[RESOLVED] 2nd Computer: Antivirus Issues - Page 2
Page 2 of 3 FirstFirst 123 LastLast
Results 16 to 30 of 33

Thread: [RESOLVED] 2nd Computer: Antivirus Issues

  1. #16
    Join Date
    Mar 2014
    Posts
    557
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-10-2014
    Ran by fireydrake (administrator) on DRAGONS on 25-10-2014 11:13:53
    Running from C:\Users\fireydrake\Desktop
    Loaded Profile: fireydrake (Available profiles: fireydrake)
    Platform: Windows 8.1 (X64) OS Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
    (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    () C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
    (DELL Inc.) C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Qualcomm®Atheros®) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe
    (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
    () C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    (SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe
    () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
    HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5762408 2013-06-03] (Dell Inc.)
    HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-10-19] (AVAST Software)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [132736 2013-10-30] ( (Qualcomm®Atheros®))
    HKLM\...\Policies\Explorer: [NoFolderOptions] 0
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-1276894799-377718809-1696388264-1001\...\Run: [Itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe [7342080 2013-06-26] ()
    HKU\S-1-5-21-1276894799-377718809-1696388264-1001\...\Run: [Facebook Update] => C:\Users\fireydrake\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-09-27] (Facebook Inc.)
    HKU\S-1-5-21-1276894799-377718809-1696388264-1001\...\MountPoints2: {5b70d30e-ff0f-11e3-825f-645a04253af6} - "E:\LaunchU3.exe"
    HKU\S-1-5-21-1276894799-377718809-1696388264-1001\...\MountPoints2: {a6d05c24-1053-11e4-8261-645a04253af6} - "E:\LaunchU3.exe"
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
    ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
    ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dell13.msn.com/?pc=DCJB
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM - {A11C34FF-C08A-45AC-89C3-BA7782362D91} URL = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=DCJB
    SearchScopes: HKLM-x32 - {A11C34FF-C08A-45AC-89C3-BA7782362D91} URL = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=DCJB
    SearchScopes: HKCU - {A11C34FF-C08A-45AC-89C3-BA7782362D91} URL =
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    Tcpip\Parameters: [DhcpNameServer] 24.116.0.53 24.116.2.50

    FireFox:
    ========
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin HKCU: @nsroblox.roblox.com/launcher -> C:\Users\fireydrake\AppData\Local\Roblox\Versions\version-d65566343374484f\\NPRobloxProxy.dll ( ROBLOX Corporation)
    FF Plugin HKCU: @nsroblox.roblox.com/launcher64 -> C:\Users\fireydrake\AppData\Local\Roblox\Versions\version-d65566343374484f\\NPRobloxProxy64.dll ( ROBLOX Corporation)
    FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\fireydrake\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
    FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\fireydrake\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
    FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-10-19]

    Chrome:
    =======
    CHR Profile: C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Docs) - C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-16]
    CHR Extension: (Google Drive) - C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-16]
    CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-16]
    CHR Extension: (YouTube) - C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-16]
    CHR Extension: (Google Search) - C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-16]
    CHR Extension: (Google Wallet) - C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-16]
    CHR Extension: (Gmail) - C:\Users\fireydrake\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-16]
    CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-19]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [317568 2013-10-30] (Windows (R) Win 7 DDK provider)
    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-10-19] (AVAST Software)
    R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
    R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
    S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-28] (Intel Corporation)
    S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-21] (Microsoft Corporation)
    S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
    S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
    R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2013-07-29] (CyberLink)
    R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor)
    R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1915920 2013-11-21] (SoftThinks SAS)
    S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-21] (Microsoft Corporation)
    S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-21] (Microsoft Corporation)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-23] (Microsoft Corporation)
    R2 WysePocketCloud; C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe [16176 2013-08-22] ()
    R2 WyseRemoteAccess; C:\Program Files (x86)\Wyse\PocketCloud\WyseRemoteAccess.exe [1785344 2013-08-19] (DELL Inc.) [File not signed]

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-19] ()
    R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-19] (AVAST Software)
    R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-19] (AVAST Software)
    R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-19] ()
    R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-19] (AVAST Software)
    R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-19] (AVAST Software)
    S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-19] (AVAST Software)
    R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-19] ()
    R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3858944 2013-10-17] (Qualcomm Atheros Communications, Inc.)
    R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-10-30] (Qualcomm Atheros)
    R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
    R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
    R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-10-25] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-10-01] (Malwarebytes Corporation)
    R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [99288 2013-08-28] (Intel Corporation)
    S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-06] (Synaptics Incorporated)
    R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-09-06] (Synaptics Incorporated)
    U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [34808 2014-10-24] ()
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-10-25 11:13 - 2014-10-25 11:14 - 00016123 _____ () C:\Users\fireydrake\Desktop\FRST.txt
    2014-10-25 11:13 - 2014-10-25 11:13 - 00000000 ____D () C:\FRST
    2014-10-25 11:12 - 2014-10-25 11:12 - 02112512 _____ (Farbar) C:\Users\fireydrake\Desktop\FRST64.exe
    2014-10-25 11:11 - 2014-10-25 11:11 - 00000627 _____ () C:\Users\fireydrake\Desktop\JRT.txt
    2014-10-25 11:03 - 2014-10-25 11:03 - 00000000 ____D () C:\Windows\ERUNT
    2014-10-25 11:02 - 2014-10-25 11:02 - 01706144 _____ (Thisisu) C:\Users\fireydrake\Desktop\JRT.exe
    2014-10-25 11:01 - 2014-10-25 11:01 - 00000000 ___RD () C:\Users\fireydrake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
    2014-10-25 10:56 - 2014-10-25 10:59 - 00000000 ____D () C:\AdwCleaner
    2014-10-25 10:56 - 2014-10-25 10:56 - 01962496 _____ () C:\Users\fireydrake\Desktop\adwcleaner_4.001.exe
    2014-10-24 18:17 - 2014-10-24 18:17 - 00001383 _____ () C:\Users\fireydrake\Desktop\ROBLOX Studio.lnk
    2014-10-24 08:03 - 2014-10-24 08:18 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
    2014-10-24 08:02 - 2014-10-24 08:18 - 00000000 ____D () C:\Users\fireydrake\Desktop\mbar
    2014-10-24 08:01 - 2014-10-24 08:01 - 14349744 _____ (Malwarebytes Corp.) C:\Users\fireydrake\Desktop\mbar-1.07.0.1012.exe
    2014-10-24 07:44 - 2014-10-24 07:44 - 00034808 _____ () C:\Windows\system32\Drivers\TrueSight.sys
    2014-10-24 07:44 - 2014-10-24 07:44 - 00000000 ____D () C:\ProgramData\RogueKiller
    2014-10-24 07:39 - 2014-10-24 07:42 - 16281688 _____ () C:\Users\fireydrake\Desktop\RogueKiller.exe
    2014-10-23 10:24 - 2014-10-23 10:24 - 00688992 _____ (Swearware) C:\Users\fireydrake\Desktop\dds.scr
    2014-10-19 16:11 - 2014-10-19 16:11 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2014-10-19 16:11 - 2014-10-19 16:11 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2014-10-19 16:11 - 2014-10-19 16:11 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2014-10-19 16:11 - 2014-10-19 16:11 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2014-10-19 16:11 - 2014-10-19 16:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2014-10-19 16:10 - 2014-10-19 16:10 - 00000000 ____D () C:\Program Files (x86)\Java
    2014-10-19 14:20 - 2014-10-25 11:10 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-10-19 14:19 - 2014-10-24 08:02 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-10-19 14:19 - 2014-10-19 14:19 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-10-19 14:19 - 2014-10-19 14:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-10-19 14:19 - 2014-10-19 14:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-10-19 14:19 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-10-19 14:19 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-10-19 13:14 - 2014-10-19 13:14 - 00001944 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
    2014-10-19 13:14 - 2014-10-19 13:14 - 00000000 ____D () C:\Users\fireydrake\AppData\Roaming\AVAST Software
    2014-10-19 13:14 - 2014-10-19 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
    2014-10-19 13:13 - 2014-10-23 18:10 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
    2014-10-19 13:13 - 2014-10-19 13:13 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
    2014-10-19 13:13 - 2014-10-19 13:13 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
    2014-10-19 13:13 - 2014-10-19 13:13 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
    2014-10-19 13:13 - 2014-10-19 13:13 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
    2014-10-19 13:13 - 2014-10-19 13:13 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
    2014-10-19 13:13 - 2014-10-19 13:13 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
    2014-10-19 13:13 - 2014-10-19 13:13 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
    2014-10-19 13:13 - 2014-10-19 13:13 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
    2014-10-19 13:13 - 2014-10-19 13:13 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
    2014-10-19 13:13 - 2014-10-19 13:13 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
    2014-10-19 13:10 - 2014-10-19 13:10 - 00000000 ____D () C:\Program Files\AVAST Software
    2014-10-17 21:21 - 2014-09-03 18:10 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
    2014-10-17 21:21 - 2014-09-03 17:57 - 00921600 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
    2014-10-17 21:21 - 2014-09-03 17:49 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
    2014-10-17 21:20 - 2014-10-09 16:16 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-10-17 21:20 - 2014-10-08 16:09 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2014-10-17 21:20 - 2014-09-18 19:24 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-10-17 21:20 - 2014-09-13 00:02 - 02779648 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2014-10-17 21:20 - 2014-09-12 23:30 - 03117568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2014-10-17 21:20 - 2014-08-28 19:58 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
    2014-10-17 21:20 - 2014-08-28 17:56 - 02646016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
    2014-10-17 21:20 - 2014-08-28 17:47 - 02321920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2014-10-17 19:24 - 2014-09-27 16:25 - 04183040 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-10-17 19:23 - 2014-09-07 21:15 - 00054752 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2014-10-17 19:23 - 2014-09-07 19:46 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2014-10-17 19:23 - 2014-09-07 19:46 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2014-10-17 19:23 - 2014-09-07 18:08 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2014-10-17 19:23 - 2014-09-07 18:07 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2014-10-17 19:23 - 2014-09-07 18:05 - 03448320 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2014-10-17 19:23 - 2014-09-07 18:04 - 00388608 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
    2014-10-17 19:23 - 2014-09-07 18:04 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2014-10-17 19:23 - 2014-09-07 18:03 - 01702400 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2014-10-17 19:23 - 2014-09-07 18:03 - 00839680 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2014-10-17 19:23 - 2014-09-07 17:59 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2014-10-17 19:23 - 2014-09-07 17:59 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2014-10-17 19:23 - 2014-09-07 17:56 - 00672256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2014-10-17 19:23 - 2014-09-07 17:56 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2014-10-17 19:22 - 2014-09-25 16:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-10-17 19:22 - 2014-09-25 16:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2014-10-17 19:22 - 2014-09-25 16:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2014-10-17 19:22 - 2014-09-25 16:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-10-17 19:22 - 2014-09-25 16:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-10-17 19:22 - 2014-09-25 16:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-10-17 19:22 - 2014-09-18 20:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-10-17 19:22 - 2014-09-18 19:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-10-17 19:22 - 2014-09-18 19:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-10-17 19:22 - 2014-09-18 19:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2014-10-17 19:22 - 2014-09-18 19:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2014-10-17 19:22 - 2014-09-18 19:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-10-17 19:22 - 2014-09-18 19:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-10-17 19:22 - 2014-09-18 19:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-10-17 19:22 - 2014-09-18 19:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2014-10-17 19:22 - 2014-09-18 19:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2014-10-17 19:22 - 2014-09-18 18:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2014-10-17 19:22 - 2014-09-18 18:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2014-10-17 19:22 - 2014-09-18 18:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-10-17 19:22 - 2014-09-18 18:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-10-17 19:22 - 2014-09-18 18:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-10-17 19:22 - 2014-09-18 18:42 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-10-17 19:22 - 2014-09-18 18:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-10-17 19:22 - 2014-09-18 18:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-10-17 19:22 - 2014-09-18 18:20 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-10-17 19:22 - 2014-09-18 18:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-10-17 19:22 - 2014-09-18 17:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-10-17 19:22 - 2014-09-18 17:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-10-17 19:22 - 2014-09-18 17:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-10-17 19:22 - 2014-09-18 17:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-10-17 19:21 - 2014-09-13 00:29 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
    2014-10-17 19:21 - 2014-09-12 23:49 - 00068608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
    2014-10-17 19:21 - 2014-09-03 18:12 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
    2014-10-17 19:21 - 2014-09-03 18:01 - 00514048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
    2014-10-17 19:20 - 2014-08-15 22:08 - 21195616 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2014-10-17 19:20 - 2014-08-15 22:08 - 01507648 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
    2014-10-17 19:20 - 2014-08-15 22:01 - 01710184 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2014-10-17 19:20 - 2014-08-15 21:58 - 01112512 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2014-10-17 19:20 - 2014-08-15 21:57 - 02498880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
    2014-10-17 19:20 - 2014-08-15 21:57 - 00428864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
    2014-10-17 19:20 - 2014-08-15 21:16 - 18722600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2014-10-17 19:20 - 2014-08-15 21:16 - 01205976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
    2014-10-17 19:20 - 2014-08-15 21:03 - 01467384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2014-10-17 19:20 - 2014-08-15 19:31 - 00838144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2014-10-17 19:20 - 2014-08-15 19:04 - 00359424 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
    2014-10-17 19:20 - 2014-08-15 18:58 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
    2014-10-17 19:20 - 2014-08-15 18:53 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll
    2014-10-17 19:20 - 2014-08-15 18:46 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\ProximityService.dll
    2014-10-17 19:20 - 2014-08-15 18:45 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
    2014-10-17 19:20 - 2014-08-15 18:43 - 00321024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
    2014-10-17 19:20 - 2014-08-15 18:43 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll
    2014-10-17 19:20 - 2014-08-15 18:31 - 00914432 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
    2014-10-17 19:20 - 2014-08-15 18:31 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\pcsvDevice.dll
    2014-10-17 19:20 - 2014-08-15 18:29 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-10-17 19:20 - 2014-08-15 18:23 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
    2014-10-17 19:20 - 2014-08-15 18:22 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
    2014-10-17 19:20 - 2014-08-15 18:22 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
    2014-10-17 19:20 - 2014-08-15 18:19 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-10-17 19:20 - 2014-08-15 18:18 - 04758528 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
    2014-10-17 19:20 - 2014-08-15 18:17 - 08757760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
    2014-10-17 19:20 - 2014-08-15 18:14 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
    2014-10-17 19:20 - 2014-08-15 18:13 - 06649344 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2014-10-17 19:20 - 2014-08-15 18:13 - 05902848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
    2014-10-17 19:20 - 2014-08-15 18:13 - 00840192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
    2014-10-17 19:20 - 2014-08-15 18:11 - 00920064 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
    2014-10-17 19:20 - 2014-08-15 18:10 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
    2014-10-17 19:20 - 2014-08-15 18:08 - 05777408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2014-10-17 19:20 - 2014-08-15 18:07 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
    2014-10-17 19:20 - 2014-07-31 17:22 - 00388729 _____ () C:\Windows\system32\ApnDatabase.xml
    2014-10-10 19:04 - 2014-09-22 00:42 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
    2014-09-27 22:05 - 2014-10-24 22:10 - 00000964 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001UA.job
    2014-09-27 22:05 - 2014-10-24 22:10 - 00000942 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001Core.job
    2014-09-27 22:05 - 2014-09-27 22:05 - 00003822 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001UA
    2014-09-27 22:05 - 2014-09-27 22:05 - 00003472 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001Core
    2014-09-27 22:05 - 2014-09-27 22:05 - 00000000 ____D () C:\Users\fireydrake\AppData\Local\Facebook

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-10-25 11:11 - 2014-06-11 10:24 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1276894799-377718809-1696388264-1001
    2014-10-25 11:07 - 2014-02-26 13:55 - 00000000 ____D () C:\Program Files (x86)\Dell Backup and Recovery
    2014-10-25 11:01 - 2014-07-21 12:11 - 00000000 ___DO () C:\Users\fireydrake\OneDrive
    2014-10-25 11:00 - 2014-06-16 11:25 - 00000918 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-10-25 11:00 - 2013-08-22 08:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-10-25 10:59 - 2014-02-26 13:43 - 01341576 _____ () C:\Windows\WindowsUpdate.log
    2014-10-25 10:59 - 2014-02-26 13:13 - 01017094 _____ () C:\Windows\PFRO.log
    2014-10-25 10:59 - 2013-08-22 07:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
    2014-10-25 10:56 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\system32\sru
    2014-10-25 09:45 - 2014-06-11 12:17 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{4A6D377C-FE6C-47F0-9EEF-F71EB4EDA74A}
    2014-10-25 09:43 - 2014-06-16 11:25 - 00000922 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-10-24 18:17 - 2014-06-11 12:41 - 00000000 ____D () C:\Users\fireydrake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
    2014-10-24 18:15 - 2014-06-11 12:42 - 00001371 _____ () C:\Users\fireydrake\Desktop\ROBLOX Player.lnk
    2014-10-24 07:28 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\system32\NDF
    2014-10-23 16:35 - 2014-02-26 13:29 - 00865408 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-10-23 16:31 - 2013-08-22 08:46 - 00023427 _____ () C:\Windows\setupact.log
    2014-10-22 20:50 - 2014-06-11 10:18 - 00000000 ____D () C:\Users\fireydrake
    2014-10-22 15:38 - 2014-06-16 11:25 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-10-22 15:38 - 2014-06-16 11:25 - 00003658 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-10-22 15:36 - 2014-06-16 11:26 - 00002205 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-10-22 14:47 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\AppReadiness
    2014-10-21 20:41 - 2014-08-02 18:56 - 00000000 ____D () C:\Users\fireydrake\AppData\Local\CrashDumps
    2014-10-19 16:11 - 2014-06-11 12:28 - 00000000 ____D () C:\ProgramData\Oracle
    2014-10-19 14:59 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\rescache
    2014-10-19 13:10 - 2014-07-13 07:07 - 00000000 ____D () C:\ProgramData\AVAST Software
    2014-10-19 13:04 - 2013-08-22 09:20 - 00000000 ____D () C:\Windows\CbsTemp
    2014-10-18 22:02 - 2014-06-11 10:19 - 00000000 ____D () C:\Users\fireydrake\AppData\Local\Packages
    2014-10-18 18:58 - 2013-08-22 08:44 - 00346744 _____ () C:\Windows\system32\FNTCACHE.DAT
    2014-10-18 18:55 - 2014-07-16 11:42 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2014-10-18 18:55 - 2013-08-22 09:36 - 00000000 ___RD () C:\Windows\ToastData
    2014-10-18 18:55 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\WinStore
    2014-10-18 18:55 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\MediaViewer
    2014-10-18 18:55 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\FileManager
    2014-10-18 18:55 - 2013-08-22 09:36 - 00000000 ____D () C:\Windows\Camera
    2014-10-18 15:47 - 2014-06-14 12:19 - 00000000 ____D () C:\Windows\system32\MRT
    2014-10-18 15:42 - 2014-06-14 12:19 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-10-10 19:04 - 2013-08-22 07:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
    2014-09-29 16:45 - 2014-07-16 11:46 - 00706016 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-09-29 16:45 - 2014-07-16 11:46 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-09-28 17:29 - 2014-09-19 19:18 - 00000000 ____D () C:\ProgramData\boost_interprocess

    Some content of TEMP:
    ====================
    C:\Users\fireydrake\AppData\Local\Temp\dllnt_dump.dll
    C:\Users\fireydrake\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
    C:\Users\fireydrake\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
    C:\Users\fireydrake\AppData\Local\Temp\ObronaBlockAdsUpdate.exe
    C:\Users\fireydrake\AppData\Local\Temp\Quarantine.exe
    C:\Users\fireydrake\AppData\Local\Temp\sqlite3.dll


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2014-10-22 18:39

    ==================== End Of Log ============================

  2. #17
    Join Date
    Mar 2014
    Posts
    557
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-10-2014
    Ran by fireydrake at 2014-10-25 11:14:44
    Running from C:\Users\fireydrake\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon)
    avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
    CyberLink LabelPrint 2.5 (x32 Version: 2.5.0.6603 - CyberLink Corp.) Hidden
    CyberLink Media Suite 10 (x32 Version: 10.0.1.3214 - CyberLink Corp.) Hidden
    CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)
    CyberLink Power2Go 8 (x32 Version: 8.0.0.3123 - CyberLink Corp.) Hidden
    CyberLink PowerDirector 10 (x32 Version: 10.0.1.3126 - CyberLink Corp.) Hidden
    CyberLink PowerDVD 12 (x32 Version: 12.0.3205.55 - CyberLink Corp.) Hidden
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dell Backup and Recovery - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.2.0 - Dell Inc.)
    Dell Backup and Recovery (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.2.0 - Dell Inc.)
    Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.16.1 - Dell Inc.)
    Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 17.0.13.0 - Synaptics Incorporated)
    Dell WLAN and Bluetooth Client Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Dell Inc.)
    DSC/AA Factory Installer (Version: 3.4.6299.48 - PC-Doctor, Inc.) Hidden
    Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
    Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden
    Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden
    Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
    Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
    Java Auto Updater (x32 Version: 2.1.71.14 - Oracle, Inc.) Hidden
    KeyPlayr (HKLM-x32\...\{A21A2C02-B537-4418-858C-1F79C309FD0C}) (Version: 1.00.0000 - KeyDownload)
    KNCTR (HKLM-x32\...\Itibiti_is1) (Version: - Itibiti Inc.)
    Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
    Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
    MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
    My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.5.6426.22 - PC-Doctor, Inc.)
    Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    PocketCloud (HKLM-x32\...\{D9752C7D-A595-4687-A0D5-362E9C311C55}) (Version: 2.7.14 - Wyse Technology)
    Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.308 - Qualcomm Atheros Communications)
    Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.15.021 - Dell Inc.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.)
    Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
    ROBLOX Player for fireydrake (HKCU\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
    ROBLOX Studio for fireydrake (HKCU\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - ROBLOX Corporation)
    Unity Web Player (HKCU\...\UnityWebPlayer) (Version: 4.5.1f3 - Unity Technologies ApS)
    Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
    Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
    Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    CustomCLSID: HKU\S-1-5-21-1276894799-377718809-1696388264-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\fireydrake\AppData\Local\Roblox\Versions\version-d65566343374484f\RobloxProxy64.dll (ROBLOX Corporation)

    ==================== Restore Points =========================

    09-10-2014 00:30:18 Windows Update
    11-10-2014 00:35:02 avast! antivirus system restore point
    18-10-2014 21:37:56 Windows Update
    19-10-2014 22:10:06 Installed Java 7 Update 71
    23-10-2014 15:32:23 Revo Uninstaller's restore point - µTorrent
    24-10-2014 13:59:33 Pre-Scan

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 07:25 - 2013-08-22 07:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
    Task: {0807304C-0EEA-46A6-95BE-A808FCCFDECB} - System32\Tasks\PocketCloudUpdater => C:\Program
    Task: {090C2CE9-255D-42D4-A81D-F3A5B095207A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001Core => C:\Users\fireydrake\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-27] (Facebook Inc.)
    Task: {092B4E6F-0F9B-48B7-90B5-39B212FD2B92} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
    Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
    Task: {1E3AB642-7567-448A-908B-C24D69786041} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
    Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
    Task: {2BB66BD8-7092-4796-9DF3-C5E0A5BF2B9F} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
    Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
    Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-21] (Microsoft Corporation)
    Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
    Task: {3B7A9471-5480-46E1-BEA2-0599350D5B17} - System32\Tasks\PocketCloudVirtualChannel => C:\Program Files (x86)\Wyse\PocketCloud\WPCRDPVirtualChannelServer.exe [2013-08-22] ()
    Task: {4282FD8B-0B81-4A41-9E17-154504AC33E0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-10-18] (Microsoft Corporation)
    Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
    Task: {4999689C-6ABD-4F93-96EC-B39032A97994} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16] (Google Inc.)
    Task: {4C4FABD6-FDDF-42EB-AF1C-43DAA49E1BAA} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001UA => C:\Users\fireydrake\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-09-27] (Facebook Inc.)
    Task: {58733106-EA22-47FA-A7E8-8E3AF486766A} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
    Task: {66BBB10A-60B1-4E1D-A922-508639715AF8} - System32\Tasks\PocketCloud => C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudDesktopApp.exe [2013-08-22] ()
    Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
    Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
    Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
    Task: {75655B71-D106-4E01-9F3B-24DB13449209} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
    Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
    Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
    Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
    Task: {925CA732-2005-4D6F-9FC4-4903C64F3A44} - System32\Tasks\Dell\Dell System Registration => C:\Program Files (x86)\System Registration\prodreg.exe [2012-07-09] (Dell, Inc.)
    Task: {97CBFA9D-90DE-4DE8-93E6-6E46240144F1} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-09-06] (Synaptics Incorporated)
    Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
    Task: {A1159F5E-ADFF-4774-A7DF-18BC100DB4BC} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2014-01-31] (PC-Doctor, Inc.)
    Task: {AA65399C-EA0B-4AA2-B219-A34C6C2EEAC1} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-10-19] (AVAST Software)
    Task: {BB6A798D-07BE-46B5-ADAE-3101AD4C573A} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
    Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
    Task: {D3F21157-86D6-4464-8D72-07EF6FFDFAD7} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-04] (CyberLink)
    Task: {D4256B34-4CB1-46B3-82DC-A985A72B9879} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-16] (Google Inc.)
    Task: {D676D224-662A-4858-A392-25D3083EF649} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2014-01-31] (PC-Doctor, Inc.)
    Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
    Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
    Task: {DB844552-FE84-4879-B6B4-182ECD3279B4} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
    Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
    Task: {F3C1782A-51D8-45AC-8D0F-D93C84D73100} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-22] (CyberLink Corp.)
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001Core.job => C:\Users\fireydrake\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1276894799-377718809-1696388264-1001UA.job => C:\Users\fireydrake\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Loaded Modules (whitelisted) =============

    2013-08-22 13:40 - 2013-08-22 13:40 - 00016176 _____ () C:\Program Files (x86)\Wyse\PocketCloud\PocketCloudService.exe
    2013-08-22 13:40 - 2013-08-22 13:40 - 00040240 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherServiceLib.dll
    2013-08-22 13:40 - 2013-08-22 13:40 - 00046384 _____ () C:\Program Files (x86)\Wyse\PocketCloud\AetherHelperLib.dll
    2013-10-30 01:11 - 2013-10-30 01:11 - 00011264 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
    2013-10-30 01:07 - 2013-10-30 01:07 - 00086016 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Modules\Map\MAP.dll
    2013-10-30 01:15 - 2013-10-30 01:15 - 00012928 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe
    2014-08-02 19:00 - 2013-06-26 16:16 - 07342080 _____ () C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
    2014-02-26 13:56 - 2013-08-19 11:21 - 00020256 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIcon.dll
    2014-02-26 13:56 - 2013-08-19 11:21 - 00019232 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayNotBackuped.dll
    2014-02-26 13:56 - 2013-11-21 19:22 - 00484880 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe
    2014-10-19 13:13 - 2014-10-19 13:13 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
    2014-10-25 11:00 - 2014-10-25 11:00 - 02897920 _____ () C:\Program Files\AVAST Software\Avast\defs\14102500\algo.dll
    2014-10-19 13:13 - 2014-10-19 13:13 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2014-02-26 13:46 - 2013-03-04 21:40 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
    2013-03-05 13:41 - 2013-03-05 13:41 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
    2014-02-26 13:38 - 2013-08-28 04:02 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
    2014-02-26 13:56 - 2013-11-21 17:00 - 01904928 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll
    2014-02-26 13:56 - 2012-11-26 00:20 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll
    2014-02-26 13:56 - 2012-11-26 00:20 - 00117608 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\Users\fireydrake\OneDrive:ms-properties

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

    ==================== EXE Association (whitelisted) =============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== MSCONFIG/TASK MANAGER disabled items =========

    (Currently there is no automatic fix for this section.)


    ========================= Accounts: ==========================

    Administrator (S-1-5-21-1276894799-377718809-1696388264-500 - Administrator - Disabled)
    fireydrake (S-1-5-21-1276894799-377718809-1696388264-1001 - Administrator - Enabled) => C:\Users\fireydrake
    Guest (S-1-5-21-1276894799-377718809-1696388264-501 - Limited - Disabled)

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (10/25/2014 11:11:59 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80070005


    System errors:
    =============

    Microsoft Office Sessions:
    =========================
    Error: (10/25/2014 11:11:59 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80070005


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz
    Percentage of memory in use: 28%
    Total physical RAM: 6024.96 MB
    Available physical RAM: 4279.57 MB
    Total Pagefile: 6984.96 MB
    Available Pagefile: 5118.71 MB
    Total Virtual: 131072 MB
    Available Virtual: 131071.8 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:456.68 GB) (Free:389.84 GB) NTFS
    Drive x: (WINRETOOLS) (Fixed) (Total:0.48 GB) (Free:0.2 GB) NTFS
    Drive y: (PBR Image) (Fixed) (Total:7.95 GB) (Free:0.69 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 465.8 GB) (Disk ID: BC44CC4C)

    Partition: GPT Partition Type.

    ==================== End Of Log ============================

  3. #18
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    I can see KNCTR and Itibiti RTC, both by Itibiti in a list of installed programs.
    Uninstall them if you don't use them.
    Let me know how it went.
    Last edited by Broni; October 26th, 2014 at 08:41 PM.

  4. #19
    Join Date
    Mar 2014
    Posts
    557
    How do I uninstall programs like those on a windows 8 computer?

  5. #20
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Press Windows logo key and start typing the following:
    Control Panel
    Click on "Control Panel" on the left.
    Click on "Programs & Features".

  6. #21
    Join Date
    Mar 2014
    Posts
    557
    I got the program uninstalled and the computer seems to be running great. I'm not the computer's primary user, so I'll check in with him for sure tonight. Other than that if he's not having any more issues and you give it the ok, then we should be good to go.

  7. #22
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    We're not totally done yet.

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Attached Files Attached Files

  8. #23
    Join Date
    Mar 2014
    Posts
    557
    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 30-10-2014
    Ran by fireydrake at 2014-10-30 10:15:49 Run:1
    Running from C:\Users\fireydrake\Desktop
    Loaded Profiles: fireydrake & (Available profiles: fireydrake)
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    HKU\S-1-5-21-1276894799-377718809-1696388264-1001\...\MountPoints2: {5b70d30e-ff0f-11e3-825f-645a04253af6} - "E:\LaunchU3.exe"
    HKU\S-1-5-21-1276894799-377718809-1696388264-1001\...\MountPoints2: {a6d05c24-1053-11e4-8261-645a04253af6} - "E:\LaunchU3.exe"
    SearchScopes: HKCU - {A11C34FF-C08A-45AC-89C3-BA7782362D91} URL =
    C:\Users\fireydrake\AppData\Local\Temp\dllnt_dump.dll
    C:\Users\fireydrake\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
    C:\Users\fireydrake\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
    C:\Users\fireydrake\AppData\Local\Temp\ObronaBlockAdsUpdate.exe
    C:\Users\fireydrake\AppData\Local\Temp\Quarantine.exe
    C:\Users\fireydrake\AppData\Local\Temp\sqlite3.dll
    AlternateDataStreams: C:\Users\fireydrake\OneDrive:ms-properties


    *****************

    "HKU\S-1-5-21-1276894799-377718809-1696388264-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b70d30e-ff0f-11e3-825f-645a04253af6}" => Key deleted successfully.
    "HKCR\CLSID\{5b70d30e-ff0f-11e3-825f-645a04253af6}" => Key not found.
    "HKU\S-1-5-21-1276894799-377718809-1696388264-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a6d05c24-1053-11e4-8261-645a04253af6}" => Key deleted successfully.
    "HKCR\CLSID\{a6d05c24-1053-11e4-8261-645a04253af6}" => Key not found.
    "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A11C34FF-C08A-45AC-89C3-BA7782362D91}" => Key deleted successfully.
    "HKCR\CLSID\{A11C34FF-C08A-45AC-89C3-BA7782362D91}" => Key not found.
    C:\Users\fireydrake\AppData\Local\Temp\dllnt_dump.dll => Moved successfully.
    C:\Users\fireydrake\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe => Moved successfully.
    C:\Users\fireydrake\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe => Moved successfully.
    C:\Users\fireydrake\AppData\Local\Temp\ObronaBlockAdsUpdate.exe => Moved successfully.
    C:\Users\fireydrake\AppData\Local\Temp\Quarantine.exe => Moved successfully.
    C:\Users\fireydrake\AppData\Local\Temp\sqlite3.dll => Moved successfully.
    "C:\Users\fireydrake\OneDrive" => ":ms-properties" ADS not found.

    ==== End of Fixlog ====

  9. #24
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    How is computer doing?

    Last scans...

    Download Security Check from here or here and save it to your Desktop.

    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:

      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services

    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.



    Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe

    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.



    Please run a free online scan with the ESET Online Scanner


    • Disable your antivirus program
    • Internet Explorer users - Click on this link to open ESET OnlineScan.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

      • Click on ESET Smart Installer to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the [img=http://www.bleepstatic.com/fhost/uploads/0/esetsmartinstaller_enu.png] icon on your desktop.

    • Check "YES, I accept the Terms of Use."
    • Click the Start button.
    • Accept any security warnings from your browser.
    • Check "Enable detection of potentially unwanted applications".
    • Click Advanced settings and make sure all 4 boxes are checkmarked (two of them are already checkmarked by default).
      Do NOT checkmark "Use custom proxy settings"
    • Click the Start button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click List Threats
    • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Click the Back button.
    • Click the Finish button.

  10. #25
    Join Date
    Mar 2014
    Posts
    557
    I noticed the two out of date things. You'll have to tell me how to update these. I'm not familiar with the Windows 8 computer I am working with.

    Results of screen317's Security Check version 0.99.89
    x64 (UAC is enabled)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Windows Defender
    avast! Antivirus
    Antivirus out of date!
    `````````Anti-malware/Other Utilities Check:`````````
    Java 7 Update 71
    Java version out of Date!
    Google Chrome 37.0.2062.124
    Google Chrome 38.0.2125.111
    ````````Process Check: objlist.exe by Laurent````````
    AVAST Software Avast AvastSvc.exe
    AVAST Software Avast avastui.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: %
    ````````````````````End of Log``````````````````````
    Last edited by Tarnished_Rose; November 3rd, 2014 at 08:13 PM.

  11. #26
    Join Date
    Mar 2014
    Posts
    557
    Farbar Service Scanner Version: 21-07-2014
    Ran by fireydrake (administrator) on 03-11-2014 at 18:07:18
    Running from "C:\Users\fireydrake\Desktop"
    Microsoft Windows 8.1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Action Center:
    ============


    Windows Update:
    ============
    wuauserv Service is not running. Checking service configuration:
    The start type of wuauserv service is set to Demand. The default start type is Auto.
    The ImagePath of wuauserv service is OK.
    The ServiceDll of wuauserv service is OK.


    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"".


    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware"=DWORD:1


    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => File is digitally signed
    C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
    C:\Windows\System32\dhcpcore.dll => File is digitally signed
    C:\Windows\System32\drivers\afd.sys => File is digitally signed
    C:\Windows\System32\drivers\tdx.sys => File is digitally signed
    C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
    C:\Windows\System32\dnsrslvr.dll => File is digitally signed
    C:\Windows\System32\mpssvc.dll => File is digitally signed
    C:\Windows\System32\bfe.dll => File is digitally signed
    C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
    C:\Windows\System32\wscsvc.dll => File is digitally signed
    C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
    C:\Windows\System32\wuaueng.dll => File is digitally signed
    C:\Windows\System32\qmgr.dll => File is digitally signed
    C:\Windows\System32\es.dll => File is digitally signed
    C:\Windows\System32\cryptsvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MsMpEng.exe => File is digitally signed
    C:\Windows\System32\ipnathlp.dll => File is digitally signed
    C:\Windows\System32\iphlpsvc.dll => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed


    **** End of log ****

  12. #27
    Join Date
    Mar 2014
    Posts
    557
    For some reason when I went to disable the Avast to run ESET it was already turned off when there's no reason it should have been.

  13. #28
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    You may want to reinstall Avast afterwards.

  14. #29
    Join Date
    Mar 2014
    Posts
    557
    C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\hstart.exe a variant of Win32/HiddenStart.A potentially unsafe application deleted - quarantined
    C:\Users\fireydrake\AppData\Roaming\Angry_Birds\Angry_Birds.exe a variant of Win32/Toolbar.Iminent.C potentially unwanted application deleted - quarantined

  15. #30
    Join Date
    Mar 2014
    Posts
    557
    This computer keeps getting kicked off of our internet. Could that be related to a virus or is that just a wifi problem?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •