Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
- Ran by bigbabybauer (administrator) on BIGBABYBAUER-PC on 08-07-2015 01:34:30
- Running from C:\Users\bigbabybauer\Desktop
- Loaded Profiles: bigbabybauer (Available Profiles: bigbabybauer & Breanna & Guest)
- Platform: Windows 7 Home Premium (X64) OS Language: English (United States)
- Internet Explorer Version 8 (Default browser: Opera)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (Microsoft Corporation) C:\Windows\System32\wlanext.exe
- (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
- (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\AsLdrSrv.exe
- (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATKGFNEX\GFNEXSrv.exe
- (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\HControl.exe
- (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
- (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\ATK Package\ATKOSD2\ATKOSD2.exe
- (ASUSTek Computer Inc.) C:\Program Files (x86)\Asus\FaceLogon\sensorsrv.exe
- (ASUS) C:\Windows\AsScrPro.exe
- (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
- (Intel Corporation) C:\Windows\System32\igfxpers.exe
- (Intel Corporation) C:\Windows\System32\hkcmd.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
- (ASUS) C:\Program Files (x86)\Asus\InstantOn for NB\InsOnSrv.exe
- (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
- (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
- (ASUS) C:\Program Files (x86)\Asus\InstantOn for NB\InsOnWMI.exe
- (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
- (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
- (SRS Labs, Inc.) C:\Users\bigbabybauer\Downloads\SRS\x64\SRS Audio Sandbox Vista 64\Cracked exe\SRSSSC.exe
- (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
- (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
- (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
- (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
- (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
- (ASUSTeK Computer Inc.) C:\Program Files (x86)\Asus\ASUS Live Update\LiveUpdate.exe
- (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
- (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\ATKOSD.exe
- (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\KBFiltr.exe
- (ASUS) C:\Program Files (x86)\Asus\ATK Package\ATK Hotkey\WDC.exe
- (Microsoft Corporation) C:\Windows\System32\alg.exe
- (Microsoft Corporation) C:\Windows\System32\dllhost.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
- (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
- (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
- (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
- (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
- (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
- ==================== Registry (Whitelisted) ==================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated)
- HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated)
- HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
- Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
- HKU\S-1-5-21-3724984598-424098314-2994088863-1000\...\Run: [SRS Audio Sandbox] => C:\Users\bigbabybauer\Downloads\SRS\x64\SRS Audio Sandbox Vista 64\Cracked exe\SRSSSC.exe [4354048 2013-11-17] (SRS Labs, Inc.)
- ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
- ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
- ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
- ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
- ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
- ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
- CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
- CHR HKU\S-1-5-21-3724984598-424098314-2994088863-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://www.google.com
- HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/p/?LinkId=255141
- HKU\S-1-5-21-3724984598-424098314-2994088863-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
- HKU\S-1-5-21-3724984598-424098314-2994088863-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/p/?LinkId=255141
- SearchScopes: HKLM -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2463} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=103&systemid=463&q={searchTerms}
- SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
- SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2463} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=103&systemid=463&q={searchTerms}
- SearchScopes: HKLM-x32 -> DefaultScope {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL =
- SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox
- SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2463} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=103&systemid=463&q={searchTerms}
- SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
- SearchScopes: HKU\S-1-5-21-3724984598-424098314-2994088863-1000 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2463} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=103&systemid=463&q={searchTerms}
- SearchScopes: HKU\S-1-5-21-3724984598-424098314-2994088863-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- SearchScopes: HKU\S-1-5-21-3724984598-424098314-2994088863-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2463} URL = http://isearch.fantastigames.com/web?src=ieb&gct=ds&appid=103&systemid=463&q={searchTerms}
- BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
- BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
- BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-22] (Oracle Corporation)
- BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
- BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)
- BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
- BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-22] (Oracle Corporation)
- Toolbar: HKU\S-1-5-21-3724984598-424098314-2994088863-1000 -> No Name - {46575637-0076-A76A-76A7-7A786E7484D7} - No File
- DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
- Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
- Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
- Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
- Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2013-03-02] (Microsoft Corporation)
- Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2013-03-02] (Microsoft Corporation)
- Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2013-03-02] (Microsoft Corporation)
- Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2013-03-02] (Microsoft Corporation)
- Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{D11B65D6-87E2-4EBD-A3CB-63161A911575}: [DhcpNameServer] 192.168.1.1
- FireFox:
- ========
- FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-23] ()
- FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2012-10-20] (Microsoft Corporation)
- FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
- FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-23] ()
- FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
- FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File
- FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-22] (Oracle Corporation)
- FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-22] (Oracle Corporation)
- FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2012-10-20] (Microsoft Corporation)
- FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
- FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
- FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
- FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
- FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
- FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
- FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
- FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
- FF Plugin HKU\S-1-5-21-3724984598-424098314-2994088863-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\bigbabybauer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-10-08] (Unity Technologies ApS)
- FF HKLM-x32\...\Firefox\Extensions: [infoatoms@infoatoms.com] - C:\Program Files (x86)\Mozilla Firefox\extensions\infoatoms@infoatoms.com
- Chrome:
- =======
- CHR Profile: C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 2
- CHR Extension: (Google Drive) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-08]
- CHR Extension: (YouTube) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-08]
- CHR Extension: (Google Search) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-08]
- CHR Extension: (Gmail) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-08]
- CHR Profile: C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3
- CHR Extension: (Google Drive) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-08]
- CHR Extension: (YouTube) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-08]
- CHR Extension: (Google Search) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-08]
- CHR Extension: (BitTorrent Surf Beta) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ibpbofogepkkeoockhkfcgngjkimndlp [2015-02-13]
- CHR Extension: (Foxish live RSS) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\jpgagcapnkccceppgljfpoadahaopjdb [2015-02-13]
- CHR Extension: (Announcify) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mmiolkcfamcbpoandjpnefiegkcpeoan [2015-02-20]
- CHR Extension: (Gmail) - C:\Users\bigbabybauer\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-08]
- Opera:
- =======
- OPR Extension: (honestbleeps) - C:\Users\bigbabybauer\AppData\Roaming\Opera Software\Opera Stable\Extensions\gfdcmdcpehpkengmkhkbpifajmbhfgae [2015-03-05]
- OPR Extension: (Adblock Plus) - C:\Users\bigbabybauer\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-01-12]
- OPR Extension: (fucuxa) - C:\Users\bigbabybauer\AppData\Roaming\Opera Software\Opera Stable\Extensions\pcfaommkmdjacdkbaoohklbccfmbnnod [2015-06-27]
- ==================== Services (Whitelisted) =================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- S3 Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDevice.exe [55336 2015-06-27] ()
- R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
- R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-02-16] (ASUS)
- R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
- R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
- S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
- R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
- R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
- R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
- ==================== Drivers (Whitelisted) ====================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R1 ATKWMIACPIIO_; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
- R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
- R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
- R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-07] (Malwarebytes Corporation)
- R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
- R3 SRS_SSCFilter; C:\Windows\System32\drivers\srs_sscfilter_amd64.sys [346992 2009-12-15] ()
- S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-06-20] (Anchorfree Inc.)
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2015-07-08 01:34 - 2015-07-08 01:34 - 00019583 _____ C:\Users\bigbabybauer\Desktop\FRST.txt
- 2015-07-08 01:02 - 2015-07-08 01:34 - 00000000 ____D C:\FRST
- 2015-07-08 01:01 - 2015-07-08 01:01 - 02112512 _____ (Farbar) C:\Users\bigbabybauer\Desktop\FRST64.exe
- 2015-07-06 15:13 - 2015-07-02 22:42 - 73420288 _____ (taig tools) C:\Users\bigbabybauer\Desktop\TaiGJBreak_EN_2300.exe
- 2015-07-06 14:50 - 2015-07-06 14:55 - 71731922 _____ C:\Users\bigbabybauer\Downloads\TaiGJBreak_EN_2300.zip
- 2015-07-04 19:28 - 2015-05-19 22:52 - 00000000 ____D C:\Users\bigbabybauer\Desktop\data
- 2015-07-04 19:23 - 2015-07-04 19:26 - 191155416 _____ C:\Users\bigbabybauer\Downloads\SSF2DemoV0_9b1982.zip
- 2015-07-01 18:09 - 2015-07-01 18:30 - 1905728395 _____ C:\Users\bigbabybauer\Downloads\iPhone6,1_8.3_12F70_Restore.ipsw
- 2015-06-27 14:10 - 2015-06-27 14:10 - 00000964 _____ C:\Users\bigbabybauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
- 2015-06-27 14:10 - 2015-06-27 14:10 - 00000956 _____ C:\Users\bigbabybauer\Desktop\osu!.lnk
- 2015-06-27 14:09 - 2015-07-06 16:28 - 00000000 ____D C:\Users\bigbabybauer\AppData\Local\osu!
- 2015-06-27 14:08 - 2015-06-27 14:08 - 03262024 _____ (ppy) C:\Users\bigbabybauer\Downloads\osu!install.exe
- 2015-06-27 12:16 - 2015-06-27 12:19 - 52266712 _____ (悠然天地科技有限公司) C:\Users\bigbabybauer\Downloads\iTunesDriver64_0205.exe
- 2015-06-27 11:26 - 2015-06-27 11:26 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\TaiG
- 2015-06-25 20:31 - 2015-06-25 20:31 - 00174110 _____ C:\Users\bigbabybauer\Downloads\Package Control.sublime-package
- 2015-06-25 20:26 - 2015-06-25 20:26 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\Sublime Text 2
- 2015-06-25 20:19 - 2015-06-25 20:19 - 06513608 _____ ( ) C:\Users\bigbabybauer\Downloads\Sublime Text 2.0.2 x64 Setup.exe
- 2015-06-25 20:14 - 2015-06-25 20:14 - 00282401 _____ C:\Users\bigbabybauer\Downloads\lua-5.3.1.tar.gz
- 2015-06-25 20:14 - 2015-06-25 20:14 - 00000000 ____D C:\Users\bigbabybauer\Desktop\lua-5.3.1
- 2015-06-25 20:10 - 2015-06-25 20:11 - 00000000 ____D C:\Users\bigbabybauer\Documents\Corona Projects
- 2015-06-25 20:09 - 2015-06-25 20:09 - 00001205 _____ C:\Users\Public\Desktop\Corona Simulator.lnk
- 2015-06-25 20:09 - 2015-06-25 20:09 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\Corona Labs
- 2015-06-25 20:08 - 2015-06-25 20:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corona SDK
- 2015-06-25 20:08 - 2015-06-25 20:08 - 00000000 ____D C:\Program Files (x86)\Corona Labs
- 2015-06-25 20:03 - 2015-06-25 20:03 - 54493184 _____ C:\Users\bigbabybauer\Downloads\CoronaSDK-2015.2646.msi
- 2015-06-17 01:23 - 2015-06-17 01:23 - 00000000 ____D C:\Users\Guest\AppData\Local\Macromedia
- 2015-06-16 17:33 - 2015-06-16 17:33 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Mozilla
- 2015-06-16 17:33 - 2015-06-16 17:33 - 00000000 ____D C:\Users\Guest\AppData\Local\Mozilla
- 2015-06-09 23:35 - 2015-06-09 23:35 - 00000000 ____D C:\Users\Breanna\AppData\Local\Macromedia
- 2015-06-09 23:34 - 2015-06-09 23:35 - 00000000 ____D C:\Users\Breanna\AppData\Roaming\Mozilla
- 2015-06-09 23:34 - 2015-06-09 23:35 - 00000000 ____D C:\Users\Breanna\AppData\Local\Mozilla
- 2015-06-09 23:34 - 2015-06-09 23:34 - 00001121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
- 2015-06-09 23:34 - 2015-06-09 23:34 - 00001109 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
- 2015-06-09 23:34 - 2015-06-09 23:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
- 2015-06-09 23:34 - 2015-06-09 23:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
- 2015-06-09 23:12 - 2015-05-22 11:47 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
- 2015-06-09 23:12 - 2015-05-22 11:47 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
- 2015-06-09 23:12 - 2015-05-22 11:47 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
- 2015-06-09 23:12 - 2015-05-22 11:47 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
- 2015-06-09 23:12 - 2015-05-22 11:47 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
- 2015-06-09 23:12 - 2015-05-22 11:47 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
- 2015-06-09 23:12 - 2015-05-22 11:42 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
- 2015-06-09 23:12 - 2015-05-21 08:12 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2015-07-08 01:18 - 2012-10-19 00:34 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\Skype
- 2015-07-08 00:55 - 2013-03-26 23:03 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
- 2015-07-07 23:46 - 2014-09-15 14:46 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
- 2015-07-07 23:05 - 2012-09-27 12:53 - 01707198 ____N C:\Windows\WindowsUpdate.log
- 2015-07-07 02:14 - 2012-10-23 13:36 - 00003982 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{6660F8DC-7A3D-4524-B7E7-6F48D8190125}
- 2015-07-06 19:19 - 2009-07-13 23:45 - 00023520 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2015-07-06 19:19 - 2009-07-13 23:45 - 00023520 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2015-07-06 19:12 - 2013-12-24 02:12 - 00000443 _____ C:\Windows\system32\Drivers\etc\hosts.ics
- 2015-07-06 19:11 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
- 2015-07-04 19:50 - 2014-11-05 16:30 - 00000000 ____D C:\Users\bigbabybauer\AppData\Local\Spotify
- 2015-07-04 19:27 - 2014-11-05 16:29 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\Spotify
- 2015-07-04 13:25 - 2014-09-15 14:46 - 00001064 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
- 2015-07-04 13:25 - 2014-09-15 14:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
- 2015-07-04 13:25 - 2014-09-15 14:46 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
- 2015-07-03 15:14 - 2013-02-18 17:01 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\SoftGrid Client
- 2015-07-02 13:57 - 2015-04-30 08:18 - 00000000 ____D C:\Users\Guest\AppData\Roaming\SoftGrid Client
- 2015-06-28 17:33 - 2014-07-25 02:56 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\uTorrent
- 2015-06-28 17:32 - 2015-03-07 17:20 - 00000000 ____D C:\Users\bigbabybauer\AppData\Local\CrashDumps
- 2015-06-28 17:32 - 2012-10-19 00:08 - 00000000 ____D C:\Windows\Minidump
- 2015-06-27 12:23 - 2012-10-30 17:14 - 00000000 ____D C:\Program Files\Common Files\Apple
- 2015-06-27 12:07 - 2013-04-05 19:31 - 00000000 ____D C:\Users\bigbabybauer\Desktop\Movies
- 2015-06-25 21:55 - 2014-12-26 14:41 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
- 2015-06-25 11:36 - 2015-01-12 21:56 - 00003844 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1421117794
- 2015-06-25 11:36 - 2015-01-12 21:56 - 00000000 ____D C:\Program Files (x86)\Opera
- 2015-06-23 18:55 - 2013-03-26 23:03 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
- 2015-06-23 18:55 - 2013-03-26 23:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
- 2015-06-23 18:55 - 2013-03-26 23:03 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
- 2015-06-23 13:30 - 2013-11-13 19:11 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
- 2015-06-18 08:41 - 2014-09-15 14:46 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
- 2015-06-18 08:41 - 2014-09-15 14:46 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
- 2015-06-18 08:41 - 2014-09-15 14:46 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
- 2015-06-13 23:56 - 2013-04-05 19:48 - 00000000 ____D C:\Users\bigbabybauer\AppData\Roaming\vlc
- 2015-06-13 13:47 - 2014-12-15 16:26 - 00000000 ____D C:\Windows\system32\appraiser
- 2015-06-13 13:47 - 2014-07-12 03:07 - 00000000 ___SD C:\Windows\system32\CompatTel
- 2015-06-13 03:09 - 2013-08-14 03:02 - 00000000 ____D C:\Windows\system32\MRT
- 2015-06-13 03:00 - 2012-10-26 08:22 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
- 2015-06-10 11:32 - 2013-07-08 14:12 - 00000000 ____D C:\Users\Breanna\AppData\Roaming\Skype
- ==================== Files in the root of some directories =======
- 2013-07-11 07:12 - 2013-07-11 07:12 - 0000046 _____ () C:\Users\bigbabybauer\AppData\Roaming\Camdata.ini
- 2013-07-11 07:12 - 2013-07-11 07:12 - 0000408 _____ () C:\Users\bigbabybauer\AppData\Roaming\CamLayout.ini
- 2013-07-11 07:12 - 2013-07-11 07:12 - 0000408 _____ () C:\Users\bigbabybauer\AppData\Roaming\CamShapes.ini
- 2013-07-11 07:12 - 2013-07-11 07:12 - 0004510 _____ () C:\Users\bigbabybauer\AppData\Roaming\CamStudio.cfg
- 2015-01-12 23:24 - 2015-01-12 23:24 - 0000000 _____ () C:\Users\bigbabybauer\AppData\Roaming\libiconv
- 2015-01-12 23:24 - 2015-01-12 23:24 - 0000000 _____ () C:\Users\bigbabybauer\AppData\Roaming\programs
- 2013-08-31 00:50 - 2013-08-31 00:56 - 0000600 _____ () C:\Users\bigbabybauer\AppData\Local\PUTTY.RND
- 2015-01-12 20:40 - 2015-01-13 19:32 - 0007601 _____ () C:\Users\bigbabybauer\AppData\Local\Resmon.ResmonCfg
- 2014-02-23 22:28 - 2014-02-23 22:28 - 0000268 ___RH () C:\ProgramData\AccountTypes
- 2014-02-23 22:24 - 2014-02-23 22:24 - 0000268 ___RH () C:\ProgramData\Application
- 2014-02-23 22:24 - 2014-02-23 22:24 - 0000020 ____H () C:\ProgramData\PKP_DLeo.DAT
- 2014-02-23 22:28 - 2014-02-23 22:28 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
- 2014-02-23 22:26 - 2015-01-12 23:24 - 0000000 ____H () C:\ProgramData\PKP_DLet.DAT
- 2014-02-23 22:26 - 2015-01-12 23:24 - 0000000 ____H () C:\ProgramData\PKP_DLev.DAT
- 2009-07-29 00:21 - 2009-07-28 13:31 - 0000223 _____ () C:\ProgramData\setwallpaper.cmd
- 2009-07-29 00:21 - 2009-07-22 20:04 - 0024576 _____ () C:\ProgramData\SetWallpaper.exe
- 2011-02-03 08:22 - 2011-02-03 08:22 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
- 2011-02-03 08:21 - 2011-02-03 08:21 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
- Files to move or delete:
- ====================
- C:\ProgramData\SetWallpaper.exe
- Some files in TEMP:
- ====================
- C:\Users\Breanna\AppData\Local\Temp\SkypeSetup.exe
- ==================== Bamital & volsnap Check =================
- (There is no automatic fix for files that do not pass verification.)
- C:\Windows\System32\winlogon.exe => File is digitally signed
- C:\Windows\System32\wininit.exe => File is digitally signed
- C:\Windows\SysWOW64\wininit.exe => File is digitally signed
- C:\Windows\explorer.exe => File is digitally signed
- C:\Windows\SysWOW64\explorer.exe => File is digitally signed
- C:\Windows\System32\svchost.exe => File is digitally signed
- C:\Windows\SysWOW64\svchost.exe => File is digitally signed
- C:\Windows\System32\services.exe => File is digitally signed
- C:\Windows\System32\User32.dll => File is digitally signed
- C:\Windows\SysWOW64\User32.dll => File is digitally signed
- C:\Windows\System32\userinit.exe => File is digitally signed
- C:\Windows\SysWOW64\userinit.exe => File is digitally signed
- C:\Windows\System32\rpcss.dll => File is digitally signed
- C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2015-07-04 14:18
- ==================== End of log ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement