Advertisement
Guest User

Untitled

a guest
Nov 13th, 2015
192
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 27.42 KB | None | 0 0
  1. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
  2. Ran by Robert (administrator) on ROBERT-PC (13-11-2015 17:44:45)
  3. Running from C:\Users\Robert\Desktop
  4. Loaded Profiles: Robert & UpdatusUser (Available Profiles: Robert & UpdatusUser)
  5. Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
  6. Internet Explorer Version 11 (Default browser not detected!)
  7. Boot Mode: Normal
  8. Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
  9.  
  10. ==================== Processes (Whitelisted) =================
  11.  
  12. (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
  13.  
  14. (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
  15. (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
  16. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
  17. (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
  18. (Amazon Inc.) C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe
  19. (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
  20. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
  21. () C:\Program Files (x86)\Cloud PC Defender\AntivirusWatcher.exe
  22. ( ) C:\Windows\System32\lxdpcoms.exe
  23. (Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
  24. (Protected Soft.) C:\Program Files\ProtectedStorageManager\lsassm.exe
  25. (Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
  26. (Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
  27. (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
  28. (The Chromium Authors) C:\Users\Robert\AppData\Local\Ninja Loader\Chrome-bin\chrome.exe
  29. (CYREN Inc.) C:\Program Files\Common Files\Commtouch\AntiVirus5\vsedsps.exe
  30. (CYREN Inc.) C:\Program Files\Common Files\Commtouch\AntiVirus5\vseqrts.exe
  31. () C:\ProgramData\WCService\WCService.exe
  32. (CYREN Inc.) C:\Program Files\Common Files\Commtouch\AntiVirus5\vseamps.exe
  33. (Protected Soft.) C:\Program Files\ProtectedStorageManager\packages\b5e1c8a5-f79c-465f-a594-7dc35153ecc4\lsassmu.exe
  34. (The Chromium Authors) C:\Users\Robert\AppData\Local\Ninja Loader\Chrome-bin\chrome.exe
  35. (The Chromium Authors) C:\Users\Robert\AppData\Local\Ninja Loader\Chrome-bin\chrome.exe
  36. () C:\Program Files (x86)\Cloud PC Defender\AntivirusUpdater.exe
  37. () C:\Program Files (x86)\Cloud PC Defender\AntivirusAgent.exe
  38. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
  39. (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
  40. (Microsoft Corporation) C:\Windows\System32\rundll32.exe
  41. (YTDownloader) C:\Program Files (x86)\YTDownloader\YTDownloader.exe
  42. (Goobzo) C:\Program Files (x86)\YTDownloader\Updater.exe
  43. (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
  44.  
  45.  
  46. ==================== Registry (Whitelisted) ===========================
  47.  
  48. (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
  49.  
  50. HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
  51. GroupPolicy: Restriction - Chrome <======= ATTENTION
  52. CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
  53.  
  54. ==================== Internet (Whitelisted) ====================
  55.  
  56. (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
  57.  
  58. HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <======= ATTENTION (Restriction - ProxySettings)
  59. ProxyEnable: [HKLM] => Proxy is enabled.
  60. ProxyEnable: [HKLM-x32] => Proxy is enabled.
  61. ProxyServer: [HKLM] => http=127.0.0.1:49791;https=127.0.0.1:49791
  62. ProxyServer: [HKLM-x32] => http=127.0.0.1:49791;https=127.0.0.1:49791
  63. AutoConfigURL: [HKLM] => http=127.0.0.1:49791;https=127.0.0.1:49791
  64. Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
  65. Tcpip\..\Interfaces\{ABED4C91-A600-41AB-9B98-195C2C900925}: [DhcpNameServer] 192.168.1.1
  66.  
  67. Internet Explorer:
  68. ==================
  69. HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
  70. HKU\S-1-5-21-1491877336-470492222-3658018201-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
  71. HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
  72. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
  73. URLSearchHook: HKLM-x32 -> Default = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
  74. SearchScopes: HKLM -> DefaultScope {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
  75. SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
  76. SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
  77. SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
  78. SearchScopes: HKU\.DEFAULT -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
  79. SearchScopes: HKU\S-1-5-21-1491877336-470492222-3658018201-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://search.twcc.com/?src=toolbar#web/{searchTerms}/1/
  80. SearchScopes: HKU\S-1-5-21-1491877336-470492222-3658018201-1000 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
  81. Toolbar: HKU\S-1-5-21-1491877336-470492222-3658018201-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
  82. Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - No File
  83.  
  84. FireFox:
  85. ========
  86. FF ProfilePath: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default
  87. FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_191.dll [2015-07-09] ()
  88. FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
  89. FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
  90. FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_191.dll [2015-07-09] ()
  91. FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
  92. FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
  93. FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-28] (Google Inc.)
  94. FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-28] (Google Inc.)
  95. FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
  96. FF Extension: Coupon Marvel - C:\Users\Robert\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\jid1-xGIjYAPvEA9ENA@jetpack.xpi [2014-10-21] [not signed]
  97. FF Extension: Search Snacks - C:\Program Files (x86)\Mozilla Firefox\extensions\{fc4350fc-3e37-4f1e-8341-5af31e09f020} [2014-12-03] [not signed]
  98. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{515c4efa-8813-4abe-9cd7-95731f5e0a90} [not found]
  99. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [not found]
  100. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\idmsq@idmsq.com [not found]
  101. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{037A8456-0903-427E-B5E0-7D95FDD598AE} [not found]
  102. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{607b689f-7600-45e4-b8e5-887f72dab15c} [not found]
  103. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\caseyathaniel30@hotmail.com [not found]
  104. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\wrigtdamon@yahoo.com [not found]
  105. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\b6e4f54065ff48dd97db30ca@c9b45f807bf54a45a4669e51c.com [not found]
  106. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{f0ec4af0-5d38-45ef-8d30-6a5f59488023}.xpi [not found]
  107. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\e4aa8e99-7176-43d9-9f3f-3c3302d236b6@gmail.com [not found]
  108. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\23fb8bb3-ac21-4230-bbfa-49b94968bc63@gmail.com [not found]
  109. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{F32E7E42-9AFA-47CA-A0C4-D07EE651D404} [not found]
  110. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\faststartff@gmail.com [not found]
  111. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\TidyNetwork@TidyNetwork [not found]
  112. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{9aafbc7e-7f71-475e-8944-dca9aba1ecb6} [not found]
  113. FF Extension: No Name - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\mppueken.default\extensions\{9aafbc7e-7f71-475e-8944-dca9aba1ecb6} [not found]
  114.  
  115. Chrome:
  116. =======
  117. CHR dev: Chrome dev build detected! <======= ATTENTION
  118. CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp
  119. CHR RestoreOnStartup: Default -> "hxxp://search.yahoo.com/?fr=hp-ddc-bd&type=840_pr__alt__ddc_dsssyc_bd_com"
  120. CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms}
  121. CHR DefaultSearchKeyword: Default -> search.ask.com
  122. CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms}
  123. CHR Profile: C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default
  124.  
  125. ==================== Services (Whitelisted) ========================
  126.  
  127. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  128.  
  129. R2 Amazon 1Button App Service; C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe [456000 2015-05-06] (Amazon Inc.)
  130. R2 AntivirusAgentSvc; C:\Program Files (x86)\Cloud PC Defender\AntivirusAgent.exe [34816 2014-06-24] () [File not signed]
  131. R2 AntivirusUpdateSvc; C:\Program Files (x86)\Cloud PC Defender\AntivirusUpdater.exe [14336 2014-06-24] () [File not signed]
  132. R2 AntivirusWatcher; C:\Program Files (x86)\Cloud PC Defender\AntivirusWatcher.exe [9216 2014-06-24] () [File not signed]
  133. S2 BrsHelper; C:\Program Files (x86)\YTDownloader\BrowserHelperSrv.exe [22376 2015-01-08] ()
  134. R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-13] (Microsoft Corporation)
  135. R2 lxdp_device; C:\Windows\system32\lxdpcoms.exe [1039872 2007-11-19] ( )
  136. S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
  137. R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
  138. R2 NinjaLoaderService; C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe [52736 2014-12-28] (Ninja Soft Inc.) [File not signed]
  139. S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
  140. R2 ProtectedStorageManager; C:\Program Files\ProtectedStorageManager\lsassm.exe [375808 2015-04-14] (Protected Soft.) [File not signed]
  141. R2 vseamps; C:\Program Files\Common Files\Commtouch\AntiVirus5\vseamps.exe [122120 2014-05-02] (CYREN Inc.)
  142. R2 vsedsps; C:\Program Files\Common Files\Commtouch\AntiVirus5\vsedsps.exe [119560 2014-05-02] (CYREN Inc.)
  143. R3 vseqrts; C:\Program Files\Common Files\Commtouch\AntiVirus5\vseqrts.exe [181512 2014-05-02] (CYREN Inc.)
  144. R2 WCService; C:\ProgramData\WCService\WCService.exe [132608 2014-12-07] () [File not signed]
  145. S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
  146.  
  147. ===================== Drivers (Whitelisted) ==========================
  148.  
  149. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  150.  
  151. R2 AMP; C:\Windows\system32\Drivers\amp.sys [174856 2014-05-02] (CYREN Inc.)
  152. R2 AMPSE; C:\Windows\system32\Drivers\ampse.sys [1766152 2014-05-02] (CYREN Inc.)
  153. S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
  154. R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2014-04-07] (EldoS Corporation)
  155. R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
  156. S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-11] (Malwarebytes)
  157. S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
  158. R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
  159. S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
  160. R2 sbmntr; C:\Program Files (x86)\YTDownloader\sbmntr.sys [58728 2015-01-08] (YTDownloader)
  161. S3 cpuz134; \??\C:\Users\Robert\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
  162.  
  163. ==================== NetSvcs (Whitelisted) ===================
  164.  
  165. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  166.  
  167.  
  168. ==================== One Month Created files and folders ========
  169.  
  170. (If an entry is included in the fixlist, the file/folder will be moved.)
  171.  
  172. 2015-11-13 17:44 - 2015-11-13 17:45 - 00013916 _____ C:\Users\Robert\Desktop\FRST.txt
  173. 2015-11-13 17:44 - 2015-11-11 17:43 - 02198528 _____ (Farbar) C:\Users\Robert\Desktop\FRST64.exe
  174. 2015-11-13 17:40 - 2015-11-13 17:40 - 00000020 ___SH C:\Users\TEMP\ntuser.ini
  175. 2015-11-13 17:40 - 2015-11-13 17:40 - 00000000 ____D C:\Users\TEMP
  176. 2015-11-13 17:40 - 2015-11-11 18:11 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\iolo
  177. 2015-11-13 17:40 - 2009-07-13 23:54 - 00000000 ___RD C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
  178. 2015-11-13 17:40 - 2009-07-13 23:49 - 00000000 ___RD C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
  179. 2015-11-13 17:39 - 2015-11-13 17:34 - 04404952 _____ (Kaspersky Lab ZAO) C:\Users\Robert\Desktop\tdsskiller.exe
  180. 2015-11-11 22:22 - 2015-11-11 20:11 - 02870984 _____ (ESET) C:\Users\Robert\Desktop\esetsmartinstaller_enu.exe
  181. 2015-11-11 22:21 - 2015-11-11 22:21 - 00000000 ____D C:\Program Files (x86)\ESET
  182. 2015-11-11 19:41 - 2015-11-11 19:41 - 00001627 _____ C:\Users\Robert\Desktop\malwarebyte.txt
  183. 2015-11-11 18:59 - 2015-11-11 18:59 - 00000000 ____D C:\Windows\pss
  184. 2015-11-11 17:50 - 2015-11-11 23:00 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
  185. 2015-11-11 17:50 - 2015-11-11 18:46 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
  186. 2015-11-11 17:50 - 2015-11-11 17:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
  187. 2015-11-11 17:50 - 2015-11-11 17:50 - 00000000 ____D C:\ProgramData\Malwarebytes
  188. 2015-11-11 17:50 - 2015-11-11 17:50 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
  189. 2015-11-11 17:50 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
  190. 2015-11-11 17:50 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
  191. 2015-11-11 17:50 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
  192. 2015-11-11 17:45 - 2015-11-13 17:45 - 00000000 ____D C:\FRST
  193. 2015-11-11 17:41 - 2015-11-11 18:11 - 00000000 ____D C:\Users\Default\AppData\Roaming\iolo
  194. 2015-11-11 17:41 - 2015-11-11 18:11 - 00000000 ____D C:\Users\Default User\AppData\Roaming\iolo
  195. 2015-11-11 17:34 - 2015-11-11 17:34 - 00000000 ____D C:\Windows\system32\%LocalAppData%
  196. 2015-11-11 17:19 - 2015-11-11 17:19 - 00000000 ____D C:\Program Files (x86)\GUM9D86.tmp
  197. 2015-11-11 17:19 - 2015-11-11 17:19 - 00000000 _____ C:\Users\Robert\AppData\Local\{7CD2C8D3-BF8B-41D9-A233-46C0B7545228}
  198.  
  199. ==================== One Month Modified files and folders ========
  200.  
