Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01
Ran by 64Bit Standard (administrator) on ACER47524G (23-08-2016 22:39:03)
Running from C:\Users\64Bit Standard\Desktop
Loaded Profiles: 64Bit Standard (Available Profiles: 64Bit Standard)
Platform: Windows 7 Ultimate (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.334\SSScheduler.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Wondershare) C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Wifi\GenieWifiService.exe
(Zbshareware Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
(SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
() C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
() C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
() C:\Windows\System32\dmwu.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(TeamViewer) C:\Program Files (x86)\ITbrain Agent\itbrain_agent.exe
() C:\Program Files (x86)\Mobogenie\MgAssist.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Mobogenie.com) C:\Program Files (x86)\Mobogenie3\MobogenieService.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TODO: <公司名>) C:\Program Files (x86)\Blazers\Watsvc.exe
() C:\Program Files (x86)\Mobogenie3\MoboGenieHelper.exe
() C:\Program Files (x86)\Blazers\wac.exe
() C:\Windows\SysWOW64\mjcm\dnkt.exe
() C:\Windows\System32\tprb\dnkt.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.EXE
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleaner.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleaner.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12632168 2011-07-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2264168 2011-07-13] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2392360 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [961184 2011-08-02] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [798880 2011-08-02] (Atheros Commnucations)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [USB Security] => C:\Program Files (x86)\USB Disk Security\USBGuard.exe [2347008 2011-11-02] (Zbshareware Lab)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-15] (Dritek System Inc.)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296096 2012-12-10] (RealNetworks, Inc.)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-12-10] (Nullsoft, Inc.)
HKLM-x32\...\Run: [SweetIM] => C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [Sweetpacks Communicator] => C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-16] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [766656 2014-01-09] ()
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4431848 2015-12-15] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM-x32\...\Run: [ApnTBMon] => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Facebook Update] => C:\Users\64Bit Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-12-11] (Facebook Inc.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Google Update] => C:\Users\64Bit Standard\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-09-02] (Google Inc.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\64Bit Standard\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [GenieFloater] => C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe [1850520 2015-02-06] (Oppoos.com)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Google Photos Backup] => C:\Users\64Bit Standard\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-09] (Google, Inc)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3961968 2016-06-10] (Tonec Inc.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {15bedbba-a344-11e3-b79b-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {2e58bdd5-5c8b-11e3-b4a6-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {3b10255c-8bb6-11e4-98f6-c0188508e944} - F:\LaunchU3.exe -a
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {84fc388b-0b51-11e4-97dd-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {84fc3896-0b51-11e4-97dd-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {dabff73f-24e2-11e4-95d9-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {ea969c82-5b13-11e3-9ca8-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {ea969c95-5b13-11e3-9ca8-001e101f4e71} - F:\AutoRun.exe
HKU\S-1-5-18\...\Run: [Mobile Partner] => C:\Program Files (x86)\Tattoo\Tattoo
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetycrt.dll
HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetycrt.dll
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
Startup: C:\Users\64Bit Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk [2016-07-05]
ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-07]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.334\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MobileGo Service.lnk [2016-07-05]
ShortcutTarget: MobileGo Service.lnk -> C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe (Wondershare)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{33B0A8AA-558B-4DA0-AA57-8E1B6BDD8C78}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{5F7A0CFB-41F7-42FB-A27B-4CEE032EC486}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{7666F337-9385-438B-BD22-53C1A3F97774}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9004E00D-FF64-48F5-A52E-515992158449}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{B9724432-5B49-4C0D-8643-D1EF391DC7F4}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{D931273D-0EC7-4F67-B8F0-90A9CE51BCF1}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010000.10016&barid={D5B1B3BF-7297-11E2-B37C-C0188508E944}
HKU\S-1-5-21-203507500-883022594-3238906040-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP&dt=071413
HKU\S-1-5-21-203507500-883022594-3238906040-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://arabic.arabia.msn.com/?C=SA
SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10016&barid={D5B1B3BF-7297-11E2-B37C-C0188508E944}
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10016&barid={D5B1B3BF-7297-11E2-B37C-C0188508E944}
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23&did=10963&UPN2=92830952916117790
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> BBC00BFB83C24DEBBF48A90BD2415880 URL = hxxp://isearch.avg.com/search?cid={35C12767-6D80-45EE-BC45-878C330E4CC7}&mid=69c45bf1447b47d1bf0a5cf8300b4423-44b62a31c6e4d7cc9a9c8373559e0e6a3350018c&lang=en&ds=AVG&pr=pr&d=&v=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=071413&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23&did=10963&UPN2=92830952916117790
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-08-05] (Oracle Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-08-05] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-12-10] (RealPlayer)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-24] (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-08-02] (Atheros Commnucations)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: SweetPacks Browser Helper -> {EEE6C35C-6118-11DC-9C72-001320C79847} -> C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-07-04] (SweetIM Technologies Ltd.)
Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-07-04] (SweetIM Technologies Ltd.)
Toolbar: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
DPF: HKLM-x32 {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} hxxp://hani.dipmap.com/cab/OCXChecker_8500.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default
FF NewTab: hxxp://www.sweetpacks-search.com/?barid=&src=97&did=10963&&st=23&UPN2=92830952916117790
FF SelectedSearchEngine: Sweetpacks Search
FF Homepage: hxxp://www.sweetpacks-search.com/?barid=&src=10&did=10963&&st=23&UPN2=92830952916117790
about:home
FF Keyword.URL: hxxp://mysearch.sweetpacks.com?src=6&barid=&did=10963&&st=23&UPN2=92830952916117790&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-13] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2011-06-21] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-08-05] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-05] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-05-26] (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2011-06-21] (DivX, LLC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-13] (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2011-11-24] (Yahoo! Inc.)
FF Plugin-x32: @real.com/nppl3260;version=15.0.6.14 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.6.14 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=15.0.6.14 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2012-12-10] (RealPlayer)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-203507500-883022594-3238906040-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\64Bit Standard\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-203507500-883022594-3238906040-1000: @tools.google.com/Google Update;version=3 -> C:\Users\64Bit Standard\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-203507500-883022594-3238906040-1000: @tools.google.com/Google Update;version=9 -> C:\Users\64Bit Standard\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll [2012-12-10] (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-12-10] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\ask-search.xml [2015-10-09]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\ask-web-search.xml [2014-12-25]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\Ask.xml [2014-07-14]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\bingp.xml [2013-07-15]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\MyStart Search.xml [2015-11-20]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\MyStart.xml [2013-09-17]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\sweetim.xml [2013-02-09]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\Sweetpacks Search.xml [2016-08-23]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml [2014-07-14]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nation-secure-search.xml [2014-05-02]
FF Extension: DivX Plus Web Player HTML5 &video& - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-02-08] [not signed]
FF Extension: IDM integration - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-06-08]
FF Extension: Adblock Plus - C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-08-05]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM-x32\...\Firefox\Extensions: [{0153E448-190B-4987-BDE1-F256CADA672F}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2016-05-16] [not signed]
FF HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\64Bit Standard\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\64Bit Standard\AppData\Roaming\IDM\idmmzcc5 [2016-08-23] [not signed]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-06-02] <==== ATTENTION
Chrome:
=======
CHR Profile: C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (internet Download Manager For Chrome) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blhjobkfabeopalncconblmakfcllmhk [2016-06-18]
CHR Extension: (YouTube) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-20]
CHR Extension: (Google Search) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-20]
CHR Extension: (Elite Unzip) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffjcmnpnoopgilmnfhloocdcbnimmmea [2015-03-21]
CHR Extension: (NetBeans Connector) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hafdlehgocfcodbgjnpecfajgkeejnaa [2016-07-21]
CHR Extension: (Internet Download Manager) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijaimklihemgfpichkhlcbcbhfkmkcip [2016-06-18]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-12-11]
CHR Extension: (Skype) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-06-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-13]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-12-10]
CHR Extension: (Gmail) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-04]
CHR Extension: (Chrome Media Router) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-23]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-06-10]
CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2013-02-09]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-12-10]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-05-24]
CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\SysWOW64\jmdp\SweetNT.crx [2014-04-06]
StartMenuInternet: Google Chrome.2GVSDOFDZMDVKYCDOSUCPWJDBI - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [198216 2016-06-18] (APN LLC.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [103584 2011-08-02] (Atheros Commnucations) [File not signed]
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4948456 2015-10-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 GenieCleanService; C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe [53400 2015-02-06] (Oppoos.com) [File not signed]
R2 GenieWifiService; C:\Program Files (x86)\Genie Soft\Genie Wifi\GenieWifiService.exe [51352 2015-03-05] (Oppoos.com) [File not signed]
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [3039536 2015-01-06] ()
S2 InstallerWrapperService; C:\Program Files\TrueKey\InstallerWrapperService.exe [47688 2016-07-20] (McAfee, Inc.)
R2 ITbrain Agent; C:\Program Files (x86)\ITbrain Agent\itbrain_agent.exe [5567488 2015-11-27] (TeamViewer) [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.334\McCHSvc.exe [293128 2016-05-31] (McAfee, Inc.)
R2 MgAssistService; C:\Program Files (x86)\Mobogenie\MgAssist.exe [105664 2014-08-14] () [File not signed]
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239184 2014-02-15] ()
R2 MobogenieService; C:\Program Files (x86)\Mobogenie3\MobogenieService.exe [127680 2015-05-28] (Mobogenie.com) [File not signed]
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2007-01-15] (Nero AG) [File not signed]
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [266240 2007-01-15] (Nero AG) [File not signed]
S3 ShareItSvc; C:\Program Files (x86)\SHAREit\SHAREit\Shareit.Service.exe [33224 2016-04-15] (SHAREit Technologies Co.Ltd)
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1072296 2016-08-23] (Enigma Software Group USA, LLC.)
