Infected with a miner (question mark?)

Q: Infected with a miner (question mark?)

Hello! I've been helped in the past by this forum, so I thought I might give it another go (also thinking about joining the training program, seems about fun and fitting for my knowledge - IT student who loves to help - so yeah).Back on topic however!I've been infected with something that takes 25% of my CPU under the process "svchost.exe".I checked and it's the actual system process, not a fake or misspelled one. I used process explorer to check what service it was, and apparently, it's wuauserv, Windows Update?I deleted most of the infection, it had a task in the Task Scheduler (fake Steam task, Steam doesn't create tasks) and a couple of folders in appdata (!) where it ran.The file had, surprisingly, no extension. It was just called "Steam", about two MBs in size. I deleted that and other suspicious files I didn't download or install myself.Apparently, the only instance remaining is the one under svchost. I have attached the Addition.txt file. Here are two screenshots (taken with Gyazo)Task manager showing %CPU for the process: https://gyazo.com/9d9c50f451c94dd095de4034152cabe4Process Explorer information on that process: https://gyazo.com/5dd83c775698b8c29bbc13435657ec38 The file will not be moved.)(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe() C:\Windows\SysWOW64\PnkBstrA.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe(Flux Software LLC) C:\Users\Edo\AppData\Local\FluxSoftware\Flux\flux.exe(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe(Microsoft Corporation) C:\Windows\System32\taskmgr.exe(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe(React) D:\Tutto\Giochi\ReactMW2\iw4m.exe(Valve Corporation) C:\Program Files (x86)\Steam\GameOverlayUI.exe(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Audition CC 2015\Adobe Audition CC.exe(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Audition CC 2015\32\dynamiclinkmanager.exe(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Audition CC 2015\32\Adobe QT32 Server.exe(Sysinternals - www.sysinternals.com) D:\Program Files (x86)\Process Explorer (ProcExp)\procexp.exe(Sysinternals - www.sysinternals.com) C:\Users\Edo\AppData\Local\Temp\procexp64.exe(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe(Telegram Messenger LLP) D:\Program Files (x86)\Telegram\Telegram.exe==================== Registry (Whitelisted) ===========================(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStartHKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-05-02] (NVIDIA Corporation)HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\Run: [f.lux] => C:\Users\Edo\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC)HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\MountPoints2: {fcf99702-2b12-11e6-81e6-bc5ff45b0521} - E:\aocsetup.exe /autorunHKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\MountPoints2: {fcf99711-2b12-11e6-81e6-bc5ff45b0521} - F:\setup.exeHKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2015-10-21] (Microsoft Corporation)ShellIconOverlayIdentifiers: [  Tortoise1Normal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise2Modified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise3Conflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise4Locked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise5ReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise6Deleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise7Added] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise8Ignored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers: [  Tortoise9Unversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise1Normal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise2Modified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise3Conflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise4Locked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise5ReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise6Deleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise7Added] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise8Ignored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)ShellIconOverlayIdentifiers-x32: [  Tortoise9Unversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2015-08-25] (hxxp://tortoisesvn.net)==================== Internet (Whitelisted) ====================(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txtTcpip\Parameters: [DhcpNameServer]\..\Interfaces\{02CCBA1B-B585-41A0-83FA-706EF7700B9A}: [DhcpNameServer] Explorer:==================BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-17] (Oracle Corporation)BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-17] (Oracle Corporation)FireFox:========FF ProfilePath: C:\Users\Edo\AppData\Roaming\Mozilla\Firefox\Profiles\5ehf03mu.defaultFF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-28] ()FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-17] (Oracle Corporation)FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-17] (Oracle Corporation)FF Plugin: @microsoft.com/GENUINE -> disabled [No File]FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-28] ()FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-03] (NVIDIA Corporation)FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-03] (NVIDIA Corporation)FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)FF Plugin HKU\S-1-5-21-3000302092-2520746345-460137575-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Edo\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)FF Plugin HKU\S-1-5-21-3000302092-2520746345-460137575-1000: @talk.google.com/O1DPlugin -> C:\Users\Edo\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)FF Plugin HKU\S-1-5-21-3000302092-2520746345-460137575-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Edo\AppData\Local\Google\Update\\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)FF Plugin HKU\S-1-5-21-3000302092-2520746345-460137575-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Edo\AppData\Local\Google\Update\\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)FF Plugin ProgramFiles/Appdata: C:\Users\Edo\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)FF Plugin ProgramFiles/Appdata: C:\Users\Edo\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)FF Extension: Web Developer - C:\Users\Edo\AppData\Roaming\Mozilla\Firefox\Profiles\5ehf03mu.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2016-04-27]FF Extension: Google Translator for Firefox - C:\Users\Edo\AppData\Roaming\Mozilla\Firefox\Profiles\5ehf03mu.default\extensions\[email protected] [2016-04-28]FF Extension: Greasemonkey - C:\Users\Edo\AppData\Roaming\Mozilla\Firefox\Profiles\5ehf03mu.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2016-04-29]FF Extension: MEGA - C:\Users\Edo\AppData\Roaming\Mozilla\Firefox\Profiles\5ehf03mu.default\Extensions\[email protected] [2016-06-14]FF Extension: uBlock Origin - C:\Users\Edo\AppData\Roaming\Mozilla\Firefox\Profiles\5ehf03mu.default\Extensions\[email protected] [2016-05-02]FF Extension: Adblock Plus - C:\Users\Edo\AppData\Roaming\Mozilla\Firefox\Profiles\5ehf03mu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-29]Chrome:=======CHR HomePage: Default -> hxxp://www.google.it/CHR StartupUrls: Default -> "hxxp://www.google.com/"CHR Profile: C:\Users\Edo\AppData\Local\Google\Chrome\User Data\DefaultCHR Extension: (Steam Community SteamRep Integration) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaclmldkenecanphogeaacolljiphmnk [2015-10-19]CHR Extension: (Presentazioni Google) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-19]CHR Extension: (Steam item search between friends.) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajlddciniccidokpjhppahkoefohkchg [2015-10-19]CHR Extension: (Documenti Google) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-19]CHR Extension: (Google Drive) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]CHR Extension: (MEGA) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2016-05-23]CHR Extension: (YouTube) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-19]CHR Extension: (Google Search) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]CHR Extension: (Fogli Google) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-19]CHR Extension: (FBDown Video Downloader) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhplmmllnpjjlncfjpbbpjadoeijkogc [2016-05-07]CHR Extension: (Stylish) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2016-05-07]CHR Extension: (Google Documenti offline) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-07]CHR Extension: (AdBlock) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-05-23]CHR Extension: (Last.fm Scrobbler) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhinaapppaileiechjoiifaancjggfjm [2016-05-07]CHR Extension: (Reddit Enhancement Suite) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2016-05-07]CHR Extension: (Window Resizer) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkelicaakdanhinjdeammmilcgefonfh [2016-05-23]CHR Extension: (Pagamenti Chrome Web Store) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-07]CHR Extension: (Gmail) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-19]CHR Extension: (Reddit Trading Flair Linker Enhanced) - C:\Users\Edo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnahghpneiabcncanmccahgloopbbbgp [2015-10-19]==================== Services (Whitelisted) ========================(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)S4 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368 2016-05-02] (NVIDIA Corporation)R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-05-02] (NVIDIA Corporation)R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-05-02] (NVIDIA Corporation)R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-05-02] (NVIDIA Corporation)S3 Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-01-22] (Electronic Arts)R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-10-29] ()S3 PSEXESVC; C:\Windows\PSEXESVC.exe [189792 2016-06-11] (Sysinternals)S2 SkypeUpdate; D:\Program Files (x86)\Skype\Updater\Updater.exe [327296 2015-07-09] (Skype Technologies)S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)===================== Drivers (Whitelisted) ==========================(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2015-10-19] (Disc Soft Ltd)S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [18528 2014-11-18] ()S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [14944 2014-11-18] ()S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] ()S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [10208 2014-11-18] ()R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-05-02] (NVIDIA Corporation)R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)S3 RTCore64; D:\Program Files (x86)\Afterburner\RTCore64.sys [13512 2015-12-09] ()S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [11968 2000-06-28] () [File not signed]R3 VBAudioVACMME; C:\Windows\System32\DRIVERS\vbaudio_cable64_win7.sys [41192 2014-09-02] (Windows ® Win 7 DDK provider)S3 HWiNFO32; \??\C:\Users\Edo\AppData\Local\Temp\HWiNFO64A.SYS [X]S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]S3 tsusbhub; system32\drivers\tsusbhub.sys [X]S3 VGPU; System32\drivers\rdvgkmd.sys [X]==================== NetSvcs (Whitelisted) ===================(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)==================== One Month Created files and folders ========(If an entry is included in the fixlist, the file/folder will be moved.)2016-06-15 22:14 - 2016-06-15 22:14 - 00000000 ____D C:\FRST2016-06-15 21:54 - 2016-06-15 21:54 - 00006172 _____ C:\Windows\system32\PerfStringBackup.TMP2016-06-15 21:50 - 2016-06-15 21:50 - 00001184 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A02016-06-15 21:50 - 2016-06-15 21:50 - 00001184 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A02016-06-15 21:48 - 2016-06-15 21:48 - 00000006 ____H C:\Windows\Tasks\SA.DAT2016-06-15 19:31 - 2016-06-15 19:31 - 00000000 ____D C:\f4a9135958f4e456d8b9d4dd422016-06-15 19:24 - 2016-06-15 19:24 - 00007679 _____ C:\Users\Edo\AppData\Local\Resmon.ResmonCfg2016-06-15 18:45 - 2016-06-15 18:46 - 00000000 ____D C:\Windows\system32\appmgmt2016-06-15 18:29 - 2016-06-15 18:35 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)2016-06-14 18:10 - 2016-06-14 18:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\devkitPro2016-06-14 18:10 - 2016-06-14 18:10 - 00000000 ____D C:\devkitPro2016-06-14 01:10 - 2016-06-14 05:48 - 00000000 ____D C:\Users\Edo\Documents\The Witcher 32016-06-12 20:41 - 2016-06-12 20:41 - 00000000 ____D C:\Users\Edo\Documents\3DSSaveBank2016-06-11 19:02 - 2015-06-07 01:13 - 00961192 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00062304 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll2016-06-11 19:02 - 2015-06-07 01:13 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00883712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00064352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll2016-06-11 19:02 - 2015-06-07 01:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll2016-06-11 13:40 - 2016-06-11 13:40 - 00001238 _____ C:\Users\Edo\Desktop\Forgotten Empires.lnk2016-06-11 03:39 - 2016-06-11 03:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AoC 1.0e Patch2016-06-11 03:34 - 2016-06-11 03:34 - 00000791 _____ C:\Users\Public\Desktop\The Conquerors.lnk2016-06-11 03:08 - 2016-06-11 03:08 - 00189792 _____ (Sysinternals) C:\Windows\PSEXESVC.exe2016-06-11 03:07 - 2014-04-28 14:44 - 00396480 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\PsExec.exe2016-06-11 03:07 - 2014-01-29 08:23 - 00227520 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\psping.exe2016-06-11 03:07 - 2012-10-17 18:28 - 00171608 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\pspasswd.exe2016-06-11 03:07 - 2012-10-01 09:23 - 00066582 _____ C:\Windows\system32\Pstools.chm2016-06-11 03:07 - 2012-06-21 23:34 - 00468592 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\pskill.exe2016-06-11 03:07 - 2012-03-22 15:53 - 00232232 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\pslist.exe2016-06-11 03:07 - 2010-04-27 11:04 - 00390520 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\PsInfo.exe2016-06-11 03:07 - 2010-04-27 11:04 - 00333176 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\PsGetsid.exe2016-06-11 03:07 - 2010-04-27 11:04 - 00183160 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\PsLoggedon.exe2016-06-11 03:07 - 2010-04-27 11:04 - 00178040 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\psloglist.exe2016-06-11 03:07 - 2010-04-27 11:04 - 00169848 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\PsService.exe2016-06-11 03:07 - 2007-11-06 09:17 - 00000039 _____ C:\Windows\system32\psversion.txt2016-06-11 03:07 - 2006-12-04 17:53 - 00207664 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\psshutdown.exe2016-06-11 03:07 - 2006-12-04 17:53 - 00187184 _____ (Sysinternals) C:\Windows\system32\pssuspend.exe2016-06-11 03:07 - 2006-12-04 17:53 - 00105264 _____ (Sysinternals) C:\Windows\system32\psfile.exe2016-06-11 03:07 - 2006-07-28 09:32 - 00007005 _____ C:\Windows\system32\Eula.txt2016-06-11 02:58 - 2016-06-11 03:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games2016-06-11 02:58 - 2016-06-11 02:58 - 00000886 _____ C:\Users\Public\Desktop\Age of Empires II.lnk2016-06-11 02:01 - 2016-06-11 02:01 - 00000000 ____D C:\Program Files (x86)\VulkanRT2016-06-11 02:01 - 2016-06-03 09:38 - 39979576 _____ C:\Windows\system32\nvcompiler.dll2016-06-11 02:01 - 2016-06-03 09:38 - 35115456 _____ C:\Windows\SysWOW64\nvcompiler.dll2016-06-11 02:01 - 2016-06-03 09:38 - 25377848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll2016-06-11 02:01 - 2016-06-03 09:38 - 21802280 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll2016-06-11 02:01 - 2016-06-03 09:38 - 21346712 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll2016-06-11 02:01 - 2016-06-03 09:38 - 18143912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll2016-06-11 02:01 - 2016-06-03 09:38 - 17738592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll2016-06-11 02:01 - 2016-06-03 09:38 - 17290416 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll2016-06-11 02:01 - 2016-06-03 09:38 - 13460536 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys2016-06-11 02:01 - 2016-06-03 09:38 - 10643240 _____ C:\Windows\system32\nvptxJitCompiler.dll2016-06-11 02:01 - 2016-06-03 09:38 - 08733608 _____ C:\Windows\SysWOW64\nvptxJitCompiler.dll2016-06-11 02:01 - 2016-06-03 09:38 - 03512888 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll2016-06-11 02:01 - 2016-06-03 09:38 - 03065280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll2016-06-11 02:01 - 2016-06-03 09:38 - 01922616 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436839.dll2016-06-11 02:01 - 2016-06-03 09:38 - 01571776 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436839.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00985144 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00908736 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00769984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00707520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00669952 _____ C:\Windows\system32\nvfatbinaryLoader.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00565392 _____ C:\Windows\SysWOW64\nvfatbinaryLoader.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00476664 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00425016 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00422752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00394912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00379448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00178136 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00155768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00153416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll2016-06-11 02:01 - 2016-06-03 09:38 - 00131768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll2016-06-11 02:01 - 2016-06-03 05:19 - 00113208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe2016-06-11 02:01 - 2016-05-04 04:23 - 00129824 _____ C:\Windows\SysWOW64\vulkan-1.dll2016-06-11 02:01 - 2016-05-04 04:22 - 00130848 _____ C:\Windows\system32\vulkan-1.dll2016-06-11 02:01 - 2016-05-04 04:22 - 00045344 _____ C:\Windows\system32\vulkaninfo.exe2016-06-11 02:01 - 2016-05-04 04:22 - 00040224 _____ C:\Windows\SysWOW64\vulkaninfo.exe2016-06-11 01:31 - 2016-06-11 01:31 - 00000000 ____D C:\ProgramData\Steam2016-06-06 22:52 - 2016-06-07 00:03 - 00000000 ____D C:\Users\Edo\AppData\Roaming\discord2016-06-06 22:52 - 2016-06-06 22:52 - 00002147 _____ C:\Users\Edo\Desktop\Discord.lnk2016-06-06 22:52 - 2016-06-06 22:52 - 00000000 ____D C:\Users\Edo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc2016-06-06 22:52 - 2016-06-06 22:52 - 00000000 ____D C:\Users\Edo\AppData\Local\SquirrelTemp2016-06-06 22:52 - 2016-06-06 22:52 - 00000000 ____D C:\Users\Edo\AppData\Local\Discord2016-06-05 21:28 - 2016-06-05 21:28 - 00000871 _____ C:\Users\Edo\Desktop\Warcraft III.lnk2016-06-05 19:46 - 2016-06-05 19:46 - 00000000 ____D C:\Users\Edo\AppData\Local\CrashRpt2016-06-05 14:38 - 2016-06-05 14:51 - 00077393 _____ C:\Windows\War3Unin.dat2016-06-05 14:38 - 2016-06-05 14:41 - 00139264 _____ (Blizzard Entertainment) C:\Windows\War3Unin.exe2016-06-05 14:38 - 2016-06-05 14:41 - 00002829 _____ C:\Windows\War3Unin.pif2016-06-05 14:38 - 2016-06-05 14:41 - 00000000 ____D C:\Users\Edo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warcraft III2016-06-05 14:17 - 2016-06-11 13:39 - 00000000 ____D C:\Users\Edo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games2016-06-05 14:00 - 2016-06-05 14:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III2016-06-04 16:12 - 2016-06-04 16:12 - 00001215 _____ C:\Users\Edo\Desktop\Audacity.lnk2016-06-04 03:36 - 2016-06-04 03:36 - 00000926 _____ C:\Users\Edo\Desktop\Pokemon - Blue Kaizo Version.lnk2016-05-31 02:19 - 2016-05-31 02:19 - 00001289 _____ C:\Users\Public\Desktop\YTD Video Downloader.lnk2016-05-31 02:19 - 2016-05-31 02:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader2016-05-30 18:43 - 2016-05-30 18:44 - 00000000 ____D C:\Users\Edo\AppData\Roaming\NVIDIA2016-05-27 17:23 - 2016-05-27 17:23 - 00001269 _____ C:\Users\Edo\Desktop\MM Server Picker.lnk2016-05-27 17:22 - 2016-05-27 17:22 - 00000757 _____ C:\Users\Edo\Desktop\chetos.lnk2016-05-27 17:20 - 2016-05-27 17:20 - 00001197 _____ C:\Users\Edo\Desktop\Vibrance GUI.lnk2016-05-27 17:14 - 2016-06-15 21:48 - 00000000 ____D C:\ProgramData\NVIDIA2016-05-27 17:14 - 2016-06-03 05:26 - 06362560 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll2016-05-27 17:14 - 2016-06-03 05:26 - 02453952 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll2016-05-27 17:14 - 2016-06-03 05:26 - 01764408 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll2016-05-27 17:14 - 2016-06-03 05:26 - 01351104 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe2016-05-27 17:14 - 2016-06-03 05:26 - 00534072 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll2016-05-27 17:14 - 2016-06-03 05:26 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll2016-05-27 17:14 - 2016-06-03 05:26 - 00081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll2016-05-27 17:14 - 2016-06-03 05:26 - 00071224 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll2016-05-27 17:14 - 2016-06-02 14:19 - 06452948 _____ C:\Windows\system32\nvcoproc.bin2016-05-27 17:14 - 2016-05-20 09:01 - 00213952 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll2016-05-27 17:14 - 2016-05-20 09:01 - 00201664 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll2016-05-27 17:13 - 2016-06-03 09:38 - 31603768 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll2016-05-27 17:13 - 2016-06-03 09:38 - 19180152 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll2016-05-27 17:13 - 2016-06-03 09:38 - 16756888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll2016-05-27 17:13 - 2016-06-03 09:38 - 14346320 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll2016-05-27 17:13 - 2016-06-03 09:38 - 03825896 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll2016-05-27 17:13 - 2016-06-03 09:38 - 03383472 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll2016-05-27 17:13 - 2016-06-03 09:38 - 00039124 _____ C:\Windows\system32\nvinfo.pb2016-05-27 17:13 - 2016-05-20 09:01 - 01922496 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436822.dll2016-05-27 17:13 - 2016-05-20 09:01 - 01573432 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436822.dll2016-05-27 17:13 - 2016-05-20 09:01 - 00000594 _____ C:\Windows\SysWOW64\nv-vk32.json2016-05-27 17:13 - 2016-05-20 09:01 - 00000594 _____ C:\Windows\system32\nv-vk64.json2016-05-27 17:02 - 2016-04-14 07:38 - 00113216 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll2016-05-27 17:02 - 2016-04-14 07:38 - 00102976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll2016-05-27 17:02 - 2016-04-14 07:38 - 00056384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys2016-05-17 09:07 - 2016-05-17 09:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XAMPP2016-05-17 09:06 - 2016-05-17 09:28 - 00000000 ____D C:\xampp2016-05-17 08:10 - 2016-05-17 08:10 - 00123652 ____H C:\Windows\system32\mlfcache.dat2016-05-17 06:40 - 2016-05-17 06:40 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\MinGW Installation Manager.lnk2016-05-17 06:39 - 2016-05-17 06:45 - 00000000 ____D C:\MinGW2016-05-17 06:15 - 2016-05-20 