OTL logfile created on: 10/9/2016 12:26:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pho_Shizzle\Desktop\Antivirus
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17420)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.95 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 75.47% Memory free
15.89 Gb Paging File | 13.73 Gb Available in Paging File | 86.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 12.05 Gb Free Space | 10.11% Space Free | Partition Type: NTFS
Drive D: | 232.88 Gb Total Space | 163.08 Gb Free Space | 70.03% Space Free | Partition Type: NTFS
Drive E: | 1863.01 Gb Total Space | 105.79 Gb Free Space | 5.68% Space Free | Partition Type: NTFS
Drive H: | 465.76 Gb Total Space | 207.95 Gb Free Space | 44.65% Space Free | Partition Type: NTFS
Drive I: | 3.48 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive R: | 2794.39 Gb Total Space | 1632.02 Gb Free Space | 58.40% Space Free | Partition Type: NTFS
Computer Name: PHO_SHIZZLE_DAR | User Name: Pho_Shizzle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Pho_Shizzle\Desktop\Antivirus\OTL.exe (OldTimer Tools)
PRC - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe ()
PRC - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\n360.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Nero AG)
PRC - C:\Program Files (x86)\Rapoo\RpWireless\RPConfig.exe (RAPOO)
PRC - C:\Program Files (x86)\MSI\Live Update\Live Update.exe (Micro-Star International)
PRC - C:\Program Files (x86)\MSI\ECO Center\ECO_Service.exe ()
PRC - C:\MSI\Smart Utilities\SuperRAIDSvc.exe ()
PRC - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (Micro-Star International)
PRC - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe (MSI)
PRC - C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.)
PRC - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe (MSI)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_ssl.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._core_.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._controls_.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._windows_.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._gdi_.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_hashlib.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._misc_.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\unicodedata.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\windows._lib_cacheinvalidation.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\pythoncom27.dll ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32com.shell.shell.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32gui.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_elementtree.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\pyexpat.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._wizard.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32file.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\PyWinTypes27.dll ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32security.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32api.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\usb_ext.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_ctypes.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._animate.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\wx._html2.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_socket.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32inet.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_psutil_windows.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32process.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_multiprocessing.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32pdh.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32pipe.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32ts.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\_yappi.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32event.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\thumbnails_ext.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32profile.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\common.time34.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\win32crypt.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\select.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Local\Temp\_MEI27802\hashobjs_ext.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winffi.user32._winffi_user32.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\fastpath.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.dll ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\libGLESv2.dll ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\libEGL.dll ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\winxpgui.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32security.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32service.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32process.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32ts.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32profile.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32gui.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32file.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32print.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32evtlog.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32pipe.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32event.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32clipboard.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\win32api.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\mmapfile.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\_jpegtran.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\sip.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\faulthandler.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\_ctypes.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\unicodedata.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\pyexpat.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\pywintypes27.dll ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\select.pyd ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\pythoncom27.dll ()
MOD - C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\librsync.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4ed67120b2f61bef90bc0e07f609eca4\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\44feb3576c38df24b7d839b443e7e715\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\a8050cc4a3237ea52de951e3cc575ae3\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d6204638b750d650b7cbb3278a5954eb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\ae206eff0a9816475cd7dd3d680faa48\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\62bb69f490deae0403b8ba7dbd7706d7\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\628d5fbb7f335e658de7cd63082c7909\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ef80bf7db724bb3ab5fea4c0e2117cae\System.ni.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b3eb55fa5864a2fc7accbbbbe7fa7246\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll ()
MOD - C:\Windows\SysWOW64\CmdRtr.DLL ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Program Files (x86)\Rapoo\RpWireless\Swap.dll ()
========== Services (SafeList) ==========
SRV:
64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (DiagTrack) -- C:\Windows\SysNative\diagtrack.dll (Microsoft Corporation)
SRV:
64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:
64bit: - (ISCTAgent) -- C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe ()
SRV:
64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Intel(R) Corporation)
SRV:
64bit: - (Qualcomm Atheros Killer Service V2) -- C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe (Qualcomm Atheros)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Garmin Device Interaction Service) -- C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe (Garmin Ltd. or its subsidiaries)
SRV - (Origin Client Service) -- H:\Origin\OriginClientService.exe (Electronic Arts)
SRV - (TeamViewer) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MSIClock_CC) -- C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe (MSI)
SRV - (EasyAntiCheat) -- C:\Windows\SysWOW64\EasyAntiCheat.exe (EasyAntiCheat Ltd)
SRV - (MSICPU_CC) -- C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe ()
SRV - (MSISuperIO_CC) -- C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe ()
SRV - (N360) -- C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\N360.exe (Symantec Corporation)
SRV - (MSIDDR_CC) -- C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe ()
SRV - (MSICTL_CC) -- C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe ()
SRV - (MSISMB_CC) -- C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe ()
SRV - (MSICOMM_CC) -- C:\Program Files (x86)\MSI\Command Center\MSICommService.exe ()
SRV - (PnkBstrB) -- C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (HTCMonitorService) -- C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Nero AG)
SRV - (MSIBIOSData_CC) -- C:\Program Files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe (MSI)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ECOSERVICE) -- C:\Program Files (x86)\MSI\ECO Center\ECO_Service.exe ()
SRV - (SuperRAIDSvc) -- C:\MSI\Smart Utilities\SuperRAIDSvc.exe ()
SRV - (MSI_LiveUpdate_Service) -- C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe (Micro-Star International)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (MSI_SuperCharger) -- C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe (MSI)
SRV - (XTU3SERVICE) -- C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel(R) Corporation)
SRV - (GamingApp_Service) -- C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe (Micro-Star Int'l Co., Ltd.)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (PassThru Service) -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (ICCS) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
SRV - (MSI_FastBoot) -- C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe (MSI)
SRV - (UsbService) -- C:\Program Files (x86)\ASUS\Printer Utilities\UsbService64.exe ()
========== Driver Services (SafeList) ==========
DRV:
64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:
64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (Disc Soft Ltd)
DRV:
64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\TeeDriverx64.sys (Intel Corporation)
DRV:
64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\N360x64\1507000.00B\symnets.sys (Symantec Corporation)
DRV:
64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\N360x64\1507000.00B\symefa64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\N360x64\1507000.00B\srtsp64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\N360x64\1507000.00B\srtspx64.sys (Symantec Corporation)
DRV:
64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\N360x64\1507000.00B\ironx64.sys (Symantec Corporation)
DRV:
64bit: - (rpwkmdrv) -- C:\Windows\SysNative\drivers\rpwkmdrv.sys ()
DRV:
64bit: - (LMouFilt) -- C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:
64bit: - (LHidFilt) -- C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:
64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:
64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:
64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:
64bit: - (ISCT) -- C:\Windows\SysNative\drivers\ISCTD.sys ()
DRV:
64bit: - (INETMON) -- C:\Windows\SysNative\drivers\INETMON.sys ()
DRV:
64bit: - (imsevent) -- C:\Windows\SysNative\drivers\imsevent.sys ()
DRV:
64bit: - (ikbevent) -- C:\Windows\SysNative\drivers\ikbevent.sys ()
DRV:
64bit: - (asstor64) -- C:\Windows\SysNative\drivers\asstor64.sys (Asmedia Technology)
DRV:
64bit: - (BfLwf) -- C:\Windows\SysNative\drivers\bflwfx64.sys (Qualcomm Atheros, Inc.)
DRV:
64bit: - (htcnprot) -- C:\Windows\SysNative\drivers\htcnprot.sys (Windows (R) Win 7 DDK provider)
DRV:
64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (ccSet_N360) -- C:\Windows\SysNative\drivers\N360x64\1507000.00B\ccsetx64.sys (Symantec Corporation)
DRV:
64bit: - (SymDS) -- C:\Windows\SysNative\drivers\N360x64\1507000.00B\symds64.sys (Symantec Corporation)
DRV:
64bit: - (asmtxhci) -- C:\Windows\SysNative\drivers\asmtxhci.sys (ASMedia Technology Inc)
DRV:
64bit: - (asmthub3) -- C:\Windows\SysNative\drivers\asmthub3.sys (ASMedia Technology Inc)
DRV:
64bit: - (ICCWDT) -- C:\Windows\SysNative\drivers\ICCWDT.sys (Intel Corporation)
DRV:
64bit: - (LGSHidFilt) -- C:\Windows\SysNative\drivers\LGSHidFilt.Sys (Logitech Inc.)
DRV:
64bit: - (Ke2200) -- C:\Windows\SysNative\drivers\e22W7x64.sys (Qualcomm Atheros, Inc.)
DRV:
64bit: - (usb_rndisx) -- C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:
64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:
64bit: - (AcpiCtlDrv) -- C:\Windows\SysNative\drivers\AcpiCtlDrv.sys (Intel Corporation)
DRV:
64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:
64bit: - (appliandMP) -- C:\Windows\SysNative\drivers\appliand.sys (Applian Technologies Inc.)
DRV:
64bit: - (appliand) -- C:\Windows\SysNative\drivers\appliand.sys (Applian Technologies Inc.)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (MSHUSBVideo) -- C:\Windows\SysNative\drivers\nx6000.sys (Microsoft Corporation)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (PcaSp60) -- C:\Windows\SysNative\drivers\PcaSp60.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV:
64bit: - (HtcVCom32) -- C:\Windows\SysNative\drivers\HtcVComV64.sys (QUALCOMM Incorporated)
DRV:
64bit: - (LGVirHid) -- C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:
64bit: - (LGBusEnum) -- C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:
64bit: - (MBfilt) -- C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.)
DRV:
64bit: - (HTCAND64) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (vuhub) -- C:\Windows\SysNative\drivers\vuhub.sys ()
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\IPSDefs\20161007.001\IDSviA64.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20161009.001\ex64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\VirusDefs\20161009.001\eng64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\Program Files (x86)\Norton Security Suite\NortonData\21.1.0.18\Definitions\BASHDefs\20161005.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NTIOLib_MSI_RAID) -- C:\MSI\Smart Utilities\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MB) -- C:\Program Files (x86)\MSI\MSI Gaming APP\Lib\NTIOLib_X64.sys (MSI)
DRV - (iocbios2) -- C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys (Intel Corporation)
DRV - (cpuz137) -- C:\Program Files (x86)\CPUID\PC Wizard 2013\pcwiz_x64.sys (CPUID)
DRV - (NTIOLib_ECO) -- C:\Program Files (x86)\MSI\ECO Center\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSIDDR_CC) -- C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSIFrequency_CC) -- C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSIRatio_CC) -- C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSICPU_CC) -- C:\Program Files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSIClock_CC) -- C:\Program Files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSISMB_CC) -- C:\Program Files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSICOMM_CC) -- C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_MSISuperIO_CC) -- C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_FastBoot) -- C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_1_0_3) -- C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys (MSI)
DRV - (NTIOLib_1_0_4) -- C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys (MSI)
DRV - (PcaSp60) -- C:\Windows\SysWOW64\drivers\PcaSp60.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (GPCIDrv) -- C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F2 DD 16 B4 00 A4 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.countryCode: "US"
FF - prefs.js..browser.search.defaultenginename.US: "Google"
FF - prefs.js..browser.search.hiddenOneOffs: "Google"
FF - prefs.js..browser.search.region: "US"
FF - prefs.js..browser.startup.homepage: "
www.yahoo.com"
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20151208
FF - prefs.js..extensions.enabledAddons: text2voice%40vik.josh:1.15
FF - prefs.js..extensions.enabledAddons: adblockpopups%40jessehakanen.net:0.9.2.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7Bce7e73df-6a44-4028-8079-5927a588c948%7D:1.1.2.1-signed.1-signed
FF - prefs.js..extensions.enabledAddons: %7Bcd617375-6743-4ee8-bac4-fbf10f35729e%7D:2.9.6
FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.3.19
FF - prefs.js..extensions.enabledAddons: %7Bc151d79e-e61b-4a90-a887-5a46d38fba99%7D:2.8.8
FF - prefs.js..extensions.enabledAddons: artur.dubovoy%40gmail.com:13.2.4
FF - prefs.js..extensions.enabledAddons: %7B5384767E-00D9-40E9-B72F-9CC39D655D6F%7D:1.5.0.9
FF - prefs.js..extensions.enabledAddons: ClassicThemeRestorer%40ArisT2Noia4dev:1.5.7
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:49.0.1
FF - prefs.js..services.sync.prefs.sync.browser.search.selectedEngine: true
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.101.2: C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.101.2: C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Pho_Shizzle\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Pho_Shizzle\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\PROGRAM FILES\ESET\ESET NOD32 ANTIVIRUS\MOZILLA THUNDERBIRD
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn\ [2016/10/09 12:04:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{40211632-250D-4B8C-B04E-DA45BAE6DF8C}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn\ [2016/10/09 12:04:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 49.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 49.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2014/07/20 00:37:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Extensions
[2016/10/09 12:05:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
[2016/01/01 23:42:30 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2016/01/01 23:41:53 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29}
[2016/01/01 23:41:29 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2016/01/01 23:42:07 | 000,000,000 | ---D | M] ("Flash Video Downloader - YouTube HD Download [4K]") -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
[email protected]
[2016/01/01 23:41:29 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="
[email protected]" em:name="Xmarks" em:type="2" em:unpack="true" em:version="4.3.7.1-signed" em:creator="Todd Agulnick" em:description="Bookmark Sync and Web Discovery" em:homepageURL="
http://www.xmarks.com/" em

ptionsURL="chrome://foxmarks/content/foxmarks-dialog.xul" em:iconURL="chrome://foxmarks/skin/images/foxmarks.ico" em:developer="LastPass">) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
[email protected]
[2016/01/01 23:41:54 | 000,000,000 | ---D | M] ("NetVideoHunter") -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
[email protected]
[2016/10/07 00:04:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions
[2016/04/26 21:22:00 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2016/08/16 00:18:36 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2015/12/09 20:47:48 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2016/09/18 11:43:47 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2016/07/30 17:45:22 | 000,000,000 | ---D | M] ("Flash Video Downloader - YouTube HD Download [4K]") -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/05/25 19:28:13 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2015/11/11 21:10:27 | 000,000,000 | ---D | M] ("NetVideoHunter") -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/01/01 23:42:18 | 000,016,005 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
[email protected]
[2016/01/01 23:41:29 | 000,151,374 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
[email protected]
[2016/01/01 23:42:18 | 000,041,764 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
[email protected]
[2016/01/01 23:41:56 | 000,043,831 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{170503FA-3349-4F17-BC86-001888A5C8E2}.xpi
[2016/01/01 23:41:55 | 000,014,076 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{76C80A11-FAD4-406c-8246-F5ED4F9367B5}.xpi
[2016/01/01 23:41:56 | 000,024,805 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi
[2016/01/01 23:41:55 | 000,636,306 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
[2016/01/01 23:41:47 | 000,198,192 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{c151d79e-e61b-4a90-a887-5a46d38fba99}.xpi
[2016/01/01 23:41:45 | 000,989,188 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2015/11/11 21:09:14 | 000,016,005 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/04/27 19:27:29 | 000,151,382 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/09/23 00:48:10 | 000,876,056 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2015/11/11 21:38:08 | 000,041,764 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/04/27 21:21:46 | 000,036,320 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/05/05 23:38:51 | 000,024,293 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/04/27 21:21:46 | 000,090,633 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/04/27 21:21:46 | 000,062,298 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/03/23 01:26:49 | 000,071,587 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\
[email protected]
[2016/09/26 21:25:05 | 001,019,941 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi
[2016/09/17 02:09:43 | 000,717,884 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
[2016/07/30 22:11:50 | 000,198,797 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{c151d79e-e61b-4a90-a887-5a46d38fba99}.xpi
[2015/12/08 22:46:49 | 000,054,485 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi
[2016/04/29 23:06:00 | 000,067,957 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi
[2016/04/28 19:19:32 | 000,073,436 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi
[2016/04/28 21:21:47 | 001,036,367 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2016/09/25 10:05:32 | 000,007,076 | ---- | M] () (No name found) -- C:\Users\Pho_Shizzle\AppData\Roaming\Mozilla\Firefox\Profiles\olzw6kxg.default-1447301196454\features\{8688fd66-85c8-4676-82eb-00f54f0411bf}\
[email protected]
[2016/09/25 00:41:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
========== Chrome ==========
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiembaoomcehoiehhdldabfgnmphappc\2.6.1_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif\1.0.5_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.7.12.30_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5216.530.0.14_0\
CHR - Extension: No name found = C:\Users\Pho_Shizzle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5316.725.0.15_0\
O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:
64bit: - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine64\21.7.0.11\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll (Oracle Corporation)
O3:
64bit: - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine64\21.7.0.11\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\21.7.0.11\coieplg.dll (Symantec Corporation)
O4:
64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4:
64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [StartCN] C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Command Center] C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe (MSI)
O4 - HKLM..\Run: [Launch] C:\Program Files (x86)\Rapoo\RpWireless\Launch.exe ()
O4 - HKLM..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\StartLiveUpdate.exe (Micro-Star International)
O4 - HKLM..\Run: [Sound Blaster Cinema 2] C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKCU..\Run: [Dropbox Update] C:\Users\Pho_Shizzle\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
O4 - Startup: C:\Users\Pho_Shizzle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E}
http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{835ABDB0-E7E4-47BB-872A-3B62C85D4870}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\osf - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/13 05:55:00 | 000,000,043 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{47f084c7-8e20-11e4-a8a9-448a5b99bb68}\Shell - "" = AutoRun
O33 - MountPoints2\{47f084c7-8e20-11e4-a8a9-448a5b99bb68}\Shell\AutoRun\command - "" = F:\HTC_Sync_Manager_PC.exe
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\SETUP.EXE -- [2009/07/13 05:55:00 | 000,111,880 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2016/10/09 12:01:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2016/10/09 12:01:23 | 000,000,000 | ---D | C] -- C:\Users\Pho_Shizzle\Desktop\Antivirus
[2016/10/09 11:55:36 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Pho_Shizzle\Desktop\HijackThis.exe
[2016/10/09 11:41:24 | 003,132,544 | ---- | C] (ESET) -- C:\Users\Pho_Shizzle\Desktop\eset_nod32_antivirus_live_installer.exe
[2016/10/06 23:58:36 | 000,192,216 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2016/10/06 23:38:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2016/10/06 23:38:44 | 000,140,672 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2016/10/06 23:38:44 | 000,064,896 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2016/10/06 23:38:44 | 000,027,008 | ---- | C] (Malwarebytes) -- C:\Windows\SysNative\drivers\mbam.sys
[2016/10/06 23:38:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2016/10/06 23:38:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2016/10/06 23:38:09 | 022,851,472 | ---- | C] (Malwarebytes ) -- C:\Users\Pho_Shizzle\Desktop\mbam-setup-2.2.1.1043.exe
[2016/10/06 21:20:27 | 000,000,000 | R--D | C] -- C:\Users\Pho_Shizzle\Searches
[2016/10/06 20:35:30 | 000,000,000 | ---D | C] -- C:\Users\Pho_Shizzle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2016/10/06 00:09:31 | 000,000,000 | ---D | C] -- C:\06bd30e4d250b7132f035809504a45
[2016/10/05 23:57:55 | 000,000,000 | ---D | C] -- C:\6ba3aff290bdfeb3e6a6ceae
[2016/10/05 19:56:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
[2016/10/05 19:50:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VulkanRT
[2016/10/01 02:35:54 | 000,000,000 | ---D | C] -- C:\Users\Pho_Shizzle\.android
[2016/09/25 00:40:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2016/09/16 12:41:34 | 000,286,600 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2016/09/16 12:41:32 | 000,110,472 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2016/09/16 12:41:18 | 000,287,112 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2016/09/16 12:41:16 | 000,523,144 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2016/09/16 12:40:00 | 000,891,272 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst_16.40.dll
[2016/09/16 12:39:42 | 000,112,520 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2016/09/16 12:39:38 | 000,103,304 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2016/09/12 18:59:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
[26 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[23 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2016/10/09 12:25:43 | 000,014,480 | ---- | M] () -- C:\Windows\SysWow64\Utility.xml
[2016/10/09 12:25:37 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/10/09 12:25:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016/10/09 12:25:08 | 2105,389,055 | -HS- | M] () -- C:\hiberfil.sys
[2016/10/09 12:13:10 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016/10/09 12:13:10 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016/10/09 12:07:21 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2016/10/09 12:04:39 | 000,000,942 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-451852660-2627386536-4071465190-1000UA.job
[2016/10/09 11:54:58 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Pho_Shizzle\Desktop\HijackThis.exe
[2016/10/09 11:38:38 | 003,132,544 | ---- | M] (ESET) -- C:\Users\Pho_Shizzle\Desktop\eset_nod32_antivirus_live_installer.exe
[2016/10/08 22:09:09 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\spu_storage.bin
[2016/10/06 23:38:48 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016/10/06 23:33:15 | 000,799,374 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2016/10/06 23:33:15 | 000,674,766 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2016/10/06 23:33:15 | 000,126,438 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2016/10/06 23:23:36 | 022,851,472 | ---- | M] (Malwarebytes ) -- C:\Users\Pho_Shizzle\Desktop\mbam-setup-2.2.1.1043.exe
[2016/10/06 20:35:51 | 000,001,115 | ---- | M] () -- C:\Users\Pho_Shizzle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2016/10/06 01:07:34 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-451852660-2627386536-4071465190-1000UA.job
[2016/10/06 01:04:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\DropboxUpdateTaskUserS-1-5-21-451852660-2627386536-4071465190-1000Core.job
[2016/10/06 00:46:56 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/10/03 21:07:42 | 000,006,704 | ---- | M] () -- C:\Users\Pho_Shizzle\Desktop\111111111re.PNG
[2016/10/02 02:07:00 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-451852660-2627386536-4071465190-1000Core.job
[2016/09/29 22:30:13 | 000,429,027 | ---- | M] () -- C:\Users\Pho_Shizzle\Desktop\486d0a1da2d142fab42c82bbe15f7641.jpeg
[2016/09/26 00:23:10 | 002,170,979 | ---- | M] () -- C:\Users\Pho_Shizzle\Desktop\HACEKM0112.pdf
[2016/09/16 12:41:50 | 000,275,336 | ---- | M] () -- C:\Windows\SysNative\GameManager64.dll
[2016/09/16 12:41:48 | 000,240,008 | ---- | M] () -- C:\Windows\SysWow64\GameManager32.dll
[2016/09/16 12:41:46 | 000,292,744 | ---- | M] () -- C:\Windows\SysNative\dgtrayicon.exe
[2016/09/16 12:41:34 | 000,286,600 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2016/09/16 12:41:32 | 000,110,472 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2016/09/16 12:41:18 | 000,287,112 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2016/09/16 12:41:16 | 000,523,144 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2016/09/16 12:41:16 | 000,230,280 | ---- | M] () -- C:\Windows\SysNative\atieah64.exe
[2016/09/16 12:41:14 | 000,208,264 | ---- | M] () -- C:\Windows\SysWow64\atieah32.exe
[2016/09/16 12:40:10 | 000,248,200 | ---- | M] () -- C:\Windows\SysNative\amdgfxinfo64.dll
[2016/09/16 12:40:06 | 000,221,064 | ---- | M] () -- C:\Windows\SysWow64\amdgfxinfo32.dll
[2016/09/16 12:40:00 | 000,891,272 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst_16.40.dll
[2016/09/16 12:39:50 | 000,267,656 | ---- | M] () -- C:\Windows\SysNative\hsa-thunk64.dll
[2016/09/16 12:39:46 | 000,233,352 | ---- | M] () -- C:\Windows\SysWow64\hsa-thunk.dll
[2016/09/16 12:39:44 | 000,269,192 | ---- | M] () -- C:\Windows\SysNative\clinfo.exe
[2016/09/16 12:39:42 | 000,112,520 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2016/09/16 12:39:38 | 000,103,304 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2016/09/16 12:00:12 | 000,751,344 | ---- | M] () -- C:\Windows\SysWow64\atiapfxx.blb
[2016/09/16 12:00:12 | 000,751,344 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb
[2016/09/16 11:58:42 | 003,437,632 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap
[2016/09/16 11:54:10 | 003,471,376 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap
[2016/09/16 00:24:11 | 000,009,216 | ---- | M] () -- C:\My3DGraph.grf
[26 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[23 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2016/10/06 23:38:48 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016/10/05 19:50:03 | 000,269,600 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1.dll
[2016/10/05 19:50:03 | 000,261,920 | ---- | C] () -- C:\Windows\SysNative\vulkan-1.dll
[2016/10/05 19:50:03 | 000,125,216 | ---- | C] () -- C:\Windows\SysNative\vulkaninfo.exe
[2016/10/05 19:50:03 | 000,110,880 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo.exe
[2016/10/03 21:07:42 | 000,006,704 | ---- | C] () -- C:\Users\Pho_Shizzle\Desktop\111111111re.PNG
[2016/09/29 22:30:12 | 000,429,027 | ---- | C] () -- C:\Users\Pho_Shizzle\Desktop\486d0a1da2d142fab42c82bbe15f7641.jpeg
[2016/09/26 00:23:10 | 002,170,979 | ---- | C] () -- C:\Users\Pho_Shizzle\Desktop\HACEKM0112.pdf
[2016/09/25 12:27:38 | 000,065,536 | ---- | C] () -- C:\Windows\SysNative\spu_storage.bin
[2016/09/16 12:41:50 | 000,275,336 | ---- | C] () -- C:\Windows\SysNative\GameManager64.dll
[2016/09/16 12:41:48 | 000,240,008 | ---- | C] () -- C:\Windows\SysWow64\GameManager32.dll
[2016/09/16 12:41:46 | 000,292,744 | ---- | C] () -- C:\Windows\SysNative\dgtrayicon.exe
[2016/09/16 12:41:16 | 000,230,280 | ---- | C] () -- C:\Windows\SysNative\atieah64.exe
[2016/09/16 12:41:14 | 000,208,264 | ---- | C] () -- C:\Windows\SysWow64\atieah32.exe
[2016/09/16 12:40:10 | 000,248,200 | ---- | C] () -- C:\Windows\SysNative\amdgfxinfo64.dll
[2016/09/16 12:40:06 | 000,221,064 | ---- | C] () -- C:\Windows\SysWow64\amdgfxinfo32.dll
[2016/09/16 12:39:50 | 000,267,656 | ---- | C] () -- C:\Windows\SysNative\hsa-thunk64.dll
[2016/09/16 12:39:46 | 000,233,352 | ---- | C] () -- C:\Windows\SysWow64\hsa-thunk.dll
[2016/09/16 12:39:44 | 000,269,192 | ---- | C] () -- C:\Windows\SysNative\clinfo.exe
[2016/09/16 12:00:12 | 000,751,344 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2016/09/16 12:00:12 | 000,751,344 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2016/09/16 11:58:42 | 003,437,632 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2016/09/16 11:54:10 | 003,471,376 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2016/09/09 11:25:58 | 000,269,600 | ---- | C] () -- C:\Windows\SysWow64\vulkan-1-1-0-26-0.dll
[2016/09/09 11:25:28 | 000,110,880 | ---- | C] () -- C:\Windows\SysWow64\vulkaninfo-1-1-0-26-0.exe
[2016/02/01 00:28:55 | 000,000,911 | ---- | C] () -- C:\Users\Pho_Shizzle\AppData\Local\recently-used.xbel
[2016/01/17 20:12:28 | 000,089,942 | ---- | C] () -- C:\Users\Pho_Shizzle\f4d5ee3b_zps7e71a244.jpg
[2015/11/01 23:32:00 | 000,011,515 | ---- | C] () -- C:\Users\Pho_Shizzle\Laptop_Wall_Mount.zip
[2015/11/01 21:29:37 | 000,025,568 | ---- | C] () -- C:\Users\Pho_Shizzle\LaptopWallMount_preview_featured.jpg
[2015/09/04 01:29:34 | 002,614,633 | ---- | C] () -- C:\Users\Pho_Shizzle\Halo_Too_manual.pdf
[2015/09/04 01:27:23 | 004,486,415 | ---- | C] () -- C:\Users\Pho_Shizzle\HALO_B_V35_Manual.pdf
[2015/08/08 10:01:12 | 004,971,247 | ---- | C] () -- C:\Users\Pho_Shizzle\Prodrive-WR-Sport-PPP-Dealer-Brochure.pdf
[2015/07/05 20:39:21 | 000,041,826 | ---- | C] () -- C:\Users\Pho_Shizzle\DSC02872.jpg
[2015/07/03 00:53:34 | 001,368,106 | ---- | C] () -- C:\Users\Pho_Shizzle\Capture.PNG
[2015/07/02 23:58:48 | 004,026,251 | ---- | C] () -- C:\Users\Pho_Shizzle\B5A-0214-00.pdf
[2015/07/02 23:42:15 | 000,006,827 | ---- | C] () -- C:\Users\Pho_Shizzle\Prescription 2.PNG
[2015/07/02 23:41:07 | 000,031,453 | ---- | C] () -- C:\Users\Pho_Shizzle\Prescription 1.PNG
[2015/02/07 22:21:08 | 000,000,400 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015/01/01 02:48:12 | 001,351,117 | ---- | C] () -- C:\Windows\unins000.exe
[2015/01/01 02:48:12 | 000,037,895 | ---- | C] () -- C:\Windows\unins000.dat
[2014/11/20 22:35:00 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2014/09/06 16:58:05 | 000,324,750 | ---- | C] () -- C:\Users\Pho_Shizzle\How to Spot a Fake.pdf
[2014/09/06 16:57:58 | 008,958,825 | ---- | C] () -- C:\Users\Pho_Shizzle\Identifying Counterfeits.pdf
[2014/07/27 23:03:36 | 000,000,098 | ---- | C] () -- C:\Users\Pho_Shizzle\AppData\Roaming\LauncherSettings_live.cfg
[2014/07/27 22:51:11 | 000,000,040 | ---- | C] () -- C:\Users\Pho_Shizzle\AppData\Roaming\TheHunterSettings_steam_live.cfg
[2014/07/19 21:44:22 | 000,007,611 | ---- | C] () -- C:\Users\Pho_Shizzle\AppData\Local\resmon.resmoncfg
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015/02/12 22:22:33 | 014,177,280 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/02/12 22:26:18 | 012,875,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 05:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2015/05/09 22:20:22 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\.mono
[2015/01/14 01:33:41 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\AMD
[2014/11/24 23:46:24 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\DAEMON Tools Lite
[2016/10/06 20:35:47 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Dropbox
[2014/12/10 22:04:05 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Garmin
[2014/10/19 20:07:24 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\GoPro
[2015/08/10 23:37:38 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\HTC
[2016/05/27 00:10:25 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\IrfanView
[2015/06/29 00:49:04 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Jasc
[2014/12/11 21:56:06 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\library_dir
[2014/07/20 12:21:13 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Maxthon3
[2015/06/06 02:07:38 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\naviextras
[2014/08/06 00:36:39 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Oracle
[2015/10/17 00:23:21 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Origin
[2014/12/24 00:27:58 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\PhraseExpress
[2016/07/14 23:05:59 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\PlaysTV
[2016/10/08 18:57:51 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Raptr
[2014/07/22 01:22:07 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Replay Media Catcher 4
[2015/05/21 01:15:09 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Steam
[2016/09/28 23:13:51 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\TeamViewer
[2014/07/27 22:51:12 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\theHunter
[2014/07/27 22:48:28 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\theHunterSteam
[2014/08/28 22:28:07 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\Thunderbird
[2016/10/02 20:50:11 | 000,000,000 | ---D | M] -- C:\Users\Pho_Shizzle\AppData\Roaming\uTorrent
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:054203E4
< End of report >