Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-10-2016 Ran by Natascha (administrator) on YAZZYBEE (01-11-2016 14:46:58) Running from C:\Users\Natascha\Downloads Loaded Profiles: Natascha (Available Profiles: Natascha & Administrator) Platform: Windows 10 Home Version 1511 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Safe Mode (with Networking) Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation) C:\Windows\HelpPane.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-09-24] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5264016 2012-08-16] (VIA) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-27] (ASUS Cloud Corporation) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073352 2012-06-25] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2013-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.) HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694048 2014-05-23] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-07-20] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation) HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443640 2014-10-31] (BlackBerry Limited) HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe [3125976 2013-09-23] (Disc Soft Ltd) HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [BitTorrent] => C:\Users\Natascha\AppData\Roaming\BitTorrent\BitTorrent.exe [1903648 2016-02-18] (BitTorrent Inc.) HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [465920 2016-07-01] (Microsoft Corporation) HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [Dropbox Update] => C:\Users\Natascha\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-20] (Dropbox, Inc.) HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [ares] => "C:\Program Files (x86)\Ares\Ares.exe" -h HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd) HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64" HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64" HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64" HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64" HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64" HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\RunOnce: [Uninstall C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64" HKU\S-1-5-21-336042120-3881833094-1070839671-1001\...\MountPoints2: {6c70926d-a3f7-11e5-bef4-08606e48acfa} - "F:\SETUP.EXE" HKU\S-1-5-18\...\Run: [] => 0 ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-12-13] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-12-13] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-12-13] () ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt9] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\FileSyncShell64.dll [2016-08-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\FileSyncShell64.dll [2016-08-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\amd64\FileSyncShell64.dll [2016-08-23] (Microsoft Corporation) ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt64.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => No File ShellIconOverlayIdentifiers: [KzShlobj2] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F3} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncShell.dll [2016-08-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncShell.dll [2016-08-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Natascha\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncShell.dll [2016-08-23] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Natascha\AppData\Roaming\Dropbox\bin\DropboxExt.1.0.dll [2016-10-24] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2016-01-15] ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.) Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-10-13] ShortcutTarget: Dropbox.lnk -> C:\Users\Natascha\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2016-10-19] ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Natascha\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook) Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OnePlus One Toolkit.lnk [2016-06-03] ShortcutTarget: OnePlus One Toolkit.lnk -> C:\Program Files (x86)\OPO Toolkit\OnePlus One Toolkit.exe () Startup: C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk [2016-06-04] ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 200.1.159.58 200.2.162.14 Tcpip\..\Interfaces\{00ebc61d-3fa3-46a3-a188-1df19733e00e}: [DhcpNameServer] 200.1.159.58 200.2.162.14 Tcpip\..\Interfaces\{74e8714a-3c3a-4950-acf7-bf14bb224506}: [DhcpNameServer] 8.8.8.8 Tcpip\..\Interfaces\{de8883bd-5604-4b2e-931a-b787e0b09ed8}: [DhcpNameServer] 200.1.159.58 200.2.162.14 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-336042120-3881833094-1070839671-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://home.lenovo.com SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-07-19] (Microsoft Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: No Name -> {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} -> No File BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-07-12] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-07-19] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-29] (Oracle Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-07-12] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-29] (Oracle Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated) Toolbar: HKLM - No Name - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - No File Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-336042120-3881833094-1070839671-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Toolbar: HKU\S-1-5-21-336042120-3881833094-1070839671-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies) Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll No File FireFox: ======== FF ProfilePath: C:\Users\Natascha\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\2r3ugg6v.default\Profiles\2r3ugg6v.default [not found] FF ProfilePath: C:\Users\Natascha\AppData\Roaming\Mozilla\Firefox\Profiles\2r3ugg6v.default [2016-11-01] FF Extension: (Firefox Hotfix) - C:\Users\Natascha\AppData\Roaming\Mozilla\Firefox\Profiles\2r3ugg6v.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-10-30] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-10-20] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.6.0.27\coFFPlgn => not found FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_205.dll [2016-10-26] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [No File] FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-12-19] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_205.dll [2016-10-26] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] () FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-29] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-29] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File] FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2014-11-28] () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-09-22] (VideoLAN) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-12-19] (Adobe Systems) FF Plugin HKU\S-1-5-21-336042120-3881833094-1070839671-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Natascha\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-09-03] (Unity Technologies ApS) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation) Chrome: ======= CHR DefaultProfile: ChromeDefaultData CHR Profile: C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-11-01] <==== ATTENTION CHR Extension: (Google Docs) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-26] CHR Extension: (Google Drive) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-26] CHR Extension: (YouTube) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-26] CHR Extension: (Google Docs Offline) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-26] CHR Extension: (Chrome Web Store Payments) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-26] CHR Extension: (Gmail) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-26] CHR Extension: (Chrome Media Router) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-26] CHR Profile: C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default [2016-10-29] CHR Extension: (Google Docs) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-03] CHR Extension: (Google Drive) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26] CHR Extension: (Google Search) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29] CHR Extension: (Google Docs Offline) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-05] CHR Extension: (Chrome Web Store Payments) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05] CHR Extension: (Gmail) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30] CHR Extension: (Chrome Media Router) - C:\Users\Natascha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-22] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.43\Exts\Chrome.crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed] S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.) S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) S3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024 2014-10-31] (BlackBerry Limited) S3 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe [654552 2013-09-23] (Disc Soft Ltd) S2 NCO; C:\Program Files (x86)\Norton Identity Safe\Engine\2014.7.0.47\NST.exe [130104 2014-05-14] (Symantec Corporation) S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2011-04-13] (Hewlett-Packard) [File not signed] S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2011-04-13] (Hewlett-Packard) [File not signed] S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed] S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7500048 2016-09-20] (TeamViewer GmbH) S2 VIAKaraokeService; C:\WINDOWS\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.) S3 vmicvss; C:\WINDOWS\System32\ICSvc.dll [511488 2015-10-30] (Microsoft Corporation) S3 wampapache64; c:\wamp\bin\apache\apache2.4.9\bin\httpd.exe [24576 2014-05-01] (Apache Software Foundation) [File not signed] S3 wampmysqld64; c:\wamp\bin\mysql\mysql5.6.17\bin\mysqld.exe [12942848 2014-05-01] () [File not signed] S2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-07-20] (Western Digital Technologies, Inc.) S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [306552 2015-07-20] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 APXACC; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation) S3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices) S1 ccSet_NST; C:\WINDOWS\system32\drivers\NSTx64\7DE07000.02F\ccSetx64.sys [162392 2014-02-20] (Symantec Corporation) R3 dtscsibus; C:\WINDOWS\system32\DRIVERS\dtscsibus.sys [29696 2015-12-15] (Disc Soft Ltd) R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 netr28x; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.) S3 RimUsb; C:\WINDOWS\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S3 RimVSerPort; C:\WINDOWS\system32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd) S1 ucdrv; C:\WINDOWS\System32\drivers:ucdrv-x64.sys [20324 ] (UC Web Inc.) <==== ATTENTION R1 UCGuard; C:\WINDOWS\System32\DRIVERS\ucguard.sys [81792 2016-08-29] (Huorong Borui (Beijing) Technology Co., Ltd.) <==== ATTENTION S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (MBB) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) NETSVCx32: HpSvc -> no filepath. ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-11-01 14:44 - 2016-11-01 14:46 - 00000000 ____D C:\FRST 2016-11-01 14:43 - 2016-11-01 14:44 - 02408960 _____ (Farbar) C:\Users\Natascha\Downloads\FRST64.exe 2016-11-01 14:37 - 2016-11-01 14:41 - 01758208 _____ (Farbar) C:\Users\Natascha\Downloads\FRST (1).exe 2016-11-01 12:55 - 2016-11-01 12:55 - 08270896 _____ (Piriform Ltd) C:\Users\Natascha\Downloads\ccsetup523pro.exe 2016-11-01 12:32 - 2016-11-01 12:32 - 01758208 _____ (Farbar) C:\Users\Natascha\Downloads\FRST.exe 2016-10-30 17:11 - 2016-10-30 17:11 - 00000000 ___HD C:\OneDriveTemp 2016-10-29 20:40 - 2016-10-29 20:40 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-10-29 03:51 - 2016-10-29 03:51 - 00004430 _____ C:\Users\Natascha\Desktop\ESETscan.txt 2016-10-28 21:56 - 2016-10-28 21:57 - 06770304 _____ (ESET spol. s r.o.) C:\Users\Natascha\Downloads\ESETOnlineScanner_ENU.exe 2016-10-28 21:56 - 2016-10-28 21:56 - 06770304 _____ (ESET spol. s r.o.) C:\Users\Natascha\Downloads\ESETOnlineScanner_ENU (2).exe 2016-10-28 17:12 - 2016-10-28 17:13 - 03851848 _____ C:\Users\Natascha\Downloads\Unconfirmed 11352.crdownload 2016-10-28 10:29 - 2016-10-28 10:29 - 00226646 _____ C:\Users\Natascha\Downloads\request.pdf 2016-10-28 00:30 - 2016-10-28 00:30 - 00001401 _____ C:\Users\Natascha\Desktop\JRT.txt 2016-10-28 00:24 - 2016-10-28 00:25 - 01631928 _____ (Malwarebytes) C:\Users\Natascha\Downloads\JRT.exe 2016-10-27 15:03 - 2016-10-27 15:03 - 06761600 _____ (ESET spol. s r.o.) C:\Users\Natascha\Downloads\esetonlinescanner_enu (1).exe 2016-10-27 11:45 - 2016-10-27 11:45 - 00000000 ____D C:\Users\Natascha\AppData\Local\ESET 2016-10-26 20:51 - 2016-10-30 17:28 - 00000000 ____D C:\AdwCleaner 2016-10-26 20:50 - 2016-10-26 20:50 - 03910208 _____ C:\Users\Natascha\Downloads\AdwCleaner.exe 2016-10-26 18:23 - 2016-10-26 18:23 - 00001173 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-10-26 18:21 - 2016-11-01 14:27 - 00640730 _____ C:\WINDOWS\ntbtlog.txt 2016-10-26 16:07 - 2016-10-26 16:07 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-10-26 16:07 - 2016-10-26 16:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-10-26 16:07 - 2016-10-26 16:07 - 00000000 ____D C:\Program Files\CCleaner 2016-10-26 15:20 - 2016-11-01 14:48 - 00030821 _____ C:\Users\Natascha\Downloads\FRST.txt 2016-10-26 00:08 - 2016-11-01 14:28 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2016-10-25 16:37 - 2016-10-25 16:37 - 00004444 _____ C:\WINDOWS\System32\Tasks\SecureUpdater 2016-10-25 15:46 - 2016-10-25 17:06 - 00000000 __SHD C:\Users\Natascha\AppData\Local\svchost 2016-10-25 15:45 - 2016-10-18 15:58 - 00567808 _____ C:\WINDOWS\SysWOW64\chtbrkg.dll 2016-10-25 15:45 - 2016-10-18 15:57 - 00753152 _____ C:\WINDOWS\system32\chtbrkg.dll 2016-10-25 15:43 - 2016-10-25 20:00 - 00002654 _____ C:\WINDOWS\System32\Tasks\UCBrowserUpdaterCore 2016-10-25 15:43 - 2016-10-25 15:43 - 00003504 _____ C:\WINDOWS\System32\Tasks\UCBrowserUpdater 2016-10-25 15:07 - 2016-10-25 15:07 - 00000000 ____D C:\ProgramData\Avira 2016-10-25 15:07 - 2016-10-25 15:07 - 00000000 ____D C:\ProgramData\Avg 2016-10-25 15:07 - 2016-10-25 15:07 - 00000000 ____D C:\ProgramData\AVAST Software 2016-10-25 15:07 - 2004-10-10 09:50 - 00278528 _____ (Real Networks, Inc) C:\WINDOWS\SysWOW64\pncrt.dll 2016-10-25 15:07 - 2004-07-02 17:33 - 00327749 _____ (RealNetworks, Inc.) C:\WINDOWS\SysWOW64\drvc.dll 2016-10-25 14:57 - 2016-08-29 07:50 - 00081792 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys 2016-10-25 13:09 - 2016-10-25 13:09 - 00000000 ____D C:\Users\Natascha\Documents\Any Video Converter Professional 2016-10-25 11:55 - 2016-10-25 11:55 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\TechSmith 2016-10-25 11:53 - 2016-10-25 11:53 - 00000000 ____D C:\Users\Natascha\Documents\Camtasia Studio 2016-10-25 11:52 - 2016-10-25 11:52 - 00001152 _____ C:\Users\Public\Desktop\Camtasia 9.lnk 2016-10-25 11:52 - 2016-10-25 11:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2016-10-25 11:50 - 2016-10-25 11:50 - 00000000 ____D C:\ProgramData\TechSmith 2016-10-25 11:50 - 2016-10-25 11:50 - 00000000 ____D C:\Program Files\TechSmith 2016-10-25 11:09 - 2016-10-25 11:40 - 285144256 _____ (TechSmith Corporation) C:\Users\Natascha\Downloads\camtasia.exe 2016-10-25 01:47 - 2016-10-25 15:06 - 00000000 ____D C:\Program Files (x86)\Windows Live 2016-10-24 19:00 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll 2016-10-24 19:00 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll 2016-10-24 19:00 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll 2016-10-24 19:00 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll 2016-10-24 19:00 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll 2016-10-24 19:00 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll 2016-10-24 19:00 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll 2016-10-24 19:00 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll 2016-10-24 18:59 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll 2016-10-24 18:59 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll 2016-10-24 18:59 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll 2016-10-24 18:59 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll 2016-10-24 18:54 - 2016-10-25 01:47 - 00000000 ____D C:\Users\Natascha\AppData\Local\Windows Live 2016-10-19 11:52 - 2016-10-19 11:52 - 00001284 _____ C:\Users\Natascha\Desktop\Facebook Gameroom.lnk 2016-10-19 11:52 - 2016-10-19 11:52 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook 2016-10-19 11:52 - 2016-10-19 11:52 - 00000000 ____D C:\Users\Natascha\AppData\Local\Facebook 2016-10-19 11:52 - 2016-10-19 11:52 - 00000000 ____D C:\Users\Natascha\AppData\Local\CEF 2016-10-19 11:50 - 2016-10-19 11:50 - 00249600 _____ (Facebook) C:\Users\Natascha\Downloads\FacebookGameroom.exe 2016-10-17 16:43 - 2016-10-22 12:18 - 00000000 ____D C:\Users\Natascha\Desktop\Gayparade ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-11-01 14:43 - 2013-10-14 01:06 - 00001605 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-11-01 14:43 - 2013-10-14 00:44 - 00001170 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-11-01 14:28 - 2013-10-14 01:04 - 00000000 ____D C:\Users\Natascha\AppData\Local\Google 2016-11-01 14:25 - 2015-12-07 05:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-11-01 14:24 - 2015-09-03 20:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-11-01 14:16 - 2015-06-20 16:38 - 00000948 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-336042120-3881833094-1070839671-1001UA.job 2016-11-01 14:16 - 2013-11-05 07:26 - 00000000 __RDO C:\Users\Natascha\SkyDrive 2016-11-01 12:38 - 2013-10-14 00:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-10-31 06:01 - 2013-10-15 02:44 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-10-31 05:44 - 2013-10-14 01:04 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-10-31 04:52 - 2015-05-10 12:28 - 00001716 _____ C:\WINDOWS\Tasks\BYAIAMUF.job 2016-10-30 21:42 - 2015-05-10 12:29 - 00001364 _____ C:\WINDOWS\Tasks\GNOK.job 2016-10-30 18:44 - 2013-10-14 01:04 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-10-30 17:16 - 2013-11-05 09:56 - 00000000 ____D C:\Users\Natascha\AppData\Local\CrashDumps 2016-10-30 17:10 - 2015-12-07 04:32 - 00000000 ____D C:\Users\Natascha 2016-10-30 15:13 - 2014-09-04 15:41 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-10-29 20:57 - 2013-11-13 13:00 - 00004158 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BA7909C2-DDCD-422F-AFD3-1068F328DC19} 2016-10-29 20:40 - 2013-10-18 13:13 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Dropbox 2016-10-29 20:30 - 2015-10-30 03:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI 2016-10-28 18:28 - 2014-05-27 19:04 - 00000000 ____D C:\ProgramData\Apple 2016-10-28 17:31 - 2016-05-19 02:28 - 00000000 ____D C:\adb 2016-10-28 11:48 - 2015-06-20 16:38 - 00000896 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-336042120-3881833094-1070839671-1001Core.job 2016-10-28 11:00 - 2015-10-30 04:21 - 00000000 ____D C:\WINDOWS\INF 2016-10-28 10:58 - 2014-02-05 20:21 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\TeamViewer 2016-10-27 01:46 - 2015-12-07 04:21 - 04986976 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-10-26 20:01 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-10-26 20:01 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-10-26 19:54 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\addins 2016-10-26 19:49 - 2015-12-17 15:35 - 00000000 ____D C:\Users\Natascha\Desktop\[Next_leveL]KMSAN140 2016-10-26 19:49 - 2015-10-22 19:45 - 00000000 ____D C:\ProgramData\BSD 2016-10-26 18:23 - 2014-07-12 15:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-10-26 18:23 - 2014-07-12 15:20 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-10-26 16:12 - 2014-12-26 23:13 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\BitTorrent 2016-10-26 16:12 - 2014-03-15 13:10 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\FileZilla 2016-10-26 16:10 - 2016-06-05 16:17 - 00000000 ____D C:\WINDOWS\Minidump 2016-10-26 16:10 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\ModemLogs 2016-10-25 23:22 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-10-25 23:20 - 2015-10-30 04:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-10-25 23:11 - 2014-02-05 20:21 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-10-25 22:52 - 2015-10-22 00:44 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-10-25 16:37 - 2013-11-10 14:52 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2016-10-25 15:07 - 2016-06-03 18:55 - 00000000 ____D C:\Program Files (x86)\OPO Toolkit 2016-10-25 15:07 - 2015-04-16 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Synchronization Services 2016-10-25 15:07 - 2013-10-15 23:57 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive 2016-10-25 15:07 - 2013-10-14 01:02 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2016-10-25 15:07 - 2012-10-28 20:21 - 00000000 ____D C:\Program Files (x86)\CyberLink 2016-10-25 15:06 - 2016-08-16 16:55 - 00000000 ____D C:\Program Files (x86)\ON1 2016-10-25 15:06 - 2016-06-04 01:34 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android 2016-10-25 15:06 - 2016-06-03 03:31 - 00000000 ____D C:\Program Files (x86)\ClockworkMod 2016-10-25 15:06 - 2016-06-02 16:19 - 00000000 ____D C:\Program Files (x86)\Spirent Communications 2016-10-25 15:06 - 2016-06-02 16:19 - 00000000 ____D C:\Program Files (x86)\HTC 2016-10-25 15:06 - 2016-06-02 15:50 - 00000000 ____D C:\Program Files (x86)\Kingo ROOT 2016-10-25 15:06 - 2016-05-19 03:43 - 00000000 ____D C:\Program Files (x86)\Minimal ADB and Fastboot 2016-10-25 15:06 - 2016-05-17 02:54 - 00000000 ____D C:\Program Files (x86)\Research In Motion 2016-10-25 15:06 - 2016-01-27 11:18 - 00000000 ____D C:\Program Files (x86)\MSECache 2016-10-25 15:06 - 2015-12-07 04:26 - 00000000 ____D C:\Program Files (x86)\ASUS 2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows NT 2016-10-25 15:06 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2016-10-25 15:06 - 2015-09-23 11:24 - 00000000 ____D C:\Program Files (x86)\Western Digital 2016-10-25 15:06 - 2015-08-24 15:10 - 00000000 ____D C:\Program Files (x86)\Ares 2016-10-25 15:06 - 2015-07-23 10:15 - 00000000 ____D C:\Program Files (x86)\iTunes 2016-10-25 15:06 - 2015-07-23 10:04 - 00000000 ____D C:\Program Files (x86)\QuickTime 2016-10-25 15:06 - 2015-07-04 18:14 - 00000000 ____D C:\Program Files (x86)\eclipse 2016-10-25 15:06 - 2015-05-04 17:05 - 00000000 ____D C:\Program Files (x86)\Java 2016-10-25 15:06 - 2015-04-16 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2016-10-25 15:06 - 2015-04-16 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2016-10-25 15:06 - 2015-04-16 18:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 10.0 2016-10-25 15:06 - 2015-04-16 18:48 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs 2016-10-25 15:06 - 2014-08-20 18:26 - 00000000 ____D C:\Program Files (x86)\Alcohol Soft 2016-10-25 15:06 - 2014-08-07 22:42 - 00000000 ____D C:\Program Files (x86)\Total Seminars 2016-10-25 15:06 - 2014-05-27 19:06 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2016-10-25 15:06 - 2014-05-27 19:04 - 00000000 ____D C:\Program Files (x86)\Bonjour 2016-10-25 15:06 - 2014-03-15 13:09 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client 2016-10-25 15:06 - 2013-11-11 07:19 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-10-25 15:06 - 2013-11-10 14:49 - 00000000 ____D C:\Program Files (x86)\Norton Identity Safe 2016-10-25 15:06 - 2013-11-05 14:36 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-10-25 15:06 - 2013-11-05 14:36 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-10-25 15:06 - 2013-10-23 20:42 - 00000000 ____D C:\Program Files (x86)\Calibre2 2016-10-25 15:06 - 2013-10-16 18:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2016-10-25 15:06 - 2013-10-16 18:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2016-10-25 15:06 - 2013-10-16 18:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2016-10-25 15:06 - 2013-10-16 01:00 - 00000000 ____D C:\Program Files (x86)\My Company Name 2016-10-25 15:06 - 2013-10-15 14:34 - 00000000 ____D C:\Program Files (x86)\NortonInstaller 2016-10-25 15:06 - 2013-10-14 01:04 - 00000000 ____D C:\Program Files (x86)\Google 2016-10-25 15:06 - 2013-10-14 00:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-10-25 15:06 - 2013-10-14 00:35 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Ultra 2016-10-25 15:06 - 2012-10-28 20:12 - 00000000 ____D C:\Program Files (x86)\Ralink 2016-10-25 15:06 - 2012-10-28 20:12 - 00000000 ____D C:\Program Files (x86)\Cisco 2016-10-25 15:06 - 2012-10-28 20:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-10-25 15:06 - 2012-10-28 20:07 - 00000000 ____D C:\Program Files (x86)\VIA 2016-10-25 15:06 - 2012-10-28 20:04 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2016-10-25 15:06 - 2012-10-28 20:04 - 00000000 ____D C:\Program Files (x86)\AMD APP 2016-10-25 15:06 - 2012-10-28 20:03 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2016-10-25 15:06 - 2012-08-04 22:42 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-10-25 11:42 - 2015-12-07 04:27 - 00000000 ____D C:\ProgramData\Package Cache 2016-10-22 12:23 - 2013-10-14 01:16 - 00000000 ____D C:\Users\Natascha\AppData\Roaming\Skype 2016-10-22 12:17 - 2016-08-28 17:25 - 00000000 ____D C:\Users\Natascha\Desktop\Shaun 2016-10-21 13:50 - 2013-07-08 13:50 - 00000000 ____D C:\Users\Natascha\AppData\Local\Packages 2016-10-21 10:53 - 2013-10-14 01:15 - 00000000 ____D C:\ProgramData\Skype 2016-10-18 20:28 - 2015-12-07 04:32 - 00000000 ____D C:\Users\Administrator 2016-10-18 20:20 - 2014-03-04 21:25 - 00000000 ____D C:\Users\Natascha\AppData\Local\ElevatedDiagnostics ==================== Files in the root of some directories ======= 2015-11-10 18:34 - 2016-02-08 20:00 - 0000132 _____ () C:\Users\Natascha\AppData\Roaming\Adobe PNG Format CS6 Prefs 2015-03-09 18:30 - 2015-03-09 18:30 - 0005487 _____ () C:\Users\Natascha\AppData\Roaming\BYAIAMUF 2016-05-16 12:31 - 2016-05-17 09:51 - 0000385 _____ () C:\Users\Natascha\AppData\Roaming\Rim.Desktop.Exception.log 2016-05-16 12:26 - 2016-05-17 02:55 - 0003048 _____ () C:\Users\Natascha\AppData\Roaming\Rim.Desktop.HttpServerSetup.log 2016-05-16 12:31 - 2016-05-17 09:51 - 0000385 _____ () C:\Users\Natascha\AppData\Roaming\Rim.DesktopHelper.Exception.log 2014-03-15 13:10 - 2014-03-15 13:10 - 0000046 _____ () C:\Users\Natascha\AppData\Roaming\WB.CFG 2014-06-30 22:13 - 2014-06-30 22:14 - 0003072 _____ () C:\Users\Natascha\AppData\Local\file__0.localstorage 2015-03-16 16:31 - 2015-03-16 18:00 - 0000600 _____ () C:\Users\Natascha\AppData\Local\PUTTY.RND 2014-12-27 03:19 - 2014-12-27 03:19 - 0000017 _____ () C:\Users\Natascha\AppData\Local\resmon.resmoncfg 2016-09-09 18:44 - 2016-09-09 18:44 - 0000000 _____ () C:\Users\Natascha\AppData\Local\{09FF1931-8FC7-4D90-8785-4B08508A9D8D} 2016-09-08 18:44 - 2016-09-08 18:44 - 0000000 _____ () C:\Users\Natascha\AppData\Local\{960C92ED-F7D5-4788-9833-E5EF87171EE3} 2012-08-04 22:42 - 2012-07-30 03:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd 2012-08-04 22:42 - 2009-07-22 07:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe Some files in TEMP: ==================== C:\Users\Natascha\AppData\Local\Temp\8B1D.tmp.exe C:\Users\Natascha\AppData\Local\Temp\F631.tmp.exe C:\Users\Natascha\AppData\Local\Temp\GURD372.exe C:\Users\Natascha\AppData\Local\Temp\GURE85B.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-10-28 10:54 ==================== End of FRST.txt ============================