This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New(used) laptop [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A friend gave me his laptop, and tried to remove viruses he thought there. I ran malwarebytes and found another 63 items which I quarantined. Had McAfee which had expired so I just removed it.

I just want to make sure it is clear before using.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-07-10 22:34:57
—————————–
22:34:57.391    OS Version: Windows x64 6.1.7601 Service Pack 1
22:34:57.391    Number of processors: 2 586 0x200
22:34:57.391    ComputerName: SHERRY-PC  UserName: sherry
22:35:01.400    Initialize success
22:35:01.525    VM: initialized successfully
22:35:01.541    VM: Amd CPU supported 
22:38:42.922    AVAST engine defs: 15071001
22:41:42.676    The log file has been saved successfully to "C:\Users\sherry\Desktop\aswMBR.txt"
 
I tried running the next tool(Farbar Recovery Scan Tool) but it is evidently not available? Did a screencap of the response
 
 
 
Hello,

Welcome to WTT.

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right-click FRST then click "Run as administrator" (XP users: click run after receipt of Windows Security Warning - Open File).
  • When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • When finished, it will produce a log called FRST.txt in the same directory the tool was run from.
  • Please copy and paste the log in your next reply.
Note 2: The first time the tool is run it generates another log (Addition.txt - also located in the same directory the tool was run from). Please also paste that, along with the FRST.txt into your next reply.
Additional scan result of Farbar Recovery Scan Tool (x64) Version:11-07-2015
Ran by [removed] at 2015-07-11 13:10:53
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2741091298-547696876-3035258377-500 - Administrator - Disabled)
ASPNET (S-1-5-21-2741091298-547696876-3035258377-1004 - Limited - Enabled)
Guest (S-1-5-21-2741091298-547696876-3035258377-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2741091298-547696876-3035258377-1002 - Limited - Enabled)
sherry (S-1-5-21-2741091298-547696876-3035258377-1000 - Administrator - Enabled) => C:\Users\sherry
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Acer Backup Manager (HKLM-x32\…\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.99 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\…\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3504 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.04.3504 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.1.0517.2011 - Acer Incorporated)
Acer Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Acer Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 2.7.1.19610 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX 64-bit (HKLM\…\Adobe Flash Player ActiveX) (Version: 11.0.1.152 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\…\{3605D89A-BD66-F5C5-779B-BE9110B41077}) (Version: 3.0.829.0 - ATI Technologies, Inc.)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 10.2.2218 - AVAST Software)
Backup Manager V3 (x32 Version: 3.0.0.99 - NTI Corporation) Hidden
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Build-a-lot 4 - Power Source (x32 Version: 2.2.0.97 - WildTangent) Hidden
Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
clear.fi (HKLM-x32\…\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 1.0.2024.00 - CyberLink Corp.)
clear.fi (x32 Version: 1.0.1517_36458 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 1.0.2024.00 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 9.0.8026 - CyberLink Corp.) Hidden
clear.fi Client (HKLM-x32\…\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.00.3500 - Acer Incorporated)
Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.54.1.55 - Conexant)
Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
ETDWare PS/2-X64 8.0.6.3_WHQL (HKLM\…\Elantech) (Version: 8.0.6.3 - ELAN Microelectronic Corp.)
Evernote v. 4.5.1 (HKLM-x32\…\{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}) (Version: 4.5.1.5451 - Evernote Corp.)
FATE: The Cursed King (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.132 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\…\LManager) (Version: 5.1.7 - Acer Inc.)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 1.1 (HKLM-x32\…\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Web Publishing Wizard 1.52 (HKLM-x32\…\WebPost) (Version:  - )
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
newsXpresso (HKLM-x32\…\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.)
newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden
Norton Online Backup (HKLM-x32\…\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\…\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9002 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9002 - NTI Corporation) Hidden
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30122 - Realtek Semiconductor Corp.)
Skype™ 5.5 (HKLM-x32\…\{AA59DDE4-B672-4621-A016-4C248204957A}) (Version: 5.5.117 - Skype Technologies S.A.)
Torchlight (x32 Version: 2.2.0.97 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Virtual Villagers 5 - New Believers (x32 Version: 2.2.0.97 - WildTangent) Hidden
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3504 - Acer Incorporated)
WildTangent Games App (Acer Games) (x32 Version: 4.0.5.14 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
11-07-2015 12:14:35 Installed Microsoft .NET Framework 1.1
11-07-2015 12:18:45 Installed The Print Shop 22
11-07-2015 12:47:12 Removed The Print Shop 22
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {4F573A44-74E2-4964-915F-831B783A0B15} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2011-08-09] (Acer)
Task: {6F4558EB-9D65-441C-AEA1-FCF5E0F93AF4} - System32\Tasks\clear.fiAgent => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe [2011-08-24] (CyberLink Corp.)
Task: {774C60B9-8BFC-4899-84D5-EA9A36A873FC} - System32\Tasks\clear.fi => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe [2011-08-24] (Acer Incorporated)
Task: {8B8878A3-31D7-4701-9701-CDFD1E89412D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-10] (Google Inc.)
Task: {A57A14BA-A995-4BEA-A85C-1932007CD8B3} - System32\Tasks\DMREngine => C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe [2011-08-24] (CyberLink)
Task: {E58CBEF8-DDF5-47BA-A6F6-C077A66B5F61} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-07-10] (Avast Software s.r.o.)
Task: {EC675B88-8143-49C4-8126-A02547334ECE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-10] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-07-10 22:54 - 2015-07-10 22:54 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-07-10 22:54 - 2015-07-10 22:54 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-07-11 10:47 - 2015-07-11 10:47 - 02956288 _____ () C:\Program Files\AVAST Software\Avast\defs\15071101\algo.dll
2011-04-23 19:29 - 2011-04-23 19:29 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2015-07-10 22:54 - 2015-07-10 22:54 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2011-04-23 19:29 - 2011-04-23 19:29 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-04-23 19:29 - 2011-04-23 19:29 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2011-08-24 16:03 - 2011-08-24 16:03 - 00206216 _____ () C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll
2015-07-10 21:30 - 2015-07-06 21:49 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.132\libglesv2.dll
2015-07-10 21:30 - 2015-07-06 21:49 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.132\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2741091298-547696876-3035258377-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{0CDEB80C-E43B-43C6-9C11-5C20857F825B}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{4EC32799-0B39-4E3E-86A4-29A65AA162D2}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{860A32B2-8B3C-4A4A-95CE-FA2C53CB3BDC}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{797A26C2-9938-43F7-9DBA-2BAA7EE1033A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3D6FB054-D62F-46F8-9232-8F24CFF0B6AF}] => (Allow) LPort=2869
FirewallRules: [{01FED352-B558-45E7-8758-D8E8B6131DD6}] => (Allow) LPort=1900
FirewallRules: [{6E0D9485-3740-4DCF-8181-15EFA7483696}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{EE865F51-7F95-4212-B7F1-29B524FD3868}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{F2FDD138-F21A-4813-B98F-E24862771AA1}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe
FirewallRules: [{7BC490F9-E83C-4F38-8B18-19BEF5163E65}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
FirewallRules: [{C26F5729-8761-435B-8B66-D0556EF0C92F}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{96448E60-93AF-4F06-B43D-75B6DAA7BE06}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{1770B8F6-9292-46B4-8C4C-4E44568F30F6}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{323739AB-6971-4FA8-8D35-1FF98F637BFC}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{E71407F4-9A0B-4223-B60A-6EB7F0C501CD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovie.exe
FirewallRules: [{8DDF041D-D81F-41A8-ADEB-D75696A33B7D}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovieService.exe
FirewallRules: [{97190731-781C-475C-99C8-38BCCF908B9D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{680358D6-836D-44BB-88AA-08476DDAEC38}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{7D84196E-B7A5-4F30-A40D-56394E45B79F}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/11/2015 12:43:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 10:27:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 10:21:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: McSvHost.exe, version: 2.0.230.0, time stamp: 0x4d41ff46
Faulting module name: naiann.dll_unloaded, version: 0.0.0.0, time stamp: 0x4d5451c2
Exception code: 0xc0000005
Fault offset: 0x000007fef771ccd8
Faulting process id: 0x6fc
Faulting application start time: 0xMcSvHost.exe0
Faulting application path: McSvHost.exe1
Faulting module path: McSvHost.exe2
Report Id: McSvHost.exe3
 
Error: (07/10/2015 10:14:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 09:27:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 09:12:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 08:54:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 08:40:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (07/11/2015 12:46:50 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v2.0.50727_X64 service to connect.
 
Error: (07/11/2015 12:45:06 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: WMPNetworkSvc0x80004005
 
Error: (07/11/2015 12:41:35 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
 
Error: (07/10/2015 10:26:39 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
 
Error: (07/10/2015 10:21:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Anti-Spam Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (07/10/2015 10:21:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Proxy Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (07/10/2015 10:21:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Network Agent service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (07/10/2015 10:21:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Services service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (07/10/2015 10:21:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The McAfee Personal Firewall Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (07/10/2015 10:21:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The McAfee SiteAdvisor Service service terminated unexpectedly.  It has done this 1 time(s).
 
 
Microsoft Office:
=========================
Error: (07/11/2015 12:43:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 10:27:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 10:21:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: McSvHost.exe2.0.230.04d41ff46naiann.dll_unloaded0.0.0.04d5451c2c0000005000007fef771ccd86fc01d0bb90006c065dC:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exenaiann.dll3fb7575f-2784-11e5-bebb-dc0ea11a77a6
 
Error: (07/10/2015 10:14:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 09:27:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 09:12:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 08:54:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/10/2015 08:40:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
==================== Memory info =========================== 
 
Processor: AMD E-450 APU with Radeon™ HD Graphics
Percentage of memory in use: 38%
Total physical RAM: 5866.9 MB
Available physical RAM: 3582.86 MB
Total Virtual: 11732 MB
Available Virtual: 9169.16 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:450.66 GB) (Free:411.28 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5FABB9C1)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450.7 GB) - (Type=07 NTFS)
 
==================== End of log ============================
 
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:11-07-2015
Ran by [removed] (administrator) on SHERRY-PC on 11-07-2015 12:57:47
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-23] (NTI Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-06-30] (Dritek System Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-24] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-08-26] (CyberLink Corp.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-10] (Avast Software s.r.o.)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2741091298-547696876-3035258377-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [456224 2010-07-29] ()
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-10] (Avast Software s.r.o.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
HKU\S-1-5-21-2741091298-547696876-3035258377-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
HKU\S-1-5-21-2741091298-547696876-3035258377-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-2741091298-547696876-3035258377-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-10] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-10] (Avast Software s.r.o.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1DFE1DD4-AD6F-4796-8D9B-07752FFF9B38}: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{4E0BA522-A68F-4F86-9DAA-97A4EB89C1B1}: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-10] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-07-10]
 