  201. (If an entry is included in the fixlist, the file/folder will be moved.)
  202.  
  203. 2015-11-13 17:49 - 2009-07-14 00:13 - 00782510 _____ C:\Windows\system32\PerfStringBackup.INI
  204. 2015-11-13 17:46 - 2009-07-13 23:45 - 00028128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  205. 2015-11-13 17:46 - 2009-07-13 23:45 - 00028128 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  206. 2015-11-13 17:37 - 2015-04-07 04:58 - 00001008 _____ C:\Windows\Tasks\1Lpsl7rkbpk08XPM.job
  207. 2015-11-13 17:37 - 2013-07-02 18:39 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
  208. 2015-11-13 17:37 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
  209. 2015-11-13 17:37 - 2009-07-13 23:51 - 00061531 _____ C:\Windows\setupact.log
  210. 2015-11-11 23:53 - 2013-06-28 21:47 - 01182342 _____ C:\Windows\WindowsUpdate.log
  211. 2015-11-11 23:18 - 2013-07-02 18:39 - 00000000 ____D C:\Program Files\Google
  212. 2015-11-11 23:18 - 2013-07-02 18:39 - 00000000 ____D C:\Program Files (x86)\Google
  213. 2015-11-11 23:18 - 2010-11-20 22:47 - 02907698 _____ C:\Windows\PFRO.log
  214. 2015-11-11 23:15 - 2015-07-09 05:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
  215. 2015-11-11 23:14 - 2014-12-10 18:36 - 00000000 ____D C:\Program Files (x86)\roadrunnertb
  216. 2015-11-11 23:10 - 2013-06-29 15:23 - 00000000 ____D C:\Program Files (x86)\Java
  217. 2015-11-11 23:08 - 2015-02-20 06:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverRestore
  218. 2015-11-11 23:08 - 2013-06-29 15:21 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
  219. 2015-11-11 23:06 - 2013-07-02 18:39 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
  220. 2015-11-11 23:05 - 2014-12-07 11:13 - 00000000 __SHD C:\Users\Robert\AppData\Local\EmieUserList
  221. 2015-11-11 23:05 - 2014-12-07 11:13 - 00000000 __SHD C:\Users\Robert\AppData\Local\EmieSiteList
  222. 2015-11-11 23:05 - 2014-12-07 11:13 - 00000000 __SHD C:\Users\Robert\AppData\Local\EmieBrowserModeList
  223. 2015-11-11 23:05 - 2014-11-15 08:23 - 00000000 __SHD C:\Users\Robert\AppData\LocalLow\EmieBrowserModeList
  224. 2015-11-11 23:05 - 2014-05-20 16:34 - 00000000 __SHD C:\Users\Robert\AppData\LocalLow\EmieUserList
  225. 2015-11-11 23:05 - 2014-05-19 19:21 - 00000000 __SHD C:\Users\Robert\AppData\LocalLow\EmieSiteList
  226. 2015-11-11 23:05 - 2013-07-02 18:39 - 00000000 ____D C:\Users\Robert\AppData\Local\Google
  227. 2015-11-11 23:05 - 2013-07-02 18:39 - 00000000 ____D C:\ProgramData\Google
  228. 2015-11-11 23:04 - 2014-12-03 06:47 - 00000000 ____D C:\Program Files\COMODO
  229. 2015-11-11 21:42 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\Speech
  230. 2015-11-11 19:06 - 2013-06-28 16:20 - 00000000 ____D C:\Users\Robert
  231. 2015-11-11 18:46 - 2015-07-01 06:59 - 00002134 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon.lnk
  232. 2015-11-11 18:46 - 2014-09-16 04:19 - 00001179 _____ C:\Users\Public\Desktop\HiDef Media Player.lnk
  233. 2015-11-11 18:46 - 2013-07-10 04:05 - 00000382 _____ C:\Users\Public\Desktop\Complete Installation of Lexmark Z2300 Series.LNK
  234. 2015-11-11 18:46 - 2013-06-29 15:18 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
  235. 2015-11-11 18:46 - 2013-06-29 15:18 - 00002022 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
  236. 2015-11-11 18:46 - 2013-06-29 15:13 - 00000080 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
  237. 2015-11-11 18:46 - 2013-06-28 21:48 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
  238. 2015-11-11 18:46 - 2013-06-28 21:48 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
  239. 2015-11-11 18:46 - 2013-06-28 19:41 - 00002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
  240. 2015-11-11 18:46 - 2009-07-13 23:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
  241. 2015-11-11 18:46 - 2009-07-13 23:57 - 00001340 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
  242. 2015-11-11 18:46 - 2009-07-13 23:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
  243. 2015-11-11 18:46 - 2009-07-13 23:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
  244. 2015-11-11 18:46 - 2009-07-13 23:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
  245. 2015-11-11 18:45 - 2015-01-10 15:05 - 00000000 ____D C:\Program Files (x86)\speed browser
  246. 2015-11-11 18:45 - 2014-12-03 06:44 - 00000000 ____D C:\ProgramData\Kromtech
  247. 2015-11-11 18:45 - 2014-10-30 06:02 - 00000000 ____D C:\Program Files (x86)\XTRM Group
  248. 2015-11-11 18:45 - 2014-08-06 06:07 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Store
  249. 2015-11-11 18:45 - 2009-07-14 00:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
  250. 2015-11-11 18:45 - 2009-07-13 23:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
  251. 2015-11-11 18:44 - 2015-07-09 09:01 - 00000000 ____D C:\Program Files (x86)\Harebrained Major
  252. 2015-11-11 18:44 - 2015-02-26 05:54 - 00000000 ____D C:\Program Files (x86)\bf6df6f9-a7e9-4aab-a042-b57fe4b10fdb
  253. 2015-11-11 18:44 - 2015-02-06 06:18 - 00000000 ____D C:\Users\Robert\AppData\Local\af80d166-99c2-4623-8a67-a42238fc5362
  254. 2015-11-11 18:44 - 2015-02-06 05:45 - 00000000 ____D C:\Program Files (x86)\81ccec0a-ced9-46d6-b2d2-674444106ad5
  255. 2015-11-11 18:44 - 2015-02-06 05:44 - 00000000 ____D C:\Program Files (x86)\2a15b561-6769-4fac-8cee-f830307686c2
  256. 2015-11-11 18:44 - 2015-02-01 18:58 - 00000000 ____D C:\ProgramData\e3c7b25600006bfd
  257. 2015-11-11 18:44 - 2015-02-01 18:04 - 00000000 ____D C:\Program Files (x86)\4f692e28-1758-4406-9a7d-7a464148e5bf
  258. 2015-11-11 18:44 - 2015-02-01 18:02 - 00000000 ____D C:\ProgramData\9525e814919641298ce6b712c8d229fa
  259. 2015-11-11 18:44 - 2015-02-01 18:02 - 00000000 ____D C:\ProgramData\{2d281167-4106-0e2c-2d28-81167410459d}
  260. 2015-11-11 18:44 - 2015-01-13 05:37 - 00000000 ____D C:\ProgramData\Browser
  261. 2015-11-11 18:44 - 2015-01-09 05:37 - 00000000 ____D C:\Program Files (x86)\globalUpdate
  262. 2015-11-11 18:44 - 2014-10-27 22:49 - 00000000 ____D C:\ProgramData\7740e5e2-3946-433b-8ea8-e4290a5c4bc8
  263. 2015-11-11 18:44 - 2014-10-16 06:20 - 00000000 ____D C:\ProgramData\APN
  264. 2015-11-11 18:44 - 2014-08-20 03:59 - 00000000 ____D C:\Users\Robert\AppData\Local\com
  265. 2015-11-11 18:44 - 2014-08-06 06:04 - 00000000 ____D C:\Program Files (x86)\Software
  266. 2015-11-11 18:44 - 2014-08-06 05:57 - 00000000 ____D C:\Users\Robert\AppData\LocalLow\Company
  267. 2015-11-11 18:44 - 2013-06-29 15:18 - 00000000 ____D C:\Program Files (x86)\Adobe
  268. 2015-11-11 17:19 - 2015-06-22 00:06 - 00003434 _____ C:\Windows\System32\Tasks\Iflopebe
  269. 2015-11-11 17:14 - 2015-07-09 05:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safer Technologies
  270. 2015-11-11 17:13 - 2015-07-09 05:09 - 00002856 _____ C:\Windows\SysWOW64\LavasoftTcpServiceOff.ini
  271. 2015-11-11 17:13 - 2015-07-09 05:09 - 00002856 _____ C:\Windows\system32\LavasoftTcpServiceOff.ini
  272. 2015-11-11 17:13 - 2015-04-05 00:56 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
  273.  
  274. ==================== Files in the root of some directories =======
  275.  
  276. 2015-03-31 03:14 - 2015-03-31 03:14 - 0005655 _____ () C:\Users\Robert\AppData\Roaming\1Lpsl7rkbpk08XPM
  277. 2015-03-02 19:46 - 2015-04-24 04:34 - 0000020 _____ () C:\Users\Robert\AppData\Roaming\appdataFr3.bin
  278. 2014-03-16 01:26 - 2014-08-20 04:09 - 0001212 _____ () C:\Users\Robert\AppData\Roaming\aps.scan.quick.results
  279. 2014-03-16 01:29 - 2014-08-20 04:09 - 0002954 _____ () C:\Users\Robert\AppData\Roaming\aps.scan.results
  280. 2014-03-16 01:26 - 2014-08-20 04:09 - 0000322 _____ () C:\Users\Robert\AppData\Roaming\aps.uninstall.scan.results
  281. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\CFKQE
  282. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\DCZGF
  283. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\DTWOOQ
  284. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\KRRXKYFY
  285. 2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Robert\AppData\Roaming\LKC
  286. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\LLUMUYCI
  287. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\MQSKHE
  288. 2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Robert\AppData\Roaming\OD
  289. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\QJJRX
  290. 2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Robert\AppData\Roaming\UVOX
  291. 2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Robert\AppData\Roaming\VR
  292. 2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Robert\AppData\Roaming\WDVFO
  293. 2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Robert\AppData\Roaming\WNXEIY
  294. 2014-09-01 03:18 - 2014-09-01 03:18 - 0002086 _____ () C:\Users\Robert\AppData\Roaming\YX
  295. 2014-09-01 03:18 - 2014-09-01 03:18 - 0001248 _____ () C:\Users\Robert\AppData\Roaming\ZSGVJ
  296. 2014-12-03 17:56 - 2014-12-03 17:56 - 0000064 _____ () C:\Users\Robert\AppData\Local\0bf183407680dbfd8267792e5a3a7ddb
  297. 2015-04-24 04:44 - 2015-04-24 04:44 - 0000000 _____ () C:\Users\Robert\AppData\Local\{343A8CA3-9AF6-4DA2-865B-7C1A33D1BF03}
  298. 2015-03-13 05:09 - 2015-03-13 05:09 - 0000000 _____ () C:\Users\Robert\AppData\Local\{641D8126-9ECB-4176-B62C-2C2FB742A8E9}
  299. 2015-11-11 17:19 - 2015-11-11 17:19 - 0000000 _____ () C:\Users\Robert\AppData\Local\{7CD2C8D3-BF8B-41D9-A233-46C0B7545228}
  300. 2015-02-03 17:11 - 2015-02-03 17:11 - 0000000 _____ () C:\Users\Robert\AppData\Local\{7F5A4415-468F-4F3D-8690-457DD4A1B4DE}
  301. 2014-08-10 10:05 - 2014-08-10 10:05 - 0000252 _____ () C:\ProgramData\FastPics.log
  302. 2014-03-16 11:02 - 2014-03-16 11:02 - 0000000 _____ () C:\ProgramData\spds90.txt
  303.  
  304. Some files in TEMP:
  305. ====================
  306. C:\Users\Robert\AppData\Local\Temp\DRHelper_uninstallComplete.exe
  307.  
  308.  
  309. ==================== Bamital & volsnap =================
  310.  
  311. (There is no automatic fix for files that do not pass verification.)
  312.  
  313. C:\Windows\system32\winlogon.exe => File is digitally signed
  314. C:\Windows\system32\wininit.exe => File is digitally signed
  315. C:\Windows\SysWOW64\wininit.exe => File is digitally signed
  316. C:\Windows\explorer.exe => File is digitally signed
  317. C:\Windows\SysWOW64\explorer.exe => File is digitally signed
  318. C:\Windows\system32\svchost.exe => File is digitally signed
  319. C:\Windows\SysWOW64\svchost.exe => File is digitally signed
  320. C:\Windows\system32\services.exe => File is digitally signed
  321. C:\Windows\system32\User32.dll => File is digitally signed
  322. C:\Windows\SysWOW64\User32.dll => File is digitally signed
  323. C:\Windows\system32\userinit.exe => File is digitally signed
  324. C:\Windows\SysWOW64\userinit.exe => File is digitally signed
  325. C:\Windows\system32\rpcss.dll => File is digitally signed
  326. C:\Windows\system32\dnsapi.dll => File is digitally signed
  327. C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
  328. C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
  329.  
  330.  
  331. LastRegBack: 2015-01-27 06:58
  332.  
  333. ==================== End of FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement