Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-05-2017
- Ran by PeterComp (administrator) on PETERCOMP-PC (31-05-2017 15:21:33)
- Running from F:\downloads\AntiMalware
- Loaded Profiles: PeterComp (Available Profiles: PeterComp)
- Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
- Internet Explorer Version 11 (Default browser: Chrome)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
- () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
- (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
- () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
- () C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
- (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
- (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
- (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
- (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
- (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
- (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
- (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
- (Valve Corporation) G:\Steam\Steam.exe
- () C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
- (Spotify Ltd) C:\Users\PeterComp\AppData\Roaming\Spotify\SpotifyWebHelper.exe
- (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
- (Windows (R) Win 7 DDK provider) C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe
- (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
- (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
- (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
- (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
- () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
- (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
- (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
- (Valve Corporation) G:\Steam\bin\cef\cef.win7\steamwebhelper.exe
- () C:\Windows\SysWOW64\PnkBstrA.exe
- (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
- (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
- (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
- (Microsoft Corporation) C:\Windows\System32\dllhost.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
- () C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Farbar) F:\downloads\AntiMalware\FarBar64.exe
- ==================== Registry (Whitelisted) ====================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13651672 2013-09-03] (Realtek Semiconductor)
- HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
- HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [567088 2016-10-14] ()
- HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc.)
- HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-05-30] (AVAST Software)
- HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
- HKLM-x32\...\Run: [FLxHCIm64] => C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe [183808 2013-07-11] (Windows (R) Win 7 DDK provider)
- HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
- HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [] => [X]
- HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
- HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [29246632 2017-05-30] (Dropbox, Inc.)
- HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [421768 2016-04-25] (Acronis International GmbH)
- HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7382232 2016-10-14] ()
- HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
- HKU\S-1-5-21-4212444594-818129302-1918108688-1000\...\Run: [AdobeBridge] => [X]
- HKU\S-1-5-21-4212444594-818129302-1918108688-1000\...\Run: [Steam] => G:\Steam\steam.exe [3019552 2017-04-25] (Valve Corporation)
- HKU\S-1-5-21-4212444594-818129302-1918108688-1000\...\Run: [Spotify Web Helper] => C:\Users\PeterComp\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-03-13] (Spotify Ltd)
- HKU\S-1-5-21-4212444594-818129302-1918108688-1000\...\MountPoints2: {84952505-a3d7-11e6-9020-74d4358c53a3} - H:\vs_ultimate.exe
- AppInit_DLLs: acaptuser64.dll => C:\Windows\system32\acaptuser64.dll [119160 2008-06-12] (Adobe Systems, Inc.)
- AppInit_DLLs-x32: acaptuser32.dll => C:\Windows\SysWOW64\acaptuser32.dll [111992 2008-06-12] (Adobe Systems, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
- ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
- ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
- ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-05-30] (AVAST Software)
- ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2016-03-18] (Acronis)
- ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2016-03-18] (Acronis)
- ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2016-03-18] (Acronis)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.16.0.dll [2017-05-30] (Dropbox, Inc.)
- Startup: C:\Users\PeterComp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk [2016-11-06]
- ShortcutTarget: Mozilla Thunderbird.lnk -> C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
- Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 75.153.171.122
- Tcpip\..\Interfaces\{1B46435C-5314-4FBD-95AB-9B9BD35BC1CF}: [DhcpNameServer] 192.168.1.254 75.153.171.122
- Tcpip\..\Interfaces\{E0475405-03A7-4BE7-B748-9760D00F91EB}: [DhcpNameServer] 7.254.254.254
- Internet Explorer:
- ==================
- HKU\S-1-5-21-4212444594-818129302-1918108688-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.youtube.com/channel/UCDsEcdYZBRdhv2dQ1vlCG9g
- BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-04-20] (Oracle Corporation)
- BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
- BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
- BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-20] (Oracle Corporation)
- BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems Incorporated)
- BHO-x32: Microsoft Web Test Recorder 12.0 Helper -> {432dd630-7e03-4c97-9d62-b99f52df4fc2} -> C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2013-10-05] (Microsoft Corporation)
- BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-04-20] (Oracle Corporation)
- BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
- BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
- BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation)
- BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-21] (Microsoft Corporation)
- BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-20] (Oracle Corporation)
- BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
- Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated)
- Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-01-23] (Microsoft Corporation)
- FireFox:
- ========
- FF Plugin: @java.com/DTPlugin,version=10.6.2 -> C:\Windows\system32\npDeployJava1.dll [2017-03-31] (Oracle Corporation)
- FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-20] (Oracle Corporation)
- FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
- FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
- FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
- FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-03-27] (Adobe Systems)
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
- FF Plugin-x32: @java.com/DTPlugin,version=10.6.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2017-03-31] (Oracle Corporation)
- FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-20] (Oracle Corporation)
- FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
- FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation)
- FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
- FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-03-27] (Adobe Systems)
- FF Plugin HKU\S-1-5-21-4212444594-818129302-1918108688-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\PeterComp\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2017-03-08] (Unity Technologies ApS)
- FF Plugin HKU\S-1-5-21-4212444594-818129302-1918108688-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2017-04-05] ()
- Chrome:
- =======
- CHR HomePage: Default -> hxxp://www.google.ca/
- CHR Session Restore: Default -> is enabled.
- CHR Profile: C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default [2017-05-31]
- CHR Extension: (Google Drive) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-20]
- CHR Extension: (YouTube) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-20]
- CHR Extension: (History 2) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cahejgbbfgmlmjgdjlibphdjeldhagkp [2016-11-20]
- CHR Extension: (Plex) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpniocchabmgenibceglhnfeimmdhdfm [2017-01-26]
- CHR Extension: (Google Docs Offline) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-20]
- CHR Extension: (Twitter unfollow) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmbbkpclbfmdacknjehonbfcilcfnkmb [2016-12-03]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
- CHR Extension: (SEO for Chrome) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\oangcciaeihlfmhppegpdceadpfaoclj [2016-11-20]
