Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.02.2018 02
- Ran by Dray (administrator) on DRAY-PC (10-02-2018 13:03:08)
- Running from C:\Users\Dray\Desktop
- Loaded Profiles: Dray & Guest (Available Profiles: Dray & Guest)
- Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
- Internet Explorer Version 11 (Default browser: Chrome)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
- (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
- (Microsoft Corporation) C:\Windows\System32\wlanext.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
- (Microsoft Corporation) C:\Windows\System32\wlanext.exe
- (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
- (Alienware) C:\Program Files\Alienware\Command Center\AlienFXWindowsService.exe
- (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
- (AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
- (Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
- (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
- (Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\msi\ODD Monitor\ODD_Monitor.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
- (The OpenVPN Project) C:\Program Files\OpenVPN\bin\openvpnserv.exe
- () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
- (Realtek) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe
- (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe
- () C:\Windows\runSW.exe
- (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
- (Realtek) C:\Windows\SwUSB.exe
- () C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
- (Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
- (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
- (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
- (Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
- (Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
- (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
- (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
- (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
- (AVAST Software) C:\Program Files (x86)\Avast Driver Updater\Avast Driver Updater.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
- (Intel Corporation) C:\Windows\System32\igfxEM.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
- (Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
- (Microsoft Corporation) C:\Windows\System32\dllhost.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
- (Spotify Ltd) C:\Users\Dray\AppData\Roaming\Spotify\Spotify.exe
- (Spotify Ltd) C:\Users\Dray\AppData\Roaming\Spotify\SpotifyWebHelper.exe
- (AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
- (Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSATray.exe
- (Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
- (Spotify Ltd) C:\Users\Dray\AppData\Roaming\Spotify\Spotify.exe
- (Spotify Ltd) C:\Users\Dray\AppData\Roaming\Spotify\Spotify.exe
- (Spotify Ltd) C:\Users\Dray\AppData\Roaming\Spotify\Spotify.exe
- (Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
- (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
- (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
- (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- ==================== Registry (Whitelisted) ===========================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- "Path" (%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files (x86)\Skype\Phone;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\OpenVPN\bin -> %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files (x86)\Skype\Phone;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\OpenVPN\bin) <==== Repaired successfully
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6412904 2011-11-03] (Realtek Semiconductor)
- HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1157224 2011-10-20] (Realtek Semiconductor)
- HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12656 2012-06-18] (Alienware)
- HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2018-01-02] (AVAST Software)
- HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297272 2017-12-05] (Apple Inc.)
- HKLM-x32\...\Run: [Alienware Survey] => c:\Program Files (x86)\Alienware Customer Surveys\AlienSurvey.exe [7338256 2012-06-19] (Alienware, Inc.)
- HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
- HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [131360 2018-01-17] (Intel)
- HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
- HKU\S-1-5-21-3100552373-3553783535-2033769964-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7964080 2018-02-04] (SUPERAntiSpyware)
- HKU\S-1-5-21-3100552373-3553783535-2033769964-1000\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [636032 2017-06-20] ()
- HKU\S-1-5-21-3100552373-3553783535-2033769964-1000\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 6\CyberGhost.exe [1248848 2017-08-31] (CyberGhost S.A.)
- HKU\S-1-5-21-3100552373-3553783535-2033769964-1000\...\Run: [Spotify] => C:\Users\Dray\AppData\Roaming\Spotify\Spotify.exe [21091728 2018-02-09] (Spotify Ltd)
- HKU\S-1-5-21-3100552373-3553783535-2033769964-1000\...\Run: [Spotify Web Helper] => C:\Users\Dray\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-02-09] (Spotify Ltd)
- HKU\S-1-5-21-3100552373-3553783535-2033769964-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-20] (Microsoft Corporation)
- HKU\S-1-5-21-3100552373-3553783535-2033769964-501\...\Run: [OPENVPN-GUI] => C:\Program Files\OpenVPN\bin\openvpn-gui.exe [636032 2017-06-20] ()
- AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [182296 2017-11-09] (NVIDIA Corporation)
- AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [182296 2017-11-09] (NVIDIA Corporation)
- AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [159736 2017-11-09] (NVIDIA Corporation)
- Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2018-02-07]
- ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software)
- GroupPolicy: Restriction <==== ATTENTION
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Tcpip\Parameters: [DhcpNameServer] 147.205.85.229 147.205.85.225 147.205.85.235
- Tcpip\..\Interfaces\{B964034D-2389-44C8-AF6F-B477432D909D}: [DhcpNameServer] 147.205.85.229 147.205.85.225 147.205.85.235
- Tcpip\..\Interfaces\{E36A7310-14A3-44C9-8F6E-B606AC5BCD46}: [DhcpNameServer] 147.205.85.229 147.205.85.225 147.205.85.235
- Tcpip\..\Interfaces\{E3DDB075-34D3-443C-A979-0472D06FF475}: [NameServer] 8.8.8.8,8.8.4.4
- Tcpip\..\Interfaces\{E3DDB075-34D3-443C-A979-0472D06FF475}: [DhcpNameServer] 147.205.85.229 147.205.85.225 147.205.85.235
- Internet Explorer:
- ==================
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
- HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
- HKU\S-1-5-21-3100552373-3553783535-2033769964-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
- SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
- SearchScopes: HKU\S-1-5-21-3100552373-3553783535-2033769964-1000 -> DefaultScope {77877866-C439-4C9D-9887-56DB49CCFD8D} URL =
- BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-03-13] (Microsoft Corporation)
- BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-13] (AVAST Software)
- BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-03-13] (Microsoft Corporation)
- BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-17] (Microsoft Corporation)
- BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-13] (AVAST Software)
- BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-03-13] (Microsoft Corporation)
- Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-08-26] (Microsoft Corporation)
- FireFox:
- ========
- FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
- FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
- FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
- FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
- FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-08-26] (Microsoft Corporation)
- FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-10-27] (NVIDIA Corporation)
- FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-10-27] (NVIDIA Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
- FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
- Chrome:
- =======
- CHR DefaultProfile: Profile 1
- CHR Profile: C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-02-10]
- CHR Extension: (Slides) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-18]
- CHR Extension: (Docs) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-18]
- CHR Extension: (Google Drive) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
- CHR Extension: (SnappySnippet) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blfngdefapoapkcdibbdkigpeaffgcil [2018-01-18]
- CHR Extension: (YouTube) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
- CHR Extension: (Adblock Plus) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-02-04]
- CHR Extension: (Google Search) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
- CHR Extension: (Sheets) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-18]
- CHR Extension: (Betternet Unlimited Free VPN Proxy) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gjknjjomckknofjidppipffbpoekiipm [2018-02-08]
- CHR Extension: (Avast Online Security) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-10-09]
- CHR Extension: (Reddit Enhancement Suite) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2018-01-21]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-02]
- CHR Extension: (Gmail) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-19]
- CHR Extension: (Chrome Media Router) - C:\Users\Dray\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-08]
- CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
- CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx <not found>
- CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
- ==================== Services (Whitelisted) ====================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-18] (SUPERAntiSpyware.com)
- R2 AlienFXWindowsService; C:\Program Files\Alienware\Command Center\AlienFXWindowsService.exe [13168 2012-06-18] (Alienware)
- R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-11-27] (Apple Inc.)
- R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7538536 2018-01-02] (AVAST Software)
- R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2018-01-02] (AVAST Software)
- S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2018-01-07] ()
- S4 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [445976 2016-08-02] (BlueStack Systems, Inc.)
- S4 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [425496 2016-08-02] (BlueStack Systems, Inc.)
- S4 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [462360 2016-08-02] (BlueStack Systems, Inc.)
- S4 CG6Service; C:\Program Files\CyberGhost 6\CyberGhost.Service.exe [232528 2017-08-31] (CyberGhost S.A.)
- R2 CleanupPSvc; C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe [7650600 2018-02-02] (AVAST Software)
- S4 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
- R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2572024 2016-03-10] (Dell Inc.)
- R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [202488 2016-03-10] (Dell Inc.)
- R2 DellDigitalDelivery; c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [166912 2012-04-10] (Dell Products, LP.) [File not signed]
- R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [22304 2018-01-17] (Intel)
- S3 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [886032 2018-01-11] ()
- R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [320472 2018-01-02] (Intel Corporation)
- S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel Corporation)
- R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-06] (Intel Corporation)
- R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
- R2 MSI_ODD_Service; c:\Program Files (x86)\msi\ODD Monitor\ODD_Monitor.exe [76800 2011-10-04] (Micro-Star Int'l Co., Ltd.) [File not signed]
- R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-10] (NVIDIA Corporation)
- S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-10] (NVIDIA Corporation)
- S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv2.exe [15872 2016-11-25] ( ) [File not signed]
- R2 OpenVPNServiceInteractive; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72832 2017-06-20] (The OpenVPN Project)
- S3 OpenVPNServiceLegacy; C:\Program Files\OpenVPN\bin\openvpnserv.exe [72832 2017-06-20] (The OpenVPN Project)
- S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2169696 2017-07-05] (Electronic Arts)
- S4 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3149664 2017-07-05] (Electronic Arts)
- S4 R-Wipe and Clean Task Service; C:\Program Files (x86)\R-Wipe&Clean\RwcTaskService.exe [117920 2017-06-16] ()
- R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-24] ()
- R2 RealtekWlanU; C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe [48856 2014-10-09] (Realtek)
- S2 RTLDHCPService; C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RTLDHCP.exe [262360 2014-10-09] (Realtek)
- R2 RunSwUSB; C:\Windows\runSW.exe [44760 2017-06-30] ()
- R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [133376 2016-09-28] (Razer Inc.)
- R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [31928 2016-04-22] (Dell Inc.)
- R2 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe [182544 2018-01-11] ()
- S3 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe [886032 2018-01-11] ()
- S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
- R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [73728 2011-11-29] (Atheros) [File not signed]
- S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
- R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
- S2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
- ===================== Drivers (Whitelisted) ======================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
- R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [185096 2018-01-02] (AVAST Software)
- R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2018-01-02] (AVAST Software)
- R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2018-01-02] (AVAST Software)
- R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2018-01-02] (AVAST Software)
- R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2018-01-02] (AVAST Software)
- R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [149344 2018-01-02] (AVAST Software)
- S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46976 2018-01-02] (AVAST Software)
- R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41832 2017-09-02] (AVAST Software)
- R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146648 2018-01-10] (AVAST Software)
- R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110336 2018-01-02] (AVAST Software)
- R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84384 2018-01-02] (AVAST Software)
- R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1025176 2018-01-02] (AVAST Software)
- R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [457896 2018-01-10] (AVAST Software)
- R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [204456 2018-01-02] (AVAST Software)
- R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [358672 2018-01-02] (AVAST Software)
- S3 Atheros Traffic Shaping; C:\Program Files (x86)\Dell Wireless\AthrTS6_x64.sys [37488 2011-11-30] ()
- S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-08-02] (BlueStack Systems)
- S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [307768 2016-07-28] (Bluestack System Inc. )
- R3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [32464 2015-09-11] (Dell Computer Corporation)
- R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation)
- R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-02-10] (Malwarebytes)
- R3 NTIOLib_X64; C:\Program Files (x86)\msi\ODD Monitor\NTIOLib_X64.sys [14136 2010-01-18] (MSI)
- S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-10] (NVIDIA Corporation)
- R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50624 2017-10-10] (NVIDIA Corporation)
- R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57976 2017-05-03] (NVIDIA Corporation)
- R3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [5413896 2016-08-12] (Realtek Semiconductor Corporation )
- R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [100352 2011-09-15] (Renesas Electronics Corporation)
- R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [216064 2011-09-15] (Renesas Electronics Corporation)
- R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [50392 2015-08-13] (Razer Inc)
- R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-09-16] (Razer, Inc.)
- R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [130880 2015-12-14] (Razer, Inc.)
- R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
- R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
- S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [41512 2018-01-11] ()
- S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [25608 2018-02-10] (SlimWare Utilities, Inc.)
- S3 catchme; \??\C:\ComboFix\catchme.sys [X]
- S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2018-02-10 13:03 - 2018-02-10 13:03 - 000026688 _____ C:\Users\Dray\Desktop\FRST.txt
- 2018-02-10 13:02 - 2018-02-10 13:03 - 000000000 ____D C:\FRST
- 2018-02-10 13:02 - 2018-02-10 13:02 - 002404864 _____ (Farbar) C:\Users\Dray\Downloads\FRST64.exe
- 2018-02-10 13:02 - 2018-02-10 13:02 - 002404864 _____ (Farbar) C:\Users\Dray\Desktop\FRST64.exe
- 2018-02-10 12:17 - 2018-02-10 12:17 - 000000000 ____D C:\ProgramData\SWCUTemp
- 2018-02-09 22:52 - 2018-02-09 22:55 - 000001708 _____ C:\Users\Dray\Desktop\Rkill.txt
- 2018-02-09 22:50 - 2018-02-09 22:51 - 000085460 _____ C:\Windows\ntbtlog.txt
- 2018-02-09 22:45 - 2018-02-09 22:45 - 001792640 _____ (Bleeping Computer, LLC) C:\Users\Dray\Downloads\rkill.exe
- 2018-02-09 22:42 - 2018-02-09 22:42 - 008222496 _____ (Malwarebytes) C:\Users\Dray\Downloads\adwcleaner_7.0.8.0.exe
- 2018-02-09 22:13 - 2018-02-09 22:13 - 000039707 _____ C:\ComboFix.txt
- 2018-02-09 21:40 - 2018-02-09 22:13 - 000000000 ____D C:\ComboFix
- 2018-02-09 21:40 - 2018-02-09 21:40 - 005659876 _____ (Swearware) C:\Users\Dray\Downloads\ComboFix (2).exe
- 2018-02-09 21:38 - 2018-02-09 21:38 - 005659876 _____ (Swearware) C:\Users\Dray\Downloads\ComboFix (1).exe
- 2018-02-09 19:19 - 2018-02-09 19:46 - 000000000 ____D C:\Users\Dray\Desktop\HCF
- 2018-02-09 18:23 - 2018-02-09 18:24 - 025710952 _____ C:\Users\Dray\Downloads\0001-Realtek_USB_Windows_Driver_1030.17.1101.2016 (1).zip
- 2018-02-09 17:53 - 2018-02-09 17:54 - 048065407 _____ C:\Users\Dray\Downloads\Vestmc HCF plugins.rar
- 2018-02-09 17:42 - 2018-02-09 17:43 - 029049285 _____ C:\Users\Dray\Downloads\HCF tutorial download Vestmc 1.zip
- 2018-02-07 17:03 - 2018-02-07 17:03 - 000003718 _____ C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
- 2018-02-07 16:57 - 2018-02-07 16:57 - 000442488 _____ C:\Windows\system32\FNTCACHE.DAT
- 2018-02-07 16:48 - 2018-02-07 17:12 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant
- 2018-02-07 16:48 - 2018-02-07 16:51 - 000003484 _____ C:\Windows\System32\Tasks\USER_ESRV_SVC_QUEENCREEK
- 2018-02-07 16:48 - 2018-02-07 16:48 - 000003616 _____ C:\Windows\System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132
- 2018-02-07 16:48 - 2018-02-07 16:48 - 000003370 _____ C:\Windows\System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon
- 2018-02-07 16:48 - 2018-02-07 16:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver and Support Assistant
- 2018-02-07 16:47 - 2018-01-11 01:25 - 000041512 _____ C:\Windows\system32\Drivers\semav6msr64.sys
- 2018-02-07 16:46 - 2018-02-07 16:46 - 013872096 _____ (Intel) C:\Users\Dray\Downloads\Intel Driver and Support Assistant Installer.exe
- 2018-02-07 16:43 - 2018-02-10 12:56 - 000025608 _____ (SlimWare Utilities, Inc.) C:\Windows\system32\Drivers\SWDUMon.sys
- 2018-02-07 16:43 - 2018-02-10 12:56 - 000002904 _____ C:\Windows\System32\Tasks\Avast Driver Updater Startup
- 2018-02-07 16:43 - 2018-02-10 12:56 - 000000480 _____ C:\Windows\Tasks\Avast Driver Updater Startup.job
- 2018-02-07 16:43 - 2018-02-07 16:43 - 000002501 _____ C:\Users\Public\Desktop\Avast Driver Updater.lnk
- 2018-02-07 16:43 - 2018-02-07 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Driver Updater
- 2018-02-07 16:43 - 2018-02-07 16:43 - 000000000 ____D C:\Program Files (x86)\Avast Driver Updater
- 2018-02-07 14:28 - 2018-02-07 14:28 - 000001749 _____ C:\Users\Public\Desktop\iTunes.lnk
- 2018-02-07 14:28 - 2018-02-07 14:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
- 2018-02-07 14:28 - 2018-02-07 14:28 - 000000000 ____D C:\Program Files\iPod
- 2018-02-07 14:27 - 2018-02-07 14:28 - 000000000 ____D C:\Program Files\iTunes
- 2018-02-07 14:27 - 2018-02-07 14:27 - 000003936 _____ C:\Windows\System32\Tasks\Avast TUNEUP Update
- 2018-02-07 14:27 - 2018-02-07 14:27 - 000001221 _____ C:\Users\Public\Desktop\Avast Cleanup Premium.lnk
- 2018-02-07 14:27 - 2018-02-07 14:27 - 000000000 ____D C:\Users\Dray\AppData\Roaming\Avast Tuneup
- 2018-02-07 14:27 - 2018-02-07 14:27 - 000000000 ____D C:\Program Files (x86)\AVAST Software
- 2018-02-07 14:25 - 2018-02-07 14:25 - 000000000 ____D C:\Windows\System32\Tasks\Apple
- 2018-02-07 14:25 - 2018-02-07 14:25 - 000000000 ____D C:\Program Files (x86)\Apple Software Update
- 2018-02-06 18:36 - 2018-02-06 18:36 - 000059042 _____ C:\Users\Dray\Downloads\twitter.zip
- 2018-02-06 18:27 - 2018-02-06 18:27 - 000727254 _____ C:\Users\Dray\Downloads\instagram.zip
- 2018-02-04 16:21 - 2018-02-07 16:43 - 000000000 ____D C:\Users\Dray\AppData\Local\AVAST Software
- 2018-02-04 14:52 - 2018-02-03 10:14 - 000002271 _____ C:\Users\Dray\Downloads\blacklist.txt
- 2018-02-04 14:28 - 2018-02-04 14:51 - 000000000 ____D C:\Users\Dray\Desktop\WC LEAK
- 2018-02-04 14:25 - 2018-02-04 14:32 - 000000000 ____D C:\Users\Dray\AppData\Roaming\Cyberduck
- 2018-02-04 14:25 - 2018-02-04 14:25 - 000000000 ____D C:\Users\Dray\AppData\Roaming\iterate_GmbH
- 2018-02-04 14:17 - 2018-02-04 14:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyberduck
- 2018-02-04 14:17 - 2018-02-04 14:17 - 000000000 ____D C:\Program Files (x86)\Cyberduck
- 2018-02-04 14:12 - 2018-02-04 14:13 - 047771632 _____ (iterate GmbH) C:\Users\Dray\Downloads\Cyberduck-Installer-6.3.5.27408.exe
- 2018-02-01 07:25 - 2018-02-01 07:27 - 000000000 ____D C:\Users\Dray\Desktop\twitter
- 2018-01-25 18:13 - 2018-01-25 18:13 - 000094526 _____ C:\Users\Dray\Downloads\CustomDrops.jar
- 2018-01-25 17:59 - 2018-01-25 18:00 - 000091389 _____ C:\Users\Dray\Downloads\BannerBoard 1.9.8.2.jar
- 2018-01-25 17:58 - 2018-01-25 17:58 - 002546048 _____ C:\Users\Dray\Downloads\LeaderHeads-CRACKED.jar
- 2018-01-25 17:54 - 2018-01-25 17:54 - 001680788 _____ C:\Users\Dray\Downloads\Featherboard (1).zip
- 2018-01-25 17:35 - 2018-01-25 17:35 - 019758011 _____ C:\Users\Dray\Downloads\spigot-1.8.8-R0.1-SNAPSHOT-latest (1).jar
- 2018-01-25 17:32 - 2018-01-25 17:32 - 000954208 _____ C:\Users\Dray\Downloads\Factions-CRACKED.jar
- 2018-01-25 17:32 - 2018-01-25 17:32 - 000346872 _____ C:\Users\Dray\Downloads\ShopGUIPlus-1.15.0-SNAPSHOT-CRACKED.jar
- 2018-01-25 17:29 - 2018-01-25 17:55 - 000000000 ____D C:\Users\Dray\Desktop\plugins
- 2018-01-25 17:28 - 2018-02-09 19:10 - 000000000 ____D C:\Users\Dray\Desktop\New folder (2)
- 2018-01-25 17:27 - 2018-02-04 14:52 - 000000000 ____D C:\Users\Dray\Desktop\Factions
- 2018-01-25 17:26 - 2018-01-25 17:27 - 165327738 _____ C:\Users\Dray\Downloads\HyvastLeak.zip
- 2018-01-25 17:26 - 2018-01-25 17:26 - 070754672 _____ C:\Users\Dray\Downloads\Factions.rar
- 2018-01-25 16:11 - 2018-01-25 16:11 - 076208433 _____ C:\Users\Dray\Downloads\factions (2.6).rar
- 2018-01-25 15:55 - 2018-01-25 15:56 - 089933502 _____ C:\Users\Dray\Downloads\MineDriod OP Prison by Minecraft BAT.7z
- 2018-01-25 15:48 - 2018-01-25 15:48 - 305878614 _____ C:\Users\Dray\Downloads\OP PRISON 1.9 - 1.12 By DiehardDavid.rar
- 2018-01-25 00:10 - 2018-01-25 00:10 - 000802880 _____ C:\Users\Dray\Downloads\MadPixels.zip
- 2018-01-24 23:38 - 2018-01-24 23:39 - 002311528 _____ C:\Users\Dray\Downloads\OptiFine_1.12.2_HD_U_C8 (1).jar
- 2018-01-23 17:55 - 2018-01-23 17:56 - 000000000 ____D C:\Users\Dray\Desktop\phish
- 2018-01-23 17:54 - 2018-01-23 17:54 - 001372160 _____ C:\Users\Dray\Downloads\pbmkr.exe
- 2018-01-23 17:20 - 2018-01-23 17:20 - 000004754 _____ C:\Users\Dray\Downloads\SMS-BOMBER-master.zip
- 2018-01-23 17:19 - 2018-01-23 17:19 - 000614806 _____ C:\Users\Dray\Downloads\JohnsSMSBomber03.jar
- 2018-01-23 16:30 - 2018-01-23 16:30 - 000030742 _____ C:\Users\Dray\Downloads\Havoc.rar
- 2018-01-23 16:30 - 2015-03-19 19:20 - 000143360 _____ C:\Users\Dray\Desktop\Havoc.exe
- 2018-01-23 16:15 - 2018-01-23 16:15 - 000011140 _____ C:\Users\Dray\Downloads\Sms bomber.rar
- 2018-01-23 16:15 - 2015-03-16 12:49 - 000039424 _____ C:\Users\Dray\Desktop\Sms bomber.exe
- 2018-01-19 21:07 - 2018-01-19 21:07 - 078844149 _____ C:\Users\Dray\Desktop\Prison.rar
- 2018-01-19 21:01 - 2017-09-30 10:37 - 000000000 ____D C:\Users\Dray\Desktop\Prison
- 2018-01-19 20:57 - 2018-01-19 20:57 - 019758011 _____ C:\Users\Dray\Downloads\spigot-1.8.8-R0.1-SNAPSHOT-latest.jar
- 2018-01-19 20:47 - 2018-01-19 20:47 - 051084812 _____ C:\Users\Dray\Desktop\Prison_11-5-2017.zip
- 2018-01-19 20:46 - 2018-01-19 20:47 - 051084812 _____ C:\Users\Dray\Downloads\Prison_11-5-2017.zip
- 2018-01-19 20:35 - 2018-01-19 20:35 - 000552962 _____ C:\Users\Dray\Downloads\Notorious.jar
- 2018-01-19 20:27 - 2018-01-19 20:27 - 001035985 _____ C:\Users\Dray\Downloads\Essentials.zip
- 2018-01-19 19:37 - 2018-01-19 19:37 - 000034365 _____ C:\Users\Dray\Downloads\MangoFix.jar
- 2018-01-19 19:34 - 2018-01-19 19:34 - 000317602 _____ C:\Users\Dray\Downloads\Vault.jar
- 2018-01-19 19:28 - 2018-01-19 19:28 - 020610577 _____ C:\Users\Dray\Downloads\spigot-1.7.10-SNAPSHOT-b1657 (2).jar
- 2018-01-19 19:27 - 2018-01-19 19:27 - 000391481 _____ C:\Users\Dray\Downloads\Mango.jar
- 2018-01-19 19:14 - 2018-01-19 19:14 - 021700569 _____ C:\Users\Dray\Downloads\paperspigot.jar
- 2018-01-19 19:14 - 2018-01-19 19:14 - 005162795 _____ C:\Users\Dray\Downloads\FaithfulMC Core.zip
- 2018-01-19 18:57 - 2018-01-19 18:57 - 008764679 _____ C:\Users\Dray\Desktop\jd-gui-1.4.0 (1).jar
- 2018-01-19 18:57 - 2018-01-19 18:57 - 007928105 _____ C:\Users\Dray\Downloads\jd-gui-windows-1.4.0.zip
- 2018-01-19 18:56 - 2018-01-19 18:57 - 008764679 _____ C:\Users\Dray\Downloads\jd-gui-1.4.0 (1).jar
- 2018-01-19 18:47 - 2018-01-19 18:51 - 035548252 _____ C:\Users\Dray\Downloads\PracticeVultex.rar
- 2018-01-19 13:51 - 2018-01-24 10:04 - 000000000 ____D C:\Users\Dray\Desktop\instagram
- 2018-01-18 16:09 - 2018-01-18 16:09 - 000547648 _____ C:\Users\Dray\Downloads\SantaGo Free Website Template - Free-CSS.com.zip
- 2018-01-18 16:09 - 2014-12-17 02:05 - 000000000 ____D C:\Users\Dray\Desktop\SantaGo-master
- 2018-01-17 00:13 - 2018-01-17 00:14 - 050354418 _____ C:\Users\Dray\Downloads\LuigicalsOPPrison-4.0.zip
- 2018-01-16 23:41 - 2018-01-16 23:35 - 430804722 _____ C:\Users\Dray\Desktop\Servidor Configurado Prision OP By Asturete.zip
- 2018-01-16 23:41 - 2018-01-16 23:17 - 332412823 _____ C:\Users\Dray\Desktop\PREMADE HUB.zip
- 2018-01-16 23:35 - 2018-01-16 23:35 - 430804722 _____ C:\Users\Dray\Downloads\Servidor Configurado Prision OP By Asturete.zip
- 2018-01-16 23:14 - 2018-01-16 23:17 - 332412823 _____ C:\Users\Dray\Downloads\PREMADE HUB.zip
- 2018-01-14 23:40 - 2018-01-14 23:40 - 000000000 ____D C:\Users\Dray\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
- 2018-01-14 15:41 - 2018-01-14 15:41 - 001884290 _____ C:\Users\Dray\Downloads\OptiFine_1.8.9_HD_U_I3.jar
- 2018-01-14 15:37 - 2018-01-14 15:37 - 003927093 _____ C:\Users\Dray\Downloads\forge-1.8.9-11.15.1.1722-installer-win.exe
- 2018-01-14 15:35 - 2018-01-14 15:35 - 003670383 _____ C:\Users\Dray\Downloads\InFjd.zip
- 2018-01-14 15:32 - 2018-01-14 15:33 - 006410420 _____ C:\Users\Dray\Downloads\oCd+1.11.2 modified by peterjiangTW.zip
- 2018-01-13 21:28 - 2018-01-19 12:31 - 000000000 ____D C:\Users\Dray\Desktop\Vids
- 2018-01-13 19:44 - 2018-01-13 19:44 - 002311528 _____ C:\Users\Dray\Downloads\OptiFine_1.12.2_HD_U_C8.jar
- 2018-01-12 03:21 - 2018-02-10 12:17 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
- 2018-01-11 21:54 - 2018-01-11 21:54 - 000001993 _____ C:\Users\Dray\Downloads\temp_vpn.ovpn
- 2018-01-11 17:28 - 2018-01-11 17:28 - 000000000 ____D C:\Users\Dray\Documents\My Games
- 2018-01-11 17:02 - 2018-01-11 17:02 - 000000222 _____ C:\Users\Dray\Desktop\Rocket League.url
- 2018-01-11 16:52 - 2018-01-11 16:52 - 000000000 ____D C:\Users\Dray\AppData\Local\TslGame
- 2018-01-11 16:07 - 2018-01-11 16:07 - 000000222 _____ C:\Users\Dray\Desktop\PLAYERUNKNOWN'S BATTLEGROUNDS.url
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2018-02-10 12:58 - 2015-07-30 11:02 - 000000000 ____D C:\ProgramData\NVIDIA
- 2018-02-10 12:56 - 2016-04-16 18:09 - 000000000 ____D C:\Users\Dray\AppData\Roaming\Spotify
- 2018-02-10 12:56 - 2015-07-22 08:03 - 000000000 __SHD C:\Users\Dray\IntelGraphicsProfiles
- 2018-02-10 12:34 - 2009-07-13 23:45 - 000021296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2018-02-10 12:34 - 2009-07-13 23:45 - 000021296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2018-02-10 12:15 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
- 2018-02-09 23:16 - 2015-07-19 18:46 - 000000000 ____D C:\Users\Dray\AppData\Local\Apps\2.0
- 2018-02-09 22:45 - 2015-08-11 16:10 - 000000000 ____D C:\AdwCleaner
- 2018-02-09 22:42 - 2015-09-15 23:18 - 000000000 ____D C:\Program Files\Java
- 2018-02-09 22:18 - 2016-04-16 18:09 - 000000000 ____D C:\Users\Dray\AppData\Local\Spotify
- 2018-02-09 21:58 - 2009-07-13 21:34 - 000000215 _____ C:\Windows\system.ini
- 2018-02-09 21:48 - 2015-09-06 12:18 - 000000000 ____D C:\Users\Dray\AppData\Local\CrashDumps
- 2018-02-09 21:40 - 2015-09-03 17:00 - 000000000 ____D C:\Qoobox
- 2018-02-09 21:39 - 2017-07-06 16:21 - 005659876 ____R (Swearware) C:\Users\Dray\Downloads\ComboFix.exe
- 2018-02-09 21:38 - 2015-07-25 17:24 - 000000000 ____D C:\Users\Dray\AppData\Local\Adobe
- 2018-02-09 21:36 - 2017-07-04 00:49 - 000004470 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
- 2018-02-09 21:36 - 2013-04-16 09:58 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
- 2018-02-09 21:36 - 2013-04-16 09:58 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
- 2018-02-09 21:36 - 2013-04-16 09:58 - 000000000 ____D C:\Windows\SysWOW64\Macromed
- 2018-02-09 21:36 - 2013-04-16 09:58 - 000000000 ____D C:\Windows\system32\Macromed
- 2018-02-09 20:56 - 2013-04-16 10:21 - 000000000 ____D C:\Program Files (x86)\Steam
- 2018-02-09 20:46 - 2015-07-19 18:58 - 000000000 ____D C:\Users\Dray\AppData\Roaming\Skype
- 2018-02-09 19:51 - 2015-09-06 11:37 - 000000000 ____D C:\Users\Dray\AppData\Roaming\.minecraft
- 2018-02-09 19:51 - 2015-07-24 21:08 - 000000616 _____ C:\Users\Dray\AppData\Roaming\jd-gui.cfg
- 2018-02-09 14:54 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
- 2018-02-08 22:31 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
- 2018-02-08 22:31 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
- 2018-02-08 12:34 - 2015-07-19 18:56 - 000000000 ____D C:\Users\Dray\AppData\Roaming\Telegram Desktop
- 2018-02-07 17:03 - 2013-04-16 10:11 - 000000000 ____D C:\ProgramData\Intel
- 2018-02-07 16:58 - 2015-07-29 22:39 - 000018208 _____ C:\Windows\system32\results.xml
- 2018-02-07 16:58 - 2015-07-22 08:03 - 000000451 _____ C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
- 2018-02-07 16:57 - 2017-02-05 14:15 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
- 2018-02-07 16:50 - 2015-07-29 22:26 - 000000000 ____D C:\Users\Dray\Downloads\Intel Components
- 2018-02-07 16:48 - 2015-07-19 20:06 - 000000000 ____D C:\ProgramData\Package Cache
- 2018-02-07 16:47 - 2013-04-16 10:11 - 000000000 ____D C:\Program Files\Intel
- 2018-02-07 16:10 - 2016-11-24 15:18 - 000000000 ____D C:\Users\Dray\Desktop\Other
- 2018-02-07 16:10 - 2016-08-03 16:10 - 000000000 ____D C:\Users\Dray\AppData\Roaming\TeamViewer
- 2018-02-07 16:10 - 2016-04-09 12:38 - 000000000 __HDC C:\ProgramData\{05EE3202-A879-4F9D-895C-AC535855E0A9}
- 2018-02-07 16:10 - 2015-07-22 08:04 - 000000000 ____D C:\Users\Dray\AppData\Roaming\Sony
- 2018-02-07 16:10 - 2015-07-19 20:17 - 000000000 ____D C:\Program Files (x86)\Minecraft
- 2018-02-07 16:10 - 2011-02-10 09:02 - 000000000 ____D C:\Windows\panther
- 2018-02-07 14:27 - 2015-07-19 18:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
- 2018-02-07 14:27 - 2015-07-19 18:55 - 000000000 ____D C:\ProgramData\AVAST Software
- 2018-02-07 14:26 - 2016-10-26 16:44 - 000000000 ____D C:\Program Files\Common Files\Apple
- 2018-02-07 14:25 - 2016-10-26 16:44 - 000002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
- 2018-02-04 14:03 - 2013-04-16 10:27 - 000000000 ____D C:\Users\Default\AppData\Local\SoftThinks
- 2018-02-04 14:03 - 2013-04-16 10:27 - 000000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
- 2018-02-04 14:03 - 2013-04-16 10:18 - 000000000 ____D C:\Program Files (x86)\AlienRespawn
- 2018-01-19 19:17 - 2017-04-09 11:09 - 000000000 ____D C:\Users\Dray\Desktop\javaserv
- 2018-01-15 20:25 - 2017-07-21 00:00 - 000000165 _____ C:\Windows\system32\Drivers\CBDriver.sys
- 2018-01-15 20:25 - 2017-07-20 23:59 - 000000000 ____D C:\Users\Dray\AppData\Roaming\CheatBreaker
- 2018-01-15 02:31 - 2016-11-15 19:35 - 000000000 ____D C:\Users\Dray\AppData\Roaming\discord
- 2018-01-14 23:40 - 2016-11-15 19:35 - 000002162 _____ C:\Users\Dray\Desktop\Discord.lnk
- 2018-01-14 23:40 - 2016-11-15 19:34 - 000000000 ____D C:\Users\Dray\AppData\Local\Discord
- 2018-01-14 15:45 - 2017-07-09 13:38 - 000000000 ____D C:\Users\Dray\Desktop\Vape
- 2018-01-11 22:01 - 2011-02-10 11:10 - 000774592 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
- ==================== Files in the root of some directories =======
- 2017-07-09 13:20 - 2017-07-20 18:21 - 000001131 ____H () C:\Users\Dray\AppData\Roaming\.ias
- 2015-07-24 21:08 - 2018-02-09 19:51 - 000000616 _____ () C:\Users\Dray\AppData\Roaming\jd-gui.cfg
- 2017-07-06 00:02 - 2017-07-06 00:02 - 000041984 ___SH () C:\Users\Dray\AppData\Roaming\Thumbs.db
- 2015-09-08 14:27 - 2015-09-08 14:27 - 000000003 _____ () C:\Users\Dray\AppData\Local\updater.log
- ==================== Bamital & volsnap ======================
- (There is no automatic fix for files that do not pass verification.)
- C:\Windows\system32\winlogon.exe => File is digitally signed
- C:\Windows\system32\wininit.exe => File is digitally signed
- C:\Windows\SysWOW64\wininit.exe => File is digitally signed
- C:\Windows\explorer.exe => File is digitally signed
- C:\Windows\SysWOW64\explorer.exe => File is digitally signed
- C:\Windows\system32\svchost.exe => File is digitally signed
- C:\Windows\SysWOW64\svchost.exe => File is digitally signed
- C:\Windows\system32\services.exe => File is digitally signed
- C:\Windows\system32\User32.dll => File is digitally signed
- C:\Windows\SysWOW64\User32.dll => File is digitally signed
- C:\Windows\system32\userinit.exe => File is digitally signed
- C:\Windows\SysWOW64\userinit.exe => File is digitally signed
- C:\Windows\system32\rpcss.dll => File is digitally signed
- C:\Windows\system32\dnsapi.dll => File is digitally signed
- C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
- C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2016-05-07 23:07
- ==================== End of FRST.txt ============================
Advertisement
Add Comment
Please, Sign In to add comment