Chrome: 
=======
CHR Profile: C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-10]
CHR Extension: (Google Docs) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-10]
CHR Extension: (Google Drive) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-10]
CHR Extension: (YouTube) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-10]
CHR Extension: (Adblock Plus) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-07-10]
CHR Extension: (Google Search) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-10]
CHR Extension: (Blur) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2015-07-10]
CHR Extension: (Google Sheets) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-10]
CHR Extension: (No Name) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpaoabcbdcfgiicfcdfkfmolkpfpjpko [2015-07-10]
CHR Extension: (Avast Online Security) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-10]
CHR Extension: (F.B Purity-Clean Up Facebook) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl [2015-07-10]
CHR Extension: (Google Wallet) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-10]
CHR Extension: (Gmail) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-10]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-10]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-10] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-07-10] (Avast Software)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-23] (NTI Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-10] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-10] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-10] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-10] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-10] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-10] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-10] (Avast Software s.r.o.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-11] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-10] (Avast Software)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-11 12:57 - 2015-07-11 12:59 - 00014954 _____ C:\Users\sherry\Downloads\FRST.txt
2015-07-11 12:57 - 2015-07-11 12:57 - 00000000 ____D C:\FRST
2015-07-11 12:56 - 2015-07-11 12:56 - 02130944 _____ (Farbar) C:\Users\sherry\Downloads\FRST64.exe
2015-07-11 12:35 - 2015-07-11 12:35 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2015-07-11 12:23 - 2015-07-11 12:23 - 00000000 ____D C:\Program Files (x86)\Web Publish
2015-07-11 12:23 - 2003-07-08 12:45 - 00970752 _____ (Amyuni Technologies http://www.amyuni.com)C:\Windows\SysWOW64\cdintf210.dll
2015-07-11 12:16 - 2015-07-11 12:16 - 00735290 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-07-11 12:15 - 2015-07-11 12:15 - 00000000 ____D C:\Windows\SysWOW64\URTTEMP
2015-07-10 22:55 - 2015-07-10 22:55 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-07-10 22:55 - 2015-07-10 22:55 - 00001926 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\Windows\SysWOW64\vbox
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\Windows\system32\vbox
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\Users\sherry\AppData\Roaming\AVAST Software
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-07-10 22:54 - 2015-07-10 22:55 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-07-10 22:54 - 2015-07-10 22:54 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-07-10 22:54 - 2015-07-10 22:54 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-07-10 22:53 - 2015-07-10 22:53 - 00000000 ____D C:\Program Files\AVAST Software
2015-07-10 22:52 - 2015-07-10 22:52 - 05481336 _____ (Avast Software s.r.o.) C:\Users\sherry\Downloads\avast_free_antivirus_setup_online_cnet.exe
2015-07-10 22:52 - 2015-07-10 22:52 - 00000000 ____D C:\ProgramData\AVAST Software
2015-07-10 22:41 - 2015-07-10 22:41 - 00000565 _____ C:\Users\sherry\Desktop\aswMBR.txt
2015-07-10 22:34 - 2015-07-10 22:34 - 05198336 _____ (AVAST Software) C:\Users\sherry\Downloads\aswMBR.exe
2015-07-10 21:54 - 2012-02-17 00:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-07-10 21:54 - 2012-02-16 23:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-07-10 21:54 - 2012-02-16 22:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-07-10 21:54 - 2012-02-16 22:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-07-10 21:40 - 2015-07-11 12:44 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-10 21:40 - 2015-07-10 21:40 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-10 21:40 - 2015-07-10 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-10 21:40 - 2015-07-10 21:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-10 21:40 - 2015-07-10 21:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-10 21:40 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-07-10 21:40 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-07-10 21:40 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-07-10 21:39 - 2015-07-10 21:39 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\sherry\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-10 21:38 - 2015-07-10 21:39 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\sherry\Downloads\mbam-setup-2.1.8.1057.exe
2015-07-10 21:30 - 2015-07-10 21:30 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-10 21:30 - 2015-07-10 21:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-10 21:29 - 2015-07-11 12:43 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-10 21:29 - 2015-07-11 12:43 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-10 21:29 - 2015-07-11 12:43 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-10 21:29 - 2015-07-10 21:37 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-10 21:29 - 2015-07-10 21:37 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-10 21:29 - 2015-07-10 21:30 - 00000000 ____D C:\Users\sherry\AppData\Local\Google
2015-07-10 21:28 - 2015-07-10 21:29 - 00000000 ____D C:\Users\sherry\AppData\Local\Deployment
2015-07-10 21:28 - 2015-07-10 21:28 - 00000000 ____D C:\Users\sherry\AppData\Local\Apps\2.0
2015-07-10 21:27 - 2015-07-10 21:27 - 00000000 ____D C:\Users\sherry\AppData\Roaming\Adobe
2015-07-10 21:14 - 2015-07-10 21:14 - 00000010 _____ C:\Users\sherry\Documents\windows pw.txt
2015-07-10 21:14 - 2014-05-14 10:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-10 21:14 - 2014-05-14 10:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-10 21:14 - 2014-05-14 10:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-10 21:14 - 2014-05-14 10:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-10 21:13 - 2014-05-14 10:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-10 21:13 - 2014-05-14 10:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-10 21:13 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-10 21:13 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-10 21:13 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-10 21:13 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-10 20:53 - 2015-07-10 20:53 - 00000000 ____D C:\Users\sherry\AppData\Roaming\PowerCinema
2015-07-10 20:53 - 2015-07-10 20:53 - 00000000 ____D C:\Users\sherry\AppData\Local\Cyberlink
2015-07-10 20:51 - 2015-07-10 20:51 - 00000000 ____D C:\Users\sherry\AppData\Local\EgisTec IPS
2015-07-10 20:42 - 2015-07-10 20:42 - 00000000 ____D C:\Windows\NAPP_Dism_Log
2015-07-10 20:40 - 2015-07-11 12:45 - 00000000 ____D C:\ProgramData\clear.fi
2015-07-10 19:54 - 2015-07-10 19:54 - 00001447 _____ C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-10 19:54 - 2015-07-10 19:54 - 00001413 _____ C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-07-10 19:51 - 2015-07-11 12:43 - 00337048 _____ C:\Users\sherry\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-10 19:51 - 2015-07-10 20:53 - 00000000 ____D C:\Users\sherry\AppData\Local\PowerCinema
2015-07-10 19:51 - 2015-07-10 19:54 - 00000000 ____D C:\Users\sherry
2015-07-10 19:51 - 2015-07-10 19:51 - 00002609 _____ C:\Users\Public\Desktop\eBay.lnk
2015-07-10 19:51 - 2015-07-10 19:51 - 00001930 _____ C:\Users\Public\Desktop\Netflix.lnk
2015-07-10 19:51 - 2015-07-10 19:51 - 00000020 ___SH C:\Users\sherry\ntuser.ini
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 __SHD C:\Recovery
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Users\sherry\AppData\Roaming\CyberLink
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Users\sherry\AppData\Local\VirtualStore
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Users\sherry\AppData\Local\Acer
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\ProgramData\OEM_E471269A730E
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Family Protection
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Program Files (x86)\OEM
2015-07-10 19:51 - 2011-10-21 01:20 - 00000000 ____D C:\Users\sherry\AppData\Roaming\Macromedia
2015-07-10 19:51 - 2009-07-13 22:54 - 00000000 ___RD C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-07-10 19:51 - 2009-07-13 22:49 - 00000000 ___RD C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-07-10 17:26 - 2015-07-10 17:26 - 00000000 ____D C:\ProgramData\EgisTec
2015-07-10 17:16 - 2015-07-10 17:18 - 00000000 ____D C:\ProgramData\CLSK
2015-07-10 17:16 - 2015-07-10 17:16 - 00003418 _____ C:\Windows\System32\Tasks\clear.fi
2015-07-10 17:16 - 2015-07-10 17:16 - 00003366 _____ C:\Windows\System32\Tasks\DMREngine
2015-07-10 17:16 - 2015-07-10 17:16 - 00003348 _____ C:\Windows\System32\Tasks\clear.fiAgent
2015-07-10 17:16 - 2015-07-10 17:16 - 00002171 _____ C:\Users\Public\Desktop\clear.fi.lnk
2015-07-10 17:15 - 2015-07-10 17:15 - 00000000 ____D C:\Program Files (x86)\Cyberlink
2015-07-10 17:13 - 2015-07-10 20:53 - 00000000 ____D C:\ProgramData\CyberLink
2015-07-10 17:13 - 2015-07-10 17:19 - 00000000 ____D C:\ProgramData\Temp
2015-07-10 17:13 - 2015-07-10 17:18 - 00015222 _____ C:\ProgramData\ArcadeDeluxe5.log
2015-07-10 17:10 - 2015-07-10 17:16 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\clear.fi
2015-07-10 17:10 - 2015-07-10 17:10 - 00001024 ___RH C:\Users\Public\Documents\NTILiveUpdateV9.dll
2015-07-10 17:10 - 2015-07-10 17:10 - 00000000 ____D C:\ProgramData\NTI Launcher
2015-07-10 17:10 - 2015-07-10 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Media Maker 9
2015-07-10 17:07 - 2015-07-10 17:07 - 00001024 ___RH C:\Users\Public\Documents\NTIMMV9REGET.dll
2015-07-10 17:07 - 2015-07-10 17:07 - 00001024 ___RH C:\Users\Public\Documents\NTIMMV9Acer.dll
2015-07-10 17:07 - 2015-07-10 17:07 - 00000000 ____D C:\ProgramData\FLEXnet
2015-07-10 17:03 - 2015-07-10 17:03 - 00002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
2015-07-10 17:03 - 2015-07-10 17:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-07-10 17:00 - 2015-07-10 17:00 - 00000000 _____ C:\Windows\ativpsrm.bin
2015-07-10 16:57 - 2015-07-10 16:57 - 00004786 _____ C:\Windows\DPINST.LOG
2015-07-10 16:57 - 2015-07-10 16:57 - 00000040 _____ C:\Windows\Driver_install.log
2015-07-10 16:57 - 2015-07-10 16:57 - 00000000 ____D C:\Program Files\Elantech
2015-07-10 16:56 - 2015-07-10 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
2015-07-10 16:56 - 2015-07-10 16:56 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2015-07-10 16:56 - 2015-07-10 16:56 - 00000000 ____D C:\Program Files (x86)\AMD APP
2015-07-10 16:56 - 2010-11-28 14:50 - 00044672 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\usbfilter.sys
2015-07-10 16:55 - 2015-07-11 12:57 - 01304061 _____ C:\Windows\WindowsUpdate.log
2015-07-10 16:55 - 2015-07-10 16:56 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-07-10 16:55 - 2015-07-10 16:55 - 00000000 ____D C:\Program Files\ATI
2015-07-10 16:53 - 2015-07-10 16:53 - 00000184 _____ C:\Windows\LMv4.UNI
2015-07-10 16:53 - 2015-07-10 16:53 - 00000000 ____D C:\Program Files (x86)\Launch Manager
2015-07-10 16:51 - 2015-07-10 16:51 - 00000000 ___HD C:\book
2015-07-10 16:51 - 2015-07-10 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-11 12:53 - 2009-07-13 23:13 - 00727362 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-11 12:52 - 2009-07-13 22:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-11 12:52 - 2009-07-13 22:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-11 12:43 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-11 12:43 - 2009-07-13 22:51 - 00033226 _____ C:\Windows\setupact.log
2015-07-11 12:42 - 2010-11-20 21:47 - 00012914 _____ C:\Windows\PFRO.log
2015-07-11 12:42 - 2009-07-13 22:45 - 00857640 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-11 12:23 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\Help
2015-07-11 12:16 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\Registration
2015-07-10 22:27 - 2011-10-21 00:55 - 00000000 ____D C:\ProgramData\McAfee
2015-07-10 21:25 - 2011-10-21 00:15 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-07-10 21:17 - 2009-07-13 23:32 - 00000000 ____D C:\Windows\system32\restore
2015-07-10 21:14 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\NDF
2015-07-10 21:13 - 2009-07-13 21:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-07-10 20:36 - 2009-07-13 23:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
2015-07-10 20:36 - 2009-07-13 23:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2015-07-10 19:55 - 2011-10-21 01:23 - 00018611 _____ C:\Windows\Patch.log
2015-07-10 19:54 - 2011-10-21 01:10 - 00000000 ____D C:\ProgramData\oem
2015-07-10 19:53 - 2011-10-21 00:55 - 00000000 ___HD C:\OEM
2015-07-10 19:51 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\Recovery
2015-07-10 17:47 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\rescache
2015-07-10 17:42 - 2009-07-13 22:46 - 00004059 _____ C:\Windows\DtcInstall.log
2015-07-10 17:42 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\sysprep
2015-07-10 17:42 - 2007-07-11 19:49 - 00000000 ____D C:\Windows\Panther
2015-07-10 17:24 - 2011-10-21 00:59 - 00000000 ____D C:\Program Files (x86)\Acer
2015-07-10 17:21 - 2011-10-21 01:00 - 00000000 ____D C:\Program Files\Acer
2015-07-10 17:08 - 2011-10-21 01:14 - 00000000 ____D C:\Program Files (x86)\NTI
2015-07-10 16:55 - 2009-07-13 21:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-07-10 16:51 - 2011-02-11 21:12 - 00000000 ____D C:\Windows\DeployWinRE2
2015-07-10 16:49 - 2011-10-21 00:06 - 00003652 _____ C:\Windows\TSSysprep.log
 
==================== Files in the root of some directories =======
 
2015-07-10 17:13 - 2015-07-10 17:18 - 0015222 _____ () C:\ProgramData\ArcadeDeluxe5.log
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-10 17:42
 
==================== End of log ============================
Hi,

Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on I agree button.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

I don't know what I should be keeping and what I shouldn't, sorry. Almost computer illiterate here.

 

# AdwCleaner v4.208 - Logfile created 11/07/2015 at 20:10:49
# Updated 09/07/2015 by Xplode
# Database : 2015-07-11.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : sherry - SHERRY-PC
# Running from : C:\Users\sherry\Downloads\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Found : C:\Users\Public\Desktop\eBay.lnk
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v9.0.8112.16421
 
 
-\\ Google Chrome v43.0.2357.132
 
[C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Found [Homepage] : hxxp://search.imesh.net
[C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Found [Startup_URLs] : E923183BB5FD6D3B0FF8FAEDD4188DBF5DFC617FF4C4E0DA4E49A5B8E000D1D2"},"software_reporter":{"prompt_reason":"64D680AF34B0429E09E469921FEFAEC67613E0E65633D6A1327D26C508A3C6FB","prompt_seed":"4D3BFDDDAAEEBF830D787A2DF3D3775164B8D7D992AF7D9FE2E4FCFDF6E32D83","prompt_version":"3F7D16242A52524127C550A0A9E649F1662E8615A45B79EEF51CED5D79979DDF"},"sync":{"remaining_rollback_tries":"959065C4E484FEEBE577B853C20C44E221E8EF2D9773AC517CAED4B9D0942378"}},"super_mac":"34F08D74E287C3381CA4AC445B7BF1782D5382D39E1F1F77E12F15FB34229399"},"session":{"restore_on_startup":5,"startup_urls":["hxxp://search.imesh.net
 
*************************
 
AdwCleaner[R0].txt - [1604 bytes] - [11/07/2015 20:10:49]
 
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1663 bytes] ##########
You're doing good.

So far the log seems good.

Please run AdwCleaner again but this time select the clean button.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
# AdwCleaner v4.208 - Logfile created 11/07/2015 at 22:36:32
# Updated 09/07/2015 by Xplode
# Database : 2015-07-11.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : sherry - SHERRY-PC
# Running from : C:\Users\sherry\Downloads\AdwCleaner (1).exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
File Deleted : C:\Users\Public\Desktop\eBay.lnk
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v9.0.8112.16421
 
 
-\\ Google Chrome v43.0.2357.132
 
[C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : hxxp://search.imesh.net
[C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Startup_URLs] : E923183BB5FD6D3B0FF8FAEDD4188DBF5DFC617FF4C4E0DA4E49A5B8E000D1D2"},"software_reporter":{"prompt_reason":"64D680AF34B0429E09E469921FEFAEC67613E0E65633D6A1327D26C508A3C6FB","prompt_seed":"4D3BFDDDAAEEBF830D787A2DF3D3775164B8D7D992AF7D9FE2E4FCFDF6E32D83","prompt_version":"3F7D16242A52524127C550A0A9E649F1662E8615A45B79EEF51CED5D79979DDF"},"sync":{"remaining_rollback_tries":"959065C4E484FEEBE577B853C20C44E221E8EF2D9773AC517CAED4B9D0942378"}},"super_mac":"34F08D74E287C3381CA4AC445B7BF1782D5382D39E1F1F77E12F15FB34229399"},"session":{"restore_on_startup":5,"startup_urls":["hxxp://search.imesh.net
 
*************************
 
AdwCleaner[R0].txt - [1742 bytes] - [11/07/2015 20:10:49]
AdwCleaner[R1].txt - [1805 bytes] - [11/07/2015 22:34:40]
AdwCleaner[S0].txt - [1738 bytes] - [11/07/2015 22:36:32]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1797  bytes] ##########

Okay we have a problem. I cannot open google chrom at all. Have been trying for the last 20 minutes. And I cannot access internet explorer either

Edit to add, finally got it up. Had to restart laptop and tried to go into safe mode but just got taken to regular screen, and finally got browser to open after 3 more attempts.

It still took 3 attempts to open google, and IE is basically gone, except for "web publishing wizard" when I click on IE in the start menu.

Today it has been okay for google

Forgot to do the scan, sorry.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
Ran by [removed] (administrator) on SHERRY-PC on 13-07-2015 20:07:38
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM-x32\…\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-23] (NTI Corporation)
HKLM-x32\…\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-06-30] (Dritek System Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-24] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-08-26] (CyberLink Corp.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-07-10] (Avast Software s.r.o.)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2741091298-547696876-3035258377-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [456224 2010-07-29] ()
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-10] (Avast Software s.r.o.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
HKU\S-1-5-21-2741091298-547696876-3035258377-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
HKU\S-1-5-21-2741091298-547696876-3035258377-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-10] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-10] (Avast Software s.r.o.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1DFE1DD4-AD6F-4796-8D9B-07752FFF9B38}: [DhcpNameServer] 192.168.1.250
Tcpip\..\Interfaces\{4E0BA522-A68F-4F86-9DAA-97A4EB89C1B1}: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-07-10] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2015-06-25] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-07-10]
 
Chrome: 
=======
CHR Profile: C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-12]
CHR Extension: (Adblock Plus) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-07-12]
CHR Extension: (Social Sponsoring) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpaoabcbdcfgiicfcdfkfmolkpfpjpko [2015-07-12]
CHR Extension: (AdBlock) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-07-12]
CHR Extension: (Avast Online Security) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-11]
CHR Extension: (F.B Purity-Clean Up Facebook) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdlagniojmheiklojdcpdaeepochckl [2015-07-12]
CHR Extension: (Google Wallet) - C:\Users\sherry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-11]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-10]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-07-10] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-07-10] (Avast Software)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [349728 2015-06-25] (WildTangent)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-23] (NTI Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-10] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-10] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-10] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-10] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-10] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-10] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-10] (Avast Software s.r.o.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-13] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-10] (Avast Software)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-13 20:07 - 2015-07-13 20:07 - 00000000 ____D C:\Users\sherry\Downloads\FRST-OlderVersion
2015-07-13 18:24 - 2015-07-13 18:24 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-13 18:24 - 2015-07-13 18:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-07-13 17:36 - 2015-07-13 17:38 - 00000000 ____D C:\81f77de3866776f91a8e
2015-07-13 17:04 - 2015-07-13 17:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-07-13 16:56 - 2015-07-13 16:56 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-07-13 16:56 - 2015-07-13 16:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-07-13 09:06 - 2014-06-30 16:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2015-07-13 09:06 - 2014-06-30 16:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2015-07-13 09:06 - 2014-06-06 00:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2015-07-13 09:06 - 2014-06-06 00:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-07-13 09:06 - 2014-03-09 15:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2015-07-13 09:06 - 2014-03-09 15:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2015-07-13 09:06 - 2014-03-09 15:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2015-07-13 09:06 - 2014-03-09 15:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2015-07-12 16:04 - 2015-07-12 16:04 - 00000088 _____ C:\Users\sherry\Downloads\Evony-Free_Forever.url
2015-07-11 20:16 - 2015-07-11 20:16 - 02248704 _____ C:\Users\sherry\Downloads\AdwCleaner (1).exe
2015-07-11 20:10 - 2015-07-11 22:36 - 00000000 ____D C:\AdwCleaner
2015-07-11 20:09 - 2015-07-11 20:10 - 02248704 _____ C:\Users\sherry\Downloads\AdwCleaner.exe
2015-07-11 17:08 - 2015-07-11 17:08 - 00000000 ____D C:\ProgramData\BlueStacks
2015-07-11 17:07 - 2015-07-11 17:09 - 00000000 ____D C:\Users\sherry\AppData\Roaming\WildTangent
2015-07-11 17:00 - 2015-07-11 17:00 - 00000000 ____D C:\Users\sherry\AppData\Roaming\LifeStyleMedia
2015-07-11 16:58 - 2015-07-11 16:58 - 00390656 _____ C:\Users\sherry\Downloads\netflix_icon_installer.msi
2015-07-11 14:59 - 2015-07-11 14:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-07-11 14:56 - 2015-07-11 14:56 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-07-11 14:54 - 2015-07-11 14:54 - 00000000 ____D C:\Program Files\Microsoft Office
2015-07-11 14:54 - 2015-07-11 14:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2015-07-11 14:53 - 2015-07-13 20:08 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-11 14:53 - 2015-07-11 14:53 - 00000000 ____D C:\Users\sherry\AppData\Local\Microsoft Help
2015-07-11 14:52 - 2015-07-11 14:52 - 00000000 __RHD C:\MSOCache
2015-07-11 13:10 - 2015-07-11 13:12 - 00023386 _____ C:\Users\sherry\Downloads\Addition.txt
2015-07-11 12:57 - 2015-07-13 20:07 - 00014026 _____ C:\Users\sherry\Downloads\FRST.txt
2015-07-11 12:57 - 2015-07-13 20:07 - 00000000 ____D C:\FRST
2015-07-11 12:56 - 2015-07-13 20:07 - 02133504 _____ (Farbar) C:\Users\sherry\Downloads\FRST64.exe
2015-07-11 12:35 - 2015-07-11 12:35 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2015-07-11 12:23 - 2015-07-11 12:23 - 00000000 ____D C:\Program Files (x86)\Web Publish
2015-07-11 12:23 - 2003-07-08 12:45 - 00970752 _____ (Amyuni Technologies http://www.amyuni.com)C:\Windows\SysWOW64\cdintf210.dll
2015-07-11 12:16 - 2015-07-11 12:16 - 00735290 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-07-11 12:15 - 2015-07-11 12:15 - 00000000 ____D C:\Windows\SysWOW64\URTTEMP
2015-07-10 22:55 - 2015-07-10 22:55 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-07-10 22:55 - 2015-07-10 22:55 - 00001926 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\Windows\SysWOW64\vbox
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\Windows\system32\vbox
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\Users\sherry\AppData\Roaming\AVAST Software
2015-07-10 22:55 - 2015-07-10 22:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-07-10 22:54 - 2015-07-10 22:55 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-07-10 22:54 - 2015-07-10 22:54 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-07-10 22:54 - 2015-07-10 22:54 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-07-10 22:54 - 2015-07-10 22:54 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-07-10 22:53 - 2015-07-10 22:53 - 00000000 ____D C:\Program Files\AVAST Software
2015-07-10 22:52 - 2015-07-10 22:52 - 05481336 _____ (Avast Software s.r.o.) C:\Users\sherry\Downloads\avast_free_antivirus_setup_online_cnet.exe
2015-07-10 22:52 - 2015-07-10 22:52 - 00000000 ____D C:\ProgramData\AVAST Software
2015-07-10 22:41 - 2015-07-10 22:41 - 00000565 _____ C:\Users\sherry\Desktop\aswMBR.txt
2015-07-10 22:34 - 2015-07-10 22:34 - 05198336 _____ (AVAST Software) C:\Users\sherry\Downloads\aswMBR.exe
2015-07-10 21:54 - 2012-02-17 00:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-07-10 21:54 - 2012-02-16 23:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-07-10 21:54 - 2012-02-16 22:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-07-10 21:54 - 2012-02-16 22:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-07-10 21:40 - 2015-07-13 17:16 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-10 21:40 - 2015-07-10 21:40 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-10 21:40 - 2015-07-10 21:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-10 21:40 - 2015-07-10 21:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-10 21:40 - 2015-07-10 21:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-10 21:40 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-07-10 21:40 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-07-10 21:40 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-07-10 21:39 - 2015-07-10 21:39 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\sherry\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-07-10 21:38 - 2015-07-10 21:39 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\sherry\Downloads\mbam-setup-2.1.8.1057.exe
2015-07-10 21:30 - 2015-07-10 21:30 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-10 21:30 - 2015-07-10 21:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-10 21:29 - 2015-07-13 20:03 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-10 21:29 - 2015-07-12 10:04 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-10 21:29 - 2015-07-11 12:43 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-10 21:29 - 2015-07-10 21:37 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-10 21:29 - 2015-07-10 21:37 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-10 21:29 - 2015-07-10 21:30 - 00000000 ____D C:\Users\sherry\AppData\Local\Google
2015-07-10 21:28 - 2015-07-10 21:29 - 00000000 ____D C:\Users\sherry\AppData\Local\Deployment
2015-07-10 21:28 - 2015-07-10 21:28 - 00000000 ____D C:\Users\sherry\AppData\Local\Apps\2.0
2015-07-10 21:27 - 2015-07-10 21:27 - 00000000 ____D C:\Users\sherry\AppData\Roaming\Adobe
2015-07-10 21:14 - 2015-07-10 21:14 - 00000010 _____ C:\Users\sherry\Documents\windows pw.txt
2015-07-10 21:14 - 2014-05-14 10:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-10 21:14 - 2014-05-14 10:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-10 21:14 - 2014-05-14 10:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-10 21:14 - 2014-05-14 10:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-10 21:13 - 2014-05-14 10:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-10 21:13 - 2014-05-14 10:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-10 21:13 - 2014-05-14 10:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-10 21:13 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-10 21:13 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-10 21:13 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-10 21:13 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-10 20:53 - 2015-07-10 20:53 - 00000000 ____D C:\Users\sherry\AppData\Roaming\PowerCinema
2015-07-10 20:53 - 2015-07-10 20:53 - 00000000 ____D C:\Users\sherry\AppData\Local\Cyberlink
2015-07-10 20:51 - 2015-07-10 20:51 - 00000000 ____D C:\Users\sherry\AppData\Local\EgisTec IPS
2015-07-10 20:42 - 2015-07-10 20:42 - 00000000 ____D C:\Windows\NAPP_Dism_Log
2015-07-10 20:40 - 2015-07-12 10:05 - 00000000 ____D C:\ProgramData\clear.fi
2015-07-10 19:54 - 2015-07-10 19:54 - 00001447 _____ C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-10 19:54 - 2015-07-10 19:54 - 00001413 _____ C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-07-10 19:51 - 2015-07-11 17:04 - 00088504 _____ C:\Users\sherry\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-10 19:51 - 2015-07-10 20:53 - 00000000 ____D C:\Users\sherry\AppData\Local\PowerCinema
2015-07-10 19:51 - 2015-07-10 19:54 - 00000000 ____D C:\Users\sherry
2015-07-10 19:51 - 2015-07-10 19:51 - 00000020 ___SH C:\Users\sherry\ntuser.ini
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 __SHD C:\Recovery
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Users\sherry\AppData\Roaming\CyberLink
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Users\sherry\AppData\Local\VirtualStore
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Users\sherry\AppData\Local\Acer
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\ProgramData\OEM_E471269A730E
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Family Protection
2015-07-10 19:51 - 2015-07-10 19:51 - 00000000 ____D C:\Program Files (x86)\OEM
2015-07-10 19:51 - 2011-10-21 01:20 - 00000000 ____D C:\Users\sherry\AppData\Roaming\Macromedia
2015-07-10 19:51 - 2009-07-13 22:54 - 00000000 ___RD C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-07-10 19:51 - 2009-07-13 22:49 - 00000000 ___RD C:\Users\sherry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-07-10 17:26 - 2015-07-10 17:26 - 00000000 ____D C:\ProgramData\EgisTec
2015-07-10 17:16 - 2015-07-10 17:18 - 00000000 ____D C:\ProgramData\CLSK
2015-07-10 17:16 - 2015-07-10 17:16 - 00003418 _____ C:\Windows\System32\Tasks\clear.fi
2015-07-10 17:16 - 2015-07-10 17:16 - 00003366 _____ C:\Windows\System32\Tasks\DMREngine
2015-07-10 17:16 - 2015-07-10 17:16 - 00003348 _____ C:\Windows\System32\Tasks\clear.fiAgent
2015-07-10 17:16 - 2015-07-10 17:16 - 00002171 _____ C:\Users\Public\Desktop\clear.fi.lnk
2015-07-10 17:15 - 2015-07-10 17:15 - 00000000 ____D C:\Program Files (x86)\Cyberlink
2015-07-10 17:13 - 2015-07-10 20:53 - 00000000 ____D C:\ProgramData\CyberLink
2015-07-10 17:13 - 2015-07-10 17:19 - 00000000 ____D C:\ProgramData\Temp
2015-07-10 17:13 - 2015-07-10 17:18 - 00015222 _____ C:\ProgramData\ArcadeDeluxe5.log
2015-07-10 17:10 - 2015-07-10 17:16 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\clear.fi
2015-07-10 17:10 - 2015-07-10 17:10 - 00001024 ___RH C:\Users\Public\Documents\NTILiveUpdateV9.dll
2015-07-10 17:10 - 2015-07-10 17:10 - 00000000 ____D C:\ProgramData\NTI Launcher
2015-07-10 17:10 - 2015-07-10 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NTI Media Maker 9
2015-07-10 17:07 - 2015-07-10 17:07 - 00001024 ___RH C:\Users\Public\Documents\NTIMMV9REGET.dll
2015-07-10 17:07 - 2015-07-10 17:07 - 00001024 ___RH C:\Users\Public\Documents\NTIMMV9Acer.dll
2015-07-10 17:07 - 2015-07-10 17:07 - 00000000 ____D C:\ProgramData\FLEXnet
2015-07-10 17:03 - 2015-07-11 15:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-07-10 17:00 - 2015-07-10 17:00 - 00000000 _____ C:\Windows\ativpsrm.bin
2015-07-10 16:57 - 2015-07-10 16:57 - 00004786 _____ C:\Windows\DPINST.LOG
2015-07-10 16:57 - 2015-07-10 16:57 - 00000040 _____ C:\Windows\Driver_install.log
2015-07-10 16:57 - 2015-07-10 16:57 - 00000000 ____D C:\Program Files\Elantech
2015-07-10 16:56 - 2015-07-10 16:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
2015-07-10 16:56 - 2015-07-10 16:56 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2015-07-10 16:56 - 2015-07-10 16:56 - 00000000 ____D C:\Program Files (x86)\AMD APP
2015-07-10 16:56 - 2010-11-28 14:50 - 00044672 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\usbfilter.sys
2015-07-10 16:55 - 2015-07-13 12:36 - 01594221 _____ C:\Windows\WindowsUpdate.log
2015-07-10 16:55 - 2015-07-10 16:56 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-07-10 16:55 - 2015-07-10 16:55 - 00000000 ____D C:\Program Files\ATI
2015-07-10 16:53 - 2015-07-10 16:53 - 00000184 _____ C:\Windows\LMv4.UNI
2015-07-10 16:53 - 2015-07-10 16:53 - 00000000 ____D C:\Program Files (x86)\Launch Manager
2015-07-10 16:51 - 2015-07-10 16:51 - 00000000 ___HD C:\book
2015-07-10 16:51 - 2015-07-10 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-07-13 20:07 - 2009-07-13 23:13 - 00727362 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-13 18:24 - 2011-10-21 00:54 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
2015-07-13 18:24 - 2011-10-21 00:53 - 00000000 ____D C:\ProgramData\Skype
2015-07-13 17:36 - 2009-07-13 21:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-07-12 10:12 - 2009-07-13 22:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-12 10:12 - 2009-07-13 22:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-12 10:04 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-12 10:04 - 2009-07-13 22:51 - 00033506 _____ C:\Windows\setupact.log
2015-07-11 22:38 - 2009-07-13 22:45 - 00363328 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-11 22:37 - 2010-11-20 21:47 - 00025216 _____ C:\Windows\PFRO.log
2015-07-11 17:07 - 2011-10-21 00:24 - 00002626 ____N C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2015-07-11 17:07 - 2011-10-21 00:24 - 00000000 ____D C:\ProgramData\WildTangent
2015-07-11 17:07 - 2009-07-13 23:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-07-11 17:06 - 2011-10-21 00:24 - 00000000 ____D C:\Program Files (x86)\WildTangent Games
2015-07-11 15:17 - 2010-11-21 01:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-07-11 15:10 - 2009-07-13 20:34 - 00000510 _____ C:\Windows\win.ini
2015-07-11 14:54 - 2010-11-21 01:16 - 00000000 ____D C:\Windows\ShellNew
2015-07-11 12:23 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\Help
2015-07-11 12:16 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\Registration
2015-07-10 22:27 - 2011-10-21 00:55 - 00000000 ____D C:\ProgramData\McAfee
2015-07-10 21:25 - 2011-10-21 00:15 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-07-10 21:17 - 2009-07-13 23:32 - 00000000 ____D C:\Windows\system32\restore
2015-07-10 21:14 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\NDF
2015-07-10 21:13 - 2009-07-13 21:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-07-10 20:36 - 2009-07-13 23:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
2015-07-10 20:36 - 2009-07-13 23:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2015-07-10 19:55 - 2011-10-21 01:23 - 00018611 _____ C:\Windows\Patch.log
2015-07-10 19:54 - 2011-10-21 01:10 - 00000000 ____D C:\ProgramData\oem
2015-07-10 19:53 - 2011-10-21 00:55 - 00000000 ___HD C:\OEM
2015-07-10 19:51 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\Recovery
2015-07-10 17:47 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\rescache
2015-07-10 17:42 - 2009-07-13 22:46 - 00004059 _____ C:\Windows\DtcInstall.log
2015-07-10 17:42 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\sysprep
2015-07-10 17:42 - 2007-07-11 19:49 - 00000000 ____D C:\Windows\Panther
2015-07-10 17:24 - 2011-10-21 00:59 - 00000000 ____D C:\Program Files (x86)\Acer
2015-07-10 17:21 - 2011-10-21 01:00 - 00000000 ____D C:\Program Files\Acer
2015-07-10 17:08 - 2011-10-21 01:14 - 00000000 ____D C:\Program Files (x86)\NTI
2015-07-10 16:51 - 2011-02-11 21:12 - 00000000 ____D C:\Windows\DeployWinRE2
2015-07-10 16:49 - 2011-10-21 00:06 - 00003652 _____ C:\Windows\TSSysprep.log
2015-06-23 13:30 - 2010-11-20 21:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
 
==================== Files in the root of some directories =======
 
2015-07-10 17:13 - 2015-07-10 17:18 - 0015222 _____ () C:\ProgramData\ArcadeDeluxe5.log
 
Some files in TEMP:
====================
C:\Users\sherry\AppData\Local\Temp\Quarantine.exe
C:\Users\sherry\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-07-10 17:42
 
==================== End of log ============================

Before we go any further, I am curious about something. What is the general consensus about resetting back to factory specs? Would that be a viable option?

I have nothing on this laptop yet that I am concerned about loosing. Any files, etc are either linked through my google account, or in dropbox.

That would be a viable or perhaps better option for you to go with. At least you will be starting to use this laptop on a clean slate. Do let me know if you decided to go with reset to factory settings so that we can close this one.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI