Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-06-2015 Ran by Armand (administrator) on NEBUE-PC on 11-06-2015 00:42:17 Running from C:\Users\Armand\Downloads Loaded Profiles: Armand & UpdatusUser (Available Profiles: Armand & Mcx1-NEBUE-PC & UpdatusUser) Platform: Windows 7 Home Premium (X64) OS Language: Français (France) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Nicolas Coolman) C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-03-19] (Avast Software s.r.o.) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X] HKU\S-1-5-21-3819893973-4152668937-1926091911-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [425984 2009-08-05] () HKU\S-1-5-21-3819893973-4152668937-1926091911-1106\...\RunOnce: [ScrSav] => C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [162336 2009-07-22] () HKU\S-1-5-21-3819893973-4152668937-1926091911-1106\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Acer.scr [425984 2009-08-05] () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-03-15] (Avast Software s.r.o.) ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll [2009-08-06] (Egis Technology Inc.) ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll [2009-08-06] (Egis Technology Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3819893973-4152668937-1926091911-1005 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKU\S-1-5-21-3819893973-4152668937-1926091911-1005 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKU\S-1-5-21-3819893973-4152668937-1926091911-1005 -> ÛŸÆîZ§’2¹Þpv¨IÍá*X(Ž2s(ÛÎÀJºÔÓµ± vË°!×—(ä¼48иpatm6êo^Mp`Ëõ÷_i£w˜¾!„Áû†x¢8€ÙjÀÿþ ´Ñ;áa´[¦†8 º~RÙxœòÜ8'£-)x­ä­ URL = SearchScopes: HKU\S-1-5-21-3819893973-4152668937-1926091911-1106 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-15] (Avast Software s.r.o.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29] (RealDownloader) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-15] (Avast Software s.r.o.) BHO-x32: Programme d'aide de l'Assistant de connexion Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Armand\AppData\Roaming\Mozilla\Firefox\Profiles\78u4wgq6.default-1420644779845 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-06-09] () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-07-28] (Tracker Software Products (Canada) Ltd.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-07-28] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-09] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll [2014-11-07] (Adobe Systems, Inc.) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-07-28] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-10-16] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-10-16] (NVIDIA Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2013-01-13] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2012-11-29] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2012-11-29] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2012-11-29] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-01-13] (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2012-11-29] (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-07-28] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3819893973-4152668937-1926091911-1005: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-07-28] (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-3819893973-4152668937-1926091911-1005: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Armand\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-05-01] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-07-28] (Tracker Software Products (Canada) Ltd.) FF Extension: Adblock Plus - C:\Users\Armand\AppData\Roaming\Mozilla\Firefox\Profiles\78u4wgq6.default-1420644779845\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-22] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-05-22] FF HKLM-x32\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-01-13] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext Chrome: ======= CHR Profile: C:\Users\Armand\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (AdBlock) - C:\Users\Armand\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-07] CHR Extension: (Bookmark Manager) - C:\Users\Armand\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Armand\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-04] CHR Extension: (Google Wallet) - C:\Users\Armand\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-15] (Avast Software s.r.o.) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4030800 2015-03-15] (Avast Software) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2014-10-16] (NVIDIA Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1795912 2014-10-16] (NVIDIA Corporation) R2 postgresql-x64-9.3; C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe [89600 2015-03-25] (PostgreSQL Global Development Group) [File not signed] R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-03-15] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-03-15] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-03-15] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-03-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-03-15] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [441728 2015-03-15] (Avast Software s.r.o.) S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-03-15] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [268640 2015-03-15] () R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2015-06-03] (Glarysoft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-10-16] (NVIDIA Corporation) R3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-03-15] (Avast Software) S0 ckihq; System32\drivers\osaai.sys [X] S3 CrystalSysInfo; \??\C:\Program Files (x86)\MediaCoder\SysInfoX64.sys [X] ========================== Drivers MD5 ======================= C:\Windows\system32\DRIVERS\1394ohci.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ACPI.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\acpipmi.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys B9384E03479D2506BC924C16A3DB87BC C:\Windows\system32\DRIVERS\agp440.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\aliide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdsata.sys 7A4B413614C055935567CF88A9734D38 C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\amdxata.sys ==> MD5 is legit C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit C:\Windows\system32\drivers\aswHwid.sys BA4B999D245287608A79C92CDAE6F3C1 C:\Windows\system32\drivers\aswMonFlt.sys 245D3A0670491E1F88759EC45C9F7314 C:\Windows\system32\drivers\aswRdr2.sys BC18D5B42B19564BA09156410E1FB9BE C:\Windows\System32\Drivers\aswRvrt.sys 713AFFD4E38553AEF04617C985B4030B C:\Windows\system32\drivers\aswSnx.sys 669F6B37965756E407B447272B5EE39F C:\Windows\system32\drivers\aswSP.sys 3A145C94A519E52FE7E99460DD0DF53C C:\Windows\system32\drivers\aswStm.sys 8CDA894FA86D03FB43063D5FD85EFCAE C:\Windows\System32\Drivers\aswVmm.sys 11644D8399F4AC8BB12C2364DCB87CB4 C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\atapi.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys 91CE0D3DC57DD377E690A2D324022B08 C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\CmBatt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\compbatt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys 3F1DC527070ACB87E40AFE46EF6DA749 C:\Windows\System32\DRIVERS\ssudbus.sys 73BDD44A6088916964945886F9025409 C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 7CB7D2B73813CE05C7BC0F5F95D27CEC C:\Windows\System32\DRIVERS\e1y62x64.sys 761B9EDD97A021AA1922501B7A056635 C:\Windows\system32\DRIVERS\evbda.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\errdev.sys ==> MD5 is legit C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\fvevol.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit C:\Windows\System32\drivers\GUBootStartup.sys C06C3D6C5A0805B314E3E940632C97CB C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\iaStor.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\iaStorV.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\igdkmd64.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHD64.sys BC64B75E8E0A0B8982AB773483164E72 C:\Windows\system32\DRIVERS\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\isapnp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\msiscsi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecdd.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecpkg.sys BBE1BF6D9B661C354D4857D5FADB943B C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\L8042Kbd.sys F33C5D79D3273530E1892A0922283A7B C:\Windows\System32\DRIVERS\L8042mou.Sys A6FE2E63441094074F57243FB0FDB45A C:\Windows\System32\DRIVERS\LEqdUsb.Sys BECBD7CD46776B8739EE18061F45A581 C:\Windows\System32\DRIVERS\LHidEqd.Sys 21D6BD7D62C270059EB8E2B1D4095880 C:\Windows\System32\DRIVERS\LHidFilt.Sys B6552D382FF070B4ED34CBD6737277C0 C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\LMouFilt.Sys 73C1F563AB73D459DFFE682D66476558 C:\Windows\System32\DRIVERS\LMouKE.Sys F518C34C137348B7DBE5343ACC646A1C C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\System32\Drivers\LUsbFilt.Sys 9D9714E78EAC9E5368208649489C920E C:\Windows\system32\drivers\mbam.sys 1E9E32AEC3E1EB1B31B8169F33168B56 C:\Windows\system32\drivers\mwac.sys F49FB3C88E263AE9A246593B0BB29294 C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mrxsmb.sys CFDCD8CA87C2A657DEBC150AC35B5E08 C:\Windows\System32\DRIVERS\mrxsmb10.sys 1BEE517B220B7F024F411AEC1571DD5A C:\Windows\System32\DRIVERS\mrxsmb20.sys 6B2D5FEF385828B6E485C1C90AFB8195 C:\Windows\system32\DRIVERS\msahci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mwlPSDFilter.sys 6FFECC25B39DC7652A0CEC0ADA9DB589 C:\Windows\System32\DRIVERS\mwlPSDNServ.sys 0BEFE32CA56D6EE89D58175725596A85 C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys D43BC633B8660463E446E28E14A51262 C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys ==> MD5 is legit C:\Windows\system32\drivers\NTIDrvr.sys 64DDD0DEE976302F4BD93E5EFCC2F013 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\drivers\nvhda64v.sys C87B11EB78428853F9E8495C47E53C10 C:\Windows\System32\DRIVERS\nvlddmkm.sys 810530F309BDD7F055BE0301E27041FB C:\Windows\system32\DRIVERS\nvraid.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\nvstor.sys ==> MD5 is legit C:\Windows\System32\drivers\nvvad64v.sys 1AF619620613869C07F9C147BC37520F C:\Windows\system32\DRIVERS\nv_agp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ohci1394.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\PFC027.SYS 3A6DCEB1848470320E4A3C12D7A35B1C C:\Windows\system32\DRIVERS\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\pciide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\Drivers\RDPWD.sys 074AC702D8B8B660B0E1371555995386 C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\Drivers\RimUsb_AMD64.sys 7B04C9843921AB1F695FB395422C5360 C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\serenum.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\serial.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sffdisk.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sfloppy.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\SysWow64\speedfan.sys 0FFE35F0B0CD5A324BBE22F02569AE3B C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\srv.sys EC8F67289105BF270498095F14963464 C:\Windows\System32\DRIVERS\srv2.sys F773D2ED090B7BAA1C1A034F3CA476C8 C:\Windows\System32\DRIVERS\srvnet.sys 26E84D3649019C3244622E654DFCD75B C:\Windows\System32\DRIVERS\ssudmdm.sys 5252D7BC56E5E0ED715AEA8FE173A455 C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys 912107716BAB424C7870E8E6AF5E07E1 C:\Windows\System32\DRIVERS\tcpip.sys 912107716BAB424C7870E8E6AF5E07E1 C:\Windows\System32\drivers\tcpipreg.sys ==> MD5 is legit C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 7518F7BCFD4B308ABC9192BACAF6C970 C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\termdd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tssecsrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit C:\Windows\system32\drivers\UBHelper.sys 2E22C1FD397A5A9FFEF55E9D1FC96C00 C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umpass.sys ==> MD5 is legit C:\Windows\System32\drivers\usbaudio.sys 77B01BC848298223A95D4EC23E1785A1 C:\Windows\System32\DRIVERS\usbccgp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\usbcir.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\usbehci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\usbhub.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\usbohci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\USBSTOR.SYS ==> MD5 is legit C:\Windows\system32\DRIVERS\usbuhci.sys ==> MD5 is legit C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys CD74DB141650A8E131F30250381E5A77 C:\Windows\System32\DRIVERS\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\vhdmp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\viaide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\volsnap.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit C:\Windows\System32\drivers\vwifibus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\drivers\WudfPf.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WUDFRd.sys ==> MD5 is legit ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Three Months Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-11 00:42 - 2015-06-11 00:43 - 00036241 _____ C:\Users\Armand\Downloads\FRST.txt 2015-06-11 00:41 - 2015-06-11 00:42 - 00000000 ____D C:\FRST 2015-06-11 00:40 - 2015-06-11 00:41 - 02108928 _____ (Farbar) C:\Users\Armand\Downloads\FRST64.exe 2015-06-11 00:38 - 2015-06-11 00:38 - 00001995 _____ C:\Users\Armand\Desktop\ZHPFix.lnk 2015-06-11 00:38 - 2015-06-11 00:38 - 00001868 _____ C:\Users\Armand\Desktop\ZHPDiag.lnk 2015-06-11 00:38 - 2015-06-11 00:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2015-06-11 00:37 - 2015-06-11 00:38 - 06880102 _____ (Nicolas Coolman ) C:\Users\Armand\Downloads\ZHPDiag2 (2).exe 2015-06-11 00:34 - 2015-06-11 00:34 - 06872436 _____ (Nicolas Coolman ) C:\Users\Armand\Downloads\ZHPDiag2 (1).exe 2015-06-10 15:05 - 2015-06-10 15:08 - 737946274 _____ C:\Users\Armand\Downloads\Papa.ou.Maman.2015.FRENCH.DVDRip.XviD.avi 2015-06-09 19:53 - 2015-06-09 19:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMU Poker 2015-06-08 17:40 - 2015-06-09 16:57 - 00000000 ____D C:\Users\Armand\AppData\Local\PornTime 2015-06-08 17:39 - 2015-06-08 17:39 - 00003210 _____ C:\Windows\System32\Tasks\PornTime 2015-06-08 17:39 - 2015-06-08 17:39 - 00001005 _____ C:\Users\Public\Desktop\PornTime.lnk 2015-06-08 17:39 - 2015-06-08 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PornTime 2015-06-08 17:39 - 2015-06-08 17:39 - 00000000 ____D C:\Program Files (x86)\PornTime 2015-06-08 17:37 - 2015-06-08 17:38 - 26894333 _____ (PornTime ) C:\Users\Armand\Downloads\porntime.exe 2015-06-08 12:41 - 2015-06-08 12:43 - 584212480 _____ C:\Users\Armand\Downloads\Game.of.Thrones.S05E09.SUBFRENCH.HDTV.XviD-ZT.zone-telechargement.com.avi 2015-06-07 16:17 - 2015-06-07 16:17 - 01124544 _____ (Adobe Systems Incorporated) C:\Users\Armand\Downloads\flashplayer17au_ha_install.exe 2015-06-07 16:16 - 2015-06-10 19:03 - 00000336 _____ C:\Windows\setupact.log 2015-06-07 16:16 - 2015-06-07 16:16 - 00000368 _____ C:\Windows\PFRO.log 2015-06-07 16:16 - 2015-06-07 16:16 - 00000000 _____ C:\Windows\setuperr.log 2015-06-07 15:05 - 2015-06-07 15:05 - 00007605 _____ C:\Users\Armand\AppData\Local\Resmon.ResmonCfg 2015-06-07 14:54 - 2015-06-07 14:54 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-06-07 14:53 - 2015-06-07 14:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Armand\Downloads\mbam-setup-2.1.6.1022(1).exe 2015-06-07 14:53 - 2015-06-07 14:53 - 00001110 _____ C:\Users\Armand\Documents\Malwarebytes Anti-Malware.lnk 2015-06-07 14:53 - 2015-06-07 14:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-06-07 14:53 - 2015-06-07 14:53 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-06-07 14:53 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-06-07 14:53 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-07 14:53 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-07 14:51 - 2015-06-07 14:51 - 00000000 ____D C:\ProgramData\GlarySoft 2015-06-03 22:33 - 2015-06-03 22:37 - 732912226 _____ C:\Users\Armand\Downloads\Wolfcop.2014.FRENCH.BDRip.XviD-GDLN-Zone-Telechargement.com.avi 2015-06-03 15:42 - 2015-06-03 15:42 - 08942592 _____ (belintesa Corp.) C:\Users\Armand\Downloads\SpeedRunner Installer.exe 2015-06-03 15:42 - 2015-06-03 15:42 - 02231296 _____ C:\Users\Armand\Downloads\adwcleaner_4.206.exe 2015-06-03 15:37 - 2015-06-03 15:37 - 00003314 _____ C:\Windows\System32\Tasks\GlaryInitialize 5 2015-06-03 15:37 - 2015-06-03 15:37 - 00001100 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk 2015-06-03 15:37 - 2015-06-03 15:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5 2015-06-03 15:36 - 2015-06-07 16:17 - 00000000 ____D C:\Program Files (x86)\Glary Utilities 5 2015-06-03 15:36 - 2015-06-03 15:36 - 00020160 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUBootStartup.sys 2015-06-03 15:36 - 2015-06-03 15:36 - 00000000 ____D C:\Users\Armand\AppData\Roaming\GlarySoft 2015-06-03 15:36 - 2015-06-03 15:36 - 00000000 ____D C:\Users\Armand\AppData\Roaming\DiskDefrag 2015-06-03 15:35 - 2015-06-03 15:36 - 15121952 _____ C:\Users\Armand\Downloads\gu5setup.exe 2015-06-03 15:32 - 2015-06-03 15:33 - 02001540 _____ C:\Users\Armand\Downloads\pc-decrapifier-3.0.0.exe 2015-06-03 15:31 - 2015-06-03 15:31 - 00002792 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2015-06-03 15:31 - 2015-06-03 15:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-06-03 15:31 - 2015-06-03 15:31 - 00000000 ____D C:\Program Files\CCleaner 2015-06-03 15:29 - 2015-06-03 15:30 - 06549184 _____ (Piriform Ltd) C:\Users\Armand\Downloads\ccsetup506.exe 2015-06-03 15:28 - 2015-06-03 15:29 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Armand\Downloads\mbam-setup-2.1.6.1022.exe 2015-06-03 13:52 - 2015-06-03 14:02 - 1464759096 _____ C:\Users\Armand\Downloads\Run.All.Night.2015.FRENCH.BDRip.XviD.AC3-GLUPS-www.Zone-Telechargement.com.avi 2015-06-03 00:02 - 2015-06-03 00:18 - 1469114373 _____ C:\Users\Armand\Downloads\Jupiter.Ascending.2015.TRUEFRENCH.BDRiP.XViD-AViTECH.zone-telechargement.com.avi 2015-06-02 16:57 - 2015-06-02 17:01 - 736888847 _____ C:\Users\Armand\Downloads\Discount.2014.FRENCH.SUBFORCED.DVDRIP.XVid-LYS.zone-telechargement.com.avi 2015-06-02 14:37 - 2015-06-02 14:43 - 730058377 _____ C:\Users\Armand\Downloads\Unfinished.Business.2015.FRENCH.BRRiP.XviD-Slay3R-www.Zone-Telechargement.com.avi 2015-06-02 01:11 - 2015-06-02 01:15 - 577548301 _____ C:\Users\Armand\Downloads\Game.of.Thrones.S05E08.VOSTFR.HDTV.XviD-ARK01.zone-telechargement.com.avi 2015-06-02 01:10 - 2015-06-02 01:10 - 00000098 _____ C:\Users\Armand\Downloads\0486f0f9-81b0-4bae-b78f-4f43d9c8f3f3.htm 2015-06-01 18:37 - 2015-06-01 18:45 - 1466744842 _____ C:\Users\Armand\Downloads\It.Follows.2014.FRENCH.BRRip.XviD.AC3-DesTroY.zone-telechargement.com.avi 2015-05-27 22:42 - 2015-05-27 22:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-05-27 14:45 - 2015-05-27 14:53 - 1485436936 _____ C:\Users\Armand\Downloads\Kidnapping.Mr.Heineken.2015.FRENCH.BRRip.XviD.AC3-S.V.zone-telechargement.com.avi 2015-05-20 20:58 - 2015-05-20 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 9.3 2015-05-20 20:52 - 2015-05-20 20:56 - 56686240 _____ (PostgreSQL Global Development Group) C:\Users\Armand\Downloads\postgresql-9.3.6-2-windows-x64.exe 2015-05-20 20:28 - 2015-05-20 20:30 - 67450848 _____ C:\Users\Armand\Downloads\PT-Install-v4.13.3.exe 2015-05-20 15:58 - 2015-05-20 15:58 - 00081280 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT 2015-05-20 15:38 - 2015-05-20 15:38 - 00003088 _____ C:\Windows\System32\Tasks\{C398BE76-57E5-47DA-B160-F3720B70BCD4} 2015-05-20 15:04 - 2015-05-20 15:18 - 1512022020 _____ C:\Users\Armand\Downloads\Alleluia.2014.FRENCH.DVDRip.XviD.AC3-S.V.zone-telechargement.com.avi 2015-05-19 19:33 - 2015-05-19 19:33 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-05-19 17:38 - 2015-05-19 17:56 - 787270154 _____ C:\Users\Armand\Documents\pt4.zip 2015-05-19 14:02 - 2015-05-19 14:06 - 574435601 _____ C:\Users\Armand\Downloads\Game.Of.Thrones.S05E06.REPACK.VOSTFR.HDTV.XviD-ATeam.zone-telechargement.com.avi 2015-05-16 14:20 - 2015-05-16 14:20 - 00798800 _____ C:\Users\Armand\Downloads\PMUPokerSetup (1).exe 2015-05-14 16:01 - 2015-05-14 16:01 - 00131487 _____ C:\Users\Armand\Downloads\video-1431612074.mp4.mp4 2015-05-14 15:51 - 2015-05-14 15:51 - 00134037 _____ C:\Users\Armand\Downloads\video-1431611137.mp4.mp4 2015-05-14 15:05 - 2015-05-14 19:04 - 1466705923 _____ C:\Users\Armand\Downloads\Loin.Des.Hommes.2014.FRENCH.BRRip.XviD.AC3-DesTroY.zone-telechargement.com.avi 2015-05-13 02:39 - 2015-05-13 02:44 - 1464955000 _____ C:\Users\Armand\Downloads\Psychose.II.1983.FRENCH.DVDRiP.XViD.AC3-HuSh.www.zone-telechargement.com.avi 2015-05-10 00:31 - 2015-05-10 00:36 - 733782025 _____ C:\Users\Armand\Downloads\71.2014.TRUEFRENCH.DvDRiP.XviD-DreamStreet.zone-telechargement.com.avi 2015-05-06 14:43 - 2015-05-06 14:56 - 734013471 _____ C:\Users\Armand\Downloads\The.Riot.Club.2014.TRUEFRENCH.DVDRiP.XViD-AViTECH-www.Zone-Telechargement.com.avi 2015-05-06 02:59 - 2015-05-06 02:59 - 02077392 _____ (Microsoft Corporation) C:\Users\Armand\Downloads\IE11-Windows6.1.exe 2015-05-05 23:57 - 2015-05-06 00:07 - 1466116100 _____ C:\Users\Armand\Downloads\Jupiter.avi 2015-04-30 17:04 - 2015-04-30 17:42 - 00000132 _____ C:\Users\Armand\AppData\Roaming\Adobe PNG Format CS5 Prefs 2015-04-30 02:37 - 2015-04-30 02:37 - 00081280 _____ C:\Windows\SysWOW64\GDIPFONTCACHEV1.DAT 2015-04-24 14:02 - 2015-04-24 14:04 - 727392254 _____ C:\Users\Armand\Downloads\What.If.2014.TRUEFRENCH.BDRip.XviD-GIANTMAX-Zone-Telechargement.com.avi 2015-04-21 19:08 - 2015-04-21 19:08 - 00001387 _____ C:\Users\Armand\Documents\Spybot-S&D Start Center.lnk 2015-04-21 19:07 - 2015-04-21 19:07 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Armand\Downloads\spybot-2.4 (2).exe 2015-04-14 01:08 - 2015-04-14 01:20 - 1760057260 _____ C:\Users\Armand\Downloads\Marie.Heurtin.2014.FRENCH.DVDRip.XviD-granit29.zone-telechargement.com.avi 2015-04-11 16:05 - 2015-04-11 16:05 - 00000841 _____ C:\Users\Armand\Documents\ZHPFixReport.txt 2015-04-11 16:00 - 2015-05-20 16:07 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2015-04-11 16:00 - 2015-05-20 15:33 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2015-04-11 16:00 - 2015-04-11 16:00 - 00000000 ___HD C:\Users\Armand\AppData\Local\FullTiltPoker 2015-04-11 16:00 - 2015-04-11 16:00 - 00000000 ____D C:\Users\Armand\AppData\Roaming\wam 2015-04-11 16:00 - 2015-04-11 16:00 - 00000000 ____D C:\Users\Armand\AppData\Roaming\fr.barrierepoker.air.D043989C8F5E91300BF71855036B28F854BB8613.1 2015-04-11 16:00 - 2015-04-11 16:00 - 00000000 ____D C:\Users\Armand\AppData\Roaming\fr.barrierepoker.air 2015-04-11 16:00 - 2015-04-11 16:00 - 00000000 ____D C:\Program Files (x86)\Full Tilt Poker 2015-04-11 16:00 - 2015-04-11 16:00 - 00000000 ____D C:\Program Files (x86)\Everest Poker.fr 2015-04-11 15:59 - 2015-04-11 15:59 - 00000000 ____D C:\Program Files (x86)\SharkScope 2015-04-11 15:45 - 2015-04-11 15:45 - 00000000 ____D C:\Program Files (x86)\PokerTracker 3 2015-04-11 01:17 - 2015-05-20 20:30 - 00001082 _____ C:\Users\Armand\Desktop\PokerTracker 4.lnk 2015-04-11 01:17 - 2015-04-11 01:17 - 00000000 ____D C:\Users\Armand\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerTracker 4 2015-04-11 01:17 - 2015-04-11 01:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerTracker 4 2015-04-11 01:15 - 2015-04-11 01:16 - 67283784 _____ C:\Users\Armand\Downloads\PT-Install-v4.13.1.exe 2015-04-11 00:58 - 2015-04-11 00:58 - 00798800 _____ C:\Users\Armand\Downloads\PMUPokerSetup.exe 2015-04-11 00:48 - 2015-04-11 00:48 - 34499928 _____ (Winamax) C:\Users\Armand\Downloads\WinamaxInstall.exe 2015-04-11 00:46 - 2015-04-11 00:46 - 00001990 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.fr.lnk 2015-04-11 00:46 - 2015-04-11 00:46 - 00001984 _____ C:\Users\Public\Desktop\PokerStars.fr.lnk 2015-04-11 00:46 - 2015-04-11 00:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.FR 2015-04-11 00:44 - 2015-04-11 00:45 - 61957688 _____ (PokerStars) C:\Users\Armand\Downloads\PokerStarsInstallFR (2).exe 2015-04-11 00:03 - 2015-04-11 16:00 - 00000000 ____D C:\Users\Armand\AppData\Roaming\wam.04351C371E530C3762CBA45FA283ED972DCDEFB6.1 2015-04-10 23:52 - 2015-04-11 16:00 - 00000000 ____D C:\Users\Armand\AppData\Roaming\PMU 2015-04-10 20:05 - 2015-04-10 20:05 - 00003164 _____ C:\Windows\System32\Tasks\{3FA55A98-6229-4B9D-A7FF-78AA2BDB4F9A} 2015-04-10 20:03 - 2015-04-10 20:04 - 61957680 _____ (PokerStars) C:\Users\Armand\Downloads\PokerStarsInstallFR (1).exe 2015-04-10 16:22 - 2015-04-10 16:22 - 01708032 _____ C:\Users\Armand\Downloads\ZHPCleaner (1).exe 2015-04-10 16:18 - 2015-04-10 16:18 - 00000512 _____ C:\PhysicalDisk0_MBR.bin 2015-04-10 16:00 - 2015-04-10 16:00 - 06879225 _____ (Nicolas Coolman ) C:\Users\Armand\Downloads\ZHPDiag2.exe 2015-04-10 16:00 - 2015-04-10 16:00 - 01708032 _____ C:\Users\Armand\Downloads\ZHPCleaner.exe 2015-04-10 15:58 - 2015-04-10 15:58 - 02217984 _____ C:\Users\Armand\Downloads\adwcleaner_4.201.exe 2015-04-07 01:46 - 2015-04-07 01:46 - 09197158 _____ C:\Users\Armand\Downloads\vidéo approche éveil.mp4 2015-04-06 05:14 - 2015-04-06 05:18 - 735045646 _____ C:\Users\Armand\Downloads\The.Tree.zone-telechargement.com (1).avi 2015-03-30 18:22 - 2015-03-30 18:22 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Armand\Downloads\spybot-2.4 (1).exe 2015-03-22 17:25 - 2015-06-10 22:42 - 01383073 _____ C:\Windows\WindowsUpdate.log 2015-03-22 17:18 - 2015-03-22 17:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-03-22 15:35 - 2015-03-22 15:35 - 00000000 ____D C:\Windows\SysWOW64\vbox 2015-03-22 15:35 - 2015-03-22 15:35 - 00000000 ____D C:\Windows\system32\vbox 2015-03-15 22:57 - 2015-03-15 23:06 - 1466705937 _____ C:\Users\Armand\Downloads\Wild.2014.FRENCH.BDRip.XviD.AC3-DesTroY.zone-telechargement.com.avi 2015-03-15 17:21 - 2015-03-15 18:54 - 1351724551 _____ C:\Users\Armand\Downloads\Les.Rois.Mages.2001.FRENCH.SUBFORCED.BRRip.x264.AC3-CHARTAIR-http.www.zone-telechargement.com.mkv 2015-03-15 13:50 - 2015-03-15 13:55 - 1468246064 _____ C:\Users\Armand\Downloads\Vie.Sauvage.2014.FRENCH.BRRip.XviD.AC3-RiDDiCK-Zone-Telechargement.com.avi 2015-03-15 13:21 - 2015-03-15 13:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2015-03-15 13:20 - 2015-03-15 13:20 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe 2015-03-15 13:18 - 2015-03-15 13:18 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr ==================== Three Months Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-06-11 00:41 - 2015-01-08 18:00 - 00000000 ____D C:\Users\Armand\AppData\Roaming\ZHP 2015-06-11 00:38 - 2015-01-08 18:00 - 00000000 ____D C:\Program Files (x86)\ZHPDiag 2015-06-11 00:23 - 2012-05-22 21:10 - 00001070 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-06-11 00:12 - 2012-05-22 20:15 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-06-10 22:44 - 2012-05-22 22:17 - 00000000 ___HD C:\Users\Armand\AppData\Local\PokerStars.FR 2015-06-10 04:23 - 2012-05-22 21:10 - 00001066 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-06-09 23:14 - 2012-05-22 20:15 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-06-09 23:14 - 2012-05-22 20:15 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-06-09 23:14 - 2012-05-22 20:15 - 00003940 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-06-09 20:15 - 2012-05-22 20:16 - 00000000 ____D C:\Program Files (x86)\PokerStars.FR 2015-06-09 19:53 - 2014-12-09 20:52 - 00001417 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PMU Poker.lnk 2015-06-09 19:53 - 2014-07-28 20:03 - 00001411 _____ C:\Users\Armand\Desktop\PMU Poker.lnk 2015-06-09 19:53 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-06-09 02:02 - 2012-05-23 04:31 - 00000000 ____D C:\Users\Armand\AppData\Roaming\vlc 2015-06-08 02:27 - 2012-05-23 04:29 - 00744568 _____ C:\Windows\system32\perfh00C.dat 2015-06-08 02:27 - 2012-05-23 04:29 - 00148086 _____ C:\Windows\system32\perfc00C.dat 2015-06-08 02:27 - 2009-07-14 07:13 - 01660386 _____ C:\Windows\system32\PerfStringBackup.INI 2015-06-07 18:35 - 2012-09-06 14:59 - 00000000 ___HD C:\Users\Armand\AppData\Local\PokerTracker 4 2015-06-07 18:35 - 2012-09-06 14:58 - 00000000 ____D C:\Program Files (x86)\PokerTracker 4 2015-06-07 16:24 - 2009-07-14 06:45 - 00015568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-06-07 16:24 - 2009-07-14 06:45 - 00015568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-06-07 16:17 - 2014-10-30 19:05 - 00000000 ____D C:\Program Files (x86)\SpeedFan 2015-06-07 16:16 - 2012-05-22 19:09 - 00000000 ____D C:\ProgramData\NVIDIA 2015-06-07 16:16 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-06-03 16:23 - 2012-05-22 19:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-06-03 16:15 - 2014-03-22 23:08 - 00000000 ____D C:\AdwCleaner 2015-06-03 15:39 - 2012-09-26 22:41 - 00000000 ____D C:\Users\Armand\Desktop\Poker 2015-06-02 20:28 - 2015-02-09 21:05 - 00001105 _____ C:\Users\Public\Desktop\Winamax Poker.lnk 2015-06-02 20:28 - 2015-02-05 20:37 - 00000000 ____D C:\Users\Armand\Winamax 2015-05-20 20:57 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2015-05-20 20:30 - 2014-10-01 15:56 - 00001082 _____ C:\Users\UpdatusUser\Desktop\PokerTracker 4.lnk 2015-05-20 20:30 - 2014-04-15 23:00 - 00001082 _____ C:\Users\Mcx1-NEBUE-PC\Desktop\PokerTracker 4.lnk 2015-05-20 16:20 - 2014-10-30 19:01 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2015-05-20 15:47 - 2013-04-16 04:54 - 00000000 ____D C:\ProgramData\Origin 2015-05-20 15:47 - 2013-04-16 04:54 - 00000000 ____D C:\Program Files (x86)\Origin 2015-05-20 15:43 - 2012-07-17 21:57 - 00000000 ____D C:\ProgramData\Skype 2015-05-20 15:42 - 2012-06-22 18:15 - 00000000 ____D C:\Users\Armand\Documents\Son1 2015-05-20 15:33 - 2012-11-20 02:20 - 00000401 _____ C:\Windows\wininit.ini 2015-05-20 15:32 - 2012-10-04 15:46 - 00000000 ____D C:\Users\Armand\AppData\Roaming\uTorrent 2015-05-18 04:18 - 2012-05-22 21:10 - 00004066 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-05-18 04:18 - 2012-05-22 21:10 - 00003814 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-05-14 01:21 - 2014-10-02 22:27 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update ==================== Files in the root of some directories ======= 2009-08-27 21:18 - 2009-02-10 21:23 - 0192484 _____ () C:\Program Files (x86)\Common Files\Acer GameZone online.ico 2015-04-30 17:04 - 2015-04-30 17:42 - 0000132 _____ () C:\Users\Armand\AppData\Roaming\Adobe PNG Format CS5 Prefs 2014-03-24 00:16 - 2014-03-24 00:16 - 0000044 _____ () C:\Users\Armand\AppData\Roaming\WB.CFG 2013-01-16 21:18 - 2013-01-16 21:18 - 0005120 ____H () C:\Users\Armand\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-06-07 15:05 - 2015-06-07 15:05 - 0007605 _____ () C:\Users\Armand\AppData\Local\Resmon.ResmonCfg 2012-05-22 19:14 - 2012-05-22 19:16 - 0008021 _____ () C:\ProgramData\ArcadeDeluxe3.log 2012-05-22 20:19 - 2012-05-22 20:19 - 0004877 _____ () C:\ProgramData\bltofzsb.qlf 2012-09-06 14:59 - 2012-09-06 14:59 - 0004929 _____ () C:\ProgramData\flwjycbm.bab 2009-08-27 21:18 - 2009-07-18 03:57 - 0036136 _____ (Oberon Media) C:\ProgramData\FullRemove.exe Some files in TEMP: ==================== C:\Users\Armand\AppData\Local\Temp\sfamcc00001.dll C:\Users\Armand\AppData\Local\Temp\sfareca00001.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-06-03 02:36 ==================== End of log ============================