hub223 Posted July 20, 2014 ID:855477 Share Posted July 20, 2014 Hello, I download something from cnet yesterday, and it completely screwed up my computer. With the programme that I downloaded, since deleted, it had about 15 PUP's. Malwarebytes got rid of them all apart from one. Spigot. Every time I run a scan, this Spigot keeps showing up, even after I quarantined it and deleted it, restarted my computer it still shows up later. I cant find any files on this on my computer, checked the reg files, nothing shows up there. In the reg files, I even searched for spigot and searched protection, and still nothing shows up. This programme must be on my computer somewhere, but I cant get rid of it, can u help? I also have CCleaner. This is the last log from a scan Memory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: DisabledHeuristics: EnabledPUP: WarnPUM: Enabled Processes: 0(No malicious items detected) Modules: 0(No malicious items detected) Registry Keys: 0(No malicious items detected) Registry Values: 0(No malicious items detected) Registry Data: 0(No malicious items detected) Folders: 0(No malicious items detected) Files: 1PUP.Optional.Spigot.A, C:\Users\andy boot\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "homepage": "https://uk.search.yahoo.com/?type=903578&fr=spigot-yhp-ch",), ,[a223acf54e2d54e2ce195187dd2745bb] Physical Sectors: 0(No malicious items detected) (end) Link to post Share on other sites More sharing options...
deeprybka Posted July 20, 2014 ID:855480 Share Posted July 20, 2014 Hi & My name is Jürgen and I will be assisting you with your Malware related problems. Before we move on, please read the following points carefully. My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.Please read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.Perform everything in the correct order. Sometimes one step requires the previous one.If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.Step 1 Please run a FRST scan. This will help us diagnose your problem. Please download Farbar Recovery Scan Tool and save it to your Desktop. (If you are not sure which version (32-/64-bit) applies to your system, download and try to start both of them as just the right one will run.)Start FRST with administator privileges.Make sure the option Addition.txt is checked and press the Scan button.When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.Please copy and paste these logs in your next reply. Link to post Share on other sites More sharing options...
hub223 Posted July 20, 2014 Author ID:855483 Share Posted July 20, 2014 Hello, This is the First log - Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014Ran by andy boot (administrator) on ANDY on 20-07-2014 20:54:01Running from C:\Users\andy boot\DownloadsPlatform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)Internet Explorer Version 10Boot Mode: Normal The only official download link for FRST:Download link for 32-Bit version: "https://www.google.co.uk/", "hxxp://www.imdb.com/", "hxxp://www.cineworld.co.uk/cinemas/28", "hxxp://www.audiojungle.com/", "hxxp://www.twitch.tv/hostagek1ll3rhd", "hxxp://www.bankofscotland.co.uk/", "hxxp://community.callofduty.com/community/call_of_duty/english/ghosts/forums/xbox_360", "hxxp://www.youtube-mp3.org/", "https://ads.youtube.com/keyword_tool/", "hxxp://googleping.com/" CHR Extension: (Skype Click to Call) - C:\Users\andy boot\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-02-03]CHR Extension: (Google Wallet) - C:\Users\andy boot\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-02]CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11] ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG)R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG)S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1030224 2014-07-17] (Avira Operations GmbH & Co. KG)R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-07] (Avira Operations GmbH & Co. KG)R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X] ==================== Drivers (Whitelisted) ==================== S1 archlp; C:\Windows\SysWow64\drivers\archlp.sys [143872 2008-08-12] ()R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-01] (Avira Operations GmbH & Co. KG)R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)R3 hcwhdpvr; C:\Windows\System32\DRIVERS\hcwhdpvr.sys [187520 2008-11-18] (Hauppauge, Inc.)R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)S3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-20 20:54 - 2014-07-20 20:54 - 00014921 _____ () C:\Users\andy boot\Downloads\FRST.txt2014-07-20 20:53 - 2014-07-20 20:54 - 00000000 ____D () C:\FRST2014-07-20 20:53 - 2014-07-20 20:53 - 02089984 _____ (Farbar) C:\Users\andy boot\Downloads\FRST64.exe2014-07-20 20:31 - 2014-07-20 20:31 - 00001254 _____ () C:\Users\andy boot\Desktop\h.txt2014-07-20 20:24 - 2014-07-20 20:24 - 00000112 _____ () C:\Windows\setupact.log2014-07-20 20:24 - 2014-07-20 20:24 - 00000000 _____ () C:\Windows\setuperr.log2014-07-20 14:43 - 2014-07-20 14:43 - 00004755 _____ () C:\Users\andy boot\Downloads\Xmen Days of future past 2014 R6 CAM x264 AAC - SiNDK8.torrent2014-07-19 20:38 - 2014-07-19 20:38 - 04812672 _____ (Piriform Ltd) C:\Users\andy boot\Downloads\ccsetup415.exe2014-07-19 17:04 - 2014-07-19 17:04 - 00004564 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log2014-07-19 17:04 - 2014-07-19 17:04 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\Oracle2014-07-19 17:04 - 2014-07-19 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java2014-07-09 04:38 - 2014-06-30 03:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll2014-07-09 04:38 - 2014-06-30 03:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll2014-07-09 04:38 - 2014-06-19 03:12 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll2014-07-09 04:38 - 2014-06-19 03:12 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll2014-07-09 04:38 - 2014-06-19 03:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe2014-07-09 04:38 - 2014-06-19 03:11 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll2014-07-09 04:38 - 2014-06-19 03:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll2014-07-09 04:38 - 2014-06-19 03:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll2014-07-09 04:38 - 2014-06-19 03:10 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll2014-07-09 04:38 - 2014-06-19 03:10 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll2014-07-09 04:38 - 2014-06-19 03:10 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll2014-07-09 04:38 - 2014-06-19 03:10 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll2014-07-09 04:38 - 2014-06-19 03:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl2014-07-09 04:38 - 2014-06-19 01:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll2014-07-09 04:38 - 2014-06-19 01:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll2014-07-09 04:38 - 2014-06-19 01:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll2014-07-09 04:38 - 2014-06-19 01:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll2014-07-09 04:38 - 2014-06-19 01:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll2014-07-09 04:38 - 2014-06-19 01:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll2014-07-09 04:38 - 2014-06-19 01:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll2014-07-09 04:38 - 2014-06-19 01:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll2014-07-09 04:38 - 2014-06-19 01:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll2014-07-09 04:38 - 2014-06-19 01:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl2014-07-09 04:38 - 2014-06-19 01:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll2014-07-09 04:38 - 2014-06-19 01:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll2014-07-09 04:38 - 2014-06-19 01:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb2014-07-09 04:38 - 2014-06-19 01:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb2014-07-09 04:38 - 2014-06-19 00:37 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe2014-07-09 04:38 - 2014-06-19 00:34 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe2014-07-09 04:38 - 2014-06-18 03:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe2014-07-09 04:38 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe2014-07-09 04:38 - 2014-06-18 02:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys2014-07-09 04:38 - 2014-06-06 11:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll2014-07-09 04:38 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll2014-07-09 04:38 - 2014-05-30 07:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys2014-07-09 04:37 - 2014-06-05 15:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll2014-07-09 04:37 - 2014-06-05 15:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll2014-07-09 04:37 - 2014-06-05 15:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll2014-07-09 04:37 - 2014-05-30 09:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll2014-07-09 04:37 - 2014-05-30 09:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll2014-07-09 04:37 - 2014-05-30 09:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll2014-07-09 04:37 - 2014-05-30 09:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll2014-07-09 04:37 - 2014-05-30 09:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll2014-07-09 04:37 - 2014-05-30 09:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll2014-07-09 04:37 - 2014-05-30 09:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll2014-07-09 04:37 - 2014-05-30 08:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll2014-07-09 04:37 - 2014-05-30 08:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll2014-07-09 04:37 - 2014-05-30 08:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll2014-07-09 04:37 - 2014-05-30 08:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll2014-07-09 04:37 - 2014-05-30 08:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll2014-07-09 04:37 - 2014-05-30 08:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll2014-07-09 04:37 - 2014-05-30 08:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll2014-07-08 21:05 - 2014-07-16 00:55 - 00000000 ____D () C:\Users\andy boot\Documents\My Games2014-07-08 21:02 - 2014-07-08 21:02 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\Microsoft Games2014-07-01 13:00 - 2014-07-01 20:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician2014-07-01 13:00 - 2014-07-01 13:00 - 00003238 _____ () C:\Windows\System32\Tasks\SamsungMagician2014-06-30 21:31 - 2013-04-10 00:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll2014-06-30 21:31 - 2013-04-02 23:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll2014-06-26 15:14 - 2014-06-26 15:55 - 00000000 ____D () C:\Users\andy boot\AppData\Local\Adobe2014-06-25 20:53 - 2014-06-25 20:54 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment2014-06-25 20:53 - 2014-06-25 20:53 - 54085656 _____ (Blizzard Entertainment) C:\Users\andy boot\Downloads\StarCraft-II-Setup-enGB.exe2014-06-25 20:53 - 2014-06-25 20:53 - 00000000 ____D () C:\Users\andy boot\Documents\StarCraft II2014-06-25 20:53 - 2014-06-25 20:53 - 00000000 ____D () C:\ProgramData\Battle.net2014-06-21 15:08 - 2014-06-21 15:12 - 569432384 _____ () C:\Users\andy boot\Documents\PowerDirector_2930_GM6_Trial_Trial_VDE140527-02.exe2014-06-21 15:08 - 2014-06-21 15:08 - 00000000 ____D () C:\ProgramData\CyberLink ==================== One Month Modified Files and Folders ======= 2014-07-20 20:54 - 2014-07-20 20:54 - 00014921 _____ () C:\Users\andy boot\Downloads\FRST.txt2014-07-20 20:54 - 2014-07-20 20:53 - 00000000 ____D () C:\FRST2014-07-20 20:54 - 2014-02-03 00:19 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\Skype2014-07-20 20:53 - 2014-07-20 20:53 - 02089984 _____ (Farbar) C:\Users\andy boot\Downloads\FRST64.exe2014-07-20 20:31 - 2014-07-20 20:31 - 00001254 _____ () C:\Users\andy boot\Desktop\h.txt2014-07-20 20:25 - 2014-04-08 20:42 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys2014-07-20 20:24 - 2014-07-20 20:24 - 00000112 _____ () C:\Windows\setupact.log2014-07-20 20:24 - 2014-07-20 20:24 - 00000000 _____ () C:\Windows\setuperr.log2014-07-20 20:14 - 2014-02-02 20:29 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job2014-07-20 20:04 - 2014-02-10 23:20 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job2014-07-20 20:03 - 2014-02-03 05:03 - 00000302 _____ () C:\Windows\Tasks\FoxTab.job2014-07-20 19:34 - 2014-03-29 14:40 - 00000000 ____D () C:\Program Files (x86)\Steam2014-07-20 19:15 - 2009-07-14 05:45 - 00015152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A02014-07-20 19:15 - 2009-07-14 05:45 - 00015152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A02014-07-20 19:13 - 2009-07-14 06:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI2014-07-20 19:11 - 2014-02-02 19:03 - 01392307 ____N () C:\Windows\WindowsUpdate.log2014-07-20 19:08 - 2014-02-02 20:29 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job2014-07-20 19:08 - 2014-02-02 19:14 - 00000000 ____D () C:\ProgramData\NVIDIA2014-07-20 19:08 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT2014-07-20 18:42 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\security2014-07-20 18:41 - 2014-02-03 15:36 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\vlc2014-07-20 14:43 - 2014-07-20 14:43 - 00004755 _____ () C:\Users\andy boot\Downloads\Xmen Days of future past 2014 R6 CAM x264 AAC - SiNDK8.torrent2014-07-19 20:57 - 2014-02-02 19:18 - 00000000 ____D () C:\Windows\pss2014-07-19 20:39 - 2014-02-03 02:57 - 00000000 ____D () C:\Windows\Panther2014-07-19 20:39 - 2014-02-03 00:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner2014-07-19 20:38 - 2014-07-19 20:38 - 04812672 _____ (Piriform Ltd) C:\Users\andy boot\Downloads\ccsetup415.exe2014-07-19 20:38 - 2014-02-03 00:14 - 00000000 ____D () C:\Program Files\CCleaner2014-07-19 17:04 - 2014-07-19 17:04 - 00004564 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log2014-07-19 17:04 - 2014-07-19 17:04 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\Oracle2014-07-19 17:04 - 2014-07-19 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java2014-07-19 17:04 - 2014-02-03 00:06 - 00000000 ____D () C:\ProgramData\Oracle2014-07-19 17:04 - 2014-02-03 00:06 - 00000000 ____D () C:\Program Files (x86)\Java2014-07-17 12:59 - 2014-02-08 21:39 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys2014-07-16 00:55 - 2014-07-08 21:05 - 00000000 ____D () C:\Users\andy boot\Documents\My Games2014-07-16 00:28 - 2014-02-08 00:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira2014-07-16 00:28 - 2014-02-08 00:40 - 00000000 ____D () C:\Program Files (x86)\Avira2014-07-16 00:28 - 2014-02-02 21:23 - 00000000 ____D () C:\ProgramData\Package Cache2014-07-14 14:01 - 2009-07-14 06:08 - 00032620 _____ () C:\Windows\Tasks\SCHEDLGU.TXT2014-07-11 23:12 - 2014-03-29 21:18 - 00000000 ____D () C:\Users\andy boot\Desktop\Games2014-07-11 22:58 - 2014-03-29 19:17 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam2014-07-11 03:02 - 2014-02-03 00:06 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll2014-07-11 02:56 - 2014-02-03 00:06 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe2014-07-11 02:56 - 2014-02-03 00:06 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe2014-07-11 02:55 - 2014-02-03 00:06 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe2014-07-11 00:15 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache2014-07-09 19:55 - 2014-05-06 21:26 - 00000000 ___SD () C:\Windows\system32\CompatTel2014-07-09 19:55 - 2009-07-14 08:45 - 00000000 ____D () C:\Program Files\Windows Journal2014-07-09 19:55 - 2009-07-14 05:45 - 04836848 _____ () C:\Windows\system32\FNTCACHE.DAT2014-07-09 19:55 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism2014-07-09 19:55 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism2014-07-09 17:58 - 2014-02-02 19:30 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe2014-07-09 17:58 - 2014-02-02 19:30 - 00000000 ____D () C:\Windows\system32\MRT2014-07-09 01:04 - 2014-02-10 23:20 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe2014-07-09 01:04 - 2014-02-10 23:20 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl2014-07-09 01:04 - 2014-02-10 23:20 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater2014-07-08 21:02 - 2014-07-08 21:02 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\Microsoft Games2014-07-08 21:02 - 2014-03-29 19:23 - 00000000 ____D () C:\Users\andy boot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games2014-07-04 22:58 - 2014-02-03 00:39 - 00000000 ____D () C:\ProgramData\Origin2014-07-04 22:58 - 2014-02-03 00:39 - 00000000 ____D () C:\Program Files (x86)\Origin2014-07-01 20:40 - 2014-07-01 13:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician2014-07-01 13:02 - 2014-02-08 00:41 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys2014-07-01 13:00 - 2014-07-01 13:00 - 00003238 _____ () C:\Windows\System32\Tasks\SamsungMagician2014-07-01 13:00 - 2014-02-07 22:22 - 00000000 ____D () C:\Program Files (x86)\Samsung Magician2014-06-30 03:09 - 2014-07-09 04:38 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll2014-06-30 03:04 - 2014-07-09 04:38 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll2014-06-27 18:33 - 2014-02-02 21:57 - 00007599 _____ () C:\Users\andy boot\AppData\Local\Resmon.ResmonCfg2014-06-26 15:57 - 2014-02-14 19:50 - 00000132 _____ () C:\Users\andy boot\AppData\Roaming\Adobe PNG Format CS5 Prefs2014-06-26 15:55 - 2014-06-26 15:14 - 00000000 ____D () C:\Users\andy boot\AppData\Local\Adobe2014-06-25 20:54 - 2014-06-25 20:53 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment2014-06-25 20:53 - 2014-06-25 20:53 - 54085656 _____ (Blizzard Entertainment) C:\Users\andy boot\Downloads\StarCraft-II-Setup-enGB.exe2014-06-25 20:53 - 2014-06-25 20:53 - 00000000 ____D () C:\Users\andy boot\Documents\StarCraft II2014-06-25 20:53 - 2014-06-25 20:53 - 00000000 ____D () C:\ProgramData\Battle.net2014-06-23 08:28 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system2014-06-22 22:07 - 2011-10-01 23:40 - 00000000 ____D () C:\Users\andy boot\audio jungle2014-06-22 17:09 - 2014-02-02 20:29 - 00003900 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA2014-06-22 17:09 - 2014-02-02 20:29 - 00003648 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore2014-06-21 15:12 - 2014-06-21 15:08 - 569432384 _____ () C:\Users\andy boot\Documents\PowerDirector_2930_GM6_Trial_Trial_VDE140527-02.exe2014-06-21 15:08 - 2014-06-21 15:08 - 00000000 ____D () C:\ProgramData\CyberLink Some content of TEMP:====================C:\Users\andy boot\AppData\Local\Temp\avgnt.exeC:\Users\andy boot\AppData\Local\Temp\BackupSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signedC:\Windows\System32\wininit.exe => File is digitally signedC:\Windows\SysWOW64\wininit.exe => File is digitally signedC:\Windows\explorer.exe => File is digitally signedC:\Windows\SysWOW64\explorer.exe => File is digitally signedC:\Windows\System32\svchost.exe => File is digitally signedC:\Windows\SysWOW64\svchost.exe => File is digitally signedC:\Windows\System32\services.exe => File is digitally signedC:\Windows\System32\User32.dll => File is digitally signedC:\Windows\SysWOW64\User32.dll => File is digitally signedC:\Windows\System32\userinit.exe => File is digitally signedC:\Windows\SysWOW64\userinit.exe => File is digitally signedC:\Windows\System32\rpcss.dll => File is digitally signedC:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-18 20:43 ==================== End Of Log ============================ THIS IS THE ADDITION LOG Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-07-2014Ran by andy boot at 2014-07-20 20:54:15Running from C:\Users\andy boot\DownloadsBoot Mode: Normal========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.)Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) HiddenAdobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) HiddenAdobe Creative Suite 5 Master Collection (HKLM-x32\...\{288DB08D-0708-4A94-B055-55B99E39EB62}) (Version: 5.0 - Adobe Systems Incorporated)Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) HiddenArcSoft TotalMedia Extreme (HKLM-x32\...\{88B05038-C890-468B-A563-0015FD53CDC3}) (Version: 1.0.9.5 - ArcSoft)Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.4.5.0 - Asmedia Technology)Avira (HKLM-x32\...\{142be4a8-895b-4ed9-b1ff-11c76357e3df}) (Version: 1.1.17.31000 - Avira Operations GmbH & Co. KG)Avira (x32 Version: 1.1.17.31000 - Avira Operations GmbH & Co. KG) HiddenAvira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.5.464 - Avira)Bandicam (HKLM-x32\...\Bandicam) (Version: 1.9.3.492 - Bandisoft.com)Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandisoft.com)CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform)Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.)Commandos 2: Men of Courage (HKLM-x32\...\Steam App 6830) (Version: - Pyro Studios)Commandos 3: Destination Berlin (HKLM-x32\...\Steam App 6840) (Version: - Pyro Studios)Commandos: Behind Enemy Lines (HKLM-x32\...\Steam App 6800) (Version: - Pyro Studios)Commandos: Beyond the Call of Duty (HKLM-x32\...\Steam App 6810) (Version: - Pyro Studios)D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) HiddenDivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.8 - DivX, LLC)Football Manager 2010 (HKLM-x32\...\Football Manager 2010) (Version: 10.0.0.0 - Sports Interactive)GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) HiddenGoogle Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) HiddenJava 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.650 - Oracle)Java Auto Updater (x32 Version: 2.1.65.20 - Oracle, Inc.) HiddenJunk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenMalwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)Mental Omega APYR (HKLM-x32\...\Mental Omega APYR3.0) (Version: 3.0 - Mentalmeisters)Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) HiddenMicrosoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) HiddenMicrosoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) HiddenMicrosoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) HiddenMicrosoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) HiddenMicrosoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) HiddenMicrosoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) HiddenMicrosoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) HiddenMicrosoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) HiddenMicrosoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) HiddenMicrosoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) HiddenMicrosoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) HiddenMicrosoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) HiddenMicrosoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) HiddenMicrosoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) HiddenMicrosoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) HiddenMicrosoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) HiddenMicrosoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) HiddenMicrosoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) HiddenMicrosoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) HiddenMioMore Desktop 7.50 (HKLM-x32\...\{A2804FE8-4101-48a0-AE1A-575B99014BF4}-Mio-7.50) (Version: 7.50.0109.128 - Mio Technology)MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) HiddenMSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) HiddenMSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) HiddenMSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) HiddenNVIDIA 3D Vision Controller Driver 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 334.89 - NVIDIA Corporation)NVIDIA 3D Vision Driver 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 334.89 - NVIDIA Corporation)NVIDIA Control Panel 334.89 (Version: 334.89 - NVIDIA Corporation) HiddenNVIDIA GeForce Experience 1.8.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.1 - NVIDIA Corporation)NVIDIA Graphics Driver 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation)NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) HiddenNVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) HiddenNVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) HiddenNVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) HiddenNVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)NVIDIA ShadowPlay 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) HiddenNVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3489 - NVIDIA Corporation) HiddenNVIDIA Update 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) HiddenNVIDIA Update Core (Version: 10.11.15 - NVIDIA Corporation) HiddenNVIDIA Virtual Audio 1.2.19 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.19 - NVIDIA Corporation)Origin (HKLM-x32\...\Origin) (Version: 9.4.1.116 - Electronic Arts, Inc.)Painkiller Hell & Damnation (HKLM-x32\...\Steam App 214870) (Version: - The Farm 51)PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) HiddenPlague Inc: Evolved (HKLM-x32\...\Steam App 246620) (Version: - Ndemic Creations)Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.0.2 r2161 - )Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.37.1229.2010 - Realtek)Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6251 - Realtek Semiconductor Corp.)Rise of Nations: Extended Edition (HKLM-x32\...\Steam App 287450) (Version: - SkyBox Labs)Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.4.0 - Samsung Electronics)SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) HiddenSkype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) HiddenVLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)WestwoodOnline (HKLM-x32\...\{BBCD6D56-8A26-4DDE-9482-DBC9C7B7341D}) (Version: 1.0.0.0 - WestwoodOnline)Windows Live Communications Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)Windows Live Essentials (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) HiddenWindows Live Installer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live Mail (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live MIME IFilter (Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live PIMT Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live SOXE (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live SOXE Definitions (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live UX Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live UX Platform Language Pack (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live Writer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWindows Live Writer Resources (x32 Version: 16.4.3528.0331 - Microsoft Corporation) HiddenWinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)XSplit Broadcaster (HKLM-x32\...\{6459F338-FE52-4034-BCA7-74772DA0F24D}) (Version: 1.3.1403.1202 - SplitMediaLabs) ==================== Restore Points ========================= 01-07-2014 02:00:10 Windows Update08-07-2014 20:02:20 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.6061008-07-2014 20:02:27 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.6061009-07-2014 16:57:33 Windows Update15-07-2014 23:54:42 Installed DirectX19-07-2014 16:04:12 Installed Java 7 Update 65 ==================== Hosts content: ========================== 2014-02-04 21:35 - 2014-02-02 22:34 - 00000866 ____A C:\Windows\system32\Drivers\etc\hosts127.0.0.1 activate.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {5603C18F-2A8A-42DA-A4AB-A5FA0B0B9D91} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd)Task: {6ADAB124-AE5A-403F-A0EC-1A8EC8B00636} - System32\Tasks\Digital Sites => C:\Users\ANDYBO~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTIONTask: {70219D03-D9BE-4CB2-9F6E-9C9FF7AAD360} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-02] (Google Inc.)Task: {7F4A02AE-2B88-424E-BAAB-68537CA3789C} - System32\Tasks\FoxTab => C:\Users\ANDYBO~1\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTIONTask: {92609F21-CD4C-4758-91B4-FEC8BD809FC0} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung Magician\Samsung Magician.exe [2014-05-19] (Samsung Electronics.)Task: {A5EEC635-7338-460B-BDBF-8E177218D81A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-02] (Google Inc.)Task: {B5485196-D0E2-4DB1-BB00-8FA521B9CE22} - System32\Tasks\UpdaterEX => C:\Users\ANDYBO~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTIONTask: {B585A226-B524-43EC-A20D-3B0E6A6E2B28} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated)Task: {D0029511-C3D9-4D8F-8CDD-BE134B3CE46D} - System32\Tasks\AdobeAAMUpdater-1.0-ANDY-andy boot => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeTask: C:\Windows\Tasks\Digital Sites.job => C:\Users\ANDYBO~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTIONTask: C:\Windows\Tasks\FoxTab.job => C:\Users\ANDYBO~1\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTIONTask: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\Windows\Tasks\UpdaterEX.job => C:\Users\ANDYBO~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-02-02 19:49 - 2014-02-08 18:42 - 00117024 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll2013-10-29 21:45 - 2013-10-29 21:45 - 00036536 _____ () C:\Program Files\Rainmeter\Rainmeter.exe2013-10-29 21:45 - 2013-10-29 21:45 - 00798392 _____ () C:\Program Files\Rainmeter\Rainmeter.dll2013-10-29 21:41 - 2013-10-29 21:41 - 00058880 _____ () C:\Program Files\Rainmeter\Plugins\WebParser.dll2014-07-07 13:53 - 2014-07-07 13:53 - 00137296 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll2014-07-07 13:52 - 2014-07-07 13:52 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll2014-01-03 12:03 - 2014-01-03 12:03 - 07816192 _____ () C:\Program Files (x86)\SplitMediaLabs\XSplit\avcodec-54.dll2014-01-03 12:03 - 2014-01-03 12:03 - 00188416 _____ () C:\Program Files (x86)\SplitMediaLabs\XSplit\avutil-52.dll2014-01-03 12:03 - 2014-01-03 12:03 - 01425920 _____ () C:\Program Files (x86)\SplitMediaLabs\XSplit\avformat-54.dll2014-01-03 12:03 - 2014-01-03 12:03 - 00336896 _____ () C:\Program Files (x86)\SplitMediaLabs\XSplit\swscale-2.dll2014-01-03 12:03 - 2014-01-03 12:03 - 00096256 _____ () C:\Program Files (x86)\SplitMediaLabs\XSplit\swresample-0.dll2014-02-02 21:31 - 2014-07-07 13:53 - 00049744 ____N () C:\Users\andy boot\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll2014-02-07 22:22 - 2014-05-06 11:24 - 00013824 _____ () C:\Program Files (x86)\Samsung Magician\SAMSUNG_SSD.dll2014-02-07 22:22 - 2014-05-19 20:20 - 00103424 _____ () C:\Program Files (x86)\Samsung Magician\PAL.dll2014-02-07 22:22 - 2014-05-19 20:20 - 00039424 _____ () C:\Program Files (x86)\Samsung Magician\SATA.dll2014-02-07 22:22 - 2014-05-19 20:19 - 00038400 _____ () C:\Program Files (x86)\Samsung Magician\SAT.dll2014-02-07 22:22 - 2014-05-19 20:20 - 00031232 _____ () C:\Program Files (x86)\Samsung Magician\SMINI.dll2014-02-07 22:22 - 2014-05-19 20:19 - 00029696 _____ () C:\Program Files (x86)\Samsung Magician\SAS.dll2014-07-18 19:17 - 2014-07-15 10:24 - 00718664 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libglesv2.dll2014-07-18 19:17 - 2014-07-15 10:24 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\libegl.dll2014-07-18 19:17 - 2014-07-15 10:24 - 08537928 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll2014-07-18 19:17 - 2014-07-15 10:24 - 00353096 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll2014-07-18 19:17 - 2014-07-15 10:24 - 01732936 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ffmpegsumo.dll2014-07-18 19:17 - 2014-07-15 10:24 - 14664008 _____ () C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00113171 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll2014-02-05 02:32 - 2014-02-05 02:32 - 02396179 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00268307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00031251 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 11148307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 01248787 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00066579 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 02021395 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00100371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00240659 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00076307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_vdr_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00045587 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00060947 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00531475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00708627 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00114195 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00040467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libstream_filter_rar_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00014867 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00133139 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 01512467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00296979 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00054291 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00038419 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libglobalhotkeys_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00189971 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00091667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libavi_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00036371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00291859 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00017939 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 01280019 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00018451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00336403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00344595 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00198675 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00027155 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libg711_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00015891 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 01371667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00146451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00022035 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00733203 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00026131 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00171027 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00019475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liba52_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 10396179 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00724499 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00026643 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_yuy2_sse2_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_yuy2_mmx_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00555027 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libswscale_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00113683 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_rgb_sse2_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi422_yuy2_sse2_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi422_yuy2_mmx_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00053779 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_rgb_mmx_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00016915 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00032275 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00020499 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00017427 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00067091 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll2014-02-05 02:32 - 2014-02-05 02:32 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00130579 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libmpgatofixed32_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00168979 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstofloat32_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00058899 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tofloat32_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 01496083 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00019475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsimple_channel_mixer_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00013331 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\liba52tospdif_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00014355 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdtstospdif_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00014867 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libdolby_surround_decoder_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00014355 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libugly_resampler_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll2014-02-05 02:31 - 2014-02-05 02:31 - 00025619 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libaudio_format_plugin.dll2014-03-31 21:35 - 2014-03-31 21:35 - 00270016 _____ () C:\Program Files (x86)\Windows Live\Writer\en\WindowsLive.Writer.Localization.resources.dll2014-03-31 21:35 - 2014-03-31 21:35 - 00270016 _____ () C:\Program Files (x86)\Windows Live\Writer\en-GB\WindowsLive.Writer.Localization.resources.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\andy boot\Cookies:7XFoUFVOrqm2yogRPMC5wCXPZiAlternateDataStreams: C:\Users\andy boot\Local Settings:MvOkdp7zC7I6rfO9JyAlternateDataStreams: C:\Users\andy boot\AppData\Local:MvOkdp7zC7I6rfO9JyAlternateDataStreams: C:\Users\andy boot\AppData\Local\Application Data:MvOkdp7zC7I6rfO9JyAlternateDataStreams: C:\Users\andy boot\AppData\Local\I4AA1zEg10L20Hu:oIujgsVqzeuS3b7mOuxHOfgkLJ ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= MSCONFIG\startupfolder: C:^Users^andy boot^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Samsung Magician.lnk => C:\Windows\pss\Samsung Magician.lnk.Startup ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors:==================Error: (07/20/2014 06:14:07 AM) (Source: SideBySide) (EventID: 63) (User: )Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error: (07/19/2014 08:58:10 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/19/2014 08:48:59 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/19/2014 08:35:29 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/18/2014 08:44:12 PM) (Source: SideBySide) (EventID: 63) (User: )Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error: (07/18/2014 02:27:05 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/18/2014 02:46:28 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/16/2014 04:00:28 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/16/2014 01:43:57 AM) (Source: SideBySide) (EventID: 63) (User: )Description: Activation context generation failed for "assemblyIdentity1".Error in manifest or policy file "assemblyIdentity2" on line assemblyIdentity3.The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error: (07/12/2014 03:22:47 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] System errors:=============Error: (07/20/2014 07:08:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )Description: The following boot-start or system-start driver(s) failed to load: archlp Error: (07/20/2014 07:08:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )Description: The OutfoxTvService service failed to start due to the following error: %%2 Error: (07/20/2014 07:08:00 PM) (Source: Application Popup) (EventID: 875) (User: )Description: Driver archlp.sys has been blocked from loading. Error: (07/20/2014 06:42:35 PM) (Source: Service Control Manager) (EventID: 7026) (User: )Description: The following boot-start or system-start driver(s) failed to load: archlp Error: (07/20/2014 06:42:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )Description: The OutfoxTvService service failed to start due to the following error: %%2 Error: (07/20/2014 06:42:25 PM) (Source: Application Popup) (EventID: 875) (User: )Description: Driver archlp.sys has been blocked from loading. Error: (07/19/2014 08:58:49 PM) (Source: Service Control Manager) (EventID: 7026) (User: )Description: The following boot-start or system-start driver(s) failed to load: archlp Error: (07/19/2014 08:58:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )Description: The OutfoxTvService service failed to start due to the following error: %%2 Error: (07/19/2014 08:58:39 PM) (Source: Application Popup) (EventID: 875) (User: )Description: Driver archlp.sys has been blocked from loading. Error: (07/19/2014 08:55:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )Description: The Computer Backup (MyPC Backup) service terminated unexpectedly. It has done this 1 time(s). Microsoft Office Sessions:=========================Error: (07/20/2014 06:14:07 AM) (Source: SideBySide) (EventID: 63) (User: )Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/19/2014 08:58:10 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/19/2014 08:48:59 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/19/2014 08:35:29 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/18/2014 08:44:12 PM) (Source: SideBySide) (EventID: 63) (User: )Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/18/2014 02:27:05 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/18/2014 02:46:28 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/16/2014 04:00:28 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (07/16/2014 01:43:57 AM) (Source: SideBySide) (EventID: 63) (User: )Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/12/2014 03:22:47 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] ==================== Memory info =========================== Percentage of memory in use: 20%Total physical RAM: 16365.41 MBAvailable physical RAM: 12951.05 MBTotal Pagefile: 32728.99 MBAvailable Pagefile: 28629.99 MBTotal Virtual: 8192 MBAvailable Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.88 GB) (Free:128.64 GB) NTFS ==>[Drive with boot components (obtained from BCD)]Drive d: (Data) (Fixed) (Total:931.51 GB) (Free:504.37 GB) NTFSDrive f: (FM2010) (CDROM) (Total:2.3 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ========================================================Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 11E760A0)Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS) ========================================================Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: DE507E45)Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Link to post Share on other sites More sharing options...
deeprybka Posted July 20, 2014 ID:855489 Share Posted July 20, 2014 Hi, Hosts: 127.0.0.1 activate.adobe.com ??? Link to post Share on other sites More sharing options...
hub223 Posted July 20, 2014 Author ID:855503 Share Posted July 20, 2014 Adobe isnt the issue, thanks Link to post Share on other sites More sharing options...
deeprybka Posted July 20, 2014 ID:855504 Share Posted July 20, 2014 https://forums.malwarebytes.org/index.php?/topic/97700-piracy/ Link to post Share on other sites More sharing options...
hub223 Posted July 20, 2014 Author ID:855506 Share Posted July 20, 2014 Mmmm, ok. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted July 23, 2014 Root Admin ID:856941 Share Posted July 23, 2014 This topic will now be closed due to evidence of cracked or pirated software on this system. Piracy Policy Link to post Share on other sites More sharing options...
Recommended Posts