This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Toshiba laptop three days old - infected now with malware?! [Solve

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop is virtually brand new, yet somehow either I or my son has visited a site or downloaded something inocuous that's brought this down on us. Grrr!

 

I'm attaching my aswMBR post. Please find something I can get rid of. I have a brand new computer and I can't even use it.

 

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-12-05 11:43:33
—————————–
11:43:33.723    OS Version: Windows x64 6.2.9200
11:43:33.723    Number of processors: 4 586 0x3D04
11:43:33.723    ComputerName: LAPTOP-L02074TA  UserName: Dykes family
11:43:35.816    Initialize success
11:43:35.832    VM: initialized successfully
11:43:35.832    VM: Intel CPU supported
11:43:43.910    VM: disk I/O iaStorA.sys
11:43:54.927    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002f
11:43:54.942    Disk 0 Vendor: TOSHIBA_MQ01ABD100 AX1P4M Size: 953869MB BusType: 11
11:43:55.099    Disk 0 MBR read successfully
11:43:55.099    Disk 0 MBR scan
11:43:55.099    Disk 0 unknown MBR code
11:43:55.114    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
11:43:55.269    Disk 0 scanning C:\Windows\system32\drivers
11:43:59.933    Service scanning
11:44:56.669    Modules scanning
11:44:56.669    Disk 0 trace - called modules:
11:44:56.731    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys
11:44:56.747    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001d18e1060]
11:44:56.747    3 CLASSPNP.SYS[fffff801879246c5] -> nt!IofCallDriver -> [0xffffe001cd7896b0]
11:44:56.763    5 ACPI.sys[fffff80186871361] -> nt!IofCallDriver -> \Device\0000002f[0xffffe001cef2d060]
11:44:56.763    Disk 0 statistics 134192/0/0 @ 15.77 MB/s
11:44:56.778    Scan finished successfully
11:46:20.935    Disk 0 MBR has been saved successfully to "E:\Downloads\Anti-malware programs\MBR.dat"
11:46:21.029    The log file has been saved successfully to "E:\Downloads\Anti-malware programs\aswMBR.txt"

 

:welcome:

 

Let me see a FRST log and the Additions log that comes with it so we can see whats going on

 

 
 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • Thanks for being so prompt! :thumbup:

     

    Here are the results:

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
    Ran by [removed] (administrator) on LAPTOP-L02074TA (05-12-2015 13:11:54)
    Running from E:\Downloads\Anti-malware programs
    [removed] Platform: Windows 10 Home (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
    (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
    (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    () C:\Windows\System32\igfxTray.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
    (TOSHIBA Corporation) C:\Program Files\TOSHIBA\System Setting\TCrdMain_Win8.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    (Microsoft Corporation) C:\Windows\System32\wuapihost.exe
    () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy\AccountsControlHost.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.23.23.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
    () C:\Program Files\WindowsApps\Microsoft.XboxApp_11.11.19012.0_x64__8wekyb3d8bbwe\XboxApp.exe
    (Microsoft Corporation) C:\Windows\System32\mspaint.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\…\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [599384 2015-06-05] (Conexant Systems, Inc.)
    HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
    HKLM\…\Run: [TCrdMain] => C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe [511280 2015-06-23] (TOSHIBA Corporation)
    HKLM\…\Run: [] => [X]
    HKLM-x32\…\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516976 2015-06-09] (TOSHIBA)
    HKLM\…\Policies\Explorer: [NoFolderOptions] 0
    HKLM\…\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\Run: [kdapll] => rundll32.exe "C:\Users\Dykes family\AppData\Local\kdapll.dll",kdapll <===== ATTENTION
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\Run: [Itibiti.exe] => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\RunOnce: [Uninstall C:\Users\Dykes family\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes family\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
    AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC64LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [247056 2015-11-15] ()
    AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219920 2015-11-15] ()

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Winsock: Catalog9 01 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 02 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 03 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 04 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 17 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9-x64 01 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 02 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 03 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 04 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 17 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{26b11a49-585f-4b43-a90c-9af3c3d7b25b}: [NameServer] 104.197.191.4
    Tcpip\..\Interfaces\{e79ab54d-b855-47b9-b876-73cdf5a0204e}: [DhcpNameServer] [removed]
    Tcpip\..\Interfaces\{efd1cb4d-c480-4627-af71-4f51f9ea6777}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba15.msn.com/?pc=TBTE
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> DefaultScope {E87B3EAC-41A7-4ECB-A37A-761A3EF860B2} URL =
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid;=CT3331213&octid;=EB_ORIGINAL_CTID&ISID;=M3BCD1F74-8D9A-4738-ACD0-BB13B3ED1F63&SearchSource;=58&CUI;=&UM;=8&UP;=SP24C44E74-9150-4124-B00A-94C809105872&D;=120515&q;={searchTerms}&SSPV;=
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {8364220B-8A5F-4522-938F-CCF2F039BD0B} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q;={searchTerms}&s;=FC5zftpbl2,6bc8c4ff-6b73-422f-92dc-567c954134f5,
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {E87B3EAC-41A7-4ECB-A37A-761A3EF860B2} URL =
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-21] (Microsoft Corporation)
    Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)

    Edge:
    ======
    Edge HomeButtonPage: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> hxxp://www.google.com/

    FireFox:
    ========
    FF ProfilePath: C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default
    FF NewTab: hxxp://www.trovi.com/?gd=&ctid;=CT3331213&octid;=EB_ORIGINAL_CTID&ISID;=M3BCD1F74-8D9A-4738-ACD0-BB13B3ED1F63&SearchSource;=69&CUI;=&SSPV;=&Lay;=1&UM;=8&UP;=SP24C44E74-9150-4124-B00A-94C809105872&D;=120515
    FF DefaultSearchEngine.US: Google
    FF Homepage: hxxps://www.google.com/
    FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation)
    FF Extension: AdBeaver - C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\Extensions\[removed] [2015-11-24]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2278152 2015-09-25] (Broadcom Corporation.)
    S2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [3240208 2015-11-15] () [File not signed]
    S2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [382312 2015-11-27] (Digital Wave Ltd.)
    R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-11-30] (Intel Corporation)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
    S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation)
    R2 TOSRMService; C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe [326960 2015-06-24] (TOSHIBA)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
    S2 Omobuvh; "C:\Users\Dykes family\AppData\Roaming\FijaeDejka\Avetde.exe" -cms [X]

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [199472 2015-09-25] (Broadcom Corporation.)
    R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7593176 2015-07-10] (Broadcom Corporation)
    S1 bsdriver; C:\Windows\system32\drivers\bsdriver.sys [34712 2015-12-05] () [File not signed]
    R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation)
    R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [301784 2015-06-01] (Realtek Semiconductor Corp.)
    R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-16] (Realtek                                            )
    R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-08-03] (Synaptics Incorporated)
    R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [45720 2015-06-13] (Toshiba Corporation)
    S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
    S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
    S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
    U3 aswMBR; C:\Users\Dykes family\AppData\Local\Temp\aswMBR.sys [62728 2015-12-05] () [File not signed]
    U3 aswVmm; C:\Users\Dykes family\AppData\Local\Temp\aswVmm.sys [224896 2015-12-05] ()
    S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-05 13:11 - 2015-12-05 13:11 - 00000000 ____D C:\FRST
    2015-12-05 13:10 - 2015-12-05 13:10 - 00016148 _____ C:\Windows\system32\LAPTOP-L02074TA_Dykes family_HistoryPrediction.bin
    2015-12-05 11:06 - 2015-12-05 11:06 - 00000000 ____D C:\Windows\system32\jike
    2015-12-05 08:42 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\Documents\PCSpeedUp
    2015-12-05 08:40 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\AppData\Local\bvxvhxvh
    2015-12-05 08:40 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\SearchProtect
    2015-12-05 08:40 - 2015-12-05 08:40 - 00000000 ____D C:\Users\Dykes family\AppData\Local\SearchProtect
    2015-12-05 08:39 - 2015-12-05 08:39 - 00000008 _____ C:\END
    2015-12-05 08:34 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\AppData\Local\gmsd_us_005010167
    2015-12-05 08:34 - 2015-12-05 11:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
    2015-12-05 08:34 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\gmsd_us_005010167
    2015-12-05 08:33 - 2015-12-05 11:06 - 00000000 ____D C:\Program Files\shopperz051220150818
    2015-12-05 08:33 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Simple Media Player
    2015-12-05 08:33 - 2015-12-05 11:00 - 00000000 ____D C:\uninst
    2015-12-05 08:33 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\Simple Media Player
    2015-12-05 08:33 - 2015-12-05 08:33 - 00034712 _____ C:\Windows\system32\Drivers\bsdriver.sys
    2015-12-05 08:33 - 2015-12-05 08:33 - 00004800 _____ C:\Windows\SysWOW64\Pajhunoour.ini
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003698 _____ C:\Windows\System32\Tasks\GoogleUp
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003686 _____ C:\Windows\System32\Tasks\import
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003592 _____ C:\Windows\System32\Tasks\Googleuptodate
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003582 _____ C:\Windows\System32\Tasks\MyDailyBackup
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003558 _____ C:\Windows\System32\Tasks\win
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003432 _____ C:\Windows\System32\Tasks\Biain
    2015-12-05 08:33 - 2015-12-05 08:33 - 00002520 _____ C:\Windows\SysWOW64\PajhunoourOff.ini
    2015-12-05 08:33 - 2015-12-05 08:33 - 00002520 _____ C:\Windows\system32\PajhunoourOff.ini
    2015-12-05 08:33 - 2015-12-05 08:33 - 00000000 ____D C:\Users\Dykes family\AppData\LocalLow\Company
    2015-12-05 08:33 - 2015-12-05 08:33 - 00000000 ____D C:\Users\Dykes family\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
    2015-12-05 08:33 - 2015-12-05 08:33 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Tempfolder
    2015-12-05 08:33 - 2015-12-05 06:13 - 00375152 ____N C:\Windows\system32\Pajhunoour64.dll
    2015-12-05 08:33 - 2015-12-05 06:12 - 00289136 ____N C:\Windows\SysWOW64\Pajhunoour.dll
    2015-12-05 08:32 - 2015-12-05 11:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WNEn
    2015-12-05 08:32 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files\WNEn
    2015-12-05 08:31 - 2015-12-05 11:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up
    2015-12-05 08:31 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\PC Speed Up
    2015-12-05 08:31 - 2015-12-05 08:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-12-05 08:31 - 2015-12-05 08:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2015-12-05 08:31 - 2015-12-05 08:31 - 00000000 ____D C:\Program Files (x86)\Consumer Input
    2015-12-05 08:30 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files\Faster Web
    2015-12-05 08:30 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\Faster Web
    2015-12-05 08:30 - 2015-12-05 08:30 - 00009216 _____ C:\Users\Dykes family\AppData\Local\kdapll.dll
    2015-12-05 08:30 - 2015-12-05 08:30 - 00002560 _____ C:\Users\Dykes family\AppData\Local\uninstall.exe
    2015-12-05 08:29 - 2015-12-05 08:29 - 00000000 ____D C:\Users\Dykes family\AppData\Local\CEF
    2015-12-05 08:28 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\winnetuse
    2015-12-05 08:20 - 2015-12-05 08:27 - 00000000 ____D C:\Users\Dykes family\AppData\Local\410000EC-1449303607-2044-2020-202020202020
    2015-12-05 08:19 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\NUIns
    2015-12-05 08:19 - 2015-12-05 08:19 - 00000000 ____D C:\Program Files (x86)\410000EC-1449321552-2044-2020-202020202020
    2015-12-05 01:21 - 2015-12-05 08:33 - 00056728 _____ C:\Windows\system32\Drivers\cherimoya.sys
    2015-12-04 20:56 - 2015-12-04 20:56 - 00000000 ____D C:\Program Files\Synaptics
    2015-12-04 20:16 - 2015-12-04 20:16 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Synaptics
    2015-12-04 19:53 - 2015-12-05 11:13 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\.minecraft
    2015-12-04 19:53 - 2015-12-04 19:53 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\java
    2015-12-04 19:51 - 2015-12-04 19:51 - 00001030 _____ C:\Users\Public\Desktop\Minecraft.lnk
    2015-12-04 19:51 - 2015-12-04 19:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
    2015-12-04 19:51 - 2015-12-04 19:51 - 00000000 ____D C:\Program Files (x86)\Minecraft
    2015-12-04 19:30 - 2015-12-04 19:30 - 00000000 ____D C:\Users\Dykes family\AppData\Local\NetworkTiles
    2015-12-01 18:57 - 2015-12-05 11:04 - 00000000 ____D C:\Windows\System32\Tasks\McAfee
    2015-12-01 02:02 - 2015-12-01 07:35 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Comms
    2015-11-30 22:31 - 2015-11-30 22:31 - 00001577 _____ C:\Users\Public\Desktop\Free Video to DVD Converter.lnk
    2015-11-30 22:31 - 2015-11-30 22:31 - 00001376 _____ C:\Users\Public\Desktop\Free DVD Video Burner.lnk
    2015-11-30 22:31 - 2015-11-30 22:31 - 00001310 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
    2015-11-30 22:31 - 2015-11-30 22:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
    2015-11-30 22:31 - 2015-11-30 22:31 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
    2015-11-30 22:28 - 2015-11-30 22:30 - 26601640 _____ (DVDVideoSoft Ltd. ) C:\Users\Dykes family\Downloads\FreeVideoToDVDConverter.exe
    2015-11-30 22:25 - 2015-11-30 22:31 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\DVDVideoSoft
    2015-11-30 22:18 - 2015-11-30 22:18 - 00000013 __RSH C:\Windows\system32\Drivers\fbd.sys
    2015-11-30 22:17 - 2015-11-30 22:18 - 01388432 _____ C:\Users\Public\VOIP.dat
    2015-11-30 22:17 - 2015-11-30 22:17 - 00000000 ____D C:\Users\Dykes family\Tracing
    2015-11-30 22:10 - 2015-12-04 19:32 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Skype
    2015-11-30 22:10 - 2015-11-30 22:10 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ___RD C:\Program Files (x86)\Skype
    2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Skype
    2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ____D C:\ProgramData\Skype
    2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-11-30 22:05 - 2015-11-30 22:05 - 01504384 _____ (Skype Technologies S.A.) C:\Users\Dykes family\Downloads\SkypeSetup.exe
    2015-11-30 22:04 - 2015-11-30 22:04 - 00003328 _____ C:\Windows\System32\Tasks\{5236EBB1-7687-40F3-95D6-10FB965F7948}
    2015-11-30 22:03 - 2015-11-30 22:03 - 00000903 _____ C:\Users\Dykes family\Desktop\µTorrent.lnk
    2015-11-30 22:03 - 2015-11-30 22:03 - 00000883 _____ C:\Users\Dykes family\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
    2015-11-30 22:02 - 2015-11-30 22:03 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\uTorrent
    2015-11-30 21:59 - 2015-11-30 22:00 - 00000000 ____D C:\ProgramData\KMSAuto
    2015-11-30 21:59 - 2013-08-22 03:40 - 00040664 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tap0901.sys
    2015-11-30 21:58 - 2015-11-30 22:00 - 00000000 ____D C:\Users\Dykes family\AppData\Local\MSfree Inc
    2015-11-30 21:56 - 2015-11-30 21:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
    2015-11-30 21:56 - 2015-11-30 21:56 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
    2015-11-30 21:55 - 2015-11-30 21:55 - 00000000 ____D C:\Windows\PCHEALTH
    2015-11-30 21:54 - 2015-11-30 21:55 - 00000000 ____D C:\Program Files\Microsoft Office
    2015-11-30 21:54 - 2015-11-30 21:54 - 00000000 __RHD C:\MSOCache
    2015-11-30 21:54 - 2015-11-30 21:54 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Microsoft Help
    2015-11-30 21:44 - 2015-12-05 08:40 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-11-30 21:44 - 2015-11-30 21:44 - 00001167 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-11-30 21:44 - 2015-11-30 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-11-30 21:44 - 2015-11-30 21:44 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-11-30 21:44 - 2015-11-30 21:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-11-30 21:44 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-11-30 21:44 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-11-30 21:44 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2015-11-30 21:40 - 2015-11-30 21:40 - 00000200 _____ C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
    2015-11-30 21:39 - 2015-11-30 21:39 - 35768808 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumdim32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 30404056 _____ (Intel Corporation) C:\Windows\system32\igd11dxva64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 29613040 _____ (Intel Corporation) C:\Windows\SysWOW64\igd11dxva32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 29084160 _____ (Intel Corporation) C:\Windows\system32\common_clang64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 19844096 _____ (Intel Corporation) C:\Windows\SysWOW64\common_clang32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 13211648 _____ (Intel Corporation) C:\Windows\system32\ig8icd64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 12880160 _____ (Intel Corporation) C:\Windows\system32\igc64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 10528136 _____ (Intel Corporation) C:\Windows\SysWOW64\igc32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 10032128 _____ (Intel Corporation) C:\Windows\SysWOW64\ig8icd32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 06741482 _____ C:\Windows\system32\igdclbif.bin
    2015-11-30 21:39 - 2015-11-30 21:39 - 05467648 _____ (Intel Corporation) C:\Windows\system32\igdmcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 05245440 _____ (Intel Corporation) C:\Windows\system32\GfxResources.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 05121136 _____ (Intel Corporation) C:\Windows\system32\igd12umd64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 05092320 _____ (Intel Corporation) C:\Windows\SysWOW64\igd12umd32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 04443136 _____ (Intel Corporation) C:\Windows\system32\igdrcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 03873280 _____ (Intel Corporation) C:\Windows\SysWOW64\igdrcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 03801600 _____ (Intel Corporation) C:\Windows\SysWOW64\igdmcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01858632 _____ (Intel Corporation) C:\Windows\system32\igdmd64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01767992 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01765408 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01565696 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01456408 _____ (Intel Corporation) C:\Windows\SysWOW64\igdmd32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01216000 _____ (Intel Corporation) C:\Windows\system32\igdfcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01156608 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 01008016 _____ C:\Windows\system32\igfxSDK.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00970752 _____ (Intel Corporation) C:\Windows\SysWOW64\igdfcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00927120 _____ (Intel Corporation) C:\Windows\system32\Gfxv4_0.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00923536 _____ (Intel Corporation) C:\Windows\system32\Gfxv2_0.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00803113 _____ C:\Windows\system32\DisplayAudiox64.cab
    2015-11-30 21:39 - 2015-11-30 21:39 - 00624128 _____ (Intel Corporation) C:\Windows\system32\MetroIntelGenericUIFramework.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00589712 _____ C:\Windows\system32\IntelCpHDCPSvc.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00519056 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiUMS64.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00511260 _____ C:\Windows\system32\cp_resources.bin
    2015-11-30 21:39 - 2015-11-30 21:39 - 00448912 _____ (Intel Corporation) C:\Windows\system32\GfxUIEx.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00425472 _____ (Intel Corporation) C:\Windows\system32\igdbcl64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00397824 _____ (Intel Corporation) C:\Windows\system32\IntelOpenCL64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00386048 _____ (Intel Corporation) C:\Windows\system32\igfxOSP.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00373248 _____ (Intel Corporation) C:\Windows\SysWOW64\igdbcl32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00331808 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiMCComp64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00313888 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiUtils64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00300032 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelOpenCL32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00284280 _____ (Intel Corporation) C:\Windows\system32\igd10idpp64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00283024 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00269360 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10idpp32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00256000 _____ C:\Windows\system32\igfxCPL.cpl
    2015-11-30 21:39 - 2015-11-30 21:39 - 00243200 _____ (Intel Corporation) C:\Windows\system32\igfxDTCM.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00219024 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00214416 _____ (Intel Corporation) C:\Windows\system32\DPTopologyApp.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00213904 _____ (Intel Corporation) C:\Windows\system32\DPTopologyAppv2_0.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00206848 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v4256.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00200856 _____ (Intel Corporation) C:\Windows\system32\igdde64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00172032 _____ (Intel Corporation) C:\Windows\system32\igdail64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00163776 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00162752 _____ (Intel Corporation) C:\Windows\system32\igfx11cmrt64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00160680 _____ (Intel Corporation) C:\Windows\SysWOW64\igdde32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00157072 _____ (Intel Corporation) C:\Windows\system32\difx64.exe
    2015-11-30 21:39 - 2015-11-30 21:39 - 00153600 _____ (Intel Corporation) C:\Windows\SysWOW64\igdail32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00143904 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiLogServer64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00141080 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00140056 _____ (Intel Corporation) C:\Windows\SysWOW64\igfx11cmrt32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00090112 _____ ( ) C:\Windows\system32\igfxSDKLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00086528 _____ (Khronos Group) C:\Windows\SysWOW64\Intel_OpenCL_ICD32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00086016 _____ C:\Windows\system32\igfxCUIServicePS.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00082944 _____ ( ) C:\Windows\system32\igfxSDKLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00082432 _____ (Khronos Group) C:\Windows\system32\Intel_OpenCL_ICD64.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00073728 _____ ( ) C:\Windows\system32\igfxDHLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00064512 _____ ( ) C:\Windows\system32\igfxDHLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00036616 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00035328 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00011776 _____ ( ) C:\Windows\system32\igfxDILib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00011264 _____ ( ) C:\Windows\system32\igfxDILibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00010240 _____ ( ) C:\Windows\system32\igfxEMLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00010240 _____ ( ) C:\Windows\system32\igfxEMLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00005120 _____ ( ) C:\Windows\system32\igfxLHMLibv2_0.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00005120 _____ ( ) C:\Windows\system32\igfxLHMLib.dll
    2015-11-30 21:39 - 2015-11-30 21:39 - 00004682 _____ C:\Windows\system32\iglhxs64.vp
    2015-11-30 21:37 - 2015-11-30 21:43 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Mozilla
    2015-11-30 21:37 - 2015-11-30 21:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2015-11-30 21:37 - 2015-11-30 21:37 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Mozilla
    2015-11-30 21:34 - 2015-11-30 21:34 - 00243656 _____ C:\Users\Dykes family\Downloads\Firefox Setup Stub 42.0.exe
    2015-11-30 21:28 - 2015-11-30 21:28 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Macromedia
    2015-11-30 21:28 - 2015-11-30 21:28 - 00000000 ____D C:\Users\Dykes family\AppData\Local\MicrosoftEdge
    2015-11-30 21:27 - 2015-12-04 19:48 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Toshiba
    2015-11-30 21:27 - 2015-11-30 21:28 - 00002351 _____ C:\Users\Dykes family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2015-11-30 21:27 - 2015-11-30 21:28 - 00000000 ___RD C:\Users\Dykes family\OneDrive
    2015-11-30 21:25 - 2015-11-30 21:25 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Publishers
    2015-11-30 21:23 - 2015-12-05 11:07 - 00000000 __SHD C:\Users\Dykes family\IntelGraphicsProfiles
    2015-11-30 21:23 - 2015-12-04 20:08 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Packages
    2015-11-30 21:23 - 2015-12-04 19:52 - 00000000 ____D C:\Users\Dykes family\AppData\Local\VirtualStore
    2015-11-30 21:23 - 2015-12-04 19:45 - 00000000 ____D C:\Users\Dykes family
    2015-11-30 21:23 - 2015-11-30 21:23 - 00016148 _____ C:\Windows\system32\LAPTOP-L02074TA_defaultuser0_HistoryPrediction.bin
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000020 ___SH C:\Users\Dykes family\ntuser.ini
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\My Documents
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Videos
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Pictures
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Music
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Adobe
    2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 ____D C:\Users\Dykes family\AppData\Local\TileDataLayer
    2015-11-30 21:15 - 2015-12-05 11:07 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2015-11-30 21:11 - 2015-08-18 23:50 - 00609592 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
    2015-11-30 21:11 - 2015-07-25 01:29 - 04532304 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2015-11-30 21:11 - 2015-07-24 23:54 - 04047288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
    2015-11-30 21:11 - 2015-07-21 22:52 - 00988672 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-05 13:11 - 2015-07-10 04:05 - 00000000 ____D C:\Windows
    2015-12-05 11:22 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\system32\NDF
    2015-12-05 11:11 - 2015-09-25 07:08 - 00875126 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-12-05 11:11 - 2015-07-10 06:02 - 00000000 ____D C:\Windows\INF
    2015-12-05 11:08 - 2015-09-25 07:06 - 00000000 __RHD C:\Users\Public\AccountPictures
    2015-12-05 11:07 - 2015-09-25 07:47 - 00000000 ____D C:\ProgramData\McAfee
    2015-12-05 11:07 - 2015-09-25 07:47 - 00000000 ____D C:\Program Files\Common Files\McAfee
    2015-12-05 11:07 - 2015-07-10 07:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-12-05 11:06 - 2015-07-10 04:05 - 00262144 ___SH C:\Windows\system32\config\BBI
    2015-12-05 11:05 - 2015-07-10 06:04 - 00000000 ___HD C:\Windows\ELAMBKUP
    2015-12-05 11:05 - 2015-07-10 04:05 - 00032768 ___SH C:\Windows\system32\config\ELAM
    2015-12-05 08:33 - 2015-09-25 07:23 - 00000000 ____D C:\ProgramData\Conexant
    2015-12-04 20:18 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\LiveKernelReports
    2015-12-04 20:17 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\AppReadiness
    2015-12-04 20:15 - 2015-07-10 06:04 - 00000000 ___HD C:\Program Files\WindowsApps
    2015-12-04 20:08 - 2015-07-10 05:55 - 00000000 ____D C:\Windows\CbsTemp
    2015-12-04 19:45 - 2015-07-10 07:20 - 00221152 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-12-03 07:52 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\appcompat
    2015-11-30 21:56 - 2015-07-10 06:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2015-11-30 21:56 - 2015-07-10 06:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-11-30 21:40 - 2015-09-25 07:19 - 00000000 ___HD C:\Intel
    2015-11-30 21:39 - 2015-09-25 07:20 - 00086528 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL
    2015-11-30 21:39 - 2015-09-25 07:20 - 00082432 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL
    2015-11-30 21:39 - 2015-03-12 01:50 - 36681912 _____ (Intel Corporation) C:\Windows\system32\igdumdim64.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 13727296 _____ (Intel Corporation) C:\Windows\system32\igd10iumd64.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 11276968 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10iumd32.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 06389688 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
    2015-11-30 21:39 - 2015-03-12 01:50 - 06305696 _____ (Intel Corporation) C:\Windows\system32\igdusc64.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 04841488 _____ (Intel Corporation) C:\Windows\SysWOW64\igdusc32.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 02028032 _____ (Intel Corporation) C:\Windows\system32\igfxLHM.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 00723456 _____ (Intel Corporation) C:\Windows\system32\igfxDH.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 00396688 _____ C:\Windows\system32\igfxTray.exe
    2015-11-30 21:39 - 2015-03-12 01:50 - 00353280 _____ (Intel Corporation) C:\Windows\system32\igfxDI.dll
    2015-11-30 21:39 - 2015-03-12 01:50 - 00351120 _____ (Intel Corporation) C:\Windows\system32\igfxCUIService.exe
    2015-11-30 21:39 - 2015-03-12 01:50 - 00328080 _____ (Intel Corporation) C:\Windows\system32\igfxEM.exe
    2015-11-30 21:39 - 2015-03-12 01:50 - 00249232 _____ (Intel Corporation) C:\Windows\system32\igfxHK.exe
    2015-11-30 21:18 - 2015-09-25 07:28 - 00000000 ____D C:\ProgramData\TOSHIBA
    2015-11-30 21:11 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\rescache

    ==================== Files in the root of some directories =======

    2015-12-05 08:30 - 2015-12-05 08:30 - 0009216 _____ () C:\Users\Dykes family\AppData\Local\kdapll.dll
    2015-12-05 08:30 - 2015-12-05 08:30 - 0002560 _____ () C:\Users\Dykes family\AppData\Local\uninstall.exe

    Files to move or delete:
    ====================
    C:\Users\Public\VOIP.dat


    Some files in TEMP:
    ====================
    C:\Users\Dykes family\AppData\Local\Temp\0277961449331430mcinst.exe
    C:\Users\Dykes family\AppData\Local\Temp\McCSPInstall.dll
    C:\Users\Dykes family\AppData\Local\Temp\mccspuninstall.exe
    C:\Users\Dykes family\AppData\Local\Temp\SpOrder.dll
    C:\Users\Dykes family\AppData\Local\Temp\Synaptics+Pointing+Device__10924_i1770961372_il1819696.exe
    C:\Users\Dykes family\AppData\Local\Temp\UninstallModule.exe


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll
    [2015-07-10 06:00] - [2015-07-10 06:00] - 0680256 ____A (Microsoft Corporation) CB664E4F97242D9D620692FE1E5A40C2

    C:\Windows\SysWOW64\dnsapi.dll
    [2015-07-10 06:00] - [2015-07-10 06:00] - 0534064 ____A (Microsoft Corporation) 9CD02B8104EA598C84D2BCF2B69784A9

    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-09-25 06:56

    ==================== End of FRST.txt ============================

     

     

     

     

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
    Ran by [removed] (2015-12-05 13:12:47)
    Running from E:\Downloads\Anti-malware programs
    Windows 10 Home (X64) (2015-12-01 02:14:34)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-843202709-3289130475-90754708-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-843202709-3289130475-90754708-503 - Limited - Disabled)
    Dykes family (S-1-5-21-843202709-3289130475-90754708-1001 - Administrator - Enabled) => C:\Users\Dykes family
    Guest (S-1-5-21-843202709-3289130475-90754708-501 - Limited - Disabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\uTorrent) (Version: 3.4.2.36615 - BitTorrent Inc.)
    Bluetooth(R) Link (HKLM\…\{3F3DCC8C-2C93-4082-A6DE-BBDC74804FA0}) (Version: 4.3.03 - Toshiba Corporation)
    Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.66.8.52 - Conexant)
    Copy Network Card (HKLM-x32\…\SoftwareUpdater) (Version: 1.0.0.0 - Copy Network Card) <==== ATTENTION
    CyberLink PowerDVD 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5509.05 - CyberLink Corp.)
    Free Video to DVD Converter (HKLM-x32\…\Free Video to DVD Converter_is1) (Version: 5.0.69.1127 - DVDVideoSoft Ltd.)
    Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
    Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4112 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
    Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
    Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
    Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Word 2013 (HKLM\…\Office15.WORD) (Version: 15.0.4569.1506 - Microsoft Corporation)
    Minecraft (HKLM-x32\…\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
    NetStream 1.0 (HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\NetStream 1.0) (Version:  - )
    Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
    Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10130.29089 - Realtek Semiconductor Corp.)
    Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
    Search Protect (HKLM-x32\…\SearchProtect) (Version: 3.0.90.9 - ) <==== ATTENTION
    Skype™ 7.15 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.15.102 - Skype Technologies S.A.)
    TOSHIBA Application Installer (HKLM\…\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.8 - Toshiba Corporation)
    TOSHIBA Audio Enhancement (HKLM\…\{1515F5E3-29EA-4CD1-A981-032D88880F09}) (Version: 3.0.0.9 - Toshiba Corporation)
    TOSHIBA Display Utility (HKLM\…\{0B39C39A-3ECE-4582-9C91-842D22819A24}) (Version: 2.0.1.0 - Toshiba Corporation)
    TOSHIBA Password Utility (HKLM-x32\…\InstallShield_{26BB68BB-CF93-4A12-BC6D-A3B6F53AC8D9}) (Version: 8.1.1.0 - Toshiba Corporation)
    TOSHIBA Service Station (HKLM\…\{0DFA8761-7735-4DE8-A0EB-2286578DCFC6}) (Version: 2.6.14 - Toshiba Corporation)
    TOSHIBA System Driver (HKLM-x32\…\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 2.00.0005 - Toshiba Corporation)
    TOSHIBA System Settings (HKLM\…\{B040D5C9-C9AA-430A-A44E-696656012E61}) (Version: 3.0.0.6406 - Toshiba Corporation)
    TOSHIBA User's Guide (HKLM-x32\…\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-843202709-3289130475-90754708-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Dykes family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

    ==================== Restore Points =========================

    30-11-2015 21:11:54 Windows Modules Installer
    30-11-2015 21:48:25 Day 1 of laptop
    04-12-2015 19:50:38 Installed Minecraft

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-07-10 06:04 - 2015-07-10 06:02 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {02C0A321-FD63-4DE7-8EDB-EB21DB915B0C} - System32\Tasks\{5236EBB1-7687-40F3-95D6-10FB965F7948} => launchwinapp.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=4.1.0.166&LastError;=404
    Task: {06EBFEF3-D10F-4C99-ABFE-0E6DD5D2F4B1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
    Task: {2A49C756-107C-4F3E-AD56-CC0F42EFEEC0} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2015-06-12] (TOSHIBA Corporation)
    Task: {4603A09B-4202-4DFE-8E18-163233E6CECD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
    Task: {469026FE-68F5-48BD-B29A-4D4AD6422F69} - System32\Tasks\MyDailyBackup => C:\Windows\system32\winupd.exe <==== ATTENTION
    Task: {53F06927-DA16-4A76-9CA7-BB66BF0CBD86} - System32\Tasks\win => C:\Windows\system32\win.exe
    Task: {55168871-DE97-4CF0-BB01-B7E68DB49571} - \impo -> No File <==== ATTENTION
    Task: {5B554B79-11E1-4622-9A36-63A7CC6C9000} - System32\Tasks\BTSchedulerTask => C:\Program Files (x86)\TOSHIBA\Toshiba Bluetooth Device Profile Utility\TosBt_NotificationScheduler.exe [2015-07-08] (Toshiba Corporation)
    Task: {5F753A44-BB07-47CC-90F9-8D55A51EEF24} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2014-04-03] (TOSHIBA Corporation)
    Task: {632CD2E0-A082-4CB6-A66E-F0D23CB52915} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
    Task: {6F792032-E46E-4F9F-A51C-66329AF9D144} - System32\Tasks\GoogleUp => C:\Windows\system32\hsysinfo.exe
    Task: {7BCB58D7-FC51-4AAF-95F5-3679D470A307} - System32\Tasks\import => C:\Windows\system32\Mint.exe
    Task: {7E884694-3DEA-4F4D-9586-86D599E51FD8} - System32\Tasks\Googleuptodate => C:\Windows\system32\Wimboldon.exe
    Task: {D116B680-9F38-44DB-90AF-7A8C7A77DFC6} - System32\Tasks\Biain => C:\PROGRA~1\SHOPPE~1\Mennulw.bat
    Task: {DD434CB0-D0FE-450E-A70F-731EC66B31E6} - \bvxvhxvh -> No File <==== ATTENTION

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-07-10 06:00 - 2015-07-10 06:00 - 00032768 _____ () C:\Windows\SYSTEM32\licensemanagerapi.dll
    2015-07-16 09:43 - 2015-07-16 09:43 - 00403968 _____ () C:\Windows\System32\diagtrack_wininternal.dll
    2015-07-10 06:00 - 2015-07-10 06:00 - 02498296 _____ () C:\Windows\system32\CoreUIComponents.dll
    2015-07-10 06:00 - 2015-07-10 06:00 - 02498296 _____ () C:\Windows\System32\CoreUIComponents.dll
    2015-03-12 01:50 - 2015-11-30 21:39 - 00396688 _____ () C:\Windows\system32\igfxTray.exe
    2015-07-10 05:59 - 2015-07-10 05:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2012-07-18 20:38 - 2012-07-18 20:38 - 00020904 _____ () C:\Program Files\TOSHIBA\System Setting\SmoothView.dll
    2015-07-10 06:00 - 2015-07-10 08:15 - 06579712 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2015-07-10 06:00 - 2015-07-10 08:15 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2015-07-10 06:00 - 2015-07-10 08:15 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2015-07-10 06:00 - 2015-07-10 08:15 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
    2015-12-04 20:04 - 2015-12-04 20:04 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
    2015-12-04 20:04 - 2015-12-04 20:04 - 11526656 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
    2015-12-04 20:02 - 2015-12-04 20:02 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
    2015-07-16 09:43 - 2015-07-16 09:43 - 02971648 _____ () C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy\AccountsControlUI.dll
    2015-11-30 22:03 - 2015-11-30 22:04 - 09074176 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.23.23.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
    2015-11-30 22:03 - 2015-11-30 22:04 - 02416640 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.23.23.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll
    2015-12-04 19:59 - 2015-12-04 19:59 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_11.11.19012.0_x64__8wekyb3d8bbwe\XboxApp.exe
    2015-12-04 19:59 - 2015-12-04 19:59 - 28704256 _____ () C:\Program Files\WindowsApps\Microsoft.XboxApp_11.11.19012.0_x64__8wekyb3d8bbwe\XboxApp.dll
    2015-12-05 08:30 - 2015-12-05 08:30 - 00009216 _____ () C:\Users\Dykes family\AppData\Local\kdapll.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Pajhunoour => ""="service"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-843202709-3289130475-90754708-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Innovation\Bishop Tree.jpg
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\Services: HomeNetSvc => 2
    MSCONFIG\Services: PCSUService => 2
    MSCONFIG\Services: SCService => 2

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{96C8546B-32FD-4AC8-8526-130F7848FA16}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
    FirewallRules: [{A0763D73-A490-4EA9-A3E9-FABAC2D73F91}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{5214CAD3-2A8C-4F4D-ADF0-98B30BDED6CB}] => (Allow) C:\Users\Dykes family\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{08A06DE6-E9A0-4ED3-80A9-893501D45650}] => (Allow) C:\Users\Dykes family\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{B0E073D4-455F-44E3-8476-20A4C39B421C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{9B137C5F-00C6-47CF-B259-7EA940886FF3}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩敮畴敳睜湩敮畴敳攮數
    FirewallRules: [{581F08B8-7B32-45FF-91F6-AAE9AD367F32}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶睜湩敮畴敳睜湩敮畴敳⹟硥e
    FirewallRules: [{CB0B5FBE-5B3F-4A98-A08C-DFFB10BFE152}] => (Allow) C:\Windows\system32\rundll32.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/05/2015 11:54:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:53:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:53:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:52:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:52:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:51:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:51:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:50:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:50:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

    Error: (12/05/2015 11:49:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
    Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.