- CHR Extension: (Gmail) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-20]
- CHR Extension: (Chrome Media Router) - C:\Users\PeterComp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-16]
- ==================== Services (Whitelisted) ====================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1244408 2016-10-14] ()
- R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [771672 2017-03-14] (Adobe Systems Incorporated)
- R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [4463592 2017-02-08] ()
- R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
- R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
- R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263304 2017-05-30] (AVAST Software)
- S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-02] (Microsoft Corporation)
- S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-26] (Dropbox, Inc.)
- S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-26] (Dropbox, Inc.)
- R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [48944 2017-05-30] (Dropbox, Inc.)
- S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2016-11-10] (Macrovision Europe Ltd.) [File not signed]
- R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2016-12-20] (Ellora Assets Corp.) [File not signed]
- S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
- R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
- S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
- R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21312 2017-03-30] (Microsoft Corporation)
- R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
- R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
- R2 mi-raysat_3dsmax2014_64; C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe [86016 2011-09-14] () [File not signed]
- S4 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4884064 2015-08-11] (Acronis)
- R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-11] (NVIDIA Corporation)
- S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2117128 2016-11-15] (Electronic Arts)
- S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2178576 2016-11-15] (Electronic Arts)
- R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2016-12-02] ()
- S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
- R2 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [9698296 2016-04-16] ()
- S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
- R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10888944 2017-04-25] (TeamViewer GmbH)
- S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [872432 2016-06-23] (Tunngle.net GmbH)
- S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
- S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation)
- S3 VSStandardCollectorService150; C:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe [128232 2017-02-08] (Microsoft Corporation)
- S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-03-25] (Microsoft Corporation)
- ===================== Drivers (Whitelisted) ======================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-05-30] (AVAST Software)
- R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [128648 2017-05-30] (AVAST Software)
- R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-05-30] (AVAST Software)
- R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1007160 2017-05-30] (AVAST Software)
- R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [569192 2017-05-30] (AVAST Software)
- R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-05-30] (AVAST Software)
- R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-05-09] ()
- R0 file_tracker; C:\Windows\System32\DRIVERS\file_tracker.sys [366432 2017-02-08] (Acronis International GmbH)
- R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [77480 2013-07-02] (Fresco Logic)
- R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [187320 2017-05-31] (Malwarebytes)
- R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [113592 2017-05-31] (Malwarebytes)
- R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-05-31] (Malwarebytes)
- R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-05-31] (Malwarebytes)
