Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:04-03-2016
Ran by Jesus (administrator) on JESUS-PC (04-03-2016 21:49:45)
Running from C:\Users\Jesus\Desktop
Loaded Profiles: Jesus (Available Profiles: Jesus & fbwuser29C8 & fbwuserFBEA & fbwuser5783)
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Realtek Semiconductor) C:\Windows\RTKAUDIOSERVICE.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects\uCamMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio64.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6453760 2008-07-15] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2008-07-15] (Realtek Semiconductor Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1220392 2008-05-20] (Synaptics, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [317280 2008-04-03] (Sony Corporation)
HKLM-x32\...\Run: [VAIOSurvey] => C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe [385024 2008-07-25] ()
HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5893920 2015-11-12] (IObit)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595504 2016-01-29] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\VESWinlogon-x32: VESWinlogon.dll [X]
HKU\S-1-5-21-3862297630-1303015323-3635741390-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3108480 2012-10-23] (DT Soft Ltd)
HKU\S-1-5-21-3862297630-1303015323-3635741390-1000\...\Run: [f.lux] => C:\Users\Jesus\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-3862297630-1303015323-3635741390-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{4051FF07-D6F1-440B-9B46-6DB26F2E76C3}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{43913E9A-76E5-43E6-9D7A-2F904D587F4E}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{9479664B-AAA3-4ACD-B723-E223B4D01FF5}: [DhcpNameServer] 8.8.8.8
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3862297630-1303015323-3635741390-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3862297630-1303015323-3635741390-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3862297630-1303015323-3635741390-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.sonystyle.ca/vaio
HKU\S-1-5-21-3862297630-1303015323-3635741390-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://
www.google.com/webhp?rlz=1W1SNYX&ie=UTF-8&oe=UTF-8
SearchScopes: HKU\S-1-5-21-3862297630-1303015323-3635741390-1000 -> DefaultScope {05FB1E52-C923-4F6C-AE91-AD5AF927BD88} URL = hxxp://
www.google.com/webhp?rlz=1W1SNYX&ie=UTF-8&oe=UTF-8
SearchScopes: HKU\S-1-5-21-3862297630-1303015323-3635741390-1000 -> {05FB1E52-C923-4F6C-AE91-AD5AF927BD88} URL = hxxp://
www.google.com/webhp?rlz=1W1SNYX&ie=UTF-8&oe=UTF-8
SearchScopes: HKU\S-1-5-21-3862297630-1303015323-3635741390-1000 -> {EC29F814-3FE6-4F8C-BFB9-567E9C5F6372} URL = hxxps://ca.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-12] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\ssv.dll [2016-02-06] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-02-06] (Oracle Corporation)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-02-01] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-02-01] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-02-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-02-06] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-06-13] [not signed]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://
www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M7684315B-37F3-49FE-9DFE-325686680F51&SearchSource=55&CUI=&UM=8&UP=SPBF496382-60B6-4495-848A-59B622EFC2AC&SSPV="
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=orcl_default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-13]
CHR Extension: (Google Docs) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-13]
CHR Extension: (Google Drive) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (Turn Off the Lights) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2016-02-29]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-11-19]
CHR Extension: (YouTube) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Adblock Plus) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-03]
CHR Extension: (Google Search) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Sheets) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-13]
CHR Extension: (Google Docs Offline) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
CHR Extension: (Gmail) - C:\Users\Jesus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-13]
CHR HKLM-x32\...\Chrome\Extension: [eedgghdcpmmmilkmfpnklknlenbiolec] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 EvtEng; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [1371136 2008-04-30] (Intel(R) Corporation) [File not signed]
R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [2442368 2016-02-17] (AnchorFree Inc.)
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [103176 2016-02-17] ()
S2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [882464 2015-11-04] (IObit)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 MSCSPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [53248 2008-05-20] (Sony Corporation) [File not signed]
S3 PACSPTISVR; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [53248 2008-05-20] (Sony Corporation) [File not signed]
R2 RegSrvc; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [826368 2008-04-30] (Intel(R) Corporation) [File not signed]
R2 RtkAudioService; C:\Windows\RtkAudioService.exe [139808 2008-07-15] (Realtek Semiconductor)
S3 SOHCImp; C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe [103712 2008-05-20] (Sony Corporation)
S3 SOHDms; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe [353568 2008-05-20] (Sony Corporation)
S3 SOHDs; C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe [62752 2008-05-20] (Sony Corporation)
S3 SPTISRV; C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe [77824 2008-05-20] (Sony Corporation) [File not signed]
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-I Visual Effects\uCamMonitor.exe [104960 2008-03-25] (ArcSoft, Inc.)
S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2008-05-22] (Sony Corporation) [File not signed]
R2 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [415744 2008-06-20] (Sony Corporation) [File not signed]
R3 Vcsw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [279848 2008-06-19] (Sony Corporation)
R2 VzCdbSvc; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [192512 2008-05-22] (Sony Corporation) [File not signed]
R3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation)
S2 WinVNC4; C:\Program Files\RealVNC\VNC4\WinVNC4.exe [2360048 2011-02-04] (RealVNC Ltd)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2008-01-20] (Microsoft Corporation)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19456 2008-01-30] (ArcSoft, Inc.)
U1 Beep; no ImagePath
S1 DMICall; C:\Windows\SysWOW64\DRIVERS\DMICall.sys [10216 2008-07-11] (Sony Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2015-06-13] (DT Soft Ltd)
R3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\FileMonitor.sys [23048 2015-03-25] (IObit)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44744 2014-05-16] (AnchorFree Inc.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-06-14] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\wlh_amd64\regfilter.sys [34848 2015-03-25] (IObit.com)
R2 risdptsk; C:\Windows\System32\DRIVERS\risdsn64.sys [76288 2015-06-14] (REDC)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-16] (Anchorfree Inc.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-03-04] ()
R3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\wlh_amd64\UrlFilter.sys [23016 2015-03-25] (IObit.com)
S3 uvhid; C:\Windows\System32\DRIVERS\uvhid.sys [25592 2015-11-05] (Windows (R) Win 7 DDK provider)
U3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-04 21:49 - 2016-03-04 21:50 - 00017075 _____ C:\Users\Jesus\Desktop\FRST.txt
2016-03-04 21:49 - 2016-03-04 21:49 - 00000000 ____D C:\Users\Jesus\Desktop\FRST-OlderVersion
2016-03-04 20:36 - 2016-03-04 20:36 - 00023178 _____ C:\ComboFix.txt
2016-03-04 20:20 - 2011-06-26 01:45 - 00256000 _____ C:\Windows\PEV.exe
2016-03-04 20:20 - 2010-11-07 12:20 - 00208896 _____ C:\Windows\MBR.exe
2016-03-04 20:20 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-03-04 20:20 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-03-04 20:20 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-03-04 20:20 - 2000-08-30 19:00 - 00098816 _____ C:\Windows\sed.exe
2016-03-04 20:20 - 2000-08-30 19:00 - 00080412 _____ C:\Windows\grep.exe
2016-03-04 20:20 - 2000-08-30 19:00 - 00068096 _____ C:\Windows\zip.exe
2016-03-04 20:17 - 2016-03-04 20:36 - 00000000 ____D C:\Qoobox
2016-03-04 20:17 - 2016-03-04 20:34 - 00000000 ____D C:\Windows\erdnt
2016-03-04 20:10 - 2016-03-04 20:11 - 05658435 ____R (Swearware) C:\Users\Jesus\Desktop\ComboFix.exe
2016-03-04 18:47 - 2016-03-04 18:59 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2016-03-04 18:35 - 2016-03-04 20:19 - 00000000 ____D C:\ProgramData\ProductData
2016-03-04 18:35 - 2016-03-04 20:07 - 00002904 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_Jesus
2016-03-04 18:35 - 2016-03-04 18:35 - 00000000 ____D C:\Users\Jesus\AppData\Roaming\ProductData
2016-03-04 18:28 - 2016-03-04 18:28 - 00006094 _____ C:\Users\Jesus\Desktop\JRT.txt
2016-03-04 18:07 - 2016-03-04 18:12 - 00000000 ____D C:\AdwCleaner
2016-03-04 18:06 - 2016-03-04 18:06 - 01518592 _____ C:\Users\Jesus\Desktop\adwcleaner_5.037.exe
2016-03-04 17:39 - 2016-03-04 18:20 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-04 17:33 - 2016-03-04 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-04 17:33 - 2016-03-04 17:33 - 00009312 _____ C:\Users\Jesus\Desktop\rogue.txt
2016-03-04 17:33 - 2016-03-04 17:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-04 17:33 - 2016-03-04 17:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-04 17:33 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-04 17:33 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-04 17:33 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-04 17:06 - 2016-03-04 17:06 - 20956744 _____ C:\Users\Jesus\Desktop\RogueKiller.exe
2016-03-04 11:13 - 2016-03-04 11:13 - 00274496 _____ C:\Windows\Minidump\Mini030416-02.dmp
2016-03-04 10:32 - 2016-03-04 10:32 - 00274336 _____ C:\Windows\Minidump\Mini030416-01.dmp
2016-03-03 23:16 - 2016-03-03 23:16 - 00274560 _____ C:\Windows\Minidump\Mini030316-02.dmp
2016-03-03 22:28 - 2016-03-03 22:29 - 00275840 _____ C:\Windows\Minidump\Mini030316-01.dmp
2016-03-03 21:55 - 2016-03-04 18:35 - 00000000 ____D C:\ProgramData\RogueKiller
2016-03-03 21:55 - 2016-03-04 17:17 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-03-03 21:42 - 2016-03-03 21:42 - 00000732 _____ C:\Users\Jesus\AppData\Local\d3d9caps64.dat
2016-03-03 21:38 - 2016-03-04 12:23 - 00480596 _____ C:\Windows\ntbtlog.txt
2016-03-03 11:41 - 2016-03-03 11:45 - 22970368 _____ C:\Users\Jesus\Downloads\Homemade Doughnuts - Techniques and Recipes for Making Sublime Doughnuts in Your Home Kitchen.pdf
2016-03-03 11:39 - 2016-03-03 11:45 - 39518208 _____ C:\Users\Jesus\Downloads\IObit advanced SystemCare Pro 9.0.3.1078 + Key [4realtorrentz].zip
2016-03-03 11:39 - 2016-03-03 11:41 - 00000000 ____D C:\Users\Jesus\Downloads\BackyardLiberty.com
2016-03-03 11:09 - 2016-03-04 21:49 - 00000000 ____D C:\FRST
2016-03-02 20:41 - 2016-03-02 23:54 - 1661174754 _____ C:\Users\Jesus\Downloads\Kung.Fu.Panda.3.2016.HC.1080p.HDRiP.x264.ShAaNiG.mkv
2016-03-02 20:34 - 2016-03-02 20:34 - 00117855 _____ C:\Users\Jesus\Downloads\[kat.cr]kung.fu.panda.3.2016.hc.hdrip.xvid.ac3.evo.torrent
2016-03-02 20:17 - 2016-03-04 18:39 - 00000000 ____D C:\Users\Jesus\Downloads\Bluestacks 2.0.2.5623 Mod Rooted
2016-03-02 20:15 - 2016-03-02 20:15 - 00014794 _____ C:\Users\Jesus\Downloads\[kat.cr]bluestacks.2.0.2.5623.mod.rooted.offline.installer.core.x.torrent
2016-03-02 20:01 - 2016-03-03 14:54 - 00000000 ____D C:\Users\Jesus\AppData\Roaming\Kodi
2016-03-02 19:59 - 2016-03-02 19:59 - 00431684 _____ C:\Users\Jesus\AppData\Local\dd_vcredistMSI6202.txt
2016-03-02 19:59 - 2016-03-02 19:59 - 00011366 _____ C:\Users\Jesus\AppData\Local\dd_vcredistUI6202.txt
2016-03-02 19:58 - 2016-03-02 19:58 - 00000000 ____D C:\Users\Jesus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi
2016-03-02 19:58 - 2016-03-02 19:58 - 00000000 ____D C:\Program Files (x86)\Kodi
2016-03-02 19:53 - 2016-03-02 19:56 - 83064067 _____ C:\Users\Jesus\Downloads\kodi-16.0-Jarvis.exe
2016-02-26 07:58 - 2016-02-26 07:58 - 00000000 ____H C:\asc_rdflag
2016-02-25 17:48 - 2016-02-25 18:40 - 00000000 ____D C:\Users\Jesus\Downloads\Ratatouille (2007) [1080p]
2016-02-25 10:00 - 2016-02-25 15:59 - 00000000 ____D C:\Users\Jesus\Downloads\Top Pot Hand-Forged Doughnuts - Mark Klebeck
2016-02-25 09:56 - 2016-02-25 09:56 - 00005450 _____ C:\Users\Jesus\Downloads\[kat.cr]top.pot.hand.forged.doughnuts.secrets.and.recipes.for.the.home.baker.mark.klebeck.epub.mentalzero.torrent
2016-02-22 09:19 - 2016-01-07 10:27 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-02-22 09:18 - 2016-01-09 12:06 - 00501760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-02-22 09:18 - 2016-01-09 11:42 - 00659968 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-22 09:17 - 2016-01-29 22:09 - 01316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-02-22 09:17 - 2016-01-29 21:44 - 01915392 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-02-22 09:12 - 2016-02-01 12:25 - 01589376 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-02-22 09:12 - 2016-02-01 12:25 - 01171696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00861696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00679424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00429056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00324608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdohlp.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2016-02-22 09:12 - 2016-01-29 22:09 - 00153088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbeio.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-02-22 09:12 - 2016-01-29 22:09 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-02-22 09:12 - 2016-01-29 22:08 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-02-22 09:12 - 2016-01-29 22:08 - 00119296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasrecst.dll
2016-02-22 09:12 - 2016-01-29 22:08 - 00107520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-02-22 09:12 - 2016-01-29 22:08 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2016-02-22 09:12 - 2016-01-29 22:08 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2016-02-22 09:12 - 2016-01-29 22:08 - 00057856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2016-02-22 09:12 - 2016-01-29 22:08 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasads.dll
2016-02-22 09:12 - 2016-01-29 22:08 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasdatastore.dll
2016-02-22 09:12 - 2016-01-29 22:07 - 00802304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-02-22 09:12 - 2016-01-29 21:48 - 04693952 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-02-22 09:12 - 2016-01-29 21:44 - 01304576 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00375808 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2016-02-22 09:12 - 2016-01-29 21:44 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\sbeio.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00154112 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2016-02-22 09:12 - 2016-01-29 21:44 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2016-02-22 09:12 - 2016-01-29 21:44 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-02-22 09:12 - 2016-01-29 21:44 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-02-22 09:12 - 2016-01-29 21:43 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-02-22 09:12 - 2016-01-29 21:43 - 01067008 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-22 09:12 - 2016-01-29 21:43 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2016-02-22 09:12 - 2016-01-29 21:43 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2016-02-22 09:12 - 2016-01-29 21:43 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-02-22 09:12 - 2016-01-29 21:43 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll
2016-02-22 09:12 - 2016-01-29 21:43 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll
2016-02-22 09:12 - 2016-01-29 20:45 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\iashost.exe
2016-02-22 09:12 - 2016-01-29 20:33 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-02-22 09:12 - 2016-01-29 20:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iashost.exe
2016-02-22 09:12 - 2016-01-29 20:24 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-02-22 09:12 - 2016-01-29 20:24 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-02-22 09:12 - 2016-01-29 20:24 - 00002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-02-22 09:11 - 2016-01-07 10:32 - 02799104 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-02-14 14:08 - 2016-02-14 14:08 - 00053054 _____ C:\Users\Jesus\Downloads\[kat.cr]matilda.1996.720p.bluray.x264.amiable.torrent
2016-02-14 13:30 - 2016-02-14 13:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-02-14 13:30 - 2016-02-14 13:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-02-09 13:04 - 2016-02-09 13:04 - 00000000 ____D C:\Users\Jesus\Downloads\35HappyBudgies_FLAC
2016-02-09 11:34 - 2016-02-09 11:54 - 367225681 _____ C:\Users\Jesus\Downloads\35HappyBudgies_FLAC.zip
2016-02-08 22:04 - 2016-02-08 22:13 - 00000000 ____D C:\Users\Jesus\Downloads\Despicable Me (2010) [1080p]
2016-02-08 22:04 - 2016-02-08 22:04 - 00017072 _____ C:\Users\Jesus\Downloads\[kat.cr]despicable.me.2010.1080p.brrip.x264.yify.torrent
2016-02-08 19:46 - 2016-02-08 19:46 - 00011890 _____ C:\Users\Jesus\Downloads\[kat.cr]dispicable.me.2010.mp4.torrent
2016-02-08 19:46 - 2016-02-08 19:46 - 00000000 ____D C:\Users\Jesus\Downloads\Am anfang war das licht
2016-02-07 02:02 - 2016-02-07 02:02 - 00278160 _____ C:\Windows\Minidump\Mini020716-01.dmp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-04 21:49 - 2016-01-14 21:26 - 02374144 _____ (Farbar) C:\Users\Jesus\Desktop\FRST64.exe
2016-03-04 21:49 - 2016-01-14 21:20 - 00000000 ____D C:\Users\Jesus\Desktop\malware tools
2016-03-04 21:34 - 2015-06-13 14:20 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-04 21:13 - 2015-06-13 09:29 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-04 20:33 - 2006-11-02 07:34 - 00000215 _____ C:\Windows\system.ini
2016-03-04 20:32 - 2015-06-13 09:04 - 00000000 ____D C:\Users\Jesus
2016-03-04 20:14 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-04 20:14 - 2006-11-02 10:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-04 20:00 - 2015-06-13 10:25 - 00041984 _____ C:\Users\Jesus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-04 18:25 - 2015-06-13 10:28 - 00000000 ____D C:\ProgramData\IObit
2016-03-04 18:25 - 2015-06-13 10:28 - 00000000 ____D C:\Program Files (x86)\IObit
2016-03-04 18:25 - 2015-06-13 10:27 - 00000000 ____D C:\Users\Jesus\AppData\Roaming\IObit
2016-03-04 18:14 - 2015-06-13 09:29 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-04 18:14 - 2006-11-02 10:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-04 18:13 - 2006-11-02 10:42 - 00032546 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-03-04 11:13 - 2015-09-11 17:16 - 00000000 ____D C:\Windows\Minidump
2016-03-04 11:12 - 2015-09-11 17:16 - 398804081 _____ C:\Windows\MEMORY.DMP
2016-03-03 15:31 - 2015-06-13 16:23 - 00000000 ____D C:\Users\Jesus\AppData\Roaming\qBittorrent
2016-03-03 14:47 - 2015-06-13 22:15 - 00000000 ____D C:\Users\Jesus\AppData\Roaming\vlc
2016-03-03 11:40 - 2016-01-06 22:27 - 00000000 ____D C:\Users\Jesus\Downloads\Life on Earth BBC
2016-03-02 20:00 - 2015-07-16 07:23 - 00000000 ____D C:\ProgramData\Package Cache
2016-02-26 07:59 - 2015-06-14 18:00 - 67006464 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak
2016-02-26 07:59 - 2015-06-14 18:00 - 00020480 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak
2016-02-26 07:58 - 2015-06-14 18:00 - 62107648 _____ C:\Windows\system32\config\COMPONENTS.iodefrag.bak
2016-02-26 07:58 - 2015-06-14 18:00 - 00229376 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak
2016-02-26 07:58 - 2015-06-14 18:00 - 00057344 _____ C:\Windows\system32\config\SAM.iodefrag.bak
2016-02-25 23:48 - 2015-06-13 22:02 - 00000000 ____D C:\ProgramData\Hotspot Shield
2016-02-25 23:47 - 2015-06-13 22:02 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
2016-02-25 17:48 - 2015-06-13 16:16 - 00000000 ____D C:\Users\Jesus\AppData\Roaming\uTorrent
2016-02-25 10:00 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\inf
2016-02-22 10:13 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\rescache
2016-02-22 10:03 - 2006-11-02 07:46 - 00759542 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-22 09:56 - 2006-11-02 10:21 - 00320824 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-22 09:53 - 2006-11-02 10:07 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-22 09:53 - 2006-11-02 10:07 - 00000000 ____D C:\Program Files\Windows Collaboration
2016-02-22 09:51 - 2015-06-13 16:43 - 00000000 ____D C:\Windows\system32\MRT
2016-02-22 09:24 - 2006-11-02 07:35 - 146614896 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2016-02-19 16:18 - 2015-06-13 09:30 - 00002037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-19 16:18 - 2015-06-13 09:30 - 00002025 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-06 09:01 - 2015-06-15 18:20 - 00000000 ____D C:\ProgramData\Oracle
2016-02-06 09:00 - 2015-06-15 18:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-06 09:00 - 2008-08-12 16:03 - 00000000 ____D C:\Program Files (x86)\Java
2016-02-06 08:59 - 2015-08-27 08:35 - 00000000 ____D C:\Users\Jesus\.oracle_jre_usage
2016-02-06 08:58 - 2015-06-15 18:31 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-02-04 07:58 - 2015-12-28 11:32 - 00000000 ____D C:\Users\Jesus\Desktop\origami
==================== Files in the root of some directories =======
2016-03-03 21:42 - 2016-03-03 21:42 - 0000732 _____ () C:\Users\Jesus\AppData\Local\d3d9caps64.dat
2015-06-13 10:25 - 2016-03-04 20:00 - 0041984 _____ () C:\Users\Jesus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-03-02 19:59 - 2016-03-02 19:59 - 0431684 _____ () C:\Users\Jesus\AppData\Local\dd_vcredistMSI6202.txt
2015-07-16 07:23 - 2015-07-16 07:24 - 0440850 _____ () C:\Users\Jesus\AppData\Local\dd_vcredistMSI6D36.txt
2015-12-20 08:03 - 2015-12-20 08:03 - 0438832 _____ () C:\Users\Jesus\AppData\Local\dd_vcredistMSI762B.txt
2016-03-02 19:59 - 2016-03-02 19:59 - 0011366 _____ () C:\Users\Jesus\AppData\Local\dd_vcredistUI6202.txt
2015-07-16 07:23 - 2015-07-16 07:24 - 0011598 _____ () C:\Users\Jesus\AppData\Local\dd_vcredistUI6D36.txt
2015-12-20 08:03 - 2015-12-20 08:03 - 0013702 _____ () C:\Users\Jesus\AppData\Local\dd_vcredistUI762B.txt
2015-06-14 18:39 - 2015-06-14 18:39 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-04 18:20
==================== End of FRST.txt ============================