09:43 - 00000000 ____D C:\Users\Edo\AppData\Local\Eclipse2016-05-17 06:14 - 2016-05-17 06:14 - 00110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll2016-05-17 06:14 - 2016-05-17 06:14 - 00000000 ____D C:\Program Files\Java2016-05-17 06:11 - 2016-05-20 09:43 - 00000000 ____D C:\Users\Edo\.p22016-05-17 06:11 - 2016-05-20 09:43 - 00000000 ____D C:\Program Files\eclipse2016-05-17 06:11 - 2016-05-17 08:25 - 00000949 _____ C:\Users\Edo\Desktop\Eclipse.lnk2016-05-17 06:11 - 2016-05-17 06:15 - 00000000 ____D C:\Users\Edo\.eclipse==================== One Month Modified files and folders ========(If an entry is included in the fixlist, the file/folder will be moved.)2016-06-15 21:56 - 2015-10-19 16:28 - 00000000 ____D C:\Users\Edo\AppData\Roaming\TS3Client2016-06-15 21:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf2016-06-15 21:49 - 2015-10-19 16:22 - 00000000 ____D C:\Program Files (x86)\Steam2016-06-15 21:48 - 2015-11-14 05:46 - 00000000 ____D C:\Users\Edo\AppData\Local\TSVNCache2016-06-15 21:48 - 2009-07-14 07:08 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT2016-06-15 19:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Resources2016-06-15 19:00 - 2015-10-19 16:05 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys2016-06-15 18:58 - 2015-10-19 15:20 - 00000000 ____D C:\Users\Edo2016-06-15 18:55 - 2015-10-19 16:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware2016-06-15 18:55 - 2015-10-19 16:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware2016-06-15 18:48 - 2015-10-19 16:19 - 00000000 ____D C:\ProgramData\Package Cache2016-06-15 18:46 - 2016-01-17 22:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live2016-06-15 18:45 - 2015-10-19 15:37 - 00000000 ____D C:\Users\Edo\AppData\Local\Deployment2016-06-15 18:43 - 2015-10-19 19:30 - 00000000 ____D C:\Program Files\Common Files\Adobe2016-06-15 18:43 - 2015-10-19 19:30 - 00000000 ____D C:\Program Files\Adobe2016-06-15 18:43 - 2015-10-19 18:33 - 00000000 ____D C:\Users\Edo\AppData\Roaming\Adobe2016-06-15 18:42 - 2015-12-04 14:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis2016-06-15 02:00 - 2015-10-19 18:33 - 00000000 ____D C:\Users\Edo\AppData\Local\Adobe2016-06-15 01:21 - 2015-10-19 16:17 - 00000000 ____D C:\Users\Edo\AppData\Roaming\vlc2016-06-15 00:46 - 2016-04-11 18:20 - 00000000 ____D C:\Users\Edo\AppData\Local\CrashDumps2016-06-14 00:39 - 2015-10-19 16:55 - 00000000 ____D C:\Users\Edo\AppData\Roaming\uTorrent2016-06-11 13:38 - 2015-11-02 11:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service2016-06-11 13:38 - 2009-07-14 06:45 - 05009320 _____ C:\Windows\system32\FNTCACHE.DAT2016-06-11 03:52 - 2016-05-07 23:12 - 00000000 ____D C:\Users\Edo\AppData\Local\Battle.net2016-06-11 03:02 - 2015-10-19 15:37 - 00089560 _____ C:\Users\Edo\AppData\Local\GDIPFONTCACHEV1.DAT2016-06-11 02:02 - 2015-10-19 15:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation2016-06-11 02:02 - 2015-10-19 15:40 - 00000000 ____D C:\ProgramData\NVIDIA Corporation2016-06-11 01:31 - 2015-10-19 15:49 - 00000000 ____D C:\Windows\SysWOW64\directx2016-06-10 22:53 - 2016-05-07 05:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox2016-06-10 19:36 - 2015-10-19 17:13 - 00000000 ____D C:\Users\Edo\AppData\Roaming\obs-studio2016-06-10 17:49 - 2016-05-07 23:11 - 00000000 ____D C:\Program Files (x86)\Battle.net2016-06-09 02:59 - 2015-10-19 15:38 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk2016-06-08 23:08 - 2016-02-21 19:18 - 00000000 ____D C:\Users\Edo\AppData\Roaming\Skype2016-06-07 07:51 - 2015-10-24 11:08 - 00003394 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily2016-06-07 07:51 - 2015-10-24 11:08 - 00003268 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine2016-06-07 07:51 - 2015-10-24 11:08 - 00000000 ____D C:\Program Files (x86)\Gyazo2016-06-05 19:47 - 2015-10-29 18:44 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.xtr2016-06-05 19:47 - 2015-10-29 18:44 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.exe2016-06-05 19:46 - 2015-10-29 18:44 - 00281768 _____ C:\Windows\SysWOW64\PnkBstrB.ex02016-06-05 13:58 - 2015-10-19 17:02 - 00000000 ____D C:\Users\Edo\AppData\Roaming\DAEMON Tools Lite2016-06-05 06:07 - 2015-10-20 21:39 - 00000000 ____D C:\Users\Edo\AppData\Roaming\Audacity2016-06-05 03:46 - 2015-10-20 01:52 - 00000000 ____D C:\Users\Edo\Documents\OFX Presets2016-05-31 02:19 - 2015-10-19 17:39 - 00000000 ____D C:\ProgramData\YTD Video Downloader2016-05-30 17:48 - 2015-10-19 15:44 - 00000000 ____D C:\Users\Edo\AppData\Local\NVIDIA Corporation2016-05-28 10:59 - 2015-11-02 16:19 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe2016-05-28 10:59 - 2015-11-02 16:19 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl2016-05-27 17:14 - 2015-10-19 15:40 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation2016-05-27 17:14 - 2015-10-19 15:38 - 00000000 ____D C:\Program Files\NVIDIA Corporation2016-05-27 17:14 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help2016-05-27 17:03 - 2015-10-19 15:44 - 00000000 ____D C:\Users\Edo\AppData\Local\NVIDIA2016-05-27 14:41 - 2015-10-22 21:20 - 00000000 ____D C:\Users\Edo\AppData\Roaming\HandBrake2016-05-26 23:00 - 2016-05-08 11:10 - 00000000 ____D C:\Users\Edo\Documents\Overwatch2016-05-17 06:14 - 2015-11-02 11:14 - 00000000 ____D C:\Users\Edo\.oracle_jre_usage2016-05-17 06:14 - 2015-11-02 11:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java==================== Files in the root of some directories =======2016-03-10 00:58 - 2016-03-10 00:59 - 0001456 _____ () C:\Users\Edo\AppData\Local\Adobe Save for Web 13.0 Prefs2016-06-15 19:24 - 2016-06-15 19:24 - 0007679 _____ () C:\Users\Edo\AppData\Local\Resmon.ResmonCfg2015-10-19 16:52 - 2015-10-19 16:52 - 0000000 ____H () C:\ProgramData\DP45977C.lflSome files in TEMP:====================C:\Users\Edo\AppData\Local\Temp\130972278783419649.exeC:\Users\Edo\AppData\Local\Temp\CmdLineExt02.dllC:\Users\Edo\AppData\Local\Temp\EBU2BFD.exeC:\Users\Edo\AppData\Local\Temp\EBU2C5B.DLLC:\Users\Edo\AppData\Local\Temp\handbrake-setup.exeC:\Users\Edo\AppData\Local\Temp\nvSCPAPI.dllC:\Users\Edo\AppData\Local\Temp\nvStInst.exeC:\Users\Edo\AppData\Local\Temp\procexp64.exeC:\Users\Edo\AppData\Local\Temp\proxy_vole8182631914574726674.dllC:\Users\Edo\AppData\Local\Temp\SIntf16.dllC:\Users\Edo\AppData\Local\Temp\SIntf32.dllC:\Users\Edo\AppData\Local\Temp\SIntfNT.dllC:\Users\Edo\AppData\Local\Temp\utils.dllC:\Users\Edo\AppData\Local\Temp\vsredistsetup.exeC:\Users\Edo\AppData\Local\Temp\war3_Install.exe==================== Bamital & volsnap =================(There is no automatic fix for files that do not pass verification.)C:\Windows\system32\winlogon.exe => File is digitally signedC:\Windows\system32\wininit.exe => File is digitally signedC:\Windows\SysWOW64\wininit.exe => File is digitally signedC:\Windows\explorer.exe => File is digitally signedC:\Windows\SysWOW64\explorer.exe => File is digitally signedC:\Windows\system32\svchost.exe => File is digitally signedC:\Windows\SysWOW64\svchost.exe => File is digitally signedC:\Windows\system32\services.exe => File is digitally signedC:\Windows\system32\User32.dll => File is digitally signedC:\Windows\SysWOW64\User32.dll => File is digitally signedC:\Windows\system32\userinit.exe => File is digitally signedC:\Windows\SysWOW64\userinit.exe => File is digitally signedC:\Windows\system32\rpcss.dll => File is digitally signedC:\Windows\system32\dnsapi.dll => File is digitally signedC:\Windows\SysWOW64\dnsapi.dll => File is digitally signedC:\Windows\system32\Drivers\volsnap.sys => File is digitally signedLastRegBack: 2016-06-07 01:54==================== End of FRST.txt ============================Additional scan result of Farbar Recovery Scan Tool (x64) Version:15-06-2016Ran by Edo (2016-06-15 22:15:09)Running from D:\Tutto\DownloadWindows 7 Ultimate Service Pack 1 (X64) (2015-10-19 13:20:22)Boot Mode: Normal============================================================================== Accounts: =============================Administrator (S-1-5-21-3000302092-2520746345-460137575-500 - Administrator - Disabled)Edo (S-1-5-21-3000302092-2520746345-460137575-1000 - Administrator - Enabled) => C:\Users\EdoGuest (S-1-5-21-3000302092-2520746345-460137575-501 - Limited - Disabled)HomeGroupUser$ (S-1-5-21-3000302092-2520746345-460137575-1002 - Limited - Enabled)==================== Security Center ========================(If an entry is included in the fixlist, it will be removed.)AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}==================== Installed Programs ======================(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)µTorrent (HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\uTorrent) (Version: - BitTorrent Inc.)7-Zip 15.09 beta (x64) (HKLM\...\7-Zip) (Version: 15.09 - Igor Pavlov)Adobe Audition CC 2015 (HKLM-x32\...\{839A3566-AED6-4787-A849-5CBE2B1DC6AE}) (Version: 8.0 - Adobe Systems Incorporated)Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.0 - Adobe Systems Incorporated)Adobe Update Management Tool (HKLM-x32\...\{534A7A1A-7102-4AF6-23EA-7CD279C7B625}_is1) (Version: 7.1 - PainteR)Age of Empires II - The Conquerors - 1.0e Patch FINAL (HKLM-x32\...\Age of Empires II - The Conquerors - 1.0e Patch FINAL_is1) (Version: 1.0e - tOrMeNtIuM/m0d)Aggiornamenti NVIDIA (Version: - NVIDIA Corporation) HiddenAsmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: - Asmedia Technology)AutoHotkey (HKLM\...\AutoHotkey) (Version: - Lexikos)Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)bl (x32 Version: 1.0.0 - Your Company Name) HiddenBroadcom NetLink Controller (HKLM\...\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: - Broadcom Corporation)Call of Duty: Black Ops III (HKLM-x32\...\Steam App 311210) (Version: - Treyarch)CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) HiddenCCleaner (HKLM\...\CCleaner) (Version: 5.10 - Piriform)Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine)Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: - Disc Soft Ltd)devkitProUpdater 1.6.0 (HKLM-x32\...\devkitProUpdater) (Version: 1.6.0 - devkitPro)Discord (HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\Discord) (Version: 0.0.291 - Hammer & Chisel, Inc.)Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)EaseUS Partition Master 10.8 (HKLM-x32\...\EaseUS Partition Master_is1) (Version: - EaseUS)Epic Games Launcher (HKLM-x32\...\{4620A9CA-A0D7-4F15-BA89-4545B5372345}) (Version: - Epic Games, Inc.)Epic Games Launcher Prerequisites (x64) (Version: - Epic Games, Inc.) HiddenerLT (x32 Version: - Logitech, Inc.) Hiddenf.lux (HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\Flux) (Version: - )File Shredder 2.5 (HKLM\...\File Shredder_is1) (Version: - Pow Tools)Gameforge Live 2.0.10 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.10 - Gameforge)GameRanger (HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\GameRanger) (Version: - GameRanger Technologies)Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios)Git version 2.8.1 (HKLM\...\Git_is1) (Version: 2.8.1 - The Git Development Community)Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.84 - Google Inc.)Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: - Google)Google Update Helper (x32 Version: - Google Inc.) HiddenGrim Fandango Remastered (HKLM-x32\...\1207667183_is1) (Version: - GOG.com)Gyazo 3.2.2 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)HandBrake 0.10.5 (HKLM-x32\...\HandBrake) (Version: 0.10.5 - )Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.14 - Oracle Corporation)Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - )LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )Launcher Prerequisites (x64) (x32 Version: - Epic Games, Inc.) HiddenMalwarebytes Anti-Malware versione (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes)Microsoft .NET Framework 4.6 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.00081 - Microsoft Corporation)Microsoft .NET Framework 4.6 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.6.00081 - Microsoft Corporation)Microsoft Age of Empires II (HKLM-x32\...\Age of Empires 2.0) (Version: - )Microsoft Age of Empires II: The Conquerors Expansion (HKLM-x32\...\Age of Empires II: The Conquerors Expansion 1.0) (Version: - )Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)Mozilla Firefox 47.0 (x86 it) (HKLM-x32\...\Mozilla Firefox 47.0 (x86 it)) (Version: 47.0 - Mozilla)Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: - Mozilla)MSI Afterburner 4.2.0 (HKLM-x32\...\Afterburner) (Version: 4.2.0 - MSI Co., LTD)NVIDIA Driver 3D Vision 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.39 - NVIDIA Corporation)NVIDIA Driver grafico 368.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation)NVIDIA GeForce Experience (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: - NVIDIA Corporation)NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)Origin (HKLM-x32\...\Origin) (Version: - Electronic Arts, Inc.)Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)Pannello di controllo NVIDIA 368.39 (Version: 368.39 - NVIDIA Corporation) Hiddenph (x32 Version: 1.0.0 - Your Company Name) HiddenPokemon Online versione (HKLM-x32\...\{3D3DE059-3951-47BE-BD7C-664898D14138}_is1) (Version: - Pokemon Online)Popcorn-Time (HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\Popcorn-Time) (Version: 0.3.9 - Popcorn Time)Python 2.7.11 (64-bit) (HKLM\...\{16E52445-1392-469F-9ADB-FC03AF00CD62}) (Version: 2.7.11150 - Python Software Foundation)Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)RivaTuner Statistics Server 6.4.1 (HKLM-x32\...\RTSS) (Version: 6.4.1 - Unwinder)Scrap Mechanic (HKLM-x32\...\Steam App 387990) (Version: - Axolot Games)SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) HiddenSHIELD Wireless Controller Driver (Version: - NVIDIA Corporation) HiddenSkype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)Software della webcam Logitech (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)Tastiera italiana estesa (1.2) (HKLM\...\{0B02661F-0C23-4182-9FD7-09EDC02A8AB0}) (Version: - tastiera-estesa.it)TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)TortoiseSVN (64 bit) (HKLM\...\{8A5AA5D6-F797-4ED3-AE08-35EF5433409E}) (Version: 1.9.26806 - TortoiseSVN)VBCABLE, The Virtual Audio Cable (HKLM\...\VB:VBCABLE {87459874-1236-4469}) (Version: - VB-Audio Software)Vegas Pro 13.0 (64-bit) (HKLM\...\{1EEE0BEE-0BC8-11E5-A19E-F04DA23A5C58}) (Version: 13.0.453 - Sony)VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)Vulkan Run Time Libraries (HKLM\...\VulkanRT1.0.11.1) (Version: - LunarG, Inc.)Warcraft III (HKLM-x32\...\Warcraft III) (Version: - )Warcraft III: All Products (HKU\S-1-5-21-3000302092-2520746345-460137575-1000\...\Warcraft III) (Version: - )Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/28/2014 11.0.0000.00000) (HKLM\...\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)XAMPP (HKLM-x32\...\xampp) (Version: 5.6.21-0 - Bitnami)YTD Video Downloader 5.6 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 5.6 - GreenTree Applications SRL) <==== ATTENTION==================== Custom CLSID (Whitelisted): ==========================(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)CustomCLSID: HKU\S-1-5-21-3000302092-2520746345-460137575-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Edo\AppData\Local\Google\Update\\psuser_64.dll (Google Inc.)CustomCLSID: HKU\S-1-5-21-3000302092-2520746345-460137575-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Edo\AppData\Local\Google\Update\\psuser_64.dll => No FileCustomCLSID: HKU\S-1-5-21-3000302092-2520746345-460137575-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Edo\AppData\Local\Google\Update\\psuser_64.dll (Google Inc.)==================== Scheduled Tasks (Whitelisted) =============(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)Task: {3377629B-F584-4F47-ADD9-EC6FBC6E857F} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-06-02] ()Task: {4348C2DB-642F-472E-BDE5-10B7C61FF3CD} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-06-02] ()Task: {A78B98F1-99BB-49F7-8CB4-948A6574BECE} - System32\Tasks\AdobeAAMUpdater-1.0-HAF-X-Edo => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-04-28] (Adobe Systems Incorporated)Task: {FC49CB74-2C26-4281-8595-AA7875DA15A8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-09-16] (Piriform Ltd)(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)==================== Shortcuts =============================(The entries could be listed to be restored or removed.)==================== Loaded Modules (Whitelisted) ==============2016-05-27 17:14 - 2016-06-03 05:26 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll2015-09-22 21:32 - 2015-09-22 21:32 - 00093568 _____ () C:\Program Files\TortoiseSVN\bin\libsasl.dll2016-04-03 15:10 - 2016-05-02 07:54 - 00369208 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll2016-04-03 15:10 - 2016-05-02 07:54 - 01148984 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll2016-04-03 15:10 - 2016-05-02 07:55 - 03613240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll2016-03-02 12:06 - 2016-05-02 07:55 - 00289848 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll2015-10-29 18:43 - 2015-10-29 18:43 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe2016-04-03 15:10 - 2016-05-02 07:55 - 01990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll2016-04-03 15:10 - 2016-05-02 07:55 - 02667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll2016-04-03 15:10 - 2016-05-02 07:55 - 01842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll2016-03-02 12:06 - 2016-05-02 07:55 - 00208952 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll2016-04-03 15:10 - 2016-05-02 07:54 - 00035896 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll2016-04-03 15:10 - 2016-05-02 07:54 - 00921656 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll2015-10-22 13:22 - 2016-04-27 15:25 - 00174872 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll2015-10-22 13:21 - 2016-04-27 15:25 - 00103192 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll2015-10-22 13:21 - 2016-04-27 15:25 - 00107800 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll2015-10-22 13:22 - 2016-04-27 15:25 - 00312088 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll2016-01-09 07:52 - 2016-01-09 07:52 - 00486912 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\soundboard.dll2015-04-16 16:15 - 2015-04-16 16:15 - 00143891 _____ () C:\Program Files\VideoLAN\VLC\libvlc.dll2015-04-16 16:16 - 2015-04-16 16:16 - 02750483 _____ () C:\Program Files\VideoLAN\VLC\libvlccore.dll2015-04-16 16:15 - 2015-04-16 16:15 - 00618515 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libdshow_plugin.dll2015-04-16 16:15 - 2015-04-16 16:15 - 00079379 _____ () C:\Program Files\VideoLAN\VLC\libgcc_s_seh-1.dll2015-04-16 16:16 - 2015-04-16 16:16 - 00038419 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll2015-04-16 16:16 - 2015-04-16 16:16 - 00035347 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll2015-04-16 16:16 - 2015-04-16 16:16 - 00083987 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll2015-04-16 16:16 - 2015-04-16 16:16 - 00075795 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll2015-10-22 13:22 - 2016-04-27 15:25 - 00485656 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll2015-05-26 12:51 - 2015-05-26 12:51 - 03499008 _____ () C:\Program Files\Adobe\Adobe Audition CC 2015\DNxHDCodec.dll2015-10-19 15:40 - 2016-05-02 08:02 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll2015-10-19 16:23 - 2016-04-29 22:10 - 00785920 _____ () C:\Program Files (x86)\Steam\SDL2.dll2015-10-19 16:23 - 2015-07-03 18:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll2015-10-19 16:23 - 2015-07-03 18:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll2015-10-19 16:23 - 2015-07-03 18:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll2015-10-19 16:23 - 2016-06-15 02:47 - 02387024 _____ () C:\Program Files (x86)\Steam\video.dll2015-10-19 16:23 - 2016-02-09 01:14 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll2015-10-19 16:23 - 2016-02-09 01:14 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll2015-10-19 16:23 - 2016-02-09 01:14 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll2015-10-19 16:23 - 2016-02-09 01:14 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll2015-10-19 16:23 - 2016-02-09 01:14 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll2015-10-19 16:23 - 2016-06-15 02:47 - 00829008 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL2016-03-09 01:12 - 2016-02-18 00:25 - 00281088 _____ () C:\Program Files (x86)\Steam\openvr_api.dll2015-10-19 16:23 - 2016-06-14 21:14 - 49826080 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll2016-04-17 19:49 - 2010-01-14 23:35 - 00093696 _____ () D:\Tutto\Giochi\ReactMW2\miles\mssmp3.asi2016-04-17 19:49 - 2015-02-27 03:59 - 00038400 _____ () D:\Tutto\Giochi\ReactMW2\miles\mssogg.asi2016-04-17 19:49 - 2010-01-14 23:35 - 00153088 _____ () D:\Tutto\Giochi\ReactMW2\miles\mssvoice.asi2016-04-17 19:49 - 2010-01-14 23:35 - 00114688 _____ () D:\Tutto\Giochi\ReactMW2\miles\milesEq.flt2016-04-17 19:49 - 2010-01-14 23:34 - 00012288 _____ () D:\Tutto\Giochi\ReactMW2\miles\mssds3d.flt2016-04-17 19:49 - 2010-01-14 23:35 - 00058368 _____ () D:\Tutto\Giochi\ReactMW2\miles\msseax.flt2015-09-22 20:52 - 2015-09-22 20:52 - 00073088 _____ () C:\Program Files\TortoiseSVN\bin\libsasl32.dll==================== Alternate Data Streams (Whitelisted) =========(If an entry is included in the fixlist, only the ADS will be removed.)AlternateDataStreams: C:\Windows\Temp:$DATA [16]==================== Safe Mode (Whitelisted) ===================(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)==================== Association (Whitelisted) ===============(If an entry is included in the fixlist, the registry item will be restored to default or r

A: Infected with a miner (question mark?)

Greetings d0dUxDJ and to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.If you would allow me to call you by your first name I would prefer to do that.===================================================Ground Rules:First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.When you post your reply, use the button instead.In the upper right hand corner of the topic you will see the button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.I would like to remind you to make no further changes to your computer unless I direct you to do so.===================================================Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.Thank you for your patience thus far.Unfortunately there is evidence of illegal software on your computer. I am going to request you completely uninstall all Adobe products and all other products for which you do not have a valid Product Key. If you are willing to do that please right click on FRST rename it to FRST64english. Check Addition.txt and scan your computer again, posting both logs. If you prefer to leave the program(s) on your computer let me know that and I will be closing the Topic.If you desire to continue please do this also.===================================================CKScanner--------------------Download CKScanner and save it to your DesktopDouble click CKScannerSelect Search For FilesOnce completed select Save List to FileA ckfiles.txt document will be placed on your DesktopCopy and paste the results of that report in your reply===================================================Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. FRST logs (2)ckfiles.txt

