Chrome:
=======
CHR HomePage: Default -> hxxp://
www.msn.com/?pc=UP97&ocid=UP97DHP
CHR StartupUrls: Default -> "hxxp://
www.google.com/ncr","hxxps://
www.facebook.com/"
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Shockwave Flash) - C:\Users\user\AppData\Local\Google\Chrome\User Data\PepperFlash\19.0.0.226\pepflashplayer.dll => No File
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\user\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-05]
CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-05]
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (WhatsChrome) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgkodfmeijboinjdegggmkbkjfiagaan [2016-03-24]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Google Cast) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-03-29]
CHR Extension: (Token signing) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckjefchnfjhjfedoccjbhjpbncimppeg [2015-06-07]
CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Google Cast (Beta)) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dliochdbjfkdbacpmhlcpmleaejidimm [2016-03-29]
CHR Extension: (Google Sheets) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-05]
CHR Extension: (Chrome Remote Desktop) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2016-03-30]
CHR Extension: (Google Docs Offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (AdBlock) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-29]
CHR Extension: (Page Ruler) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlpkojjdgbllmedoapgfodplfhcbnbpn [2015-01-20]
CHR Extension: (Skype) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-19]
CHR Extension: (Messenger (Unofficial)) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok [2015-08-05]
CHR Extension: (YSlow) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ninejjcohidippngpapiilnmkgllmakh [2015-02-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-01]
CHR Extension: (Google Tone) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnckehldicaciogcbchegobnafnjkcne [2015-10-03]
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
CHR Extension: (Inbox by Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkclgpgponpjmpfokoepglboejdobkpl [2016-02-22]
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Profile 1
CHR HKLM-x32\...\Chrome\Extension: [ckjefchnfjhjfedoccjbhjpbncimppeg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [309376 2014-09-19] (Qualcomm Atheros) [File not signed]
S2 AVerRECentral; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [1924608 2014-10-15] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [814464 2015-02-06] ()
R2 Bonjour Service; C:\Program Files (x86)\Xamarin\Bonjour\mDNSResponder.exe [384512 2015-01-24] (Apple Inc.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2828016 2016-02-09] (Microsoft Corporation)
R2 Ds3Service; D:\Programs\Scarlet.Crush Productions\bin\ScpService.exe [388352 2013-05-05] (Scarlet.Crush Productions)
S3 EHttpSrv; C:\Program Files\ESET\ESET Endpoint Antivirus\ehttpsrv.exe [41160 2015-10-02] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [1576712 2015-10-02] (ESET)
S3 eshasrv; C:\Program Files\ESET\ESET Endpoint Antivirus\eshasrv.exe [182984 2015-10-02] (ESET)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-03-08] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-08-04] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-28] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-28] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-12-10] (Intel Corporation)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [22744 2014-10-15] (Microsoft Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 Micro Star SCM; C:\WINDOWS\SysWOW64\MSIService.exe [160768 2009-07-10] (Micro-Star International Co., Ltd.) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-03-08] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-03-08] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-03-08] (NVIDIA Corporation)
S3 Origin Client Service; C:\Users\user\Desktop\Games\OriginClientService.exe [2104840 2016-03-16] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2015-12-18] ()
S2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [387584 2014-09-20] (Qualcomm Atheros) [File not signed]
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [186048 2014-12-10] ()
S2 SkypeUpdate; D:\Programs\Skype\Updater\Updater.exe [327296 2015-07-09] (Skype Technologies)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation)
R3 wampapache64; D:\Programs\wamp\bin\apache\apache2.4.17\bin\httpd.exe [29184 2015-10-11] (Apache Software Foundation) [File not signed]
R3 wampmysqld64; D:\Programs\wamp\bin\mysql\mysql5.7.9\bin\mysqld.exe [38587904 2015-10-12] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 atrfiltr; C:\Windows\system32\DRIVERS\atrfiltr.sys [16224 2014-09-11] (Windows (R) Win 7 DDK provider)
S3 AVer330USB; C:\Windows\system32\DRIVERS\AVer330USB.sys [1550464 2014-11-05] (AVerMedia TECHNOLOGIES, Inc.)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [97968 2014-09-12] (Qualcomm Atheros, Inc.)
S3 cxbu0x64; C:\Windows\system32\DRIVERS\cxbu0x64.sys [147576 2015-08-30] (HID Global Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2015-01-23] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255272 2015-09-09] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [186272 2015-07-24] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [169744 2015-07-24] (ESET)
S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-10-26] (LogMeIn Inc.)
