Jump to content

need help to remove Funacce and Fundata!


dezike

Recommended Posts

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-10-2014

Ran by lang (administrator) on KEN on 23-10-2014 01:00:52

Running from C:\Users\lang\Desktop

Loaded Profile: lang (Available profiles: lang)

Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)

Internet Explorer Version 11

Boot Mode: Normal


 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe

(VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe

(BitTorrent Inc.) C:\Users\lang\AppData\Roaming\uTorrent\uTorrent.exe

(Dropbox, Inc.) C:\Users\lang\AppData\Roaming\Dropbox\bin\Dropbox.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe

(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

(Power Software Ltd) D:\PowerISO\PWRISOVM.EXE

() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe

(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

 

==================== Registry (Whitelisted) ==================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)

HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"

HKLM\...\Run: [shadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5120144 2012-05-23] (VIA)

HKLM-x32\...\Run: [iAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)

HKLM-x32\...\Run: [uSB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)

HKLM-x32\...\Run: [PWRISOVM.EXE] => D:\PowerISO\PWRISOVM.EXE [337432 2013-01-27] (Power Software Ltd)

HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)

HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-15] (AVAST Software)

HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)

HKU\S-1-5-21-2607981345-4006741287-2006815445-1000\...\Run: [C3] => C:\Program Files (x86)\Vivox\C3\c3.exe

HKU\S-1-5-21-2607981345-4006741287-2006815445-1000\...\Run: [itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe

HKU\S-1-5-21-2607981345-4006741287-2006815445-1000\...\Run: [uTorrent] => C:\Users\lang\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-10-07] (BitTorrent Inc.)

HKU\S-1-5-21-2607981345-4006741287-2006815445-1000\...\Run: [OutfoxTV] => C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe

Startup: C:\Users\lang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()

Startup: C:\Users\lang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk

ShortcutTarget: Dropbox.lnk -> C:\Users\lang\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

ShellIconOverlayIdentifiers: [FunOverlay] -> {A5662DF9-0C2E-4A56-9FE1-BACFF6966D88} => C:\Users\Public\Fundata\Lucifer.dll (Funshion)

CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 


HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ca.yahoo.com/?fr=hp-avast&type=avastbcl

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/?ocid=iehp

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-CA

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB102B1F45015CE01

HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://ca.yahoo.com/?fr=hp-avast&type=avastbcl

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://ca.yahoo.com/?fr=hp-avast&type=avastbcl

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://ca.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = https://ca.yahoo.com/?fr=hp-avast&type=avastbcl

BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)

BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll No File

BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)

BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)

BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll No File

BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)

Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File

Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File

Winsock: Catalog9 01 C:\Users\Public\FunAcce\FunAcce.dll [187728] (Funshion Online Technologies Ltd.)

Winsock: Catalog9 02 C:\Users\Public\FunAcce\FunAcce.dll [187728] (Funshion Online Technologies Ltd.)

Winsock: Catalog9 03 C:\Users\Public\FunAcce\FunAcce.dll [187728] (Funshion Online Technologies Ltd.)

Winsock: Catalog9 14 C:\Users\Public\FunAcce\FunAcce.dll [187728] (Funshion Online Technologies Ltd.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

 

FireFox:

========

FF Plugin: @microsoft.com/GENUINE -> disabled No File

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)

FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)

FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)

FF Plugin-x32: @funshion.com/npFunshion -> C:\Users\lang\funshion\funshiontools\npFunshion.dll No File

FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)

FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)

FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF Plugin HKCU: @nsroblox.roblox.com/launcher -> C:\Users\lang\AppData\Local\Roblox\Versions\version-c2a7e6748ad54a86\\NPRobloxProxy.dll ( ROBLOX Corporation)

FF Plugin HKCU: @nsroblox.roblox.com/launcher64 -> C:\Users\lang\AppData\Local\Roblox\Versions\version-c2a7e6748ad54a86\\NPRobloxProxy64.dll ( ROBLOX Corporation)

FF HKLM-x32\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - D:\Wondershare\Video Converter Ultimate\SVRFirefoxExt

FF Extension: Wondershare Video Converter Ultimate - D:\Wondershare\Video Converter Ultimate\SVRFirefoxExt [2013-02-08]

FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-15]

 

Chrome: 

=======

CHR HomePage: Default -> hxxp://www.google.com

CHR StartupUrls: Default -> "https://www.youtube.com/"

CHR Profile: C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default

CHR Extension: (Google Slides) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-06]

CHR Extension: (Google Docs) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-06]

CHR Extension: (Google Drive) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-06]

CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]

CHR Extension: (YouTube) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-06]

CHR Extension: (Adblock Plus) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-09-06]

CHR Extension: (Google Search) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-06]

CHR Extension: (Google Sheets) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-06]

CHR Extension: (Avast Online Security) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-15]

CHR Extension: (Search Box) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\mknehpjhljpfaghmicofickbkdagooni [2014-09-06]

CHR Extension: (Google Wallet) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]

CHR Extension: (Gmail) - C:\Users\lang\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-06]

CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-15]

 

==================== Services (Whitelisted) =================

 

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

 

S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-15] (AVAST Software)

R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [106488 2014-10-16] (AVAST Software)

R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)

S3 ICCS; C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]

S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)

R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)

R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)

R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)

R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.)

 

==================== Drivers (Whitelisted) ====================

 

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

 

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] ()

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-15] ()

R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-10-16] (AVAST Software)

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-15] (AVAST Software)

R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [448400 2014-10-16] (AVAST Software)

R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-15] (AVAST Software)

R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-15] ()

R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-15] (AVAST Software)

R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-15] (AVAST Software)

R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-15] (AVAST Software)

R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-15] ()

S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-05-19] ()

R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)

R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-22] (Malwarebytes Corporation)

R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)

S3 MWAC; \??\C:\Windows\system32\drivers\ [0 ] () [File not signed]

S3 MWAC; \??\C:\Windows\SysWOW64\drivers\ [0 ] () [File not signed]

S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2012-09-10] (Apple Inc.) [File not signed]

R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)

R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)

R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)

S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]

R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.)

S3 WinRing0_1_2_0; D:\Razer Game Booster\Driver\WinRing0x64.sys [14544 2012-11-13] (OpenLibSys.org)

R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.)

S3 MSICDSetup; \??\E:\CDriver64.sys [X]

S3 VGPU; System32\drivers\rdvgkmd.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

 

 

==================== One Month Created Files and Folders ========

 

(If an entry is included in the fixlist, the file\folder will be moved.)

 

2014-10-23 01:00 - 2014-10-23 01:00 - 00018387 _____ () C:\Users\lang\Desktop\FRST.txt

2014-10-23 00:55 - 2014-10-23 00:55 - 02112000 _____ (Farbar) C:\Users\lang\Desktop\FRST64.exe

2014-10-22 14:11 - 2014-10-22 14:11 - 00001358 _____ () C:\Users\lang\Desktop\ROBLOX Studio.lnk

2014-10-16 15:53 - 2014-10-16 15:53 - 00448400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys

2014-10-16 15:53 - 2014-10-16 15:53 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys

2014-10-16 14:42 - 2014-10-16 14:46 - 00000000 ____D () C:\Users\lang\AppData\Roaming\mIRC

2014-10-16 13:14 - 2014-10-16 13:21 - 00000000 ____D () C:\AdwCleaner

2014-10-16 12:50 - 2014-10-16 12:50 - 00000000 ____D () C:\Windows\ERUNT

2014-10-16 12:31 - 2014-10-23 01:00 - 00000000 ____D () C:\FRST

2014-10-15 14:05 - 2014-10-15 14:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET

2014-10-15 04:15 - 2014-10-15 04:14 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll

2014-10-15 04:14 - 2014-10-15 04:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

2014-10-15 04:14 - 2014-10-15 04:14 - 00000000 ____D () C:\Program Files (x86)\Java

2014-10-15 01:55 - 2014-10-22 00:32 - 00000000 ___RD () C:\Users\lang\Dropbox

2014-10-15 01:38 - 2014-10-22 00:32 - 00000000 ____D () C:\Users\lang\AppData\Roaming\Dropbox

2014-10-15 01:38 - 2014-10-15 04:21 - 00000000 ____D () C:\Users\lang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

2014-10-15 01:28 - 2014-10-23 00:55 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update

2014-10-15 01:28 - 2014-10-16 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast

2014-10-15 01:28 - 2014-10-15 01:28 - 00000000 ____D () C:\Users\lang\AppData\Roaming\AVAST Software

2014-10-15 01:27 - 2014-10-15 01:28 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys

2014-10-15 01:27 - 2014-10-15 01:27 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys

2014-10-15 01:27 - 2014-10-15 01:27 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe

2014-10-15 01:27 - 2014-10-15 01:27 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys

2014-10-15 01:27 - 2014-10-15 01:27 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys

2014-10-15 01:27 - 2014-10-15 01:27 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys

2014-10-15 01:27 - 2014-10-15 01:27 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys

2014-10-15 01:27 - 2014-10-15 01:27 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys

2014-10-15 01:27 - 2014-10-15 01:27 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr

2014-10-15 01:27 - 2014-10-15 01:27 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys

2014-10-15 01:26 - 2014-10-15 01:26 - 00000000 ____D () C:\Program Files\AVAST Software

2014-10-15 01:19 - 2014-10-15 01:25 - 00001945 _____ () C:\Windows\epplauncher.mif

2014-10-14 19:52 - 2014-10-06 22:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll

2014-10-14 19:52 - 2014-10-06 22:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll

2014-10-14 19:52 - 2014-09-28 20:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

2014-10-14 19:52 - 2014-09-25 18:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2014-10-14 19:52 - 2014-09-25 18:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2014-10-14 19:52 - 2014-09-25 18:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2014-10-14 19:52 - 2014-09-25 18:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2014-10-14 19:52 - 2014-09-25 18:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2014-10-14 19:52 - 2014-09-25 18:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl

2014-10-14 19:52 - 2014-09-18 21:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb

2014-10-14 19:52 - 2014-09-18 21:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll

2014-10-14 19:52 - 2014-09-18 21:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2014-10-14 19:52 - 2014-09-18 21:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll

2014-10-14 19:52 - 2014-09-18 21:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll

2014-10-14 19:52 - 2014-09-18 21:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll

2014-10-14 19:52 - 2014-09-18 21:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe

2014-10-14 19:52 - 2014-09-18 21:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2014-10-14 19:52 - 2014-09-18 21:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll

2014-10-14 19:52 - 2014-09-18 21:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll

2014-10-14 19:52 - 2014-09-18 21:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2014-10-14 19:52 - 2014-09-18 21:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll

2014-10-14 19:52 - 2014-09-18 20:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2014-10-14 19:52 - 2014-09-18 20:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2014-10-14 19:52 - 2014-09-18 20:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2014-10-14 19:52 - 2014-09-18 20:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2014-10-14 19:52 - 2014-09-18 20:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll

2014-10-14 19:52 - 2014-09-18 20:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll

2014-10-14 19:52 - 2014-09-18 20:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe

2014-10-14 19:52 - 2014-09-18 20:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll

2014-10-14 19:52 - 2014-09-18 20:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2014-10-14 19:52 - 2014-09-18 20:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll

2014-10-14 19:52 - 2014-09-18 19:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2014-10-14 19:52 - 2014-08-18 23:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi

2014-10-14 19:52 - 2014-08-18 23:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi

2014-10-14 19:52 - 2014-08-18 23:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll

2014-10-14 19:52 - 2014-08-18 23:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll

2014-10-14 19:52 - 2014-08-18 23:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll

2014-10-14 19:52 - 2014-08-18 23:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe

2014-10-14 19:52 - 2014-08-18 23:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe

2014-10-14 19:52 - 2014-08-18 23:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll

2014-10-14 19:52 - 2014-08-18 23:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll

2014-10-14 19:52 - 2014-08-18 23:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe

2014-10-14 19:52 - 2014-08-18 22:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll

2014-10-14 19:52 - 2014-08-18 22:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll

2014-10-14 19:52 - 2014-08-18 22:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys

2014-10-14 19:52 - 2014-07-06 22:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll

2014-10-14 19:52 - 2014-07-06 22:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll

2014-10-14 19:52 - 2014-07-06 22:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe

2014-10-14 19:52 - 2014-07-06 22:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe

2014-10-14 19:52 - 2014-07-06 22:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe

2014-10-14 19:52 - 2014-07-06 22:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll

2014-10-14 19:52 - 2014-07-06 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx

2014-10-14 19:52 - 2014-07-06 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll

2014-10-14 19:52 - 2014-07-06 22:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL

2014-10-14 19:52 - 2014-07-06 22:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe

2014-10-14 19:52 - 2014-07-06 22:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll

2014-10-14 19:52 - 2014-07-06 21:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys

2014-10-14 19:52 - 2014-07-06 21:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll

2014-10-14 19:52 - 2014-07-06 21:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx

2014-10-14 19:52 - 2014-07-06 21:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll

2014-10-14 19:52 - 2014-07-06 21:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL

2014-10-14 19:52 - 2014-07-06 21:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe

2014-10-14 19:52 - 2014-07-06 21:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe

2014-10-14 19:52 - 2014-07-06 21:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe

2014-10-14 19:52 - 2014-07-06 21:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe

2014-10-14 19:52 - 2014-07-06 21:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll

2014-10-14 19:52 - 2014-06-27 20:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe

2014-10-14 19:52 - 2014-06-27 20:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe

2014-10-14 19:52 - 2014-06-27 20:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll

2014-10-14 19:52 - 2014-06-18 18:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll

2014-10-14 19:52 - 2014-06-18 18:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll

2014-10-14 19:52 - 2014-06-18 18:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll

2014-10-14 19:52 - 2014-06-18 18:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll

2014-10-14 19:52 - 2014-06-18 18:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll

2014-10-14 19:52 - 2014-06-18 18:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll

2014-10-14 19:51 - 2014-09-25 18:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll

2014-10-14 19:51 - 2014-09-18 22:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll

2014-10-14 19:51 - 2014-09-18 21:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll

2014-10-14 19:51 - 2014-09-18 21:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll

2014-10-14 19:51 - 2014-09-18 21:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll

2014-10-14 19:51 - 2014-09-18 21:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll

2014-10-14 19:51 - 2014-09-18 21:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll

2014-10-14 19:51 - 2014-09-18 21:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll

2014-10-14 19:51 - 2014-09-18 21:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe

2014-10-14 19:51 - 2014-09-18 21:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2014-10-14 19:51 - 2014-09-18 21:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll

2014-10-14 19:51 - 2014-09-18 21:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe

2014-10-14 19:51 - 2014-09-18 21:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2014-10-14 19:51 - 2014-09-18 21:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll

2014-10-14 19:51 - 2014-09-18 21:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll

2014-10-14 19:51 - 2014-09-18 20:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll

2014-10-14 19:51 - 2014-09-18 20:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll

2014-10-14 19:51 - 2014-09-18 20:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2014-10-14 19:51 - 2014-09-18 20:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll

2014-10-14 19:51 - 2014-09-18 20:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll

2014-10-14 19:51 - 2014-09-18 20:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll

2014-10-14 19:51 - 2014-09-18 20:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll

2014-10-14 19:51 - 2014-09-18 19:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2014-10-14 19:51 - 2014-09-18 19:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll

2014-10-14 19:51 - 2014-09-18 19:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

2014-10-14 19:51 - 2014-09-17 22:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll

2014-10-14 19:51 - 2014-09-17 21:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll

2014-10-14 19:51 - 2014-09-12 21:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll

2014-10-14 19:51 - 2014-09-12 21:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll

2014-10-14 19:51 - 2014-09-04 22:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll

2014-10-14 19:51 - 2014-09-04 21:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll

2014-10-14 19:51 - 2014-09-04 01:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll

2014-10-14 19:51 - 2014-09-04 01:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll

2014-10-14 19:51 - 2014-08-28 22:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll

2014-10-14 19:51 - 2014-07-16 22:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll

2014-10-14 19:51 - 2014-07-16 22:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe

2014-10-14 19:51 - 2014-07-16 22:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll

2014-10-14 19:51 - 2014-07-16 22:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll

2014-10-14 19:51 - 2014-07-16 22:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll

2014-10-14 19:51 - 2014-07-16 22:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll

2014-10-14 19:51 - 2014-07-16 21:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll

2014-10-14 19:51 - 2014-07-16 21:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll

2014-10-14 19:51 - 2014-07-16 21:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll

2014-10-14 19:51 - 2014-07-16 21:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys

2014-10-14 19:51 - 2014-07-16 21:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys

2014-10-01 00:15 - 2014-09-24 22:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll

2014-10-01 00:15 - 2014-09-24 21:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll

2014-09-24 13:29 - 2014-09-24 13:29 - 00000000 ____D () C:\Users\lang\AppData\Roaming\Oracle

2014-09-24 05:07 - 2014-09-09 18:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll

2014-09-24 05:07 - 2014-09-09 17:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll

 

==================== One Month Modified Files and Folders =======

 

(If an entry is included in the fixlist, the file\folder will be moved.)

 

2014-10-23 01:00 - 2013-02-08 22:26 - 00000000 ____D () C:\Users\lang\AppData\Roaming\uTorrent

2014-10-23 00:37 - 2013-09-23 23:00 - 00000000 ___HD () C:\Users\Public\Fundata

2014-10-23 00:26 - 2013-04-18 11:38 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job

2014-10-23 00:23 - 2014-02-07 05:46 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2014-10-23 00:14 - 2014-07-03 12:22 - 00000000 ___HD () C:\Users\Public\FunAcce

2014-10-22 22:11 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\migwiz

2014-10-22 19:59 - 2013-02-08 22:03 - 01907216 _____ () C:\Windows\WindowsUpdate.log

2014-10-22 16:23 - 2014-02-07 05:46 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2014-10-22 14:11 - 2014-07-14 22:06 - 00000000 ____D () C:\Users\lang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox

2014-10-22 14:11 - 2014-07-14 22:06 - 00000000 ____D () C:\Users\lang\AppData\Local\Roblox

2014-10-22 00:39 - 2009-07-14 00:45 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2014-10-22 00:39 - 2009-07-14 00:45 - 00026576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2014-10-22 00:38 - 2014-05-07 22:56 - 00421078 _____ () C:\Windows\system32\perfh011.dat

2014-10-22 00:38 - 2014-05-07 22:56 - 00126268 _____ () C:\Windows\system32\perfc011.dat

2014-10-22 00:38 - 2014-05-07 22:53 - 00513714 _____ () C:\Windows\system32\perfh006.dat

2014-10-22 00:38 - 2014-05-07 22:53 - 00102826 _____ () C:\Windows\system32\perfc006.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00749756 _____ () C:\Windows\system32\perfh00A.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00747798 _____ () C:\Windows\system32\perfh013.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00744658 _____ () C:\Windows\system32\perfh015.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00733318 _____ () C:\Windows\system32\prfh0816.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00728900 _____ () C:\Windows\system32\perfh019.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00718180 _____ () C:\Windows\system32\prfh0416.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00688054 _____ () C:\Windows\system32\perfh00E.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00673140 _____ () C:\Windows\system32\perfh005.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00668020 _____ () C:\Windows\system32\perfh01D.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00660982 _____ () C:\Windows\system32\perfh01F.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00611288 _____ () C:\Windows\system32\perfh008.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00498814 _____ () C:\Windows\system32\perfh014.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00485802 _____ () C:\Windows\system32\perfh00B.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00432724 _____ () C:\Windows\system32\perfh012.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00402642 _____ () C:\Windows\system32\prfh0404.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00385470 _____ () C:\Windows\system32\prfh0804.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00175442 _____ () C:\Windows\system32\perfc00E.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00162642 _____ () C:\Windows\system32\perfc00A.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00160040 _____ () C:\Windows\system32\perfc015.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00157270 _____ () C:\Windows\system32\perfc013.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00157074 _____ () C:\Windows\system32\prfc0816.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00155010 _____ () C:\Windows\system32\perfc019.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00151824 _____ () C:\Windows\system32\prfc0416.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00146642 _____ () C:\Windows\system32\perfc01D.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00145594 _____ () C:\Windows\system32\perfc005.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00144168 _____ () C:\Windows\system32\perfc01F.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00124552 _____ () C:\Windows\system32\perfc012.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00123760 _____ () C:\Windows\system32\prfc0804.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00119258 _____ () C:\Windows\system32\prfc0404.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00115296 _____ () C:\Windows\system32\perfc008.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00105688 _____ () C:\Windows\system32\perfc00B.dat

2014-10-22 00:38 - 2014-04-18 12:12 - 00099572 _____ () C:\Windows\system32\perfc014.dat

2014-10-22 00:38 - 2014-04-18 02:41 - 00396644 _____ () C:\Windows\system32\perfh00D.dat

2014-10-22 00:38 - 2014-04-18 02:41 - 00088926 _____ () C:\Windows\system32\perfc00D.dat

2014-10-22 00:38 - 2014-04-18 02:37 - 00744346 _____ () C:\Windows\system32\perfh010.dat

2014-10-22 00:38 - 2014-04-18 02:37 - 00151014 _____ () C:\Windows\system32\perfc010.dat

2014-10-22 00:38 - 2014-04-18 02:35 - 00750016 _____ () C:\Windows\system32\perfh00C.dat

2014-10-22 00:38 - 2014-04-18 02:35 - 00483314 _____ () C:\Windows\system32\perfh001.dat

2014-10-22 00:38 - 2014-04-18 02:35 - 00153748 _____ () C:\Windows\system32\perfc00C.dat

2014-10-22 00:38 - 2014-04-18 02:35 - 00098940 _____ () C:\Windows\system32\perfc001.dat

2014-10-22 00:38 - 2014-04-18 02:31 - 00701508 _____ () C:\Windows\system32\perfh007.dat

2014-10-22 00:38 - 2014-04-18 02:31 - 00153284 _____ () C:\Windows\system32\perfc007.dat

2014-10-22 00:38 - 2009-07-14 01:13 - 17444788 _____ () C:\Windows\system32\PerfStringBackup.INI

2014-10-22 00:32 - 2014-07-04 02:33 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2014-10-22 00:32 - 2013-02-08 22:08 - 00000000 ____D () C:\ProgramData\NVIDIA

2014-10-22 00:32 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT

2014-10-22 00:32 - 2009-07-14 00:51 - 00114185 _____ () C:\Windows\setupact.log

2014-10-17 17:19 - 2014-07-14 22:07 - 00001346 _____ () C:\Users\lang\Desktop\ROBLOX Player.lnk

2014-10-17 16:18 - 2014-02-07 05:46 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA

2014-10-17 16:18 - 2014-02-07 05:46 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

2014-10-16 15:55 - 2010-11-20 23:47 - 02496462 _____ () C:\Windows\PFRO.log

2014-10-16 14:17 - 2009-07-14 01:08 - 00032568 _____ () C:\Windows\Tasks\SCHEDLGU.TXT

2014-10-16 12:45 - 2013-02-08 22:03 - 00000000 ____D () C:\Users\lang

2014-10-16 12:27 - 2013-02-10 03:57 - 00000000 ____D () C:\Users\lang\AppData\Local\Deployment

2014-10-15 17:46 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache

2014-10-15 04:19 - 2009-07-14 01:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD

2014-10-15 04:18 - 2009-07-14 00:45 - 00278656 _____ () C:\Windows\system32\FNTCACHE.DAT

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\uk-UA

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\th-TH

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\sr-Latn-CS

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\sl-SI

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\ro-RO

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\lv-LV

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\lt-LT

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\hr-HR

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\he-IL

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\et-EE

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\bg-BG

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\ar-SA

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\uk-UA

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\tr-TR

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\th-TH

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\sr-Latn-CS

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\sl-SI

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\sk-SK

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\ro-RO

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\lv-LV

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\lt-LT

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\hr-HR

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\he-IL

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\et-EE

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\bg-BG

2014-10-15 04:17 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\ar-SA

2014-10-15 04:14 - 2013-10-25 04:26 - 00000000 ____D () C:\ProgramData\Oracle

2014-10-15 02:01 - 2013-02-08 22:46 - 00000000 ____D () C:\Users\lang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

2014-10-15 02:01 - 2013-02-08 22:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR

2014-10-15 01:59 - 2013-09-24 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX

2014-10-15 01:59 - 2013-09-24 15:52 - 00000000 ____D () C:\Program Files\DivX

2014-10-15 01:59 - 2013-09-24 15:52 - 00000000 ____D () C:\Program Files (x86)\DivX

2014-10-15 01:59 - 2013-09-24 15:51 - 00000000 ____D () C:\ProgramData\DivX

2014-10-15 01:28 - 2013-07-14 21:44 - 00000000 ____D () C:\Windows\system32\MRT

2014-10-15 01:27 - 2013-02-08 22:03 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

2014-10-15 01:26 - 2013-02-09 04:41 - 00000000 ____D () C:\ProgramData\AVAST Software

2014-10-14 01:59 - 2014-04-21 22:00 - 00000000 ____D () C:\Users\lang\AppData\Roaming\CloudMedia

2014-10-10 00:57 - 2014-02-06 01:46 - 00000000 ____D () C:\Users\lang\AppData\Local\CrashDumps

2014-10-04 02:42 - 2014-07-29 10:25 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll

2014-10-04 02:42 - 2014-04-18 01:38 - 02197680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll

2014-10-04 02:41 - 2014-07-29 10:25 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll

2014-10-04 02:41 - 2014-04-18 01:38 - 02800296 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll

2014-10-03 18:13 - 2014-09-19 19:42 - 00000000 ____D () C:\ProgramData\boost_interprocess

2014-10-02 15:53 - 2010-11-20 23:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

2014-09-24 05:26 - 2014-09-10 02:26 - 03675824 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe

2014-09-24 05:26 - 2013-04-18 11:38 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater

2014-09-24 05:26 - 2013-03-19 13:28 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2014-09-24 05:26 - 2013-03-19 13:28 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

 

Some content of TEMP:

====================

C:\Users\lang\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpx1rbzs.dll

C:\Users\lang\AppData\Local\Temp\mirc736.exe

C:\Users\lang\AppData\Local\Temp\uninstall.exe

 

 

==================== Bamital & volsnap Check =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\System32\winlogon.exe => File is digitally signed

C:\Windows\System32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\System32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\System32\services.exe => File is digitally signed

C:\Windows\System32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\System32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\System32\rpcss.dll => File is digitally signed

C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2014-10-16 00:56

 

==================== End Of Log ============================

 

 

Addition.txt

FRST.txt

Link to post
Share on other sites

Hello,
    
 
They call me TwinHeadedEagle around here, and I'll be working with you.
 
     
    
Before we start please read and note the following:

  • Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
  • Please be patient. I know it is frustrating when your PC isn't working properly, but malware removal takes time.
  • Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
  • Do not paste the logs in your posts, attachments make my work easier. There is a More reply options button, that gives you Upload Files option below which you can use to attach your reports. Always attach reports from all tools.
  • Always execute my instructions in given order. If for some reason you cannot completely follow one instruction, inform me about that.
  • Stay with me to the end, the absence of symptoms doesn't mean that your machine is fully operational.
  • Note that we may live in totally different time zones, what may cause some delays between answers.
  • Do not ask for help for your business PC. Companies are making revenue via computers, so it is good thing to pay someone to repair it.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.

:excl: I can't foresee everything, so if anything unexpected happens, please stop and inform me!
:excl: There are no silly questions. Never be afraid to ask if in doubt!
 
 
 
  warning.gif Rules and policies
 
We won't support any piracy.
That being told, if any evidence of illegal OS, software, cracks/keygens or any other will be revealed, any further assistance will be suspended. If you are aware that there is this kind of stuff on your machine, remove it before proceeding!
The same applies to any use of P2P software: uTorrent, BitTorrent, Vuze, Kazaa, Ares... We don't provide any help for P2P, except for their removal. All P2P software has to be uninstalled or at least fully disabled before proceeding!
 
Failure to follow these guidelines will result with closing your topic and withdrawning any assistance.
 
 
 
 

51a46ae42d560-malwarebytes_anti_malware. Scan with Malwarebytes' Anti-Malware
 
Please download Malwarebytes Anti-Malware and save it to your desktop.

  • Install the progam and select update.
  • Once updated, click the Settings tab, in the left panel choose Detection & Protection and tick Scan for rootkits.
  • Click the Scan tab, choose Threat Scan is checked and click Scan Now.
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • At the bottom click Export and choose Text file.

Save the file to your desktop and include its content in your next reply.
 
 
 
 

adwcleaner_new.png Fix with AdwCleaner
 
Please download AdwCleaner by Xplode and save the file to your Desktop.

  • Right-click on adwcleaner_new.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait until the database is updated.
  • Accept the Terms of use and click Scan.
  • When finished, please click Clean.
  • Upon completion, click Report. A log (AdwCleaner[s*].txt) will open.

Please include the contents of that file in your reply.
 
Note: Reports will be saved in your system partition, usually at C:\Adwcleaner
 
 
 
 

FRST.gif Scan with Farbar Recovery Scan Tool
 
Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

Link to post
Share on other sites

FRST.gif Fix with Farbar Recovery Scan Tool
 


icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

 
Download attached fixlist.txt file and save it to the Desktop:
 
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.

fixlist.txt

Link to post
Share on other sites

Don't worry, your more than welcome :)
 
 
 
Glad I could help. We will delete all used tools and I'll give you some tips to harden your security and learn how to protect yourself :)
 
 

Recommended reading:

 
 
icon_exclaim.gifMUST READ - security tips:

icon_exclaim.gifMUST READ - general maintenance:

The Importance of Software Updating:

 

 
In order to stay protected it is very important that you regularly update all of your software. Cybercriminals depend on the apathy of users around software updates to keep their malicious endeavor running.
 
Operating systems, such as Windows, and applications, such as Adobe Reader or JAVA, are used by tens of millions of computers and devices around the world, making them a huge target for cybercriminals. Downloading updates and installing them can sometimes be tedious, but the advantages you get from the updates are certainly worth it.

Recommended additional software:

 
 
icon_arrow.gifTFC - to clean unneeded temporary files.
icon_arrow.gifMalwarebytes' Anti-Malware - to scan your system from time to time in search for malware.
icon_arrow.gifMalwarebytes' Anti-Exploit - to prevent plenty of mostly exploited vulnerabilities.
icon_arrow.gifMcShield - to prevent infections spread by removable media.
icon_arrow.gifUnchecky - to prevent from installing additional foistware, implemented in legitimate installations.
icon_arrow.gifFiheHippo.com Update Checker - to keep your programs up-to-date.
icon_arrow.gifAdblock - to surf the web without annoying ads! 
 
 

Post-cleanup procedures:

 

 
Download DelFix by Xplode and save it to your desktop.

  • Run the tool by right click on the 51a5ce45263de-delfix.png icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run.
  • The program will run for a few seconds and display a notepad report. You do not need to attach it.

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning. 
 
 
 


My help is free for everybody.

If you're happy with the help provided and/or wish to buy me a beer for the assistance you received, then you can consider a donation: xbtn_donate_SM.gif.pagespeed.ic.MMi5tqVp

Thank you!

 
 
Stay safe,
TwinHeadedEagle   :)

Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.