Hosted with ♥ by Up2Sha.reOriginal
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2016
Ran by Natascha (administrator) on YAZZYBEE (01-11-2016 14:46:58)
Running from C:\Users\Natascha\Downloads
Loaded Profiles: Natascha (Available Profiles: Natascha & Administrator)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5264016 2012-08-16] (VIA)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-27] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073352 2012-06-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2013-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694048 2014-05-23] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-07-20] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443640 2014-10-31] (BlackBerry Limited)
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe [3125976 2013-09-23] (Disc Soft Ltd)
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [BitTorrent] => C:\Users\Natascha\AppData\Roaming\BitTorrent\BitTorrent.exe [1903648 2016-02-18] (BitTorrent Inc.)
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [465920 2016-07-01] (Microsoft Corporation)
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [Dropbox Update] => C:\Users\Natascha\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-20] (Dropbox, Inc.)
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [ares] => "C:\Program Files (x86)\Ares\Ares.exe" -h
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64"
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\MountPoints2: {6c70926d-a3f7-11e5-bef4-08606e48acfa} - "F:\SETUP.EXE" 
HKU\S-1-5-18\...\Run: [] => 0
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-12-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-12-13] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-12-13] ()
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\FileSyncShell64.dll [2016-08-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\FileSyncShell64.dll [2016-08-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\FileSyncShell64.dll [2016-08-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} =>  No File
ShellIconOverlayIdentifiers: [KzShlobj2] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncShell.dll [2016-08-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncShell.dll [2016-08-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncShell.dll [2016-08-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2016-01-15]
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-10-13]
ShortcutTarget: Dropbox.lnk -> C:\Users\Natascha\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2016-10-19]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Natascha\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook)
Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OnePlus One Toolkit.lnk [2016-06-03]
ShortcutTarget: OnePlus One Toolkit.lnk -> C:\Program Files (x86)\OPO Toolkit\OnePlus One Toolkit.exe ()
Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk [2016-06-04]
ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 200.1.159.58 200.2.162.14
Tcpip\..\Interfaces\{00ebc61d-3fa3-46a3-a188-1df19733e00e}: [DhcpNameServer] 200.1.159.58 200.2.162.14
Tcpip\..\Interfaces\{74e8714a-3c3a-4950-acf7-bf14bb224506}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{de8883bd-5604-4b2e-931a-b787e0b09ed8}: [DhcpNameServer] 200.1.159.58 200.2.162.14

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-336042120-3881833094-1070839671-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://home.lenovo.com
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-07-19] (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: No Name -> {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} -> No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-07-12] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-07-19] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-29] (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-07-12] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-29] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {A13C2648-91D4-4bf3-BC6D-0079707C4389} -  No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-336042120-3881833094-1070839671-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-336042120-3881833094-1070839671-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll No File

FireFox:
========
FF ProfilePath: C:\Users\Natascha\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\2r3ugg6v.default\Profiles\2r3ugg6v.default [not found]
FF ProfilePath: C:\Users\Natascha\AppData\Roaming\Mozilla\Firefox\Profiles\2r3ugg6v.default [2016-11-01]
FF Extension: (Firefox Hotfix) - C:\Users\Natascha\AppData\Roaming\Mozilla\Firefox\Profiles\2r3ugg6v.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-10-30]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-10-20] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.6.0.27\coFFPlgn => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll [2016-10-26] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File]
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-12-19] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll [2016-10-26] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2014-11-28] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-09-22] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-12-19] (Adobe Systems)
FF Plugin HKU\S-1-5-21-336042120-3881833094-1070839671-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Natascha\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-09-03] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)

Chrome: 
=======
CHR DefaultProfile: ChromeDefaultData
CHR Profile: C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-11-01] <==== ATTENTION
CHR Extension: (Google Docs) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-26]
CHR Extension: (Google Drive) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-26]
CHR Extension: (YouTube) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-26]
CHR Extension: (Google Docs Offline) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-26]
CHR Extension: (Gmail) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-26]
CHR Profile: C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default [2016-10-29]
CHR Extension: (Google Docs) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-03]
CHR Extension: (Google Drive) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Google Docs Offline) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05]
CHR Extension: (Gmail) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR Extension: (Chrome Media Router) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-22]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\Exts\Chrome.crx <not found>

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed]
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024 2014-10-31] (BlackBerry Limited)
S3 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe [654552 2013-09-23] (Disc Soft Ltd)
S2 NCO; C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.47\NST.exe [130104 2014-05-14] (Symantec Corporation)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2011-04-13] (Hewlett-Packard) [File not signed]
S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2011-04-13] (Hewlett-Packard) [File not signed]
S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7500048 2016-09-20] (TeamViewer GmbH)
S2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
S3 vmicvss; C:\WINDOWS\System32\ICSvc.dll [511488 2015-10-30] (Microsoft Corporation)
S3 wampapache64; c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe [24576 2014-05-01] (Apache Software Foundation) [File not signed]
S3 wampmysqld64; c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe [12942848 2014-05-01] () [File not signed]
S2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-07-20] (Western Digital Technologies, Inc.)
S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [306552 2015-07-20] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation)
S3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S1 ccSet_NST; C:\WINDOWS\system32\drivers\NSTx64\7DE07000.02F\ccSetx64.sys [162392 2014-02-20] (Symantec Corporation)
R3 dtscsibus; C:\WINDOWS\system32\DRIVERS\dtscsibus.sys [29696 2015-12-15] (Disc Soft Ltd)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 netr28x; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.)
S3 RimUsb; C:\WINDOWS\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 RimVSerPort; C:\WINDOWS\system32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
S1 ucdrv; C:\WINDOWS\System32\drivers:ucdrv-x64.sys [20324 ] (UC Web Inc.) <==== ATTENTION
R1 UCGuard; C:\WINDOWS\System32\DRIVERS\ucguard.sys [81792 2016-08-29] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== ATTENTION
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (MBB)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

NETSVCx32: HpSvc -> no filepath.

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-01 14:44 - 2016-11-01 14:46 - 00000000 ____D C:\FRST
2016-11-01 14:43 - 2016-11-01 14:44 - 02408960 _____ (Farbar) C:\Users\Natascha\Downloads\FRST64.exe
2016-11-01 14:37 - 2016-11-01 14:41 - 01758208 _____ (Farbar) C:\Users\Natascha\Downloads\FRST (1).exe
2016-11-01 12:55 - 2016-11-01 12:55 - 08270896 _____ (Piriform Ltd) C:\Users\Natascha\Downloads\ccsetup523pro.exe
2016-11-01 12:32 - 2016-11-01 12:32 - 01758208 _____ (Farbar) C:\Users\Natascha\Downloads\FRST.exe
2016-10-30 17:11 - 2016-10-30 17:11 - 00000000 ___HD C:\OneDriveTemp
2016-10-29 20:40 - 2016-10-29 20:40 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-10-29 03:51 - 2016-10-29 03:51 - 00004430 _____ C:\Users\Natascha\Desktop\ESETscan.txt
2016-10-28 21:56 - 2016-10-28 21:57 - 06770304 _____ (ESET spol. s r.o.) C:\Users\Natascha\Downloads\ESETOnlineScanner_ENU.exe
2016-10-28 21:56 - 2016-10-28 21:56 - 06770304 _____ (ESET spol. s r.o.) C:\Users\Natascha\Downloads\ESETOnlineScanner_ENU (2).exe
2016-10-28 17:12 - 2016-10-28 17:13 - 03851848 _____ C:\Users\Natascha\Downloads\Unconfirmed 11352.crdownload
2016-10-28 10:29 - 2016-10-28 10:29 - 00226646 _____ C:\Users\Natascha\Downloads\request.pdf
2016-10-28 00:30 - 2016-10-28 00:30 - 00001401 _____ C:\Users\Natascha\Desktop\JRT.txt
2016-10-28 00:24 - 2016-10-28 00:25 - 01631928 _____ (Malwarebytes) C:\Users\Natascha\Downloads\JRT.exe
2016-10-27 15:03 - 2016-10-27 15:03 - 06761600 _____ (ESET spol. s r.o.) C:\Users\Natascha\Downloads\esetonlinescanner_enu (1).exe
2016-10-27 11:45 - 2016-10-27 11:45 - 00000000 ____D C:\Users\Natascha\AppData\Local\ESET
2016-10-26 20:51 - 2016-10-30 17:28 - 00000000 ____D C:\AdwCleaner
2016-10-26 20:50 - 2016-10-26 20:50 - 03910208 _____ C:\Users\Natascha\Downloads\AdwCleaner.exe
2016-10-26 18:23 - 2016-10-26 18:23 - 00001173 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-10-26 18:21 - 2016-11-01 14:27 - 00640730 _____ C:\WINDOWS\ntbtlog.txt
2016-10-26 16:07 - 2016-10-26 16:07 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-10-26 16:07 - 2016-10-26 16:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-10-26 16:07 - 2016-10-26 16:07 - 00000000 ____D C:\Program Files\CCleaner
2016-10-26 15:20 - 2016-11-01 14:48 - 00030821 _____ C:\Users\Natascha\Downloads\FRST.txt
2016-10-26 00:08 - 2016-11-01 14:28 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2016-10-25 16:37 - 2016-10-25 16:37 - 00004444 _____ C:\WINDOWS\System32\Tasks\SecureUpdater
2016-10-25 15:46 - 2016-10-25 17:06 - 00000000 __SHD C:\Users\Natascha\AppData\Local\svchost
2016-10-25 15:45 - 2016-10-18 15:58 - 00567808 _____ C:\WINDOWS\SysWOW64\chtbrkg.dll
2016-10-25 15:45 - 2016-10-18 15:57 - 00753152 _____ C:\WINDOWS\system32\chtbrkg.dll
2016-10-25 15:43 - 2016-10-25 20:00 - 00002654 _____ C:\WINDOWS\System32\Tasks\UCBrowserUpdaterCore
2016-10-25 15:43 - 2016-10-25 15:43 - 00003504 _____ C:\WINDOWS\System32\Tasks\UCBrowserUpdater
2016-10-25 15:07 - 2016-10-25 15:07 - 00000000 ____D C:\ProgramData\Avira
2016-10-25 15:07 - 2016-10-25 15:07 - 00000000 ____D C:\ProgramData\Avg
2016-10-25 15:07 - 2016-10-25 15:07 - 00000000 ____D C:\ProgramData\AVAST Software
2016-10-25 15:07 - 2004-10-10 09:50 - 00278528 _____ (Real Networks, Inc) C:\WINDOWS\SysWOW64\pncrt.dll
2016-10-25 15:07 - 2004-07-02 17:33 - 00327749 _____ (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\drvc.dll
2016-10-25 14:57 - 2016-08-29 07:50 - 00081792 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-10-25 13:09 - 2016-10-25 13:09 - 00000000 ____D C:\Users\Natascha\Documents\Any Video Converter Professional
2016-10-25 11:55 - 2016-10-25 11:55 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\TechSmith
2016-10-25 11:53 - 2016-10-25 11:53 - 00000000 ____D C:\Users\Natascha\Documents\Camtasia Studio
2016-10-25 11:52 - 2016-10-25 11:52 - 00001152 _____ C:\Users\Public\Desktop\Camtasia 9.lnk
2016-10-25 11:52 - 2016-10-25 11:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2016-10-25 11:50 - 2016-10-25 11:50 - 00000000 ____D C:\ProgramData\TechSmith
2016-10-25 11:50 - 2016-10-25 11:50 - 00000000 ____D C:\Program Files\TechSmith
2016-10-25 11:09 - 2016-10-25 11:40 - 285144256 _____ (TechSmith Corporation) C:\Users\Natascha\Downloads\camtasia.exe
2016-10-25 01:47 - 2016-10-25 15:06 - 00000000 ____D C:\Program Files (x86)\Windows Live
2016-10-24 19:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2016-10-24 19:00 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2016-10-24 19:00 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2016-10-24 19:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2016-10-24 19:00 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-10-24 19:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-10-24 19:00 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2016-10-24 19:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2016-10-24 18:59 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2016-10-24 18:59 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2016-10-24 18:59 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2016-10-24 18:59 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2016-10-24 18:54 - 2016-10-25 01:47 - 00000000 ____D C:\Users\Natascha\AppData\Local\Windows Live
2016-10-19 11:52 - 2016-10-19 11:52 - 00001284 _____ C:\Users\Natascha\Desktop\Facebook Gameroom.lnk
2016-10-19 11:52 - 2016-10-19 11:52 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
2016-10-19 11:52 - 2016-10-19 11:52 - 00000000 ____D C:\Users\Natascha\AppData\Local\Facebook
2016-10-19 11:52 - 2016-10-19 11:52 - 00000000 ____D C:\Users\Natascha\AppData\Local\CEF
2016-10-19 11:50 - 2016-10-19 11:50 - 00249600 _____ (Facebook) C:\Users\Natascha\Downloads\FacebookGameroom.exe
2016-10-17 16:43 - 2016-10-22 12:18 - 00000000 ____D C:\Users\Natascha\Desktop\Gayparade

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-01 14:43 - 2013-10-14 01:06 - 00001605 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-01 14:43 - 2013-10-14 00:44 - 00001170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-11-01 14:28 - 2013-10-14 01:04 - 00000000 ____D C:\Users\Natascha\AppData\Local\Google
2016-11-01 14:25 - 2015-12-07 05:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-01 14:24 - 2015-09-03 20:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-11-01 14:16 - 2015-06-20 16:38 - 00000948 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-336042120-3881833094-1070839671-1001UA.job
2016-11-01 14:16 - 2013-11-05 07:26 - 00000000 __RDO C:\Users\Natascha\SkyDrive
2016-11-01 12:38 - 2013-10-14 00:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-10-31 06:01 - 2013-10-15 02:44 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-10-31 05:44 - 2013-10-14 01:04 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-31 04:52 - 2015-05-10 12:28 - 00001716 _____ C:\WINDOWS\Tasks\BYAIAMUF.job
2016-10-30 21:42 - 2015-05-10 12:29 - 00001364 _____ C:\WINDOWS\Tasks\GNOK.job
2016-10-30 18:44 - 2013-10-14 01:04 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-30 17:16 - 2013-11-05 09:56 - 00000000 ____D C:\Users\Natascha\AppData\Local\CrashDumps
2016-10-30 17:10 - 2015-12-07 04:32 - 00000000 ____D C:\Users\Natascha
2016-10-30 15:13 - 2014-09-04 15:41 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-10-29 20:57 - 2013-11-13 13:00 - 00004158 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BA7909C2-DDCD-422F-AFD3-1068F328DC19}
2016-10-29 20:40 - 2013-10-18 13:13 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Dropbox
2016-10-29 20:30 - 2015-10-30 03:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2016-10-28 18:28 - 2014-05-27 19:04 - 00000000 ____D C:\ProgramData\Apple
2016-10-28 17:31 - 2016-05-19 02:28 - 00000000 ____D C:\adb
2016-10-28 11:48 - 2015-06-20 16:38 - 00000896 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-336042120-3881833094-1070839671-1001Core.job
2016-10-28 11:00 - 2015-10-30 04:21 - 00000000 ____D C:\WINDOWS\INF
2016-10-28 10:58 - 2014-02-05 20:21 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\TeamViewer
2016-10-27 01:46 - 2015-12-07 04:21 - 04986976 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-10-26 20:01 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-10-26 20:01 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-10-26 19:54 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\addins
2016-10-26 19:49 - 2015-12-17 15:35 - 00000000 ____D C:\Users\Natascha\Desktop\[Next_leveL]KMSAN140
2016-10-26 19:49 - 2015-10-22 19:45 - 00000000 ____D C:\ProgramData\BSD
2016-10-26 18:23 - 2014-07-12 15:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-10-26 18:23 - 2014-07-12 15:20 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-26 16:12 - 2014-12-26 23:13 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\BitTorrent
2016-10-26 16:12 - 2014-03-15 13:10 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\FileZilla
2016-10-26 16:10 - 2016-06-05 16:17 - 00000000 ____D C:\WINDOWS\Minidump
2016-10-26 16:10 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-10-25 23:22 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-10-25 23:20 - 2015-10-30 04:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-10-25 23:11 - 2014-02-05 20:21 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-10-25 22:52 - 2015-10-22 00:44 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-10-25 16:37 - 2013-11-10 14:52 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-10-25 15:07 - 2016-06-03 18:55 - 00000000 ____D C:\Program Files (x86)\OPO Toolkit
2016-10-25 15:07 - 2015-04-16 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services
2016-10-25 15:07 - 2013-10-15 23:57 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2016-10-25 15:07 - 2013-10-14 01:02 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2016-10-25 15:07 - 2012-10-28 20:21 - 00000000 ____D C:\Program Files (x86)\CyberLink
2016-10-25 15:06 - 2016-08-16 16:55 - 00000000 ____D C:\Program Files (x86)\ON1
2016-10-25 15:06 - 2016-06-04 01:34 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2016-10-25 15:06 - 2016-06-03 03:31 - 00000000 ____D C:\Program Files (x86)\ClockworkMod
2016-10-25 15:06 - 2016-06-02 16:19 - 00000000 ____D C:\Program Files (x86)\Spirent Communications
2016-10-25 15:06 - 2016-06-02 16:19 - 00000000 ____D C:\Program Files (x86)\HTC
2016-10-25 15:06 - 2016-06-02 15:50 - 00000000 ____D C:\Program Files (x86)\Kingo ROOT
2016-10-25 15:06 - 2016-05-19 03:43 - 00000000 ____D C:\Program Files (x86)\Minimal ADB and Fastboot
2016-10-25 15:06 - 2016-05-17 02:54 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2016-10-25 15:06 - 2016-01-27 11:18 - 00000000 ____D C:\Program Files (x86)\MSECache
2016-10-25 15:06 - 2015-12-07 04:26 - 00000000 ____D C:\Program Files (x86)\ASUS
2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows NT
2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-10-25 15:06 - 2015-09-23 11:24 - 00000000 ____D C:\Program Files (x86)\Western Digital
2016-10-25 15:06 - 2015-08-24 15:10 - 00000000 ____D C:\Program Files (x86)\Ares
2016-10-25 15:06 - 2015-07-23 10:15 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-10-25 15:06 - 2015-07-23 10:04 - 00000000 ____D C:\Program Files (x86)\QuickTime
2016-10-25 15:06 - 2015-07-04 18:14 - 00000000 ____D C:\Program Files (x86)\eclipse
2016-10-25 15:06 - 2015-05-04 17:05 - 00000000 ____D C:\Program Files (x86)\Java
2016-10-25 15:06 - 2015-04-16 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-10-25 15:06 - 2015-04-16 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2016-10-25 15:06 - 2015-04-16 18:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0
2016-10-25 15:06 - 2015-04-16 18:48 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2016-10-25 15:06 - 2014-08-20 18:26 - 00000000 ____D C:\Program Files (x86)\Alcohol Soft
2016-10-25 15:06 - 2014-08-07 22:42 - 00000000 ____D C:\Program Files (x86)\Total Seminars
2016-10-25 15:06 - 2014-05-27 19:06 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-10-25 15:06 - 2014-05-27 19:04 - 00000000 ____D C:\Program Files (x86)\Bonjour
2016-10-25 15:06 - 2014-03-15 13:09 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2016-10-25 15:06 - 2013-11-11 07:19 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-10-25 15:06 - 2013-11-10 14:49 - 00000000 ____D C:\Program Files (x86)\Norton Identity Safe
2016-10-25 15:06 - 2013-11-05 14:36 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-10-25 15:06 - 2013-11-05 14:36 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-10-25 15:06 - 2013-10-23 20:42 - 00000000 ____D C:\Program Files (x86)\Calibre2
2016-10-25 15:06 - 2013-10-16 18:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2016-10-25 15:06 - 2013-10-16 18:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2016-10-25 15:06 - 2013-10-16 18:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-10-25 15:06 - 2013-10-16 01:00 - 00000000 ____D C:\Program Files (x86)\My Company Name
2016-10-25 15:06 - 2013-10-15 14:34 - 00000000 ____D C:\Program Files (x86)\NortonInstaller
2016-10-25 15:06 - 2013-10-14 01:04 - 00000000 ____D C:\Program Files (x86)\Google
2016-10-25 15:06 - 2013-10-14 00:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-25 15:06 - 2013-10-14 00:35 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Ultra
2016-10-25 15:06 - 2012-10-28 20:12 - 00000000 ____D C:\Program Files (x86)\Ralink
2016-10-25 15:06 - 2012-10-28 20:12 - 00000000 ____D C:\Program Files (x86)\Cisco
2016-10-25 15:06 - 2012-10-28 20:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-10-25 15:06 - 2012-10-28 20:07 - 00000000 ____D C:\Program Files (x86)\VIA
2016-10-25 15:06 - 2012-10-28 20:04 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2016-10-25 15:06 - 2012-10-28 20:04 - 00000000 ____D C:\Program Files (x86)\AMD APP
2016-10-25 15:06 - 2012-10-28 20:03 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2016-10-25 15:06 - 2012-08-04 22:42 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-10-25 11:42 - 2015-12-07 04:27 - 00000000 ____D C:\ProgramData\Package Cache
2016-10-22 12:23 - 2013-10-14 01:16 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Skype
2016-10-22 12:17 - 2016-08-28 17:25 - 00000000 ____D C:\Users\Natascha\Desktop\Shaun
2016-10-21 13:50 - 2013-07-08 13:50 - 00000000 ____D C:\Users\Natascha\AppData\Local\Packages
2016-10-21 10:53 - 2013-10-14 01:15 - 00000000 ____D C:\ProgramData\Skype
2016-10-18 20:28 - 2015-12-07 04:32 - 00000000 ____D C:\Users\Administrator
2016-10-18 20:20 - 2014-03-04 21:25 - 00000000 ____D C:\Users\Natascha\AppData\Local\ElevatedDiagnostics

==================== Files in the root of some directories =======

2015-11-10 18:34 - 2016-02-08 20:00 - 0000132 _____ () C:\Users\Natascha\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-03-09 18:30 - 2015-03-09 18:30 - 0005487 _____ () C:\Users\Natascha\AppData\Roaming\BYAIAMUF
2016-05-16 12:31 - 2016-05-17 09:51 - 0000385 _____ () C:\Users\Natascha\AppData\Roaming\Rim.Desktop.Exception.log
2016-05-16 12:26 - 2016-05-17 02:55 - 0003048 _____ () C:\Users\Natascha\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2016-05-16 12:31 - 2016-05-17 09:51 - 0000385 _____ () C:\Users\Natascha\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-03-15 13:10 - 2014-03-15 13:10 - 0000046 _____ () C:\Users\Natascha\AppData\Roaming\WB.CFG
2014-06-30 22:13 - 2014-06-30 22:14 - 0003072 _____ () C:\Users\Natascha\AppData\Local\file__0.localstorage
2015-03-16 16:31 - 2015-03-16 18:00 - 0000600 _____ () C:\Users\Natascha\AppData\Local\PUTTY.RND
2014-12-27 03:19 - 2014-12-27 03:19 - 0000017 _____ () C:\Users\Natascha\AppData\Local\resmon.resmoncfg
2016-09-09 18:44 - 2016-09-09 18:44 - 0000000 _____ () C:\Users\Natascha\AppData\Local\{09FF1931-8FC7-4D90-8785-4B08508A9D8D}
2016-09-08 18:44 - 2016-09-08 18:44 - 0000000 _____ () C:\Users\Natascha\AppData\Local\{960C92ED-F7D5-4788-9833-E5EF87171EE3}
2012-08-04 22:42 - 2012-07-30 03:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
2012-08-04 22:42 - 2009-07-22 07:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe

Some files in TEMP:
====================
C:\Users\Natascha\AppData\Local\Temp\8B1D.tmp.exe
C:\Users\Natascha\AppData\Local\Temp\F631.tmp.exe
C:\Users\Natascha\AppData\Local\Temp\GURD372.exe
C:\Users\Natascha\AppData\Local\Temp\GURE85B.exe


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-10-28 10:54

==================== End of FRST.txt ============================