R2 IntelHaxm; C:\Windows\system32\DRIVERS\IntelHaxm.sys [84992 2015-01-30] (Intel Corporation)
S3 Ke2200; C:\Windows\System32\drivers\e22w8x64.sys [130224 2014-03-27] (Qualcomm Atheros, Inc.)
R3 KillerEth; C:\Windows\System32\drivers\e2xw10x64.sys [170128 2016-02-05] (Qualcomm Atheros, Inc.)
S4 LMIRfsClientNP; no ImagePath
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-03-08] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2016-03-08] (NVIDIA Corporation)
R3 Qcamain10x64; C:\Windows\system32\DRIVERS\Qcamain10x64.sys [2356184 2015-10-25] (Qualcomm Atheros, Inc.)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466648 2014-02-21] (Realsil Semiconductor Corporation)
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [39592 2014-12-30] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-12-10] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-12-10] (Razer, Inc.)
R3 SAlphamHid; C:\Windows\System32\drivers\SAlpham64.sys [39168 2014-05-27] (SteelSeries Corporation)
R3 SAlphaPS2; C:\Windows\System32\drivers\SAlphaPS264.sys [27520 2014-05-16] (SteelSeries Corporation)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-06] (Scarlet.Crush Productions)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-07-31] (Synaptics Incorporated)
R3 sshid; C:\Windows\System32\drivers\sshid.sys [51392 2015-10-04] (SteelSeries ApS)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R3 WINIO; C:\Program Files (x86)\MSI\Dragon Gaming Center\winio64.sys [15160 2010-06-07] ()
R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
S2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [X]
S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-11 09:02 - 2016-04-11 09:03 - 00000000 ____D C:\FRST
2016-04-10 11:05 - 2016-04-10 11:05 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-10 11:05 - 2016-04-10 11:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-10 11:05 - 2016-04-10 11:05 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-04-05 19:58 - 2016-04-05 19:58 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FonePaw
2016-04-05 19:58 - 2016-04-05 19:58 - 00000000 ____D C:\Users\user\AppData\Roaming\FonePaw
2016-04-05 19:58 - 2016-04-05 19:58 - 00000000 ____D C:\Users\user\AppData\Local\FonePaw
2016-04-05 19:58 - 2016-04-05 19:58 - 00000000 ____D C:\Program Files (x86)\FonePaw
2016-04-04 16:25 - 2016-04-04 16:25 - 00000000 ____D C:\WINDOWS\LastGood
2016-04-04 13:14 - 2016-04-04 16:40 - 00000000 ____D C:\Users\user\AppData\Roaming\RIA
2016-04-04 13:14 - 2016-04-04 13:14 - 00001998 _____ C:\Users\Public\Desktop\DigiDoc3 crypto.lnk
2016-04-04 13:14 - 2016-04-04 13:14 - 00001036 _____ C:\Users\Public\Desktop\DigiDoc3 client.lnk
2016-04-04 13:14 - 2016-04-04 13:14 - 00001021 _____ C:\Users\Public\Desktop\ID-card utility.lnk
2016-04-04 13:14 - 2016-04-04 13:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ID-card
2016-04-04 13:14 - 2016-04-04 13:14 - 00000000 ____D C:\Program Files\Open-EID
2016-04-04 13:14 - 2016-04-04 13:14 - 00000000 ____D C:\Program Files (x86)\Open-EID
2016-03-31 14:50 - 2016-03-31 14:51 - 00000760 _____ C:\Users\Public\Desktop\Wampserver64.lnk
2016-03-31 14:50 - 2016-03-31 14:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wampserver64
2016-03-31 14:37 - 2016-03-31 14:42 - 00000000 ____D C:\Users\user\Desktop\www
2016-03-31 14:11 - 2016-03-31 14:11 - 00000000 ___HD C:\OneDriveTemp
2016-03-30 15:32 - 2016-03-30 15:41 - 00000000 ____D C:\Users\user\Desktop\urmur2_AME
2016-03-30 15:27 - 2016-03-31 08:33 - 00479056 _____ C:\Users\user\Desktop\urmur2.aep
2016-03-30 11:10 - 2016-03-30 15:10 - 00448700 _____ C:\Users\user\Desktop\urmur.aep
2016-03-30 10:34 - 2016-03-30 10:34 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-03-28 18:42 - 2016-03-29 09:02 - 00000000 ____D C:\Users\user\AppData\Local\Skyrim
2016-03-25 16:34 - 2016-03-30 21:27 - 00000000 __SHD C:\ProgramData\Unknown
2016-03-25 16:03 - 2016-03-29 07:36 - 00000000 __SHD C:\ProgramData\ilhdxm
2016-03-22 19:15 - 2016-03-22 19:15 - 00000000 ____D C:\Users\user\AppData\Roaming\DS4Windows
2016-03-18 13:05 - 2016-03-18 13:05 - 00000000 ____D C:\Users\user\AppData\Roaming\NVIDIA
2016-03-17 20:26 - 2016-03-31 14:10 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-17 20:26 - 2016-03-17 20:26 - 00000000 ____D C:\Users\user\AppData\Local\NVIDIA
2016-03-17 20:26 - 2016-03-17 20:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.0
2016-03-17 20:26 - 2016-03-17 20:26 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-03-17 20:26 - 2016-03-08 13:27 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-03-17 20:26 - 2016-03-08 13:27 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-03-17 20:26 - 2016-03-08 13:27 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-03-17 20:26 - 2016-03-08 13:27 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-03-17 20:26 - 2016-03-08 13:27 - 00213952 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2016-03-17 20:26 - 2016-03-08 13:27 - 00203320 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2016-03-17 20:26 - 2016-03-08 13:27 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-03-17 20:26 - 2016-03-08 09:42 - 06371384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-03-17 20:26 - 2016-03-08 09:42 - 02992576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-03-17 20:26 - 2016-03-08 09:42 - 02563128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-03-17 20:26 - 2016-03-08 09:42 - 01264064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-03-17 20:26 - 2016-03-08 09:42 - 00530880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-03-17 20:26 - 2016-03-08 09:42 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-03-17 20:26 - 2016-03-08 09:42 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-17 20:26 - 2016-03-08 09:42 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-03-17 20:26 - 2016-03-08 09:05 - 00110016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-03-17 20:26 - 2016-03-07 07:22 - 06203411 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-03-17 20:26 - 2016-02-14 04:47 - 00125720 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2016-03-17 20:26 - 2016-02-14 04:46 - 00126232 _____ C:\WINDOWS\system32\vulkan-1.dll
2016-03-17 20:26 - 2016-02-14 04:45 - 00045848 _____ C:\WINDOWS\system32\vulkaninfo.exe
2016-03-17 20:26 - 2016-02-14 04:45 - 00042264 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2016-03-17 20:24 - 2016-03-10 06:19 - 12653504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-03-17 20:24 - 2016-03-08 13:27 - 42968120 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 37609528 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 22971960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 21322480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 20863920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 20061152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 18906048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 17732960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 17368424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 17325400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 17320280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 14226864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 10547128 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 08657936 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 03681672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 03259176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 02613696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 02257344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 01922496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00955328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00885184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00786872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00784640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00750016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00692160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00678704 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00632152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00630592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00601752 _____ C:\WINDOWS\system32\nvmcumd.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00385080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00379296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00377792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00346560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00317656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-03-17 20:24 - 2016-03-08 13:27 - 00047760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2016-03-17 20:24 - 2016-03-08 13:27 - 00037702 _____ C:\WINDOWS\system32\nvinfo.pb
2016-03-17 20:24 - 2016-03-08 13:27 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-03-17 20:24 - 2016-03-08 13:27 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-03-17 09:28 - 2016-03-17 09:30 - 00000000 ____D C:\Users\user\Documents\Need For Speed
2016-03-16 11:48 - 2016-03-16 11:48 - 00000000 ____D C:\Program Files (x86)\Origin Games
2016-03-15 15:18 - 2016-03-15 15:18 - 00000000 ____D C:\Users\user\AppData\Roaming\Xfer
2016-03-15 15:16 - 2016-03-15 15:16 - 00000000 ____D C:\Users\user\Documents\Xfer
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-11 09:02 - 2015-10-30 10:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-04-11 08:50 - 2015-07-16 09:40 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0bf92534c146b.job
2016-04-11 08:45 - 2015-01-15 11:29 - 00000000 ____D C:\Users\user\AppData\Local\Packages
2016-04-11 08:40 - 2015-01-20 21:30 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-11 08:19 - 2015-08-18 09:52 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2707210134-101100643-1977969362-1001UA.job
2016-04-11 08:19 - 2015-01-15 12:59 - 00004140 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EE494239-FD0C-4259-8F7F-302738D33E3B}
2016-04-10 20:18 - 2015-08-18 09:52 - 00000860 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2707210134-101100643-1977969362-1001Core.job
2016-04-10 14:42 - 2015-10-30 10:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-10 11:11 - 2015-10-25 15:17 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-04-10 10:12 - 2015-10-30 10:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-09 12:40 - 2015-01-20 21:31 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-08 17:57 - 2016-02-29 21:24 - 00000000 ____D C:\Users\user\AppData\Roaming\qBittorrent
2016-04-07 07:50 - 2015-01-20 21:30 - 00000910 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-06 16:25 - 2015-06-22 09:47 - 00000000 ____D C:\Users\user\AppData\Roaming\FileZilla
2016-04-06 15:27 - 2015-01-21 18:14 - 00000000 ____D C:\Users\user\AppData\Roaming\Skype
2016-04-05 19:58 - 2015-07-20 19:18 - 00000000 ____D C:\Users\user\AppData\Local\CrashDumps
2016-04-05 08:49 - 2015-02-10 22:55 - 00000000 ____D C:\Users\user\AppData\Roaming\vlc
2016-04-04 13:15 - 2015-10-30 10:21 - 00000000 ____D C:\WINDOWS\INF
2016-04-04 13:14 - 2015-06-07 21:04 - 00003442 _____ C:\WINDOWS\System32\Tasks\id updater task
2016-04-04 13:14 - 2015-01-21 17:54 - 00000000 ____D C:\ProgramData\Package Cache
2016-03-31 14:16 - 2015-11-29 21:52 - 00973920 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-31 14:11 - 2015-01-23 15:38 - 00000000 __RDO C:\Users\user\OneDrive
2016-03-31 14:10 - 2015-11-29 22:02 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-31 14:10 - 2015-10-30 09:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2016-03-31 14:10 - 2015-08-18 11:02 - 00000091 _____ C:\HaxLogs.txt
2016-03-30 21:27 - 2015-11-29 21:50 - 05104592 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-30 21:27 - 2015-10-30 10:24 - 00000000 ____D C:\WINDOWS\SystemApps
2016-03-29 09:02 - 2015-09-23 07:05 - 00000000 ____D C:\ProgramData\Steam
2016-03-29 07:35 - 2015-01-21 18:19 - 00000000 ___RD C:\Users\user\Desktop\Games
2016-03-28 18:42 - 2015-03-26 17:08 - 00000000 ____D C:\Users\user\Documents\My Games
2016-03-27 10:48 - 2015-01-24 11:10 - 00000000 ____D C:\ProgramData\Origin
2016-03-26 15:27 - 2016-02-27 12:46 - 00000000 ____D C:\Users\user\AppData\Roaming\StardewValley
2016-03-26 14:17 - 2015-10-17 12:19 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-03-24 11:29 - 2015-08-17 10:05 - 00000000 ____D C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2016-03-23 08:35 - 2015-10-30 10:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-18 11:30 - 2015-01-24 11:12 - 00000000 ____D C:\Users\user\AppData\Roaming\Origin
2016-03-17 20:29 - 2015-01-15 12:10 - 00000000 ____D C:\Users\user\AppData\Local\NVIDIA Corporation
2016-03-17 20:28 - 2015-11-29 21:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-17 20:26 - 2015-11-29 21:51 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-17 20:26 - 2015-10-30 10:24 - 00000000 ____D C:\WINDOWS\Help
2016-03-17 20:26 - 2015-06-30 10:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-17 20:26 - 2015-03-31 20:34 - 00000000 ____D C:\Temp
2016-03-17 20:26 - 2015-01-15 12:10 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-15 08:50 - 2015-10-30 10:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-03-15 08:50 - 2015-02-12 19:24 - 00000000 ____D C:\Program Files\Microsoft Office 15
==================== Files in the root of some directories =======
2015-03-07 14:04 - 2015-10-23 16:39 - 0000132 _____ () C:\Users\user\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-07-06 19:50 - 2015-07-06 19:50 - 0001456 _____ () C:\Users\user\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-08-12 14:31 - 2015-08-12 14:31 - 0000000 ___SH () C:\Users\user\AppData\Local\LumaEmu
2015-01-23 15:21 - 2015-03-14 16:30 - 0007602 _____ () C:\Users\user\AppData\Local\Resmon.ResmonCfg
2015-11-29 21:51 - 2015-11-29 21:51 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\user\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\user\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\user\AppData\Local\Temp\nvStInst.exe
C:\Users\user\AppData\Local\Temp\Open-EID-3.12.2.1653_x86.exe
C:\Users\user\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-04-04 07:39
==================== End of FRST.txt ============================