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-03] (DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7183632 2016-07-18] (TeamViewer GmbH)
R2 Watsvc; C:\Program Files (x86)\Blazers\Watsvc.exe [107160 2015-04-16] (TODO: <公司名>) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.2.0.5\WsAppService.exe [411648 2016-03-31] (Wondershare) [File not signed]
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MirrorGo\DriverInstall.exe [115856 2016-04-14] (Wondershare)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [158160 2015-05-21] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360400 2015-05-21] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [204192 2016-03-03] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [249296 2015-05-26] (AVG Technologies CZ, s.r.o.)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-08-23] ()
S3 HtcUsbMdmV64; C:\Windows\System32\DRIVERS\HtcUsbMdmV64.sys [121800 2010-03-08] (QUALCOMM Incorporated)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-07-28] (Apple, Inc.) [File not signed]
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-23 22:39 - 2016-08-23 22:41 - 00035060 _____ C:\Users\64Bit Standard\Desktop\FRST.txt
2016-08-23 22:37 - 2016-08-23 22:39 - 00000000 ____D C:\FRST
2016-08-23 22:36 - 2016-08-23 22:35 - 02396672 _____ (Farbar) C:\Users\64Bit Standard\Desktop\FRST64.exe
2016-08-23 21:51 - 2016-08-23 21:51 - 00000000 _____ C:\autoexec.bat
2016-08-23 21:50 - 2016-08-23 21:50 - 00003366 _____ C:\Windows\System32\Tasks\SpyHunter4Startup
2016-08-23 21:50 - 2016-08-23 21:50 - 00000937 _____ C:\Users\64Bit Standard\Desktop\SpyHunter.lnk
2016-08-23 21:50 - 2016-08-23 21:50 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2016-08-23 21:50 - 2016-08-23 21:50 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Enigma Software Group
2016-08-23 21:48 - 2016-08-23 21:49 - 00000000 ____D C:\sh4ldr
2016-08-23 21:34 - 2016-08-23 21:34 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
2016-08-23 21:32 - 2016-08-23 21:32 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-08-20 23:21 - 2016-08-20 23:21 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-08-20 23:21 - 2016-08-20 23:21 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-08-20 21:05 - 2016-08-20 21:05 - 00001845 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2016-08-20 21:05 - 2016-08-20 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2016-08-20 21:05 - 2016-08-20 21:05 - 00000000 ____D C:\Program Files (x86)\QuickTime
2016-08-15 15:33 - 2016-08-15 15:33 - 00000000 ____D C:\Users\64Bit Standard\.fontconfig
2016-08-09 00:36 - 2016-08-09 00:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit
2016-08-09 00:13 - 2016-08-23 22:38 - 00000000 ____D C:\Program Files (x86)\ITbrain Agent
2016-08-09 00:13 - 2016-08-09 00:13 - 00000000 __HDC C:\ProgramData\{651038AD-E038-410A-BD90-28FB006FD850}
2016-08-09 00:13 - 2016-08-09 00:13 - 00000000 ____D C:\Users\Default\AppData\Local\PackageAware
2016-08-09 00:13 - 2016-08-09 00:13 - 00000000 ____D C:\Users\Default User\AppData\Local\PackageAware
2016-08-09 00:06 - 2016-08-09 00:06 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2016-08-07 10:36 - 2016-08-07 10:36 - 00001964 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-08-07 10:36 - 2016-08-07 10:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-08-07 10:36 - 2016-08-07 10:36 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-08-05 08:59 - 2016-08-05 09:00 - 00000000 ____D C:\Program Files\Defraggler
2016-08-05 08:59 - 2016-08-05 08:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2016-08-05 08:56 - 2016-08-15 23:48 - 00000000 ____D C:\Program Files\Recuva
2016-08-05 08:56 - 2016-08-05 08:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2016-08-05 08:50 - 2016-08-05 08:50 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\CEF
2016-08-05 08:49 - 2016-08-05 08:49 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2016-08-05 08:49 - 2016-08-05 08:49 - 00000000 ____D C:\ProgramData\McAfee
2016-08-05 08:48 - 2016-08-05 08:48 - 00000000 ____D C:\Program Files\TrueKey
2016-08-05 08:47 - 2016-08-05 23:17 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-03 23:15 - 2016-08-05 08:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-07-24 04:10 - 2016-07-24 04:10 - 00003260 _____ C:\Windows\System32\Tasks\{ADD6E3C7-939C-4FF3-B4EE-157E0DA5FDC8}
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-23 22:21 - 2014-03-23 17:02 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\DMCache
2016-08-23 22:10 - 2014-03-23 17:02 - 00000000 ____D C:\Users\64Bit Standard\Downloads\Compressed
2016-08-23 21:55 - 2012-12-10 01:41 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-08-23 21:50 - 2012-12-12 06:46 - 00000944 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000UA.job
2016-08-23 21:23 - 2012-12-11 17:18 - 00000964 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000UA.job
2016-08-23 21:23 - 2009-07-14 13:13 - 00717892 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-23 21:23 - 2009-07-14 12:45 - 00010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-23 21:23 - 2009-07-14 12:45 - 00010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-23 21:23 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\inf
2016-08-23 21:22 - 2012-02-08 23:25 - 00000000 ____D C:\ProgramData\MFAData
2016-08-23 21:18 - 2015-03-23 15:50 - 00000436 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2016-08-23 21:17 - 2015-04-23 12:59 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\cmsiex
2016-08-23 21:17 - 2014-01-18 23:56 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\newnext.me
2016-08-23 21:17 - 2013-09-17 16:52 - 00018688 _____ C:\Users\64Bit Standard\AppData\LocalLow\SkwConfig.bin
2016-08-23 21:17 - 2012-02-08 23:16 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Skype
2016-08-23 21:16 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-23 12:56 - 2012-12-11 18:59 - 00000220 _____ C:\Windows\popcinfo.dat
2016-08-23 12:53 - 2014-08-14 13:13 - 00000000 ___HD C:\Users\64Bit Standard\Desktop\my movies
2016-08-22 14:49 - 2012-12-11 17:18 - 00000942 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000Core.job
2016-08-21 01:16 - 2014-03-23 17:02 - 00000000 ____D C:\Users\64Bit Standard\Desktop\Video
2016-08-21 00:05 - 2012-12-11 19:04 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\vlc
2016-08-20 23:21 - 2012-02-08 22:45 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-08-20 23:04 - 2012-02-08 22:45 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-08-20 22:25 - 2012-12-25 14:19 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\CrashDumps
2016-08-20 20:43 - 2016-06-18 00:20 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\IDM
2016-08-16 00:40 - 2016-06-15 08:28 - 00000000 ____D C:\Users\64Bit Standard\Downloads\SHAREit
2016-08-15 23:51 - 2012-02-08 21:59 - 00000000 ____D C:\Users\64Bit Standard
2016-08-12 10:42 - 2014-09-24 16:51 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\SWDS
2016-08-11 19:50 - 2012-12-12 06:46 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000Core.job
2016-08-09 09:57 - 2012-12-10 01:37 - 00002419 _____ C:\Users\64Bit Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-09 00:36 - 2016-06-15 08:28 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\Lenovo
2016-08-09 00:36 - 2016-06-15 08:27 - 00001113 _____ C:\Users\Public\Desktop\SHAREit.lnk
2016-08-09 00:07 - 2016-07-02 01:34 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-08-07 00:12 - 2014-08-14 10:32 - 00000000 ____D C:\Program Files (x86)\Mobogenie3
2016-08-05 08:56 - 2012-12-14 18:30 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Media Player Classic
2016-08-05 08:56 - 2012-02-09 00:02 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\uTorrent
2016-08-05 08:56 - 2012-02-08 22:42 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Winamp
2016-08-05 08:50 - 2012-12-10 01:40 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\Adobe
2016-08-05 08:48 - 2015-01-02 12:16 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-08-05 08:46 - 2012-12-10 01:40 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-08-05 08:46 - 2012-02-08 22:29 - 00000000 ____D C:\ProgramData\Adobe
2016-08-05 08:40 - 2012-12-11 17:21 - 00000000 ____D C:\Program Files\Java
2016-08-05 08:39 - 2016-06-23 02:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-08-05 08:39 - 2016-06-23 02:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-08-05 08:36 - 2016-06-23 02:28 - 00000000 ____D C:\Users\64Bit Standard\.oracle_jre_usage
2016-08-05 08:35 - 2012-12-11 17:22 - 00110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2016-08-04 09:31 - 2012-12-10 01:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 19:45 - 2012-12-12 06:46 - 00003936 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000UA
2016-07-29 19:45 - 2012-12-12 06:46 - 00003540 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000Core
2016-07-26 23:29 - 2014-01-18 23:55 - 00000000 ____D C:\Program Files (x86)\Mobogenie
==================== Files in the root of some directories =======
2014-05-02 10:54 - 2013-12-15 10:38 - 6200595 _____ () C:\Program Files\SAM_2294 - Copy.JPG
2014-01-08 20:25 - 2014-05-02 09:53 - 0001703 _____ () C:\Program Files (x86)\Mozilla Firefoxnation-secure-search.xml
2015-12-30 10:10 - 2016-01-13 19:49 - 0003584 _____ () C:\Users\64Bit Standard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-17 15:03 - 2015-06-17 15:03 - 0004096 ____H () C:\Users\64Bit Standard\AppData\Local\keyfile3.drm
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-08-20 21:58
==================== End of FRST.txt ============================
Ran by 64Bit Standard (administrator) on ACER47524G (23-08-2016 22:39:03)
Running from C:\Users\64Bit Standard\Desktop
Loaded Profiles: 64Bit Standard (Available Profiles: 64Bit Standard)
Platform: Windows 7 Ultimate (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.334\SSScheduler.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Wondershare) C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Wifi\GenieWifiService.exe
(Zbshareware Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
(SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
() C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
() C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
() C:\Windows\System32\dmwu.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(TeamViewer) C:\Program Files (x86)\ITbrain Agent\itbrain_agent.exe
() C:\Program Files (x86)\Mobogenie\MgAssist.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Mobogenie.com) C:\Program Files (x86)\Mobogenie3\MobogenieService.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TODO: <公司名>) C:\Program Files (x86)\Blazers\Watsvc.exe
() C:\Program Files (x86)\Mobogenie3\MoboGenieHelper.exe
() C:\Program Files (x86)\Blazers\wac.exe
() C:\Windows\SysWOW64\mjcm\dnkt.exe
() C:\Windows\System32\tprb\dnkt.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.EXE
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleaner.exe
(Oppoos.com) C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleaner.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12632168 2011-07-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2264168 2011-07-13] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2392360 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [961184 2011-08-02] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [798880 2011-08-02] (Atheros Commnucations)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [USB Security] => C:\Program Files (x86)\USB Disk Security\USBGuard.exe [2347008 2011-11-02] (Zbshareware Lab)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-15] (Dritek System Inc.)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296096 2012-12-10] (RealNetworks, Inc.)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-12-10] (Nullsoft, Inc.)
HKLM-x32\...\Run: [SweetIM] => C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [Sweetpacks Communicator] => C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-16] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [766656 2014-01-09] ()
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4431848 2015-12-15] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM-x32\...\Run: [ApnTBMon] => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Facebook Update] => C:\Users\64Bit Standard\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-12-11] (Facebook Inc.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Google Update] => C:\Users\64Bit Standard\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-09-02] (Google Inc.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [NextLive] => C:\Windows\SysWOW64\rundll32.exe "C:\Users\64Bit Standard\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [GenieFloater] => C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieFloater.exe [1850520 2015-02-06] (Oppoos.com)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Google Photos Backup] => C:\Users\64Bit Standard\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-09] (Google, Inc)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3961968 2016-06-10] (Tonec Inc.)
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {15bedbba-a344-11e3-b79b-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {2e58bdd5-5c8b-11e3-b4a6-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {3b10255c-8bb6-11e4-98f6-c0188508e944} - F:\LaunchU3.exe -a
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {84fc388b-0b51-11e4-97dd-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {84fc3896-0b51-11e4-97dd-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {dabff73f-24e2-11e4-95d9-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {ea969c82-5b13-11e3-9ca8-c0188508e944} - F:\AutoRun.exe
HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\MountPoints2: {ea969c95-5b13-11e3-9ca8-001e101f4e71} - F:\AutoRun.exe
HKU\S-1-5-18\...\Run: [Mobile Partner] => C:\Program Files (x86)\Tattoo\Tattoo
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x86] -> C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\safetycrt.dll
HKLM\...\AppCertDlls: [x64] -> C:\Program Files (x86)\Browser Tab Search by Ask\SafetyNut\x64\safetycrt.dll
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
Startup: C:\Users\64Bit Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk [2016-07-05]
ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2016-08-07]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.334\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MobileGo Service.lnk [2016-07-05]
ShortcutTarget: MobileGo Service.lnk -> C:\Program Files (x86)\Wondershare\MobileGo\MobileGoService.exe (Wondershare)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{33B0A8AA-558B-4DA0-AA57-8E1B6BDD8C78}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{5F7A0CFB-41F7-42FB-A27B-4CEE032EC486}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{7666F337-9385-438B-BD22-53C1A3F97774}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9004E00D-FF64-48F5-A52E-515992158449}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{B9724432-5B49-4C0D-8643-D1EF391DC7F4}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{D931273D-0EC7-4F67-B8F0-90A9CE51BCF1}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010000.10016&barid={D5B1B3BF-7297-11E2-B37C-C0188508E944}
HKU\S-1-5-21-203507500-883022594-3238906040-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP&dt=071413
HKU\S-1-5-21-203507500-883022594-3238906040-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://arabic.arabia.msn.com/?C=SA
SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10016&barid={D5B1B3BF-7297-11E2-B37C-C0188508E944}
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10016&barid={D5B1B3BF-7297-11E2-B37C-C0188508E944}
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23&did=10963&UPN2=92830952916117790
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> BBC00BFB83C24DEBBF48A90BD2415880 URL = hxxp://isearch.avg.com/search?cid={35C12767-6D80-45EE-BC45-878C330E4CC7}&mid=69c45bf1447b47d1bf0a5cf8300b4423-44b62a31c6e4d7cc9a9c8373559e0e6a3350018c&lang=en&ds=AVG&pr=pr&d=&v=&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=071413&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23&did=10963&UPN2=92830952916117790
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_101\bin\ssv.dll [2016-08-05] (Oracle Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-08-05] (Oracle Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-12-10] (RealPlayer)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-24] (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-08-02] (Atheros Commnucations)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: SweetPacks Browser Helper -> {EEE6C35C-6118-11DC-9C72-001320C79847} -> C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-07-04] (SweetIM Technologies Ltd.)
Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2012-07-04] (SweetIM Technologies Ltd.)
Toolbar: HKU\S-1-5-21-203507500-883022594-3238906040-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
DPF: HKLM-x32 {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} hxxp://hani.dipmap.com/cab/OCXChecker_8500.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default
FF NewTab: hxxp://www.sweetpacks-search.com/?barid=&src=97&did=10963&&st=23&UPN2=92830952916117790
FF SelectedSearchEngine: Sweetpacks Search
FF Homepage: hxxp://www.sweetpacks-search.com/?barid=&src=10&did=10963&&st=23&UPN2=92830952916117790
about:home
FF Keyword.URL: hxxp://mysearch.sweetpacks.com?src=6&barid=&did=10963&&st=23&UPN2=92830952916117790&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-13] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2011-06-21] (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-08-05] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-05] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-05-26] (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2011-06-21] (DivX, LLC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-13] (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2011-11-24] (Yahoo! Inc.)
FF Plugin-x32: @real.com/nppl3260;version=15.0.6.14 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.6.14 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=15.0.6.14 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2012-12-10] (RealPlayer)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-203507500-883022594-3238906040-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\64Bit Standard\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-203507500-883022594-3238906040-1000: @tools.google.com/Google Update;version=3 -> C:\Users\64Bit Standard\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-203507500-883022594-3238906040-1000: @tools.google.com/Google Update;version=9 -> C:\Users\64Bit Standard\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll [2012-12-10] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll [2012-12-10] (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-12-10] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\ask-search.xml [2015-10-09]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\ask-web-search.xml [2014-12-25]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\Ask.xml [2014-07-14]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\bingp.xml [2013-07-15]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\MyStart Search.xml [2015-11-20]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\MyStart.xml [2013-09-17]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\sweetim.xml [2013-02-09]
FF SearchPlugin: C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\searchplugins\Sweetpacks Search.xml [2016-08-23]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml [2014-07-14]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\nation-secure-search.xml [2014-05-02]
FF Extension: DivX Plus Web Player HTML5 &video& - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-02-08] [not signed]
FF Extension: IDM integration - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-06-08]
FF Extension: Adblock Plus - C:\Users\64Bit Standard\AppData\Roaming\Mozilla\Firefox\Profiles\v9t9xa8x.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-08-05]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM-x32\...\Firefox\Extensions: [{0153E448-190B-4987-BDE1-F256CADA672F}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2016-05-16] [not signed]
FF HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-203507500-883022594-3238906040-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\64Bit Standard\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\64Bit Standard\AppData\Roaming\IDM\idmmzcc5 [2016-08-23] [not signed]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-06-02] <==== ATTENTION
Chrome:
=======
CHR Profile: C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (internet Download Manager For Chrome) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blhjobkfabeopalncconblmakfcllmhk [2016-06-18]
CHR Extension: (YouTube) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-20]
CHR Extension: (Google Search) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-20]
CHR Extension: (Elite Unzip) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffjcmnpnoopgilmnfhloocdcbnimmmea [2015-03-21]
CHR Extension: (NetBeans Connector) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\hafdlehgocfcodbgjnpecfajgkeejnaa [2016-07-21]
CHR Extension: (Internet Download Manager) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijaimklihemgfpichkhlcbcbhfkmkcip [2016-06-18]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2012-12-11]
CHR Extension: (Skype) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-06-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-13]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-12-10]
CHR Extension: (Gmail) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-04]
CHR Extension: (Chrome Media Router) - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-23]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-06-10]
CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2013-02-09]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-12-10]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-05-24]
CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\SysWOW64\jmdp\SweetNT.crx [2014-04-06]
StartMenuInternet: Google Chrome.2GVSDOFDZMDVKYCDOSUCPWJDBI - C:\Users\64Bit Standard\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [198216 2016-06-18] (APN LLC.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [103584 2011-08-02] (Atheros Commnucations) [File not signed]
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4948456 2015-10-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 GenieCleanService; C:\Program Files (x86)\Genie Soft\Genie Cleaner\GenieCleanService.exe [53400 2015-02-06] (Oppoos.com) [File not signed]
R2 GenieWifiService; C:\Program Files (x86)\Genie Soft\Genie Wifi\GenieWifiService.exe [51352 2015-03-05] (Oppoos.com) [File not signed]
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [3039536 2015-01-06] ()
S2 InstallerWrapperService; C:\Program Files\TrueKey\InstallerWrapperService.exe [47688 2016-07-20] (McAfee, Inc.)
R2 ITbrain Agent; C:\Program Files (x86)\ITbrain Agent\itbrain_agent.exe [5567488 2015-11-27] (TeamViewer) [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.334\McCHSvc.exe [293128 2016-05-31] (McAfee, Inc.)
R2 MgAssistService; C:\Program Files (x86)\Mobogenie\MgAssist.exe [105664 2014-08-14] () [File not signed]
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239184 2014-02-15] ()
R2 MobogenieService; C:\Program Files (x86)\Mobogenie3\MobogenieService.exe [127680 2015-05-28] (Mobogenie.com) [File not signed]
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2007-01-15] (Nero AG) [File not signed]
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [266240 2007-01-15] (Nero AG) [File not signed]
S3 ShareItSvc; C:\Program Files (x86)\SHAREit\SHAREit\Shareit.Service.exe [33224 2016-04-15] (SHAREit Technologies Co.Ltd)
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1072296 2016-08-23] (Enigma Software Group USA, LLC.)
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-03] (DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7183632 2016-07-18] (TeamViewer GmbH)
R2 Watsvc; C:\Program Files (x86)\Blazers\Watsvc.exe [107160 2015-04-16] (TODO: <公司名>) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.2.0.5\WsAppService.exe [411648 2016-03-31] (Wondershare) [File not signed]
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\MirrorGo\DriverInstall.exe [115856 2016-04-14] (Wondershare)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [158160 2015-05-21] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360400 2015-05-21] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [204192 2016-03-03] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [249296 2015-05-26] (AVG Technologies CZ, s.r.o.)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-08-23] ()
S3 HtcUsbMdmV64; C:\Windows\System32\DRIVERS\HtcUsbMdmV64.sys [121800 2010-03-08] (QUALCOMM Incorporated)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-07-28] (Apple, Inc.) [File not signed]
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-23 22:39 - 2016-08-23 22:41 - 00035060 _____ C:\Users\64Bit Standard\Desktop\FRST.txt
2016-08-23 22:37 - 2016-08-23 22:39 - 00000000 ____D C:\FRST
2016-08-23 22:36 - 2016-08-23 22:35 - 02396672 _____ (Farbar) C:\Users\64Bit Standard\Desktop\FRST64.exe
2016-08-23 21:51 - 2016-08-23 21:51 - 00000000 _____ C:\autoexec.bat
2016-08-23 21:50 - 2016-08-23 21:50 - 00003366 _____ C:\Windows\System32\Tasks\SpyHunter4Startup
2016-08-23 21:50 - 2016-08-23 21:50 - 00000937 _____ C:\Users\64Bit Standard\Desktop\SpyHunter.lnk
2016-08-23 21:50 - 2016-08-23 21:50 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2016-08-23 21:50 - 2016-08-23 21:50 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Enigma Software Group
2016-08-23 21:48 - 2016-08-23 21:49 - 00000000 ____D C:\sh4ldr
2016-08-23 21:34 - 2016-08-23 21:34 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
2016-08-23 21:32 - 2016-08-23 21:32 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-08-20 23:21 - 2016-08-20 23:21 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-08-20 23:21 - 2016-08-20 23:21 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-08-20 21:05 - 2016-08-20 21:05 - 00001845 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2016-08-20 21:05 - 2016-08-20 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2016-08-20 21:05 - 2016-08-20 21:05 - 00000000 ____D C:\Program Files (x86)\QuickTime
2016-08-15 15:33 - 2016-08-15 15:33 - 00000000 ____D C:\Users\64Bit Standard\.fontconfig
2016-08-09 00:36 - 2016-08-09 00:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit
2016-08-09 00:13 - 2016-08-23 22:38 - 00000000 ____D C:\Program Files (x86)\ITbrain Agent
2016-08-09 00:13 - 2016-08-09 00:13 - 00000000 __HDC C:\ProgramData\{651038AD-E038-410A-BD90-28FB006FD850}
2016-08-09 00:13 - 2016-08-09 00:13 - 00000000 ____D C:\Users\Default\AppData\Local\PackageAware
2016-08-09 00:13 - 2016-08-09 00:13 - 00000000 ____D C:\Users\Default User\AppData\Local\PackageAware
2016-08-09 00:06 - 2016-08-09 00:06 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2016-08-07 10:36 - 2016-08-07 10:36 - 00001964 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-08-07 10:36 - 2016-08-07 10:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2016-08-07 10:36 - 2016-08-07 10:36 - 00000000 ____D C:\Program Files\McAfee Security Scan
2016-08-05 08:59 - 2016-08-05 09:00 - 00000000 ____D C:\Program Files\Defraggler
2016-08-05 08:59 - 2016-08-05 08:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2016-08-05 08:56 - 2016-08-15 23:48 - 00000000 ____D C:\Program Files\Recuva
2016-08-05 08:56 - 2016-08-05 08:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2016-08-05 08:50 - 2016-08-05 08:50 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\CEF
2016-08-05 08:49 - 2016-08-05 08:49 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2016-08-05 08:49 - 2016-08-05 08:49 - 00000000 ____D C:\ProgramData\McAfee
2016-08-05 08:48 - 2016-08-05 08:48 - 00000000 ____D C:\Program Files\TrueKey
2016-08-05 08:47 - 2016-08-05 23:17 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-03 23:15 - 2016-08-05 08:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-07-24 04:10 - 2016-07-24 04:10 - 00003260 _____ C:\Windows\System32\Tasks\{ADD6E3C7-939C-4FF3-B4EE-157E0DA5FDC8}
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-08-23 22:21 - 2014-03-23 17:02 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\DMCache
2016-08-23 22:10 - 2014-03-23 17:02 - 00000000 ____D C:\Users\64Bit Standard\Downloads\Compressed
2016-08-23 21:55 - 2012-12-10 01:41 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-08-23 21:50 - 2012-12-12 06:46 - 00000944 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000UA.job
2016-08-23 21:23 - 2012-12-11 17:18 - 00000964 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000UA.job
2016-08-23 21:23 - 2009-07-14 13:13 - 00717892 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-23 21:23 - 2009-07-14 12:45 - 00010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-23 21:23 - 2009-07-14 12:45 - 00010208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-23 21:23 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\inf
2016-08-23 21:22 - 2012-02-08 23:25 - 00000000 ____D C:\ProgramData\MFAData
2016-08-23 21:18 - 2015-03-23 15:50 - 00000436 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2016-08-23 21:17 - 2015-04-23 12:59 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\cmsiex
2016-08-23 21:17 - 2014-01-18 23:56 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\newnext.me
2016-08-23 21:17 - 2013-09-17 16:52 - 00018688 _____ C:\Users\64Bit Standard\AppData\LocalLow\SkwConfig.bin
2016-08-23 21:17 - 2012-02-08 23:16 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Skype
2016-08-23 21:16 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-23 12:56 - 2012-12-11 18:59 - 00000220 _____ C:\Windows\popcinfo.dat
2016-08-23 12:53 - 2014-08-14 13:13 - 00000000 ___HD C:\Users\64Bit Standard\Desktop\my movies
2016-08-22 14:49 - 2012-12-11 17:18 - 00000942 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000Core.job
2016-08-21 01:16 - 2014-03-23 17:02 - 00000000 ____D C:\Users\64Bit Standard\Desktop\Video
2016-08-21 00:05 - 2012-12-11 19:04 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\vlc
2016-08-20 23:21 - 2012-02-08 22:45 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-08-20 23:04 - 2012-02-08 22:45 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-08-20 22:25 - 2012-12-25 14:19 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\CrashDumps
2016-08-20 20:43 - 2016-06-18 00:20 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\IDM
2016-08-16 00:40 - 2016-06-15 08:28 - 00000000 ____D C:\Users\64Bit Standard\Downloads\SHAREit
2016-08-15 23:51 - 2012-02-08 21:59 - 00000000 ____D C:\Users\64Bit Standard
2016-08-12 10:42 - 2014-09-24 16:51 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\SWDS
2016-08-11 19:50 - 2012-12-12 06:46 - 00000892 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000Core.job
2016-08-09 09:57 - 2012-12-10 01:37 - 00002419 _____ C:\Users\64Bit Standard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-09 00:36 - 2016-06-15 08:28 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\Lenovo
2016-08-09 00:36 - 2016-06-15 08:27 - 00001113 _____ C:\Users\Public\Desktop\SHAREit.lnk
2016-08-09 00:07 - 2016-07-02 01:34 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-08-07 00:12 - 2014-08-14 10:32 - 00000000 ____D C:\Program Files (x86)\Mobogenie3
2016-08-05 08:56 - 2012-12-14 18:30 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Media Player Classic
2016-08-05 08:56 - 2012-02-09 00:02 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\uTorrent
2016-08-05 08:56 - 2012-02-08 22:42 - 00000000 ____D C:\Users\64Bit Standard\AppData\Roaming\Winamp
2016-08-05 08:50 - 2012-12-10 01:40 - 00000000 ____D C:\Users\64Bit Standard\AppData\Local\Adobe
2016-08-05 08:48 - 2015-01-02 12:16 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-08-05 08:46 - 2012-12-10 01:40 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-08-05 08:46 - 2012-02-08 22:29 - 00000000 ____D C:\ProgramData\Adobe
2016-08-05 08:40 - 2012-12-11 17:21 - 00000000 ____D C:\Program Files\Java
2016-08-05 08:39 - 2016-06-23 02:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-08-05 08:39 - 2016-06-23 02:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-08-05 08:36 - 2016-06-23 02:28 - 00000000 ____D C:\Users\64Bit Standard\.oracle_jre_usage
2016-08-05 08:35 - 2012-12-11 17:22 - 00110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2016-08-04 09:31 - 2012-12-10 01:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 19:45 - 2012-12-12 06:46 - 00003936 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000UA
2016-07-29 19:45 - 2012-12-12 06:46 - 00003540 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-203507500-883022594-3238906040-1000Core
2016-07-26 23:29 - 2014-01-18 23:55 - 00000000 ____D C:\Program Files (x86)\Mobogenie
==================== Files in the root of some directories =======
2014-05-02 10:54 - 2013-12-15 10:38 - 6200595 _____ () C:\Program Files\SAM_2294 - Copy.JPG
2014-01-08 20:25 - 2014-05-02 09:53 - 0001703 _____ () C:\Program Files (x86)\Mozilla Firefoxnation-secure-search.xml
2015-12-30 10:10 - 2016-01-13 19:49 - 0003584 _____ () C:\Users\64Bit Standard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-17 15:03 - 2015-06-17 15:03 - 0004096 ____H () C:\Users\64Bit Standard\AppData\Local\keyfile3.drm
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-08-20 21:58
==================== End of FRST.txt ============================