Dear all,

It seems I have picked up a nasty NanaCore virus and also keep getting the "Do you want to install NanoCore?" dialog.

I looked into it and it seems NanoCore is a commercially available virus/RAT.

I have run Bitdefender and it picked up nothing. I ran Malwarebytes and that picked up two trojans which I deleted. However, this dubious prompt is still coming up.

The dialog seems to be triggered by RegSvcs.exe in C:\Windows\Microsoft.NET\Framework\v4.0.30319\

I will post my FRST result below.

Any help would be seriously appreciated.

2016-11-09 13:21 - 2016-10-25 05:34 - 00687616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-11-09 13:21 - 2016-10-25 05:34 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-11-09 13:21 - 2016-10-25 05:32 - 02050048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-11-09 13:21 - 2016-10-25 05:30 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-11-09 13:21 - 2016-10-25 05:28 - 02800128 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2016-11-09 13:21 - 2016-10-25 05:28 - 01526272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-11-09 13:21 - 2016-10-25 05:19 - 16984576 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2016-11-09 13:21 - 2016-10-25 05:17 - 04895744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-11-09 13:21 - 2016-10-25 05:14 - 00651776 _____ (Microsoft Corporation) C:\Windows\system32\UserLanguagesCpl.dll
2016-11-09 13:21 - 2016-10-25 05:13 - 22375936 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-11-09 13:21 - 2016-10-25 05:12 - 11544576 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2016-11-09 13:21 - 2016-10-25 05:10 - 01568256 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2016-11-09 13:21 - 2016-10-25 05:05 - 06312448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2016-11-09 13:21 - 2016-10-25 05:02 - 24610304 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-11-09 13:21 - 2016-10-25 05:02 - 06976512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-11-09 13:21 - 2016-10-25 05:02 - 03994624 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2016-11-09 13:21 - 2016-10-25 05:02 - 03459584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2016-11-09 13:21 - 2016-10-25 05:01 - 13392384 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-11-09 13:21 - 2016-10-25 04:48 - 07838208 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-11-09 13:21 - 2016-10-25 04:45 - 18673664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-11-09 13:21 - 2016-10-25 04:44 - 19348480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-11-09 13:21 - 2016-10-25 04:44 - 12134400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-11-09 13:21 - 2016-10-25 04:43 - 03664384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-11-09 13:21 - 2016-10-25 04:26 - 05660160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-11-09 13:21 - 2016-10-25 02:19 - 00775336 _____ C:\Windows\SysWOW64\locale.nls
2016-11-09 13:21 - 2016-10-25 02:19 - 00775336 _____ C:\Windows\system32\locale.nls
2016-11-09 13:21 - 2016-10-25 01:47 - 00445873 _____ C:\Windows\system32\ApnDatabase.xml
2016-11-09 13:21 - 2016-09-07 05:22 - 00604920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-11-09 13:21 - 2016-01-05 01:45 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll
2016-11-09 13:20 - 2016-11-02 15:12 - 00379232 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-11-09 13:20 - 2016-11-02 14:25 - 00045568 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-11-09 13:20 - 2016-10-25 09:44 - 01030416 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-11-09 13:20 - 2016-10-25 09:42 - 00037744 _____ (Microsoft Corporation) C:\Windows\system32\wldp.dll
2016-11-09 13:20 - 2016-10-25 09:39 - 01238584 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe
2016-11-09 13:20 - 2016-10-25 09:39 - 00754664 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2016-11-09 13:20 - 2016-10-25 09:26 - 00528736 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2016-11-09 13:20 - 2016-10-25 08:38 - 00374008 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2016-11-09 13:20 - 2016-10-25 08:37 - 01603224 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2016-11-09 13:20 - 2016-10-25 08:37 - 00725776 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2016-11-09 13:20 - 2016-10-25 08:36 - 01540216 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-11-09 13:20 - 2016-10-25 08:36 - 00692136 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-11-09 13:20 - 2016-10-25 08:34 - 01128104 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2016-11-09 13:20 - 2016-10-25 08:34 - 00625000 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2016-11-09 13:20 - 2016-10-25 08:34 - 00106928 _____ (Microsoft Corporation) C:\Windows\system32\phoneactivate.exe
2016-11-09 13:20 - 2016-10-25 08:33 - 00341936 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2016-11-09 13:20 - 2016-10-25 08:01 - 00324448 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2016-11-09 13:20 - 2016-10-25 07:46 - 00376528 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MediaControl.dll
2016-11-09 13:20 - 2016-10-25 07:32 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\msctfp.dll
2016-11-09 13:20 - 2016-10-25 07:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\vss_ps.dll
2016-11-09 13:20 - 2016-10-25 07:21 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2016-11-09 13:20 - 2016-10-25 07:19 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2016-11-09 13:20 - 2016-10-25 07:13 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\SCardDlg.dll
2016-11-09 13:20 - 2016-10-25 07:13 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\HttpsDataSource.dll
2016-11-09 13:20 - 2016-10-25 07:12 - 00221696 _____ (Microsoft Corporation) C:\Windows\system32\NPSMDesktopProvider.dll
2016-11-09 13:20 - 2016-10-25 07:10 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\NPSM.dll
2016-11-09 13:20 - 2016-10-25 07:09 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\oemlicense.dll
2016-11-09 13:20 - 2016-10-25 07:05 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\FingerprintEnrollment.dll
2016-11-09 13:20 - 2016-10-25 07:02 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\IdCtrls.dll
2016-11-09 13:20 - 2016-10-25 06:59 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-11-09 13:20 - 2016-10-25 06:59 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2016-11-09 13:20 - 2016-10-25 06:59 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\fhsvc.dll
2016-11-09 13:20 - 2016-10-25 06:59 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2016-11-09 13:20 - 2016-10-25 06:58 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2016-11-09 13:20 - 2016-10-25 06:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2016-11-09 13:20 - 2016-10-25 06:57 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2016-11-09 13:20 - 2016-10-25 06:56 - 00301056 _____ (Microsoft Corporation) C:\Windows\system32\Dxpserver.exe
2016-11-09 13:20 - 2016-10-25 06:55 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2016-11-09 13:20 - 2016-10-25 06:55 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\NetworkDesktopSettings.dll
2016-11-09 13:20 - 2016-10-25 06:54 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.PicturePassword.dll
2016-11-09 13:20 - 2016-10-25 06:53 - 00714240 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
2016-11-09 13:20 - 2016-10-25 06:53 - 00567808 _____ (Microsoft Corporation) C:\Windows\system32\AdmTmpl.dll
2016-11-09 13:20 - 2016-10-25 06:52 - 00475648 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2016-11-09 13:20 - 2016-10-25 06:52 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\APHostService.dll
2016-11-09 13:20 - 2016-10-25 06:51 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2016-11-09 13:20 - 2016-10-25 06:51 - 00469504 _____ (Microsoft Corporation) C:\Windows\system32\fhsettingsprovider.dll
2016-11-09 13:20 - 2016-10-25 06:51 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\ExecModelClient.dll
2016-11-09 13:20 - 2016-10-25 06:50 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_StorageSense.dll
2016-11-09 13:20 - 2016-10-25 06:50 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2016-11-09 13:20 - 2016-10-25 06:47 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2016-11-09 13:20 - 2016-10-25 06:47 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2016-11-09 13:20 - 2016-10-25 06:47 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\edputil.dll
2016-11-09 13:20 - 2016-10-25 06:45 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
2016-11-09 13:20 - 2016-10-25 06:44 - 01479168 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll
2016-11-09 13:20 - 2016-10-25 06:44 - 00602112 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2016-11-09 13:20 - 2016-10-25 06:43 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\certreq.exe
2016-11-09 13:20 - 2016-10-25 06:42 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2016-11-09 13:20 - 2016-10-25 06:41 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.UserAccountsHandlers.dll
2016-11-09 13:20 - 2016-10-25 06:41 - 00484352 _____ (Microsoft Corporation) C:\Windows\system32\DataSenseHandlers.dll
2016-11-09 13:20 - 2016-10-25 06:41 - 00356864 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2016-11-09 13:20 - 2016-10-25 06:40 - 00555520 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnrGidsHandler.dll
2016-11-09 13:20 - 2016-10-25 06:38 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
2016-11-09 13:20 - 2016-10-25 06:38 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2016-11-09 13:20 - 2016-10-25 06:38 - 00480768 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll
2016-11-09 13:20 - 2016-10-25 06:37 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Bluetooth.dll
2016-11-09 13:20 - 2016-10-25 06:37 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2016-11-09 13:20 - 2016-10-25 06:35 - 00515072 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-11-09 13:20 - 2016-10-25 06:34 - 00436736 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-11-09 13:20 - 2016-10-25 06:33 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2016-11-09 13:20 - 2016-10-25 06:32 - 01037824 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2016-11-09 13:20 - 2016-10-25 06:32 - 00990208 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2016-11-09 13:20 - 2016-10-25 06:32 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2016-11-09 13:20 - 2016-10-25 06:32 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\syncutil.dll
2016-11-09 13:20 - 2016-10-25 06:29 - 01575936 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
2016-11-09 13:20 - 2016-10-25 06:27 - 02731008 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2016-11-09 13:20 - 2016-10-25 06:24 - 04456448 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2016-11-09 13:20 - 2016-10-25 06:24 - 01211904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Cred.dll
2016-11-09 13:20 - 2016-10-25 06:23 - 01073152 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2016-11-09 13:20 - 2016-10-25 06:22 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
2016-11-09 13:20 - 2016-10-25 06:21 - 01570816 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2016-11-09 13:20 - 2016-10-25 06:21 - 00236032 _____ (Microsoft Corporation) C:\Windows\system32\licensingdiag.exe
2016-11-09 13:20 - 2016-10-25 06:16 - 03415040 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2016-11-09 13:20 - 2016-10-25 06:11 - 00701952 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.dll
2016-11-09 13:20 - 2016-10-25 06:09 - 00584704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2016-11-09 13:20 - 2016-10-25 06:03 - 06675968 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe
2016-11-09 13:20 - 2016-10-25 06:01 - 01755648 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2016-11-09 13:20 - 2016-10-25 05:52 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\internetmail.dll
2016-11-09 13:20 - 2016-10-25 05:47 - 03355136 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2016-11-09 13:20 - 2016-10-25 05:47 - 00453632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AdmTmpl.dll
2016-11-09 13:20 - 2016-10-25 05:40 - 00984576 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2016-11-09 13:20 - 2016-10-25 05:35 - 02902528 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2016-11-09 13:20 - 2016-10-25 05:26 - 02563584 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2016-11-09 13:20 - 2016-10-25 05:20 - 01797120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2016-11-09 13:20 - 2016-10-25 05:13 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-11-09 13:20 - 2016-10-25 05:10 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2016-11-09 13:20 - 2016-10-25 05:05 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-11-09 13:20 - 2016-10-25 05:03 - 00636928 _____ (Microsoft Corporation) C:\Windows\system32\hgcpl.dll
2016-11-09 13:20 - 2016-10-25 04:44 - 01087488 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2016-11-09 13:20 - 2016-10-25 04:43 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\GlobCollationHost.dll
One Month Modified files and folders
If an entry is included in the fixlist, the file/folder will be moved.
2016-12-09 17:17 - 2016-10-20 08:47 - 00000000 ____D C:\Users\Jason\Documents\Outlook
2016-12-09 17:10 - 2016-10-20 01:05 - 00000928 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-09 16:59 - 2016-10-20 19:20 - 00004164 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9C16B1BD-782D-43E2-9AEB-BB58837C0402}
2016-12-09 16:53 - 2016-10-20 08:42 - 00000000 ____D C:\Program Files\Bitdefender Agent
2016-12-09 12:46 - 2015-10-30 07:24 - 00000000 ____D C:\Windows\AppReadiness
2016-12-09 04:26 - 2015-10-30 07:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-12-09 04:06 - 2016-10-20 16:49 - 00000000 ____D C:\Users\Jason\AppData\Local\Adobe
2016-12-09 03:59 - 2016-10-23 21:45 - 00000000 ____D C:\Users\Public\Documents\AdobeGC
2016-12-09 03:49 - 2015-10-30 06:28 - 00065536 ___SH C:\Windows\system32\config\ELAM
2016-12-09 03:47 - 2016-10-20 01:05 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-09 03:46 - 2016-10-20 10:20 - 00000000 ____D C:\ProgramData\Reprise
2016-12-09 03:45 - 2016-10-20 01:03 - 00000000 ____D C:\ProgramData\NVIDIA
2016-12-09 03:45 - 2016-10-20 00:44 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-12-09 03:44 - 2015-10-30 06:28 - 00524288 ___SH C:\Windows\system32\config\BBI
2016-12-08 23:17 - 2016-10-20 09:00 - 00016513 _____ C:\bdlog.txt
2016-12-08 21:59 - 2016-10-20 00:40 - 06289728 _____ C:\Windows\system32\FNTCACHE.DAT
2016-12-08 21:58 - 2016-10-20 00:51 - 00000000 ____D C:\Users\Jason
2016-12-08 21:57 - 2016-10-20 01:59 - 00000000 ____D C:\Users\Jason\AppData\Roaming\uTorrent
2016-12-08 20:39 - 2016-10-20 01:01 - 00000000 ____D C:\ProgramData\Package Cache
2016-12-08 20:22 - 2016-10-20 00:51 - 00000000 ____D C:\Users\Jason\AppData\Local\Packages
2016-12-08 14:46 - 2016-10-20 08:56 - 00520032 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2016-12-08 06:01 - 2016-10-20 02:00 - 00000000 ____D C:\Users\Jason\AppData\LocalLow\uTorrent
2016-12-06 20:16 - 2016-10-20 17:46 - 00000982 _____ C:\Users\Jason\Desktop\Mattress.txt
2016-12-05 18:25 - 2016-10-28 06:07 - 00000000 ____D C:\Users\Jason\AppData\Roaming\vlc
2016-12-04 19:41 - 2016-10-24 21:56 - 00000000 ____D C:\Users\Jason\AppData\Local\CrashDumps
2016-12-04 19:30 - 2016-11-04 04:25 - 00000000 ____D C:\Users\Jason\FoundryAnalytics
2016-12-04 12:14 - 2016-11-08 10:48 - 00000000 ____D C:\Users\Jason\Downloads\BlacksOnBlondes.16.11.08.Katy.Jayne.XXX.1080p.MP4-KTR[rarbg]
2016-12-04 10:56 - 2016-10-20 00:56 - 00879220 _____ C:\Windows\system32\PerfStringBackup.INI
2016-12-04 10:56 - 2015-10-30 07:21 - 00000000 ____D C:\Windows\INF
2016-12-04 02:01 - 2016-10-20 17:46 - 00001308 _____ C:\Users\Jason\Desktop\Web hosts.txt
2016-12-03 20:10 - 2016-10-20 10:18 - 00000000 ____D C:\Users\Jason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Next Limit
2016-12-03 20:10 - 2016-10-20 10:17 - 00000000 ____D C:\Program Files\Next Limit
2016-12-03 19:24 - 2016-10-20 09:02 - 00000000 ____D C:\Users\Jason\Documents\realflow
2016-11-30 18:21 - 2016-10-20 08:47 - 00000000 ____D C:\Users\Jason\Documents\Medical Evidence
2016-11-29 19:49 - 2016-05-18 04:54 - 07684608 ____R (Side Effects Software Inc.) C:\Windows\system32\sesinetd.exe
2016-11-26 20:59 - 2016-10-20 17:45 - 00000000 ____D C:\Users\Jason\Desktop\Useful Keyboard Shortcuts
2016-11-26 19:26 - 2016-10-20 17:28 - 00000000 ____D C:\Users\Jason\Desktop\3D
2016-11-22 10:41 - 2016-10-20 17:44 - 00000000 ____D C:\Users\Jason\Desktop\Politics links
2016-11-21 12:23 - 2016-10-20 20:12 - 00000000 ____D C:\Program Files\Autodesk
2016-11-20 11:22 - 2016-10-24 22:03 - 00000000 ____D C:\Windows\SysWOW64\directx
2016-11-18 15:13 - 2016-10-20 08:58 - 00000000 ____D C:\ProgramData\BDLogging
2016-11-18 15:06 - 2016-10-20 00:51 - 00000000 ____D C:\Users\Jason\AppData\Roaming\Adobe
2016-11-18 11:10 - 2016-10-20 17:32 - 00000000 ____D C:\Users\Jason\Desktop\ESA Form
2016-11-18 10:49 - 2016-10-20 17:32 - 00000000 ____D C:\Users\Jason\Desktop\ESA
2016-11-18 10:17 - 2016-10-20 17:45 - 00000000 ____D C:\Users\Jason\Desktop\Useful Links
2016-11-18 09:40 - 2016-10-20 17:32 - 00000000 ____D C:\Users\Jason\Desktop\ESA Guidance
2016-11-18 07:27 - 2016-10-29 19:23 - 00000000 ____D C:\Users\Jason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Knald Technologies
2016-11-18 07:26 - 2016-10-29 19:22 - 00000000 ____D C:\Program Files\Knald Technologies
2016-11-17 12:56 - 2016-10-20 08:56 - 00182944 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2016-11-15 07:36 - 2016-10-20 17:45 - 00000000 ____D C:\Users\Jason\Desktop\Website
2016-11-15 06:48 - 2016-10-20 17:31 - 00000000 ____D C:\Users\Jason\Desktop\Dental
2016-11-15 06:28 - 2016-10-20 16:49 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2016-11-15 06:27 - 2016-10-20 17:19 - 00000000 ____D C:\Users\Jason\Documents\Adobe
2016-11-15 06:23 - 2016-10-20 17:03 - 00000000 ____D C:\Program Files\Adobe
2016-11-15 05:20 - 2016-11-04 04:19 - 00000000 ____D C:\ProgramData\Apple
2016-11-15 02:59 - 2016-10-20 08:49 - 00000000 ____D C:\Windows\Minidump
2016-11-14 21:11 - 2016-10-20 01:06 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-14 21:11 - 2016-10-20 01:06 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-11-14 10:16 - 2015-10-30 07:24 - 00000000 ____D C:\Windows\rescache
2016-11-13 08:38 - 2016-10-20 17:44 - 00000000 ____D C:\Users\Jason\Desktop\PIP
2016-11-12 11:31 - 2016-10-20 08:28 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-11-12 10:35 - 2016-11-08 02:38 - 00000000 ____D C:\Users\Jason\Downloads\CLO Enterprise 2.5.78 Win x64
2016-11-12 10:27 - 2015-10-30 07:24 - 00000000 ____D C:\Windows\system32\setup
2016-11-12 04:39 - 2015-10-30 07:17 - 00480256 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dplayx.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\dpnathlp.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnathlp.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpwsockx.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\dpnsvr.exe
2016-11-12 04:39 - 2015-10-30 07:17 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpmodemx.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnsvr.exe
2016-11-12 04:39 - 2015-10-30 07:17 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dplaysvr.exe
2016-11-12 04:39 - 2015-10-30 07:17 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dpnhupnp.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dpnhpast.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhupnp.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnhpast.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\dpnlobby.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnlobby.dll
2016-11-12 04:39 - 2015-10-30 07:17 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnaddr.dll
2016-11-12 04:39 - 2015-10-30 07:11 - 00000000 ____D C:\Windows\CbsTemp
2016-11-12 04:35 - 2016-10-20 10:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-11-12 04:25 - 2016-10-20 08:45 - 00000000 ____D C:\Program Files\Bitdefender
2016-11-12 04:22 - 2016-10-20 08:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2017
2016-11-12 03:51 - 2015-10-30 07:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-11-12 03:51 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-11-12 03:36 - 2016-10-26 19:38 - 00000000 ____D C:\Users\Jason\Documents\Allegorithmic
2016-11-12 03:36 - 2016-10-26 19:38 - 00000000 ____D C:\Users\Jason\AppData\Local\Allegorithmic
2016-11-12 03:35 - 2016-10-26 19:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allegorithmic
2016-11-12 03:35 - 2016-10-26 19:37 - 00000000 ____D C:\Program Files\Allegorithmic
2016-11-12 02:02 - 2016-10-20 10:21 - 00000000 ____D C:\Users\Jason\AppData\Roaming\MAXON
2016-11-12 00:56 - 2016-10-20 10:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON
2016-11-12 00:56 - 2016-10-20 10:00 - 00000000 ____D C:\Program Files\MAXON
2016-11-10 12:48 - 2015-10-30 07:24 - 00000000 ____D C:\Windows\system32\appraiser
2016-11-10 12:34 - 2015-10-30 07:24 - 00000000 ___SD C:\Windows\SysWOW64\F12
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ___SD C:\Windows\system32\F12
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ___RD C:\Windows\PrintDialog
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ___RD C:\Windows\DevicesFlow
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ____D C:\Windows\system32\oobe
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ____D C:\Windows\system32\migwiz
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ____D C:\Windows\Provisioning
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Defender
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-11-10 12:33 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-11-09 16:48 - 2015-10-30 07:24 - 00000167 _____ C:\Windows\win.ini
2016-11-09 16:47 - 2016-10-20 01:18 - 00000000 ____D C:\Windows\system32\MRT
2016-11-09 16:42 - 2016-10-20 01:18 - 141011376 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-11-09 01:08 - 2016-10-20 16:49 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
Files in the root of some directories
2016-10-20 18:31 - 2016-10-20 18:31 - 0000034 _____ () C:\Users\Jason\AppData\Roaming\AdobeWLCMCache.dat
2016-12-05 23:57 - 2016-12-05 23:57 - 1238528 _____ (Microsoft Corporation) C:\Users\Jason\AppData\Roaming\Local service.exe
2016-10-20 08:42 - 2016-10-20 08:42 - 0046528 _____ () C:\ProgramData\agent.1476952966.bdinstall.bin
2016-11-02 04:15 - 2016-11-02 04:15 - 0028756 _____ () C:\ProgramData\agent.1478060109.bdinstall.bin
2016-11-18 15:13 - 2016-11-18 15:13 - 0028189 _____ () C:\ProgramData\agent.1479482019.bdinstall.bin
2016-10-20 08:59 - 2016-10-20 08:59 - 0357562 _____ () C:\ProgramData\cl.1476953770.bdinstall.bin
2016-10-20 09:00 - 2016-10-20 09:00 - 0054516 _____ () C:\ProgramData\dm.1476954024.bdinstall.bin
2016-10-20 09:02 - 2016-10-20 09:02 - 0034918 _____ () C:\ProgramData\dm.1476954168.bdinstall.bin
2016-11-12 04:25 - 2016-11-12 04:25 - 0055173 _____ () C:\ProgramData\dm.1478924713.bdinstall.bin
2016-11-18 15:14 - 2016-11-18 15:14 - 0040026 _____ () C:\ProgramData\dm.1479482036.bdinstall.bin
Files to move or delete:
Bamital & volsnap
There is no automatic fix for files that do not pass verification.
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-12-07 01:09
==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-12-2016
Ran by Jason (09-12-2016 17:21:16)
Running from C:\Users\Jason\Desktop
Windows 10 Pro Version 1511 (X64) (2016-10-20 00:49:51)
µTorrent (HKU\S-1-5-21-3557252084-2468944355-21857965-1001\...\uTorrent) (Version: - BitTorrent Inc.)
ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Abrosoft FantaMorph Deluxe v5.4.1 (HKLM-x32\...\Abrosoft FantaMorph Deluxe v5. (Version: 5.4.1 - Friends in War)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated)
Adobe After Effects CC 2014 (HKLM-x32\...\{2B22C750-5C3B-4738-B621-BA786AC7A494}) (Version: 13.0.0 - Adobe Systems Incorporated)
Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.0 - Adobe Systems Incorporated)
Adobe Dreamweaver CC 2015 (HKLM-x32\...\{EE2A0AA8-0386-11E5-8603-BC82F5DB1A71}) (Version: 16.0.0 - Adobe Systems Incorporated)
Adobe Illustrator CC 2015 (HKLM-x32\...\{5680D629-B263-49CC-821E-3CEBD4507B51}) (Version: 19.0 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2014 (HKLM-x32\...\{663DEEEF-EF34-4DCB-8687-73A7AA146E02}) (Version: 8.0.0 - Adobe Systems Incorporated)
Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.0 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2015 (HKLM-x32\...\{38C72D42-0672-43B1-9E05-E7631684F9A1}) (Version: 9.0.0 - Adobe Systems Incorporated)
Allegorithmic Bitmap2Material 3.1.2 (HKLM-x32\...\Bitmap2Material_3) (Version: 3.1.2 build 17903 (2016-05-12) - Allegorithmic)
Allegorithmic Substance Designer 5.5.2 (HKLM\...\{25E7D16D-1FBA-49EA-BF36-E2D6B20A9206}_is1) (Version: 5.5.2 - Allegorithmic)
Ansel (Version: 373.06 - NVIDIA Corporation) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: - Apple Inc.)
Autodesk 3ds Max 2016 (HKLM\...\Autodesk 3ds Max 2016) (Version: 18.0.873.0 - Autodesk)
Autodesk 3ds Max 2016 (Version: 18.0.873.0 - Autodesk) Hidden
Autodesk 3ds Max 2016 Populate Data (HKLM\...\{57E92DED-DC7C-41E5-B9E1-76D83BD2EABE}) (Version: - Autodesk)
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: - Autodesk)
Autodesk Backburner 2016 (HKLM-x32\...\{8C5F38D2-9EFE-49A4-B3F5-BF3210FED168}) (Version: - Autodesk)
Autodesk Civil View for 3ds Max 2016 64-bit (HKLM\...\{1C4FFAF0-6DBB-4F7A-A386-46747D060826}) (Version: - Autodesk)
Autodesk Desktop App (HKLM-x32\...\Autodesk Desktop App) (Version: - Autodesk)
Autodesk DirectConnect 2016 64-bit (HKLM\...\Autodesk DirectConnect 2016 64-bit) (Version: - Autodesk)
Autodesk DirectConnect 2016 64-bit (Version: - Autodesk) Hidden
Autodesk Inventor Server Engine for 3ds Max 2016 (HKLM\...\{9167CA34-4E58-49E3-8892-3C439739D2D3}) (Version: 18.0 - Autodesk)
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: - Autodesk)
Autodesk Material Library Medium Resolution Image Library 2016 (HKLM-x32\...\{415A5A54-325E-4815-9940-62A889CA3877}) (Version: - Autodesk)
Autodesk Maya 2016 (HKLM\...\Autodesk Maya 2016) (Version: 16.0.1312.0 - Autodesk)
Autodesk Maya 2016 (Version: 16.0.1312.0 - Autodesk) Hidden
Autodesk Revit Interoperability for 3ds Max  (HKLM\...\Autodesk Revit Interoperability for 3ds Max ) (Version: 16.0.394.0 - Autodesk)
Autodesk Revit Interoperability for 3ds Max  (Version: 16.0.394.0 - Autodesk) Hidden
Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: - Bitdefender)
Bitdefender Device Management (HKLM\...\Bitdefender Device Management) (Version: - Bitdefender)
Bitdefender Total Security 2017 (HKLM\...\Bitdefender) (Version: - Bitdefender)
BitTorrent (HKU\S-1-5-21-3557252084-2468944355-21857965-1001\...\BitTorrent) (Version: - BitTorrent Inc.)
Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: - Apple Inc.)
Boris Continuum Complete 10 CE for Adobe CS5, CS6, CC (HKLM\...\{31710219-9BBB-47A6-85E0-7B406FB76738}) (Version: 10.0.1005 - Boris FX, Inc.)
C4DtoA for Cinema4D R16 (HKLM\...\C4DtoA_R16) (Version: - Solid Angle)
Camtasia 9 (HKLM-x32\...\{48cb006a-7b5b-4a48-98fd-fbd7af456b0d}) (Version: - TechSmith Corporation)
Camtasia 9 (Version: - TechSmith Corporation) Hidden
Cinec 2.7.5 Gold (HKLM-x32\...\{265D36E4-F099-42DA-ADA8-85008F02D7AA}) (Version: 2.7.5 - Cinemartin)
CINEMA 4D 16.050 (HKLM\...\MAXON8B6F11F9) (Version: 16.050 - MAXON Computer GmbH)
CINEMA 4D 17.055 (HKLM\...\MAXONFC68216F) (Version: 17.055 - MAXON Computer GmbH)
CINEMA 4D 18.011 (HKLM\...\MAXON6CD73CFE) (Version: 18.011 - MAXON Computer GmbH)
ColorSchemer Studio 2 (HKLM-x32\...\ColorSchemerStudio2_is1) (Version: Studio v2.0 - ColorSchemer)
CPUID CPU-Z 1.77 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Crazybump (remove only) (HKLM-x32\...\Crazybump) (Version:  - )
CrazyTalk Animator v2.1 Pipeline (HKLM-x32\...\{7127D4CC-78E6-41E3-8BCB-A50ED34846E2}) (Version: 2.1.1624.1 - Reallusion Inc.)
CrazyTalk v8.0 Pipeline (HKLM-x32\...\{239FA754-71DE-44A4-9DBC-9C9070AF058E}) (Version: 8.0.1218.2 - Reallusion Inc.)
CuteFTP 9 (HKLM-x32\...\{89B9E358-75C6-4C6B-BD38-803FF156CC4B}) (Version: 9.0.0 - Globalscape)
DENoise 3, After Effects-compatible plugin set (HKLM-x32\...\DENoise 3, After Effects-compatible plugin set) (Version:  - )
Digieffects Suite 3.0.0 CE (HKLM\...\Digieffects Suite CE_is1) (Version: 3.0.0 - Team V.R)
Digital Anarchy Beauty Box AE v3.0.6 (HKLM\...\Beauty Box AE 3_is1) (Version: 3.06 - Team V.R)
Digital Anarchy Beauty Box v3.0.7 Photoshop (HKLM\...\Beauty Box 3 Photoshop (Team V.R CE)_is1) (Version: 3.0.7 - Team V.R)
Effects Suite v11.1.6 (HKLM-x32\...\{4DD8EE5E-F571-4EC8-9526-E7C62FE39B19}_is1) (Version: 11.1.6 - Red Giant, LLC)
EPSON Easy Photo Print (HKLM-x32\...\{8A8F8391-4C2C-4BE1-A984-CD4A5A546467}) (Version: - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
EPSON Stylus SX200_SX400_TX200_TX400 Manual (HKLM-x32\...\EPSON Stylus SX200_SX400_TX200_TX400 User’s Guide) (Version:  - )
EPSON Stylus SX400 Series Printer Uninstall (HKLM\...\EPSON Stylus SX400 Series) (Version:  - SEIKO EPSON Corporation)
fayIN 2.1 for After Effects CC 2015 (Version: - fayteq) Hidden
fayIN 2.4 for After Effects CC (2014) (Version: - fayteq) Hidden
fayIN License Service (Version: - fayteq) Hidden
fayteq fayIN 2.1 for After Effects CC 2015 (HKLM-x32\...\{786a07fa-8353-46f6-82d8-db8d10d0fc2b}) (Version: - fayteq)
fayteq fayIN 2.4 for After Effects CC (2014) (HKLM-x32\...\{6ae3a601-b2a2-4d19-8207-104376b9768f}) (Version: - fayteq)
FilExile (HKLM-x32\...\{1310229C-E62A-4F05-87DB-13979A5D2EFC}_is1) (Version: 2.00 - Bryan Carey)
FLT 7.0v2 (HKLM-x32\...\FLT 7.0v2_is1) (Version:  - The Foundry)
GenArts Sapphire AE (HKLM\...\GenArts Sapphire AE_is1) (Version: 10.0 - Team V.R)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 54.0.2840.99 - Google Inc.)
Google Update Helper (x32 Version: - Google Inc.) Hidden
HDR Light Studio 5 (HKLM-x32\...\HDR Light Studio 5) (Version: 5.2016.0627 - Lightmap LTD)
Houdini 15.5.480 (HKLM\...\Houdini 15.5.480) (Version: 15.5.480 - Side Effects Software)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
iTunes (HKLM\...\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: - Apple Inc.)
Juicer 3.90 (HKLM-x32\...\{640EAE56-81A2-49D4-9B8C-00DA3C0031AF}_is1) (Version:  - Digital Juice, Inc.)
Keying Suite v11.1.5 (HKLM-x32\...\{21AD9423-3C17-43E2-AFD7-8305C965500F}_is1) (Version: 11.1.5 - Red Giant, LLC)
K-Lite Codec Pack 12.6.0 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 12.6.0 - KLCP)
Knald (HKLM-x32\...\Knald64) (Version: 1.2.0 - Knald Technologies, LLC)
Krakatoa for Cinema 4D (HKLM\...\Krakatoa for Cinema 4D 2.3.2) (Version: 2.3.2 - Thinkbox Software)
Magic Bullet Suite v12.0.6 (HKLM-x32\...\{99487911-8011-42BC-B594-8B02BFD32B1D}_is1) (Version: 12.0.6 - Red Giant, LLC)
Mari 3.0v3 (HKLM\...\Mari 3.0v3_is1) (Version:  - The Foundry)
Marvelous Designer 5 Enterprise (HKLM-x32\...\Marvelous Designer 5 Enterprise) (Version:  - CLO Virtual Fashion Inc.)
Megascans Studio version 0.901 (HKLM\...\{696362E1-CAA9-473E-9E0B-688602F65F5E}_is1) (Version: 0.901 - Quixel AB)
Microsoft LifeCam (HKLM\...\{6965A8D2-465D-4F98-9FAA-0E9E2348F329}) (Version: - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visio Professional 2013 (HKLM\...\Office15.VISPROR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MODO 901 Content 1 (HKLM-x32\...\MODO901_Content1) (Version:  - )
MODO 901 Content 2 (HKLM-x32\...\MODO901_Content2) (Version:  - )
MODO 901 Content 3 (HKLM-x32\...\MODO901_Content3) (Version:  - )
MtoA for Maya 2016 (HKU\S-1-5-21-3557252084-2468944355-21857965-1001\...\MtoA2016) (Version: - Solid Angle)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 373.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 373.06 - NVIDIA Corporation)
NVIDIA Graphics Driver 373.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 373.06 - NVIDIA Corporation)
NVIDIA HD Audio Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Package Kit (HKLM-x32\...\modoPack) (Version:  - )
PFTrack 2015.1 (HKLM\...\{A8AC5FC4-5B7F-4E17-9D2A-0130829410F0}) (Version: 15.1.1033 - The Pixel Farm)
PixPlant 2.1.68 Registered (HKLM-x32\...\PixPlant2 App_is1) (Version: 2.1.68 Registered - FaronStudio)
Quixel SUITE 2.1.5 (HKLM\...\{37962BCF-EF4D-4F9D-8AA1-8E2AAD546B67}_is1) (Version: 2.15 - Quixel)
RealFlow 10 (HKLM-x32\...\RealFlow 10) (Version:  - )
RealFlow 2015 (HKLM-x32\...\RealFlow 2015) (Version:  - )
RealFlow Plug-in for Cinema4D (HKLM-x32\...\RealFlowC4D) (Version: 1.0 - Next Limit)
RealFlow|Cinema4D (HKLM-x32\...\RealFlowCinema4D) (Version: 1.0 - Next Limit)
Red Giant Link (HKLM-x32\...\{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1) (Version: - Red Giant, LLC)
ReelSmart Motion Blur 5, After Effects-compatible plugin set (HKLM-x32\...\ReelSmart Motion Blur 5, After Effects-compatible plugin set) (Version:  - )
REFlex v5, After Effects plugin set (HKLM-x32\...\REFlex v5, After Effects plugin set) (Version:  - )
REMatch v1, After Effects-compatible plugin set (HKLM-x32\...\REMatch v1, After Effects-compatible plugin set) (Version:  - )
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0051-0000-1000-0000000FF1CE}_Office15.VISPROR_{F0C12872-B60D-4E37-A2F9-20C46A5E1F1A}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
ShaderMap 3.0.7 (HKLM\...\ShaderMap™ 3_is1) (Version:  - Rendering Systems Inc.)
Shave And A Haircut for Maya 2016 (HKLM\...\{5FCAC9DE-AF84-44C6-BC9C-DC7713E4F420}) (Version: 9.0v52 - Joe Alter, Inc)
Shooter Suite v12.7.2 (HKLM-x32\...\{7DFC5E36-8CC9-4EC5-9C24-A3770A669E3F}_is1) (Version: 12.7.2 - Red Giant, LLC)
Skype™ 7.29 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.29.102 - Skype Technologies S.A.)
Substance Painter 2 version 2.4.0 (HKLM\...\{f42b7a996fa1d13a1d0a2e33eea2c0800bb5d1b8}_is1) (Version: 2.4.0 - Allegorithmic)
The Foundry MODO 10.2v1 build 126693 (HKLM-x32\...\10.2v1_64) (Version:  - )
Trapcode Suite v12.1.9 (HKLM-x32\...\{DFD2DC6B-C634-4C1C-81CC-5EF852E71CEE}_is1) (Version: 12.1.9 - Red Giant, LLC)
Twixtor 6, After Effects-compatible plugin set (HKLM-x32\...\Twixtor 6, After Effects-compatible plugin set) (Version:  - )
Unfold3D Network 9.0.3 (HKLM\...\Unfold3D Network 9.0.3_is1) (Version:  - Polygonal Design)
Universe (HKLM\...\Universe Premium_is1) (Version: 2.0 CE - Team V.R)
Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{0FA8AE0C-69AE-4F60-A1AB-F79C6BA5A999}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.VISPROR_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version:  - Microsoft)
Update for Skype for Business 2015 (KB3127934) 64-Bit Edition (HKLM\...\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUS_{670823C5-9E0F-444C-A115-E8C4F37C5707}) (Version:  - Microsoft)
VideoCopilot Element 3D v2.2.2 CE for After Effects (HKLM\...\Element 3D CE for After Effects_is1) (Version: 2.2.2 - Team V.R)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
V-Ray for 3dsmax 2016 for x64 (HKLM\...\V-Ray for 3dsmax 2016 for x64) (Version: 3.20.02 - Chaos Software Ltd)
V-Ray for Maya 2016 for x64 (HKLM\...\V-Ray for Maya 2016 for x64) (Version: 3.10.01 - Chaos Software Ltd)
Vulkan Run Time Libraries (HKLM\...\VulkanRT1.0.26.0) (Version: - LunarG, Inc.)
Wacom (HKLM\...\Pen Tablet Driver) (Version: 5.3.5-3 - Wacom Technology Corp.)
Wampserver64 3.0.6 (HKLM\...\{wampserver64}_is1) (Version: 3.0.6 - Dominique Ottello aka Otomatic)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: - Wacom Technology Corp.)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
WinHTTrack Website Copier 3.48-22 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.48.22 - HTTrack)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
World Machine 2 Professional Edition (HKLM-x32\...\World Machine2Pro) (Version:  - )
ZBrush 4R7 (HKLM-x32\...\ZBrush 4R7 4R7) (Version: 4R7 - Pixologic)
CustomCLSID: HKU\S-1-5-21-3557252084-2468944355-21857965-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2016\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3557252084-2468944355-21857965-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2016\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3557252084-2468944355-21857965-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2016\Inventor Server\Bin\TestServer.dll => No File
Task: {0A1B1522-C26C-453A-A39A-BCC7170FF839} - System32\Tasks\cfdrp => C:\Users\Jason\cfdrp\ezac.exe [2016-10-09] (AutoIt Team)
Task: {35C2D355-2A63-436E-8337-36C2C35D3395} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2016-11-22] ()
Task: {4071DBF7-84CC-444C-B1AF-373429AB6C76} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-7DO5G64-Jason => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {5051DA81-8884-44CD-A516-51484B25A91E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-10-21] (Adobe Systems Incorporated)
Task: {7EEDF0C9-6E21-4E8E-99CF-5DBC850D776F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.)
Task: {86D77E73-C0CE-4266-9445-8D0253F6A4E6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-20] (Google Inc.)
Task: {98D7FCF4-C968-4B0B-9810-7BA6E86641A3} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2016-10-21] (Bitdefender)
Task: {A132CEBB-6DD9-41DD-991A-1126EEC9E4AD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {A9EDE338-5288-4265-A4AE-83BFDAAA97D3} - System32\Tasks\Bitdefender AgentTask_AD394AE64E874073B10A89FEEC305A3C => C:\Program Files\Bitdefender\Bitdefender 2017\bdagent.exe [2016-12-08] (Bitdefender)
Task: {CDBDDE38-701A-46B6-A789-0ECB58BB1B50} - System32\Tasks\Red Giant Link => C:\Program Files\Red Giant Link\Red Giant Link.exe
Task: {DFB8D7EF-5E83-4FBE-8937-BDC60740E955} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {EA29DFE8-ECF4-4260-B99D-6B9B7ECA4185} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-10-30 07:18 - 2015-10-30 07:18 - 00185856 _____ () C:\Windows\SYSTEM32\ism32k.dll
2016-10-20 08:57 - 2013-09-03 13:29 - 00111832 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\bdmetrics.dll
2016-10-20 08:57 - 2016-12-08 14:47 - 00138880 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\ECEvents.dll
2016-11-14 15:39 - 2016-11-14 15:40 - 01008448 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttpbr.mdl
2016-11-14 15:39 - 2016-11-14 15:40 - 00541952 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttpdsp.mdl
2016-11-14 15:39 - 2016-11-14 15:40 - 03202816 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttpph.mdl
2016-11-14 15:39 - 2016-11-14 15:40 - 01542976 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\otengines_02351_002\ashttprbl.mdl
2016-10-20 01:03 - 2016-10-01 19:53 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-12-08 21:43 - 2016-11-29 06:27 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2016-12-08 21:43 - 2016-11-29 06:27 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-11-09 13:21 - 2016-10-25 09:42 - 02656952 _____ () C:\Windows\system32\CoreUIComponents.dll
2016-10-20 20:16 - 2014-08-19 19:12 - 01356568 _____ () C:\Program Files\Tablet\Pen\libxml2.dll
2016-11-09 13:21 - 2016-10-25 09:42 - 02656952 _____ () C:\Windows\System32\CoreUIComponents.dll
2016-10-21 00:55 - 2016-10-21 00:55 - 01864384 _____ () C:\Users\Jason\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\ClientTelemetry.dll
2016-08-16 12:30 - 2016-08-16 12:30 - 08909504 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2016-11-09 13:21 - 2016-10-25 04:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-09 13:21 - 2016-10-25 04:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-11-09 13:21 - 2016-10-25 04:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-09 13:21 - 2016-10-25 04:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-10-20 08:58 - 2016-12-08 14:48 - 00023328 _____ () C:\Program Files\Bitdefender\Bitdefender 2017\lang\en-US\bdsystray.txtui
2016-10-20 01:13 - 2015-12-07 04:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-10-20 01:15 - 2016-07-01 03:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-11-09 13:22 - 2016-10-25 07:01 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-11-14 21:11 - 2016-11-08 21:03 - 02367080 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libglesv2.dll
2016-11-14 21:11 - 2016-11-08 21:03 - 00107112 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libegl.dll
2016-09-30 23:36 - 2016-09-30 23:36 - 07011000 _____ () C:\Program Files (x86)\Adobe\Acrobat DC\PDFMaker\Common\X64\AdobePDFMakerX.dll
2015-02-10 13:12 - 2015-02-10 13:12 - 02210480 _____ () C:\Program Files\Microsoft Office\Office15\tmpod.dll
2015-10-13 14:10 - 2015-10-13 14:10 - 01428648 _____ () C:\Program Files\Microsoft Office\Office15\ADDINS\UmOutlookAddin.dll
2016-09-30 23:36 - 2016-09-30 23:36 - 02861752 _____ () C:\Program Files (x86)\Adobe\Acrobat DC\PDFMaker\Common\X64\SendAsLinkX.dll
2016-10-23 12:52 - 2016-07-01 06:39 - 00110608 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qjson0.dll
2016-10-23 12:52 - 2016-07-01 06:39 - 00061968 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\QtSolutions_Service-head.dll
2016-10-21 00:55 - 2016-10-21 00:55 - 01383616 _____ () C:\Users\Jason\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\ClientTelemetry.dll
2016-10-21 00:55 - 2016-10-21 00:55 - 00118976 _____ () C:\Users\Jason\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncViews.dll
2016-10-23 12:52 - 2013-09-23 17:52 - 00043912 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\QtSolutions_MFCMigrationFramework_Ad_2.dll
2016-10-23 12:52 - 2015-11-05 12:07 - 00052224 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qoauth_Ad_1.dll
2016-10-23 12:52 - 2015-11-05 12:07 - 00195584 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qjson_Ad_0.dll
2016-10-23 12:52 - 2015-11-05 12:07 - 00742400 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qca_Ad_2.dll
2016-10-23 12:52 - 2016-07-01 06:05 - 00285120 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\en-US\AdWingManRes.dll
2016-10-23 12:52 - 2015-09-08 06:31 - 40640808 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libcef.dll
2016-08-16 12:31 - 2016-08-16 12:31 - 08909504 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2016-10-23 12:52 - 2014-09-03 00:29 - 00912384 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libglesv2.dll
2016-10-23 12:52 - 2014-09-03 00:29 - 00134144 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libegl.dll
2016-10-23 12:52 - 2014-09-03 00:29 - 00950272 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\ffmpegsumo.dll
AlternateDataStreams: C:\Users\Jason\Desktop\FRST64.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\BDSysLog_i.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\cpu-z_1.77-en.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\dotNetFx40_Full_setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\epson374975eu.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\epson512526eu.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\FilExilev1.51_Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\FilExilev2.00_Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\klcp_update_1261_20161122.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\LifeCam3.22.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\mb3-setup-consumer- [0]
AlternateDataStreams: C:\Users\Jason\Downloads\NetFxRepairTool.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\swfdownloader.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\video-download-capture.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\vlc-2.2.4-win32.exe:BDU [0]
AlternateDataStreams: C:\Users\Jason\Downloads\w_cproc_p_11.1.072_redist_intel64.exe:BDU [0]
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
2015-10-30 07:24 - 2016-11-12 04:35 - 00008216 ____A C:\Windows\system32\Drivers\etc\hosts       localhost
There are 0 more lines.
HKU\S-1-5-21-3557252084-2468944355-21857965-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jason\Pictures\filling_the_void_1920x1200.jpg
DNS Servers: -
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [{71BD774A-3B2F-434B-8E56-048FD93C590B}] => C:\Users\Jason\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{2C80C885-1D93-4E6A-9DC3-A6EECF3C93E8}] => C:\Users\Jason\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{60767F3C-AD11-4217-8170-86470B8B5FF7}] => C:\Users\Jason\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5B260E85-E93F-4A6C-BE82-AEE977D2120E}] => C:\Users\Jason\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{6ADDB730-8D6A-4306-BDC4-E5FA36C761F4}] => C:\Users\Jason\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{ACCCD77E-AA01-422E-9E50-0CCEA6C3FA7F}] => C:\Users\Jason\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E4855B1B-4A41-479F-A629-8FF396FF51D6}] => C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{88F0EF17-65E7-4322-9799-C210C7A116AB}] => C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{078C75D7-0AC0-475C-9961-60E85C5E61D5}] => C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{21A60F96-2CA9-47A7-B518-7DC05A1C2144}] => C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{17031B04-9362-4F85-B835-B554FDAD86F3}] => C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{758C6009-13CA-442D-ADA9-C078906A801A}] => C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{814492DB-CA32-44F5-9BCE-CC78CA88E095}] => C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{002F28AE-3797-45E1-8684-EFF43BA5B089}] => C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{C467DC1B-7D58-4123-98E5-22CCF940CB62}] => C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{FE26ABED-D638-49CC-B217-04BE6C568E6B}] => C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{07C9E5BF-225E-4F36-A08F-EA5C340A1B98}] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{E3F9AAAC-7F89-4C09-ABB0-B720C3ABDFF9}] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{514CBCBE-F822-41C9-BA63-A1DF92BDD3BA}] => C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{8744166C-D26C-41B2-A7DA-7821646E343E}] => C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{D6AF08AA-39E2-4B74-8523-A684B9F8BC3F}] => C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{6E5393AE-19B6-4F4B-8DFA-26502CA0A1DC}] => C:\Program Files (x86)\Red Giant\Offload\Offload.exe
FirewallRules: [{1120B2FA-D529-4611-B46A-5DEEC4A78465}] => C:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64server.exe
FirewallRules: [{19EBD498-9493-4ED5-AF15-8D8B93686A1B}] => C:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64server.exe
FirewallRules: [{BA5B2A4A-33BA-4539-98E2-255DC1E69E27}] => C:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64.exe
FirewallRules: [{E1C09F43-0AD0-46BE-8A15-DDFE1609ABAB}] => C:\Program Files\Autodesk\3ds Max 2016\NVIDIA\Satellite\raysat_3dsmax2016_64.exe
FirewallRules: [{B89F8EDE-D861-4900-A223-113A2D01D489}] => C:\Program Files\The Pixel Farm\PFTrack 2015.1\PFLicenseManager.exe
FirewallRules: [{21DF0BD6-B6FF-4B73-91CF-28ED144E6A61}] => C:\Program Files\The Pixel Farm\PFTrack 2015.1\PFTrack.exe
FirewallRules: [{50D57564-E340-4BEC-A775-E5F5F0618D78}] => C:\Program Files\Chaos Group\V-Ray\3dsmax 2016 for x64\vrlservice.exe
FirewallRules: [{7F9F18E5-C67C-4B97-81FC-8B6E3A7A4DAD}] => C:\Program Files\Chaos Group\V-Ray\3dsmax 2016 for x64\vrlservice.exe
FirewallRules: [{7286358D-DFAB-4867-BCA3-7216E9B0774D}] => C:\Program Files (x86)\Crazybump\CrazyBump.exe
FirewallRules: [{C0A61048-2282-4696-B6C5-59F4E04AC250}] => C:\Program Files (x86)\Crazybump\CrazyBump.exe
FirewallRules: [{0514A81A-F939-4C7D-B0BB-28BFEF52CF03}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3F780C48-D380-4D8D-96CD-532C0E5B65A2}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B85E867F-74A7-46D8-B854-D0B72952AFD0}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{9293FC6B-803C-41E6-9A3B-BD4DEF894AFA}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6B65E359-375C-4BB3-B12C-15093C2208CE}] => C:\Program Files\Luxology\modo\10.2v1\modo.exe
FirewallRules: [{BB280A63-9584-43E2-BB32-5D90C4557A69}] => C:\Program Files\Luxology\modo\10.2v1\modo.exe
FirewallRules: [{F370C734-CBF1-44FC-9803-EEAF8E082B40}] => C:\Program Files\Autodesk\Maya2016\vray\bin\vray.exe
FirewallRules: [{3102DB5D-1704-4A9D-AEF8-8662291F27C1}] => C:\Program Files\Autodesk\Maya2016\vray\bin\vray.exe
FirewallRules: [{BD918FE4-3329-48B5-A28B-BB0808376F6B}] => C:\Windows\system32\hasplms.exe
FirewallRules: [{F5265208-7F2C-4C7D-8844-A1284E1CDDB4}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{4757D953-937B-4E8D-9CFE-2C8BA0316ED6}] => C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{0366609E-7412-4BE9-81E0-65945897FCE2}] => C:\Users\Jason\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{1E0F9198-7267-45A4-9335-9AE3E1878A76}] => C:\Users\Jason\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{09CC399F-D9D3-4325-A54B-77521EF77D8F}] => C:\Users\Jason\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{148A293A-2AF0-47CC-BAD6-86D50E4446C0}] => C:\Users\Jason\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{7D505B0A-E383-47D6-A890-BA966D9067D8}] => C:\Users\Jason\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{21AB8971-E949-4338-854A-E844B576454D}] => C:\Users\Jason\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{6444F4E4-8113-4C39-8C5C-699A6A4314F3}] => LPort=8318
01-12-2016 09:53:13 Scheduled Checkpoint
06-12-2016 14:13:31 Installed Blender
08-12-2016 20:25:49 Camtasia 9
Name: Multimedia Video Controller
Description: Multimedia Video Controller
Class Guid: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Error: (12/09/2016 05:06:09 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\MAXON\CINEMA 4D R16\resource\modules\python\Python.win64.framework\Lib\distutils\command\wininst-8_d.exe".
Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (12/09/2016 05:06:09 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\MAXON\CINEMA 4D R16\resource\modules\python\Python.win32.framework\Lib\distutils\command\wininst-8_d.exe".
Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (12/09/2016 05:05:32 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.0 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5268.  Message ID: [0x2509].
Error: (12/09/2016 05:05:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\MAXON\CINEMA 4D R16\resource\modules\python\Python.win64.framework\Lib\distutils\command\wininst-8_d.exe".
Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (12/09/2016 05:05:25 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\MAXON\CINEMA 4D R16\resource\modules\python\Python.win32.framework\Lib\distutils\command\wininst-8_d.exe".
Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (12/09/2016 05:00:31 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.0 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 10776.  Message ID: [0x2509].
Error: (12/09/2016 04:55:32 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.0 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 8648.  Message ID: [0x2509].
Error: (12/09/2016 12:37:30 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.0 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5540.  Message ID: [0x2509].
Error: (12/09/2016 12:30:31 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.0 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5964.  Message ID: [0x2509].
Error: (12/09/2016 12:25:33 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.0 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 7264.  Message ID: [0x2509].
Error: (12/09/2016 03:48:16 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {B548B6A5-B4C1-4DE2-8DB2-B60C1E80387E} did not register with DCOM within the required timeout.
Error: (12/09/2016 03:43:56 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7DO5G64)
Description: The server {F9717507-6651-4EDB-BFF7-AE615179BCCF} did not register with DCOM within the required timeout.
Error: (12/09/2016 03:43:51 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
Error: (12/09/2016 03:43:50 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
Error: (12/09/2016 03:43:26 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
Error: (12/09/2016 03:43:26 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
Error: (12/09/2016 03:43:25 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
Error: (12/09/2016 03:43:24 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
Error: (12/09/2016 03:43:21 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
Error: (12/09/2016 03:43:20 AM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-7DO5G64)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
  Date: 2016-12-09 17:07:08.877
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Red Giant Link\tools\tools\update_installer\USERENV.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
  Date: 2016-12-09 17:07:08.856
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Red Giant Link\tools\tools\update_installer\USERENV.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
  Date: 2016-12-09 03:50:09.432
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2016-12-08 22:04:19.235
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2016-12-08 21:57:26.768
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Red Giant Link\tools\tools\update_installer\USERENV.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
  Date: 2016-12-08 20:41:54.804
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Red Giant Link\tools\tools\update_installer\USERENV.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
  Date: 2016-12-08 20:34:26.318
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Red Giant Link\tools\tools\update_installer\USERENV.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
  Date: 2016-12-08 20:34:26.295
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Red Giant Link\tools\tools\update_installer\USERENV.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
  Date: 2016-12-08 05:34:24.718
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2016-12-04 22:59:23.007
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\vsservp.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2017\dbghelp.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz
Percentage of memory in use: 55%
Total physical RAM: 8189.1 MB
Available physical RAM: 3684 MB
Total Virtual: 9469.1 MB
Available Virtual: 4952.68 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.27 GB) (Free:223.32 GB) NTFS
Drive d: () (Fixed) (Total:465.76 GB) (Free:161.46 GB) NTFS
==================== MBR & Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 92DF84AA)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.3 GB) - (Type=07 NTFS)
Disk: 1 (Size: 465.8 GB) (Disk ID: 73736572)
Partition 1: (Not Active) - (Size=866 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.6 GB) - (Type=6C)
Partition 00: (Not Active) - (Size=0) - (Type=00) ATTENTION ===> 0 byte partition bootkit.
Partition 3: (Not Active) - (Size=224 KB) - (Type=00)
==================== End of Addition.txt ============================

Hello Heisenberg and welcome to Malwarebytes,

Continue as follows...

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Open FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.


Please open Malwarebytes Anti-Malware.
  • On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits".
  • Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware
  • Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the Scan is complete Apply Actions to any found entries.
  • Wait for the prompt to restart the computer to appear (if applicable), then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.

To get the log from Malwarebytes do the following:
  • Click on the History tab > Application Logs.
  • Double click on the Scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have three options:
    Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
    Text file (*.txt) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
    XML file (*.xml) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
  • Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…


Download AdwCleaner by Xplode onto your Desktop.
  • Double click on Adwcleaner.exe to run the tool.
  • Click on the Scan in the Actions box
  • Please wait fot the scan to finish..
  • When "Waiting for action.Please uncheck elements you want to keep" shows in top line..
  • Click on the Cleaning box.
  • Next click OK on the "Closing Programs" pop up box.
  • Click OK on the Information box & again OK to allow the necessary reboot
  • After restart the AdwCleaner(C*)-Notepad log will appear, please copy/paste it in your next reply. Where * is the number relative to list of scans completed...


Download Sophos Free Virus Removal Tool and save it to your desktop.

If your security alerts to this scan either accept the alert or turn off your security to allow Sophos to run and complete.....
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
  • If no threats were found please confirm that result....

Let me see those logs, also tell me if there are any remaining issues or concerns...

Thank you,



Hello Heisenberg and welcome to Malwarebytes,

Continue as follows...

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Open FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.


Please open Malwarebytes Anti-Malware.
  • On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits".
  • Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware
  • Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the Scan is complete Apply Actions to any found entries.
  • Wait for the prompt to restart the computer to appear (if applicable), then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.

To get the log from Malwarebytes do the following:
  • Click on the History tab > Application Logs.
  • Double click on the Scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have three options:
    Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
    Text file (*.txt) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
    XML file (*.xml) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
  • Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…


Download AdwCleaner by Xplode onto your Desktop.
  • Double click on Adwcleaner.exe to run the tool.
  • Click on the Scan in the Actions box
  • Please wait fot the scan to finish..
  • When "Waiting for action.Please uncheck elements you want to keep" shows in top line..
  • Click on the Cleaning box.
  • Next click OK on the "Closing Programs" pop up box.
  • Click OK on the Information box & again OK to allow the necessary reboot
  • After restart the AdwCleaner(C*)-Notepad log will appear, please copy/paste it in your next reply. Where * is the number relative to list of scans completed...


Download Sophos Free Virus Removal Tool and save it to your desktop.

If your security alerts to this scan either accept the alert or turn off your security to allow Sophos to run and complete.....
  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View log file... (bottom left hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
  • If no threats were found please confirm that result....

Let me see those logs, also tell me if there are any remaining issues or concerns...

Thank you,



Hi Kevin,

Thank you so much for your help here.

I've run the first 2 steps and here is the scan report:


Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)


Attached is Fixlog.txt.

Is it best to disconnect from the web when I do this? The NanoCore dialog is still appearing?

Many thanks.



Does this issue only affect a specific browser, or more than one..? Run the following please:

Please download Zemana AntiMalware and save it to your Desktop.
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
    Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please re-boot your computer manually.
  • Open Zemana AntiMalware again.
  • Click on user posted image icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • Attach saved report in your next message.


Run FRST one more time, ensure all boxes are checkmarked under "Whitelist" but only Addition.txt under "Optional scan" Select scan, when done post the new logs. "FRST.txt" and "Addition.txt"

Let me see those logs, also give an update on any remaining issues or concerns...

Thank you,




Yes, it doesn't seem browser related.

Zamana picked up the following which it called a "hollow process":

Status             : Scanned
Object             : %systemroot%\microsoft.net\framework\v2.0.50727\regsvcs.exe
MD5                : 1176AEC8BE8D3009E3762764607B4D73
Publisher          : Microsoft Windows
Size               : 32768
Version            : 2.0.50727.8670
Detection          : Hollow Process
Cleaning Action    : Repair
Related Objects    :
                Process - 176 - C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
                File - %systemroot%\microsoft.net\framework\v2.0.50727\regsvcs.exe


I forget to mention, I moved the .NET framework v4 regsvcs.exe to the deskptop then moved it back and now it seems to initiate via the .NET framework v2.

Edited by Heisenberg
Link to post
Share on other sites

Ok lets wait for that log... RegSvcs.exe does seem to be part of the infection, but in your case at this address: C:\Users\Jason\RegSvcs.exe

When the Zemana log is ready post it, also the following:

Run FRST one more time, ensure all boxes are checkmarked under "Whitelist" but only Addition.txt under "Optional scan" Select scan, when done post the new logs. "FRST.txt" and "Addition.txt"





Here is the relevant part of  Zamana report (it couldn't remove the virus it seems):

Status             : Scanned
Object             : %systemroot%\microsoft.net\framework\v2.0.50727\regsvcs.exe
MD5                : 1176AEC8BE8D3009E3762764607B4D73
Publisher          : Microsoft Windows
Size               : 32768
Version            : 2.0.50727.8670
Detection          : Hollow Process
Cleaning Action    : Repair
Related Objects    :
                Process - 176
                File - %systemroot%\microsoft.net\framework\v2.0.50727\regsvcs.exe

Cleaning Result
Cleaned               : 0
Reported as safe      : 2
Failed                : 1

Failed Objects
Status             : Scanned
Object             : %systemroot%\microsoft.net\framework\v2.0.50727\regsvcs.exe
MD5                : 1176AEC8BE8D3009E3762764607B4D73
Publisher          : Microsoft Windows
Size               : 32768
Version            : 2.0.50727.8670
Detection          : Hollow Process
Cleaning Action    : Repair
Related Objects    :
                Process - 176
                File - %systemroot%\microsoft.net\framework\v2.0.50727\regsvcs.exe


Link to post
Share on other sites

Does this issue still happen, i`m not so sure Zemana is correct. Yes RegSvcs.exe does seem to be associated with this infection but it appears to run from a user folder. I`ve got another two threads and same issue....

Can you run Virus Total as follows:

Go to http://www.virustotal.com/
  • Click the Choose file button
  • Navigate to the file C:\Users\Jason\cfdrp\ezac.exe
  • Click the Scan it tab
  • If you get a message saying File has already been analyzed: click Reanalyze file now
  • Copy and paste the results back here please.


Run FRST one more time:

Type the following in the edit box after "Search:".


Click Search Files button and post the log (Search.txt) it makes to your reply.


Search results:

Farbar Recovery Scan Tool (x64) Version: 07-12-2016
Ran by Jason (10-12-2016 21:05:56)
Running from C:\Users\Jason\Desktop
Boot Mode: Normal

================== Search Files: "RegSvcs.exe" =============

[2015-10-30 07:19][2015-10-30 07:19] 0045216 ____N (Microsoft Corporation) 7A9AFA1680BD6880968BB5F14127C5C3 [File is digitally signed]

[2016-10-20 20:14][2015-10-23 16:47] 0032768 ____A (Microsoft Corporation) 1176AEC8BE8D3009E3762764607B4D73 [File is digitally signed]

[2015-10-30 07:19][2015-10-30 07:19] 0044192 ____N (Microsoft Corporation) 32AF682D08E6915187D733CAB239105B [File is digitally signed]

[2016-10-20 20:14][2015-10-09 20:24] 0028672 ____A (Microsoft Corporation) F4BBDABF3DB0C9A089BFBBC62F02A494 [File is digitally signed]

[2016-12-09 17:16][2015-10-30 07:19] 0045216 ____A (Microsoft Corporation) 7A9AFA1680BD6880968BB5F14127C5C3 [File is digitally signed]

[2016-10-20 20:14][2015-10-09 20:24] 0028672 ____A (Microsoft Corporation) F4BBDABF3DB0C9A089BFBBC62F02A494 [File is digitally signed]

[2016-10-20 20:14][2015-10-23 16:47] 0032768 ____A (Microsoft Corporation) 1176AEC8BE8D3009E3762764607B4D73 [File is digitally signed]

====== End of Search ======

Link to post
Share on other sites

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Open FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.

Post that log. Also let me know if the issue clears..