- R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-05-31] (Malwarebytes)
- R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
- R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
- R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [23968 2015-10-01] (Saitek)
- R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [51488 2015-10-01] (Saitek)
- R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [39464 2016-04-27] (Tunngle.net GmbH)
- R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1267552 2017-02-08] (Acronis International GmbH)
- R2 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [193376 2017-02-08] (Acronis International GmbH)
- S3 tnd; C:\Windows\System32\DRIVERS\tnd.sys [601432 2017-02-08] (Acronis International GmbH)
- R2 virtual_file; C:\Windows\System32\DRIVERS\virtual_file.sys [279392 2017-02-08] (Acronis International GmbH)
- S3 _hid_0738_1708; C:\Windows\System32\DRIVERS\_hid_0738_1708.sys [180928 2015-10-01] (Saitek)
- S3 _usb_0738_1708; C:\Windows\System32\DRIVERS\_usb_0738_1708.sys [46528 2015-10-01] (Saitek)
- S3 dbx; system32\DRIVERS\dbx.sys [X]
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-05-31 15:21 - 2017-05-31 15:21 - 00000000 ____D C:\FRST
- 2017-05-31 14:53 - 2017-05-31 14:53 - 00395160 _____ C:\Windows\Minidump\053117-11062-01.dmp
- 2017-05-31 14:44 - 2017-05-31 14:53 - 00113592 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
- 2017-05-31 14:44 - 2017-05-31 14:53 - 00084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
- 2017-05-31 14:44 - 2017-05-31 14:44 - 00187320 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
- 2017-05-31 14:43 - 2017-05-31 14:53 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
- 2017-05-31 14:43 - 2017-05-31 14:53 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
- 2017-05-31 14:43 - 2017-05-31 14:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
- 2017-05-31 14:43 - 2017-05-31 14:43 - 00000000 ____D C:\ProgramData\Malwarebytes
- 2017-05-31 14:43 - 2017-05-31 14:43 - 00000000 ____D C:\Program Files\Malwarebytes
- 2017-05-31 14:43 - 2017-05-09 16:37 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
- 2017-05-31 14:24 - 2017-05-31 14:24 - 00000000 ____D C:\Users\PeterComp\Desktop\Armaan
- 2017-05-31 13:46 - 2017-05-31 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
- 2017-05-31 13:44 - 2017-05-31 13:44 - 00388568 _____ C:\Windows\Minidump\053117-11546-01.dmp
- 2017-05-31 04:28 - 2017-05-31 04:28 - 00388648 _____ C:\Windows\Minidump\053117-12500-01.dmp
- 2017-05-31 04:25 - 2017-05-31 04:25 - 00389272 _____ C:\Windows\Minidump\053117-10281-01.dmp
- 2017-05-31 04:21 - 2017-05-31 04:21 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
- 2017-05-31 04:21 - 2017-05-31 04:21 - 00000342 ____H C:\Windows\Tasks\Avast Emergency Update.job
- 2017-05-31 04:21 - 2017-05-30 23:20 - 00400456 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
- 2017-05-31 04:18 - 2017-05-31 04:21 - 00281904 _____ C:\Windows\ntbtlog.txt
- 2017-05-31 04:18 - 2017-05-31 04:18 - 00409032 _____ C:\Windows\Minidump\053117-10343-01.dmp
- 2017-05-30 23:26 - 2017-05-30 23:26 - 00047120 _____ C:\Users\PeterComp\AppData\Roaming\itunes_ftp.dat
- 2017-05-30 23:25 - 2017-05-30 23:25 - 00245264 _____ C:\Users\PeterComp\AppData\Roaming\itunes_el.dat
- 2017-05-30 23:21 - 2017-05-30 23:21 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\AVAST Software
- 2017-05-30 23:21 - 2017-05-30 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
- 2017-05-30 23:20 - 2017-05-30 23:20 - 01007160 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00569192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00232464 _____ C:\Users\PeterComp\AppData\Roaming\itunes_br.dat
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00128648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
- 2017-05-30 23:20 - 2017-05-30 23:20 - 00000000 ____D C:\Program Files\AVAST Software
- 2017-05-30 23:18 - 2017-05-30 23:20 - 00000000 ____D C:\ProgramData\AVAST Software
- 2017-05-30 23:17 - 2017-05-31 14:51 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\tor
- 2017-05-30 23:09 - 2017-05-30 23:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
- 2017-05-30 23:09 - 2017-05-30 23:09 - 00000000 ____D C:\Program Files\7-Zip
- 2017-05-30 22:48 - 2017-05-30 22:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Beast Mode Night of the Werewolf
- 2017-05-30 22:48 - 2017-05-30 22:48 - 00000000 _____ C:\Users\Public\Desktop\Beast Mode
- 2017-05-30 21:34 - 2017-05-31 04:15 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Clickteam
- 2017-05-30 20:56 - 2017-05-30 20:56 - 00003234 _____ C:\Windows\System32\Tasks\{5FAC499B-F547-4307-858C-F3A5A66F3787}
- 2017-05-30 19:30 - 2017-05-30 21:32 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\solicus
- 2017-05-30 19:30 - 2017-05-30 19:30 - 00000000 ____D C:\Program Files (x86)\solicus
- 2017-05-30 03:22 - 2017-05-30 03:22 - 00048944 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
- 2017-05-29 21:00 - 2017-05-29 21:00 - 00000000 ____D C:\Users\PeterComp\Desktop\UE4AppData
- 2017-05-28 13:50 - 2017-05-28 13:51 - 195230341 _____ C:\Users\PeterComp\Desktop\Believable Humans (In Video Game Animation).mp4
- 2017-05-27 18:17 - 2017-05-27 18:17 - 00000000 ____D C:\Users\Public\Apeirogon
- 2017-05-27 17:15 - 2017-05-27 17:16 - 18868893 _____ C:\Bubbles.wmv
- 2017-05-27 14:22 - 2017-05-27 14:53 - 00000000 ____D C:\Users\PeterComp\Desktop\Source
- 2017-05-27 14:13 - 2017-05-27 14:20 - 00000000 ____D C:\Users\PeterComp\Desktop\OceanProjectBuild
- 2017-05-26 22:47 - 2017-05-26 22:47 - 00000000 ____D C:\Users\PeterComp\AppData\Local\SirenGame
- 2017-05-25 13:44 - 2017-05-25 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
- 2017-05-25 13:44 - 2017-05-25 13:44 - 00000000 ____D C:\Program Files\CPUID
- 2017-05-24 23:58 - 2017-05-24 23:58 - 00000000 ____D C:\Users\PeterComp\AppData\LocalLow\Spiderling Games
- 2017-05-24 23:34 - 2017-05-24 23:40 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Apple Computer
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\Users\PeterComp\AppData\Local\Apple Computer
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\Users\PeterComp\AppData\Local\Apple
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\ProgramData\Apple Computer
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\Program Files\iTunes
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\Program Files\iPod
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\Program Files\Bonjour
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\Program Files (x86)\Bonjour
- 2017-05-24 23:34 - 2017-05-24 23:34 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
- 2017-05-24 23:33 - 2017-05-24 23:34 - 00000000 ____D C:\ProgramData\Apple
- 2017-05-24 23:33 - 2017-05-24 23:34 - 00000000 ____D C:\Program Files\Common Files\Apple
- 2017-05-23 12:21 - 2017-05-23 12:23 - 00001200 _____ C:\Users\Public\Desktop\CrotchRockets 4.15.lnk
- 2017-05-22 14:02 - 2017-05-22 15:02 - 00000000 ____D C:\Users\PeterComp\Desktop\Craigslist
- 2017-05-22 10:23 - 2017-05-31 14:53 - 00000000 ____D C:\Users\PeterComp\AppData\LocalLow\Mozilla
- 2017-05-21 11:46 - 2017-05-21 11:47 - 00000000 ____D C:\Users\PeterComp\Desktop\MinimapPluginClean
- 2017-05-16 23:31 - 2017-05-16 23:43 - 66349331 _____ C:\RadarStillBroken.wmv
- 2017-05-16 15:53 - 2017-05-16 15:53 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Google
- 2017-05-15 22:33 - 2017-05-15 22:33 - 00000000 ____D C:\Users\PeterComp\AppData\Local\.IdentityService
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\3082
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\2052
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1055
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1049
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1046
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1045
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1042
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1041
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1040
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1036
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1031
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1029
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\SysWOW64\1028
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\3082
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\2052
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1055
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1049
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1046
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1045
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1042
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1041
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1040
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1036
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1031
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1029
- 2017-05-15 22:28 - 2017-05-15 22:28 - 00000000 ____D C:\Windows\system32\1028
- 2017-05-15 22:25 - 2017-05-15 22:25 - 00001467 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2017.lnk
- 2017-05-15 22:25 - 2017-05-15 22:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2017
- 2017-05-15 22:18 - 2017-05-15 22:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
- 2017-05-15 22:18 - 2017-05-15 22:18 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio Installer.lnk
- 2017-05-15 22:18 - 2017-05-15 22:18 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\vstelemetry
- 2017-05-15 22:18 - 2017-05-15 22:18 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Visual Studio Setup
- 2017-05-15 22:18 - 2017-05-15 22:18 - 00000000 ____D C:\Users\PeterComp\AppData\Local\ServiceHub
- 2017-05-13 23:23 - 2017-05-13 23:23 - 00000000 ____D C:\Users\PeterComp\AppData\Local\id Software
- 2017-05-13 01:47 - 2017-05-14 02:49 - 00000000 __RHD C:\Users\PeterComp\Creative Cloud Files
- 2017-05-13 01:47 - 2017-05-14 02:49 - 00000000 ____D C:\ProgramData\boost_interprocess
- 2017-05-13 01:47 - 2017-05-13 01:47 - 00000040 ____H C:\60D9A22A5A43
- 2017-05-13 01:46 - 2017-05-13 01:46 - 00001221 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
- 2017-05-11 23:45 - 2017-05-12 00:57 - 00000000 ____D C:\Users\PeterComp\Desktop\RadarFixes
- 2017-05-10 18:02 - 2017-05-10 18:02 - 00000000 ____D C:\Users\PeterComp\AppData\Local\Quixel
- 2017-05-10 17:59 - 2017-05-10 17:59 - 00001097 _____ C:\Users\Public\Desktop\dDo x64.lnk
- 2017-05-10 17:59 - 2017-05-10 17:59 - 00000000 ____D C:\ProgramData\Quixel
- 2017-05-10 03:09 - 2017-05-10 03:23 - 63387809 _____ C:\RadarBroken.wmv
- 2017-05-10 01:46 - 2017-05-10 01:56 - 58491614 _____ C:\RadarAddingEnemiesAfterRemoved.wmv
- 2017-05-02 17:58 - 2017-05-02 17:58 - 00000000 ____D C:\Users\PeterComp\AppData\Local\redout
- 2017-05-02 15:53 - 2017-05-02 15:53 - 00001174 _____ C:\Users\Public\Desktop\Silhouette 4.15.lnk
- 2017-05-02 03:02 - 2017-05-02 03:03 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Maxscript
- 2017-05-01 23:27 - 2017-05-01 23:27 - 00000000 ____D C:\Users\PeterComp\Desktop\Silhouette0.2
- 2017-05-01 18:53 - 2017-05-01 20:55 - 335642829 _____ C:\Fundamentals of Blueprint - Health System.wmv
- 2017-05-01 02:08 - 2017-05-01 02:08 - 00010344 _____ C:\Users\PeterComp\Desktop\UV2.uvw
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-05-31 15:04 - 2016-12-06 18:37 - 00004990 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for PeterComp-PC-PeterComp PeterComp-PC
- 2017-05-31 15:01 - 2009-07-13 21:45 - 00032416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2017-05-31 15:01 - 2009-07-13 21:45 - 00032416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2017-05-31 15:00 - 2009-07-13 22:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
- 2017-05-31 15:00 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
- 2017-05-31 14:53 - 2017-04-05 22:35 - 00000000 ____D C:\Program Files (x86)\FormatFactory
- 2017-05-31 14:53 - 2017-01-08 20:48 - 1725462113 _____ C:\Windows\MEMORY.DMP
- 2017-05-31 14:53 - 2017-01-08 20:48 - 00000000 ____D C:\Windows\Minidump
- 2017-05-31 14:53 - 2016-11-26 15:28 - 00000910 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
- 2017-05-31 14:53 - 2016-11-05 21:13 - 00000000 ____D C:\ProgramData\NVIDIA
- 2017-05-31 14:53 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
- 2017-05-31 13:52 - 2016-11-26 15:28 - 00000914 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
- 2017-05-31 13:46 - 2016-11-26 15:28 - 00000000 ____D C:\Users\PeterComp\AppData\Local\Dropbox
- 2017-05-31 13:46 - 2016-11-26 15:28 - 00000000 ____D C:\Program Files (x86)\Dropbox
- 2017-05-31 13:45 - 2016-11-06 20:15 - 00000000 ____D C:\Users\PeterComp\AppData\Local\CrashDumps
- 2017-05-31 04:35 - 2016-11-06 14:48 - 00000000 ____D C:\Program Files (x86)\FlashFXP 5
- 2017-05-31 02:53 - 2016-11-08 16:35 - 00000000 ____D C:\Users\PeterComp\AppData\LocalLow\uTorrent
- 2017-05-31 02:53 - 2016-11-08 16:33 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\uTorrent
- 2017-05-31 02:00 - 2016-11-05 21:40 - 00000000 ____D C:\Users\PeterComp\AppData\Local\Adobe
- 2017-05-30 19:27 - 2005-01-01 01:30 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Skype
- 2017-05-30 17:39 - 2016-11-06 23:00 - 00000132 _____ C:\Users\PeterComp\AppData\Roaming\Adobe PNG Format CS6 Prefs
- 2017-05-30 00:00 - 2016-11-06 16:53 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\vlc
- 2017-05-29 21:01 - 2016-11-05 23:58 - 00000000 ____D C:\Users\PeterComp\AppData\Local\UnrealEngine
- 2017-05-29 20:32 - 2009-07-13 22:08 - 00032574 _____ C:\Windows\Tasks\SCHEDLGU.TXT
- 2017-05-29 12:38 - 2016-11-06 20:47 - 00000132 _____ C:\Users\PeterComp\AppData\Roaming\Adobe Targa Format CS6 Prefs
- 2017-05-28 13:14 - 2016-11-23 20:25 - 00000000 ____D C:\Program Files (x86)\TeamViewer
- 2017-05-27 16:41 - 2016-11-05 23:52 - 00000000 ____D C:\ProgramData\FLEXnet
- 2017-05-24 15:36 - 2016-12-22 18:54 - 00001684 _____ C:\Windows\SysWOW64\AltST.rdt
- 2017-05-23 22:33 - 2016-11-05 21:04 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
- 2017-05-23 22:32 - 2016-11-05 21:12 - 00000000 ____D C:\ProgramData\Package Cache
- 2017-05-23 12:05 - 2016-11-21 22:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
- 2017-05-23 12:05 - 2016-11-06 04:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
- 2017-05-16 14:26 - 2016-11-05 21:23 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2017-05-15 22:28 - 2017-04-03 13:24 - 00000000 ____D C:\Windows\SysWOW64\1033
- 2017-05-15 22:28 - 2017-04-03 13:23 - 00000000 ____D C:\Windows\system32\1033
- 2017-05-15 22:27 - 2017-04-03 13:23 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
- 2017-05-15 22:25 - 2009-07-13 22:32 - 00000000 ____D C:\Program Files (x86)\MSBuild
- 2017-05-14 02:46 - 2016-11-05 18:34 - 00000000 ____D C:\Users\PeterComp
- 2017-05-13 02:22 - 2016-11-05 21:43 - 00000000 ____D C:\Program Files (x86)\Adobe
- 2017-05-13 02:19 - 2016-11-05 19:48 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Adobe
- 2017-05-13 01:47 - 2016-11-05 21:40 - 00000000 ____D C:\ProgramData\Adobe
- 2017-05-13 00:04 - 2016-11-08 18:21 - 00001456 _____ C:\Users\PeterComp\AppData\Local\Adobe Save for Web 13.0 Prefs
- 2017-05-11 22:45 - 2016-11-23 21:37 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Tunngle
- 2017-05-11 20:19 - 2017-03-13 21:44 - 00000000 ____D C:\ProgramData\Tunngle
- 2017-05-10 17:59 - 2016-12-25 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quixel
- 2017-05-09 13:08 - 2016-12-16 16:57 - 00803320 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
- 2017-05-09 13:08 - 2016-12-16 16:57 - 00144888 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
- 2017-05-09 13:08 - 2016-12-16 16:57 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
- 2017-05-09 13:08 - 2016-12-16 16:57 - 00000000 ____D C:\Windows\system32\Macromed
- 2017-05-09 13:08 - 2016-11-05 21:43 - 00000000 ____D C:\Windows\SysWOW64\Macromed
- 2017-05-09 12:51 - 2017-03-09 17:44 - 00000000 ___RD C:\Program Files (x86)\Skype
- 2017-05-09 12:51 - 2005-01-01 01:30 - 00000000 ____D C:\ProgramData\Skype
- 2017-05-08 22:08 - 2016-12-05 17:02 - 00000000 ____D C:\Users\PeterComp\AppData\Roaming\Spotify
- 2017-05-08 22:08 - 2016-12-05 17:02 - 00000000 ____D C:\Users\PeterComp\AppData\Local\Spotify
- 2017-05-05 14:20 - 2017-03-28 12:46 - 00000274 _____ C:\Users\PeterComp\Desktop\CityOfBurnaby.txt
- 2017-05-05 14:09 - 2009-07-13 21:45 - 05090824 _____ C:\Windows\system32\FNTCACHE.DAT
- 2017-05-04 22:27 - 2016-11-05 21:03 - 00128264 _____ C:\Users\PeterComp\AppData\Local\GDIPFONTCACHEV1.DAT
- 2017-05-04 13:49 - 2017-04-09 04:44 - 00000274 _____ C:\Windows\ulead32.ini
- 2017-05-02 21:47 - 2017-04-03 22:41 - 00001144 _____ C:\Users\Public\Desktop\BeastMode 4.15.lnk
- ==================== Files in the root of some directories =======
- 2016-11-06 23:00 - 2017-05-30 17:39 - 0000132 _____ () C:\Users\PeterComp\AppData\Roaming\Adobe PNG Format CS6 Prefs
- 2016-11-06 20:47 - 2017-05-29 12:38 - 0000132 _____ () C:\Users\PeterComp\AppData\Roaming\Adobe Targa Format CS6 Prefs
- 2017-05-30 23:20 - 2017-05-30 23:20 - 0232464 _____ () C:\Users\PeterComp\AppData\Roaming\itunes_br.dat
- 2017-05-30 23:25 - 2017-05-30 23:25 - 0245264 _____ () C:\Users\PeterComp\AppData\Roaming\itunes_el.dat
- 2017-05-30 23:26 - 2017-05-30 23:26 - 0047120 _____ () C:\Users\PeterComp\AppData\Roaming\itunes_ftp.dat
- 2016-12-05 02:41 - 2017-05-10 16:40 - 0000025 ____H () C:\Users\PeterComp\AppData\Roaming\uninst45.log
- 2016-11-08 18:21 - 2017-05-13 00:04 - 0001456 _____ () C:\Users\PeterComp\AppData\Local\Adobe Save for Web 13.0 Prefs
- 2017-01-12 14:59 - 2017-04-26 17:43 - 0006144 _____ () C:\Users\PeterComp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- 2017-01-17 15:47 - 2017-01-17 15:47 - 0000292 _____ () C:\Users\PeterComp\AppData\Local\HamsterBookConverter.cfg
- 2016-12-05 02:41 - 2017-05-10 16:40 - 0000025 ____H () C:\Users\PeterComp\AppData\Local\uninst36.log
- 2016-11-05 21:04 - 2016-11-05 21:04 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
- 2017-01-07 19:26 - 2017-01-07 19:26 - 0000016 _____ () C:\ProgramData\mntemp
- 2016-12-05 02:41 - 2017-05-10 16:40 - 0000025 ____H () C:\ProgramData\temp54.log
- Files to move or delete:
- ====================
- C:\Users\PeterComp\{58C482E3-0C46-43EC-8EE5-C7230FFBC3D6}.dat
- C:\Users\PeterComp\{7FE16F2D-3565-4432-91C0-C1E96A2EB147}.dat
- Some files in TEMP:
- ====================
- 2017-05-30 23:16 - 2017-05-30 23:16 - 5169152 _____ (Puffelli ) C:\Users\PeterComp\AppData\Local\Temp\35849.exe
- 2016-11-05 23:50 - 2013-01-18 14:24 - 0040328 _____ (Autodesk, Inc.) C:\Users\PeterComp\AppData\Local\Temp\AcDeltree.exe
- 2016-12-20 15:53 - 2016-12-20 16:31 - 2016632 _____ (Flexera Software LLC) C:\Users\PeterComp\AppData\Local\Temp\FNP_ACT_InstallerCA.dll
- 2016-11-28 23:08 - 2016-11-28 23:08 - 32075848 _____ (Ellora Assets Corporation ) C:\Users\PeterComp\AppData\Local\Temp\FreemakeVideoConverterFull.exe
- 2016-11-08 13:47 - 2016-11-08 13:47 - 17993968 _____ (Ellora Assets Corporation ) C:\Users\PeterComp\AppData\Local\Temp\FreemakeVideoDownloaderFull.exe
- 2017-04-20 01:37 - 2017-04-20 01:37 - 0739904 _____ (Oracle Corporation) C:\Users\PeterComp\AppData\Local\Temp\jre-8u131-windows-au.exe
- 2012-11-10 11:29 - 2012-11-10 11:29 - 0178760 ____R (Microsoft Corporation) C:\Users\PeterComp\AppData\Local\Temp\ose00000.exe
- 2017-03-09 17:44 - 2017-03-09 17:44 - 14456872 _____ (Microsoft Corporation) C:\Users\PeterComp\AppData\Local\Temp\vc_redist.x86.exe
- 2011-07-09 18:07 - 2011-07-09 18:07 - 0118784 _____ () C:\Users\PeterComp\AppData\Local\Temp\xmlUpdater.exe
- ==================== Bamital & volsnap ======================
- (There is no automatic fix for files that do not pass verification.)
- C:\Windows\system32\winlogon.exe => File is digitally signed
- C:\Windows\system32\wininit.exe => File is digitally signed
- C:\Windows\SysWOW64\wininit.exe => File is digitally signed
- C:\Windows\explorer.exe => File is digitally signed
- C:\Windows\SysWOW64\explorer.exe => File is digitally signed
- C:\Windows\system32\svchost.exe => File is digitally signed
- C:\Windows\SysWOW64\svchost.exe => File is digitally signed
- C:\Windows\system32\services.exe => File is digitally signed
- C:\Windows\system32\User32.dll => File is digitally signed
- C:\Windows\SysWOW64\User32.dll => File is digitally signed
- C:\Windows\system32\userinit.exe => File is digitally signed
- C:\Windows\SysWOW64\userinit.exe => File is digitally signed
- C:\Windows\system32\rpcss.dll => File is digitally signed
- C:\Windows\system32\dnsapi.dll => File is digitally signed
- C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
- C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2017-05-23 16:00
- ==================== End of FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment