01011504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinUsbCoInstaller2.dll
2017-07-04 19:40 - 2016-01-13 13:34 - 01730360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01009.dll
2017-07-04 19:36 - 2017-07-04 19:39 - 21136092 _____ C:\Users\Nick\Downloads\WIN_Driver12.2.16.zip
2017-07-04 19:23 - 2017-07-04 19:23 - 07098268 _____ (Huion Animation ) C:\Users\Nick\Downloads\Windows8.exe
2017-07-04 19:15 - 2017-07-04 19:16 - 07098268 _____ (Huion Animation ) C:\Users\Nick\Downloads\Windows10 (1).exe
2017-07-04 18:57 - 2017-07-04 19:00 - 00521948 _____ C:\TDSSKiller.3.1.0.15_04.07.2017_18.57.11_log.txt
2017-07-04 18:55 - 2017-07-04 18:56 - 00008162 _____ C:\TDSSKiller.3.1.0.15_04.07.2017_18.55.29_log.txt
2017-07-04 18:50 - 2017-07-04 18:53 - 00267926 _____ C:\TDSSKiller.3.1.0.15_04.07.2017_18.50.43_log.txt
2017-07-04 18:45 - 2017-07-04 18:49 - 00184656 _____ C:\TDSSKiller.3.1.0.15_04.07.2017_18.45.33_log.txt
2017-07-04 18:43 - 2017-07-04 18:47 - 00416516 _____ C:\WINDOWS\Minidump\070417-25671-01.dmp
2017-07-04 18:22 - 2017-07-04 18:23 - 05198336 _____ (AVAST Software) C:\Users\Nick\Downloads\aswMBR.exe
2017-07-04 17:48 - 2017-07-04 17:48 - 07098268 _____ (Huion Animation ) C:\Users\Nick\Downloads\Windows10.exe
2017-07-04 16:54 - 2017-07-04 16:58 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-07-04 16:47 - 2017-07-04 16:47 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Nick\Downloads\mbar-1.09.3.1001.exe
2017-07-04 16:39 - 2017-07-04 18:53 - 00000000 ____D C:\TDSSKiller_Quarantine
2017-07-04 16:35 - 2017-07-04 16:44 - 00529140 _____ C:\TDSSKiller.3.1.0.15_04.07.2017_16.35.40_log.txt
2017-07-04 16:34 - 2017-07-04 16:35 - 04922400 _____ (AO Kaspersky Lab) C:\Users\Nick\Downloads\tdsskiller.exe
2017-07-03 11:47 - 2017-07-03 11:47 - 00000000 ____D C:\Xlide
2017-07-03 10:19 - 2017-07-03 10:19 - 00470837 _____ C:\Users\Nick\Downloads\88874d9ab3d8c6f727743d0e5ec0e1ff.png.old
2017-07-03 07:55 - 2017-07-03 07:56 - 17252144 _____ C:\Users\Nick\Downloads\RedLightCenterSetup.exe
2017-07-02 21:47 - 2017-07-02 21:47 - 00000222 _____ C:\Users\Nick\Desktop\Kindergarten.url
2017-07-02 00:51 - 2017-07-02 00:51 - 00234384 _____ C:\Users\Nick\Downloads\f992b26a9b8ccc4bb88e5b0dba4b3a42.jpeg
2017-07-01 12:05 - 2017-07-01 12:05 - 00001127 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2017-07-01 11:10 - 2017-07-01 11:10 - 01971103 _____ C:\Users\Nick\Downloads\1498913291850.webm
2017-06-30 22:04 - 2017-06-30 22:04 - 00000000 ____D C:\Users\Nick\AppData\Local\Tempzxpsign5d0e75bdcdd61b6e
2017-06-30 13:10 - 2017-06-30 13:10 - 00000000 ____D C:\Users\Nick\AppData\Local\DFX
2017-06-30 13:10 - 2017-06-30 13:10 - 00000000 ____D C:\ProgramData\DFX
2017-06-30 13:08 - 2017-06-30 13:08 - 00000000 ____D C:\Users\Guest\AppData\Roaming\vlc
2017-06-30 13:08 - 2017-06-30 13:08 - 00000000 ____D C:\Users\Guest
2017-06-30 13:08 - 2017-06-30 13:08 - 00000000 ____D C:\Users\DefaultAccount\AppData\Roaming\vlc
2017-06-30 13:08 - 2017-06-30 13:08 - 00000000 ____D C:\Users\DefaultAccount
2017-06-30 13:08 - 2017-06-30 13:08 - 00000000 ____D C:\Users\Banana\AppData\Roaming\vlc
2017-06-30 13:08 - 2017-06-30 13:08 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\vlc
2017-06-30 13:08 - 2017-06-30 13:08 - 00000000 ____D C:\Users\Administrator
2017-06-30 13:07 - 2017-06-30 13:07 - 04867672 _____ (FxSound) C:\Users\Nick\Downloads\fxsound_13.007_setup.exe
2017-06-30 13:06 - 2017-06-30 13:07 - 02433992 _____ (DivX, LLC) C:\Users\Nick\Downloads\DivXInstaller.exe
2017-06-29 21:31 - 2017-06-29 21:33 - 167777153 _____ (Realtek Semiconductor Corp.) C:\Users\Nick\Downloads\0008-32bit_Win7_Win8_Win81_Win10_R281.exe
2017-06-28 21:32 - 2017-06-28 21:32 - 00218306 _____ C:\Users\Nick\Downloads\19054312_243780706103592_7218227831292035072_n.mp4
2017-06-28 19:13 - 2017-06-28 19:13 - 00000000 ____D C:\Users\Nick\AppData\Roaming\Imagine
2017-06-28 18:39 - 2017-06-28 18:39 - 00969388 _____ C:\Users\Nick\Downloads\Imagine_1.0.9_x64_Unicode.exe
2017-06-28 14:02 - 2017-06-28 14:02 - 05681862 _____ C:\Users\Nick\Desktop\5654165464.psd
2017-06-28 10:34 - 2017-06-28 10:34 - 00000000 ____D C:\Users\Nick\AppData\Local\Tempzxpsign58b56f9318dfcc93
2017-06-27 20:44 - 2017-06-27 20:44 - 00000000 ____D C:\Users\Nick\AppData\Local\Tempzxpsign7629264ef594f75e
2017-06-27 20:44 - 2017-06-27 20:44 - 00000000 ____D C:\Users\Nick\AppData\Local\Tempzxpsign340a75688aa69487
2017-06-27 15:41 - 2017-06-27 15:41 - 00000000 ____D C:\Users\Nick\AppData\Local\Tempzxpsign4270bd05285f9e84
2017-06-27 13:59 - 2017-06-27 14:02 - 247558712 _____ (Hewlett-Packard ) C:\Users\Nick\Downloads\sp74726.exe
2017-06-27 13:29 - 2017-06-27 13:30 - 18759824 _____ C:\Users\Nick\Downloads\nomacs-setup.exe
2017-06-27 13:15 - 2017-06-27 13:15 - 13223048 _____ (Duong Dieu Phap ) C:\Users\Nick\Downloads\ImageGlass_4.0.4.15.exe
2017-06-27 01:12 - 2017-06-27 01:31 - 00000000 ____D C:\Users\Nick\AppData\Roaming\PotPlayerMini64
2017-06-27 01:09 - 2017-06-27 01:09 - 00001025 _____ C:\Users\Nick\Desktop\PotPlayer 64 bit.lnk
2017-06-27 01:09 - 2017-06-27 01:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
2017-06-27 01:09 - 2017-06-27 01:09 - 00000000 ____D C:\Program Files\DAUM
2017-06-27 01:06 - 2017-06-27 01:08 - 22018200 _____ (Kakao) C:\Users\Nick\Downloads\PotPlayerSetup64.exe
2017-06-27 00:53 - 2017-06-27 01:25 - 00000000 ____D C:\Users\Nick\Desktop\Fun
2017-06-27 00:48 - 2017-06-27 01:28 - 00000000 ____D C:\Users\Nick\Downloads\New folder (2)
2017-06-26 19:26 - 2017-06-26 19:26 - 00228804 _____ C:\Users\Nick\Downloads\full.jpeg
2017-06-25 15:50 - 2017-06-25 15:50 - 00040212 _____ C:\Users\Nick\Downloads\FN-TalentAvatar-Guy-Fieri-800x800.jpg.rend.hgtvcom.616.616.jpeg
2017-06-25 12:16 - 2017-06-25 12:16 - 00000000 ____D C:\Users\Nick\AppData\Local\Tempzxpsign1523467ffd011c54
2017-06-24 22:06 - 2017-06-24 22:06 - 00000844 _____ C:\Users\Nick\Desktop\PureRef.lnk
2017-06-24 22:06 - 2017-06-24 22:06 - 00000000 ____D C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PureRef
2017-06-24 22:06 - 2017-06-24 22:06 - 00000000 ____D C:\Program Files\PureRef
2017-06-23 20:00 - 2017-06-27 14:10 - 00000000 ____D C:\WINDOWS\LastGood
2017-06-23 19:58 - 2017-06-23 19:58 - 00001661 _____ C:\Users\Public\Desktop\Costume Quest.lnk
2017-06-23 19:58 - 2017-06-23 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Costume Quest [GOG.com]
2017-06-23 19:14 - 2017-06-23 19:22 - 342999048 _____ (InstallShield Software Corporation ) C:\Users\Nick\Downloads\sp77787.exe
2017-06-23 16:16 - 2017-06-23 16:16 - 00066815 _____ C:\Users\Nick\Downloads\32f52e58268a8be5806a0727a1172f48.jpeg
2017-06-23 10:55 - 2017-06-23 19:54 - 00000000 ____D C:\Users\Nick\Desktop\Costume Quest (October 15, 2011)
2017-06-21 22:31 - 2017-06-21 22:31 - 00000000 ____D C:\Users\Nick\Downloads\Picarto.TV -Modeseven_2017.06.05.22.06.07.flv's Video popout_files
2017-06-21 16:30 - 2017-06-27 20:11 - 00000000 ____D C:\Users\Nick\AppData\Roaming\.minecraft
2017-06-21 16:30 - 2017-06-21 16:30 - 00001037 _____ C:\Users\Public\Desktop\Minecraft.lnk
2017-06-21 16:30 - 2017-06-21 16:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
2017-06-19 13:44 - 2017-06-19 13:44 - 00039048 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\dfx12x64.sys
2017-06-19 13:44 - 2017-06-19 13:44 - 00028008 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\dfx11_1x64.sys
2017-06-19 09:40 - 2017-06-19 09:41 - 01436580 _____ C:\Users\Nick\Downloads\2143519 - Dragon_Quest Dragon_Quest_VIII Gerph Jessica_Albert.jpeg
2017-06-19 09:11 - 2017-06-19 09:11 - 00351367 _____ C:\Users\Nick\Downloads\2031196%20-%20Padme_Amidala%20Star_Wars%20Turk128.jpeg
2017-06-19 09:10 - 2017-06-19 09:10 - 00349908 _____ C:\Users\Nick\Downloads\1909836%20-%20Anakin_Solo%20Princess_Leia_Organa%20Star_Wars%20Turk128%20Winter_Celchu.jpeg
2017-06-19 09:10 - 2017-06-19 09:10 - 00222418 _____ C:\Users\Nick\Downloads\1915715%20-%20Danny_Phantom%20Madeline_Fenton%20Turk128.jpeg
2017-06-19 09:08 - 2017-06-19 09:08 - 00237761 _____ C:\Users\Nick\Downloads\1909675%20-%20Atomic_Betty%20Betty_Barrett%20Space_Ace%20Turk128%20borf%20crossover.jpeg
2017-06-16 22:27 - 2017-06-16 22:27 - 00000000 ____D C:\Users\Nick\AppData\Local\Tempzxpsign3eea5cb35c34132c
2017-06-16 11:02 - 2017-06-16 11:02 - 00412332 _____ C:\WINDOWS\Minidump\061617-32234-01.dmp
2017-06-12 17:40 - 2017-06-16 10:12 - 00000000 ____D C:\Users\Nick\Desktop\Totally Spies
2017-06-12 17:33 - 2017-06-19 14:38 - 00000000 ____D C:\Users\Nick\Desktop\Doug
2017-06-12 14:19 - 2017-06-12 14:19 - 00000000 ____D C:\Users\Nick\Downloads\New folder
2017-06-12 12:22 - 2017-06-12 12:24 - 00000011 _____ C:\Users\Nick\Desktop\New Text Document.txt
2017-06-11 02:30 - 2017-06-11 02:30 - 10127400 _____ (HP Inc ) C:\Users\Nick\Downloads\sp80569.exe
2017-06-11 01:47 - 2017-06-11 01:47 - 00000000 ____D C:\Users\Nick\AppData\LocalLow\AMD
2017-06-11 01:43 - 2017-06-11 01:45 - 00412404 _____ C:\WINDOWS\Minidump\061117-29937-01.dmp
2017-06-10 01:51 - 2017-06-10 01:51 - 03956442 _____ C:\Users\Nick\Downloads\..2020.psd
2017-06-09 21:46 - 2017-06-09 21:46 - 00000946 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2017-06-09 21:46 - 2017-06-09 21:46 - 00000934 _____ C:\Users\Public\Desktop\GIMP 2.lnk
2017-06-09 21:43 - 2017-06-09 21:45 - 00000000 ____D C:\Program Files\GIMP 2
2017-06-09 21:41 - 2017-06-09 21:42 - 89579672 _____ (The GIMP Team ) C:\Users\Nick\Downloads\gimp-2.8.22-setup.exe
2017-06-07 11:28 - 2017-06-07 19:38 - 00000000 ____D C:\Users\Nick\Desktop\New folder
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-07 14:00 - 2016-04-11 14:46 - 00000000 ____D C:\Users\Nick\AppData\Roaming\Skype
2017-07-07 13:27 - 2016-11-01 23:09 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-07 02:00 - 2016-04-13 04:38 - 00000000 ____D C:\Users\Nick\AppData\Local\Adobe
2017-07-06 22:51 - 2016-04-11 14:27 - 00000000 ____D C:\Program Files (x86)\Steam
2017-07-06 22:00 - 2016-07-16 07:45 - 00000000 ____D C:\WINDOWS\INF
2017-07-06 21:30 - 2016-04-23 19:28 - 00000000 ____D C:\Users\Nick\AppData\Local\Warframe
2017-07-06 21:18 - 2016-11-01 23:17 - 01249522 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-06 12:19 - 2016-11-01 23:19 - 00000000 ____D C:\Users\Nick
2017-07-06 11:59 - 2017-04-03 21:31 - 516052243 _____ C:\WINDOWS\MEMORY.DMP
2017-07-06 11:59 - 2017-01-23 20:40 - 00000000 ____D C:\WINDOWS\Minidump
2017-07-06 11:59 - 2016-11-01 23:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-05 15:59 - 2016-12-08 12:29 - 00000000 ____D C:\Users\Nick\AppData\Local\CrashDumps
2017-07-05 15:59 - 2016-04-12 12:23 - 00000000 ____D C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-07-05 15:57 - 2016-05-10 16:53 - 00000000 ____D C:\ModOrganizer
2017-07-05 06:24 - 2016-04-11 20:01 - 00000000 ____D C:\Users\Nick\AppData\Roaming\uTorrent
2017-07-04 23:07 - 2016-04-20 01:15 - 00000000 ____D C:\Users\Nick\AppData\Local\ElevatedDiagnostics
2017-07-04 18:54 - 2016-11-01 23:13 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-07-04 18:54 - 2016-07-16 02:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-04 16:52 - 2016-11-30 11:15 - 00000000 ____D C:\Users\Nick\AppData\Roaming\IMVU
2017-07-04 16:52 - 2016-06-27 21:42 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-07-04 16:35 - 2016-06-27 21:42 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-04 16:27 - 2017-04-04 11:38 - 00000000 ____D C:\Rito
2017-07-03 11:47 - 2016-04-27 18:38 - 00000000 ____D C:\Users\Nick\Documents\Stuff
2017-07-02 19:49 - 2016-12-13 01:50 - 00000000 ____D C:\Users\Nick\Documents\ShareX
2017-07-02 11:25 - 2016-08-26 00:57 - 00000000 ____D C:\Users\Nick\AppData\Roaming\MacroCreator
2017-07-01 12:05 - 2016-11-01 23:58 - 00003948 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1460536304
2017-07-01 12:05 - 2016-04-13 04:31 - 00000000 ____D C:\Program Files (x86)\Opera
2017-06-30 11:23 - 2016-04-28 00:32 - 00000000 ____D C:\Users\Nick\Documents\Eventually
2017-06-29 23:35 - 2016-11-01 23:13 - 00001851 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DTS Audio Control.lnk
2017-06-29 23:33 - 2016-11-01 23:13 - 00021910 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2017-06-29 23:33 - 2016-11-01 23:13 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-06-29 23:29 - 2016-03-25 07:41 - 00000000 ___HD C:\Program Files (x86)\Temp
2017-06-29 21:24 - 2016-03-25 07:42 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2017-06-29 18:04 - 2016-04-11 14:45 - 00000000 ____D C:\ProgramData\Skype
2017-06-29 18:03 - 2016-10-23 08:49 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-06-27 14:21 - 2017-05-23 18:33 - 00000000 ____D C:\Users\Nick\Downloads\Randoms
2017-06-27 14:21 - 2017-01-21 01:41 - 00000000 ____D C:\Users\Nick\Downloads\web
2017-06-27 14:04 - 2015-12-14 12:28 - 00000000 ____D C:\SWSetup
2017-06-27 02:19 - 2016-12-17 15:39 - 00000000 ____D C:\Users\Nick\Downloads\Flock mod
2017-06-27 01:40 - 2016-05-07 20:59 - 00000000 ____D C:\Users\Nick\AppData\Roaming\vlc
2017-06-26 17:01 - 2017-04-27 16:14 - 00002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-26 17:01 - 2017-04-27 16:14 - 00002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-26 09:07 - 2016-11-29 22:27 - 00000000 ____D C:\flockmod-tablet
2017-06-23 19:54 - 2016-07-14 14:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-23 19:52 - 2016-10-29 07:35 - 00000000 ____D C:\GOG Games
2017-06-21 16:32 - 2016-11-07 06:00 - 00000000 ____D C:\Program Files (x86)\Minecraft
2017-06-18 18:16 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-06-15 19:18 - 2016-06-18 19:58 - 00000000 ____D C:\Users\Nick\AppData\Roaming\discord
2017-06-13 20:32 - 2016-07-16 17:16 - 00000000 ____D C:\Program Files (x86)\Bethesda.net Launcher
2017-06-13 19:31 - 2016-04-12 12:27 - 00000000 ____D C:\Users\Nick\Documents\My Games
2017-06-12 19:55 - 2016-10-13 01:17 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2017-06-12 19:53 - 2016-07-06 21:11 - 00000000 ____D C:\Users\Nick\AppData\Roaming\Battle.net
2017-06-12 19:46 - 2016-07-06 21:11 - 00000000 ____D C:\Program Files (x86)\Battle.net
2017-06-12 01:04 - 2016-09-05 20:07 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-06-09 23:23 - 2017-04-27 16:05 - 00000000 ____D C:\PaintToolSAI
2017-06-08 00:01 - 2017-06-05 18:31 - 00000000 ____D C:\Users\Nick\AppData\Local\Lazy Nezumi Pro
2017-06-07 01:06 - 2016-12-16 15:00 - 00000000 ____D C:\Users\Banana
==================== Files in the root of some directories =======
2017-03-18 22:36 - 2017-03-18 22:40 - 0000132 _____ () C:\Users\Nick\AppData\Roaming\Adobe GIF Format CS6 Prefs
2016-11-17 17:40 - 2017-05-06 13:12 - 0000132 _____ () C:\Users\Nick\AppData\Roaming\Adobe PNG Format CS6 Prefs
2017-07-07 00:05 - 2017-07-07 00:05 - 0001145 _____ () C:\Users\Nick\AppData\Roaming\PureRef.ini
2016-07-22 18:12 - 2016-02-17 23:30 - 15384576 _____ () C:\Users\Nick\AppData\Roaming\Sandra.mdb
2017-03-23 18:30 - 2017-03-23 18:45 - 0001456 _____ () C:\Users\Nick\AppData\Local\Adobe Save for Web 13.0 Prefs
2016-04-23 18:12 - 2016-04-23 18:12 - 0000218 _____ () C:\Users\Nick\AppData\Local\recently-used.xbel
2017-06-04 22:35 - 2017-06-04 22:35 - 0000060 _____ () C:\ProgramData\SoftwareUpdateTemp.xml
Some files in TEMP:
====================
2017-07-04 17:06 - 2017-07-04 17:06 - 0510848 _____ (Sysinternals -
www.sysinternals.com) C:\Users\Nick\AppData\Local\Temp\DGPSOD.exe
2017-04-26 06:11 - 2017-04-26 06:11 - 1292712 _____ (Bandisoft.com) C:\Users\Nick\AppData\Local\Temp\HVShell64.dll
2017-05-16 18:44 - 2017-06-24 03:48 - 58684896 _____ (Skype Technologies S.A.) C:\Users\Nick\AppData\Local\Temp\SkypeSetup.exe
2017-07-04 17:00 - 2017-07-04 17:00 - 0424832 _____ (Sysinternals -
www.sysinternals.com) C:\Users\Nick\AppData\Local\Temp\YATBLN.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-02 05:31
==================== End of FRST.txt ============================