    System errors:
    =============
    Error: (12/05/2015 01:11:31 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Windows Update service terminated with the following error:
    %%2147952506

    Error: (12/05/2015 01:11:31 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (12/05/2015 11:53:40 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Windows Update service terminated with the following error:
    %%2147952506

    Error: (12/05/2015 11:53:40 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (12/05/2015 11:51:40 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Windows Update service terminated with the following error:
    %%2147952506

    Error: (12/05/2015 11:51:40 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (12/05/2015 11:49:40 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Windows Update service terminated with the following error:
    %%2147952506

    Error: (12/05/2015 11:49:40 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (12/05/2015 11:47:40 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The Windows Update service terminated with the following error:
    %%2147952506

    Error: (12/05/2015 11:47:40 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-L02074TA)
    Description: {E60687F7-01A1-40AA-86AC-DB1CBF673334}


    CodeIntegrity:
    ===================================
      Date: 2015-12-05 08:37:42.890
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:37:13.044
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:36:04.341
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:35:56.706
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:35:55.000
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:35:54.830
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:35:54.669
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:35:54.462
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:35:54.284
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

      Date: 2015-12-05 08:35:54.126
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz
    Percentage of memory in use: 17%
    Total physical RAM: 8106.14 MB
    Available physical RAM: 6714.13 MB
    Total Virtual: 16810.14 MB
    Available Virtual: 15454.83 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:930.79 GB) (Free:893.9 GB) NTFS
    Drive e: (KINGSTON) (Removable) (Total:14.53 GB) (Free:5.03 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 931.5 GB) (Disk ID: 00000000)

    Partition: GPT.

    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 14.5 GB) (Disk ID: C3072E18)
    Partition 1: (Active) - (Size=14.5 GB) - (Type=0C)

    ==================== End of Addition.txt ============================

    Hi,

     

    You have a lot going on. Before we proceed what can you tell me about Microsoft Word, there is a marker in your log to suggest its not valid.  You have uTorrent installed, bad idea, almost 100% of programs downloaded via the torrents are infected, you need to go to Programs and Features in the Control Panel and uninstall it. If word was downloaded via the torrents than you need to uninstall that too. Look through your Additions log under Firewall rules, uTorrent has access in and out of your computer bringing with it whatever it wants.

     

    We have a lot to do so hang on to your hat

     

    Your running FRST64 from E:\Downloads\Anti-malware programs, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST64, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST64 exactly where we want it to be. 

     

     

    Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
    Please copy the entire contents Inside of the code box below beginning with START and ending with END
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
    Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
     
    Start
    CloseProcesses:
    CreateRestorePoint: 
    HKLM\…\Run: [] => [X]
    HKLM\…\Policies\Explorer: [NoFolderOptions] 0
    HKLM\…\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\Run: [kdapll] => rundll32.exe "C:\Users\Dykes family\AppData\Local\kdapll.dll",kdapll <===== ATTENTION
    AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC64LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [247056 2015-11-15] ()
    AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219920 2015-11-15] ()
    Winsock: Catalog9 01 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 02 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 03 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 04 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 17 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9-x64 01 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 02 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 03 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 04 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 17 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> DefaultScope {E87B3EAC-41A7-4ECB-A37A-761A3EF860B2} URL =
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=M3BCD1F74-8D9A-4738-ACD0-BB13B3ED1F63&SearchSource=58&CUI=&UM=8&UP=SP24C44E74-9150-4124-B00A-94C809105872&D=120515&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {8364220B-8A5F-4522-938F-CCF2F039BD0B} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=FC5zftpbl2,6bc8c4ff-6b73-422f-92dc-567c954134f5,
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {E87B3EAC-41A7-4ECB-A37A-761A3EF860B2} URL =
    FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=M3BCD1F74-8D9A-4738-ACD0-BB13B3ED1F63&SearchSource=69&CUI=&SSPV=&Lay=1&UM=8&UP=SP24C44E74-9150-4124-B00A-94C809105872&D=120515
    FF Extension: AdBeaver - C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\Extensions\[removed] [2015-11-24]
    2015-12-05 08:42 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\Documents\PCSpeedUp
    2015-12-05 08:40 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\AppData\Local\bvxvhxvh
    2015-12-05 08:40 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\SearchProtect
    2015-12-05 08:40 - 2015-12-05 08:40 - 00000000 ____D C:\Users\Dykes family\AppData\Local\SearchProtect
    2015-12-05 08:33 - 2015-12-05 11:06 - 00000000 ____D C:\Program Files\shopperz051220150818
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003582 _____ C:\Windows\System32\Tasks\MyDailyBackup
    2015-12-05 08:33 - 2015-12-05 08:33 - 00004800 _____ C:\Windows\SysWOW64\Pajhunoour.ini
    2015-12-05 08:33 - 2015-12-05 08:33 - 00002520 _____ C:\Windows\SysWOW64\PajhunoourOff.ini
    2015-12-05 08:33 - 2015-12-05 08:33 - 00002520 _____ C:\Windows\system32\PajhunoourOff.ini
    2015-12-05 08:33 - 2015-12-05 06:13 - 00375152 ____N C:\Windows\system32\Pajhunoour64.dll
    2015-12-05 08:33 - 2015-12-05 06:12 - 00289136 ____N C:\Windows\SysWOW64\Pajhunoour.dll
    2015-12-05 08:31 - 2015-12-05 11:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up
    2015-12-05 08:31 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\PC Speed Up
    2015-12-05 08:31 - 2015-12-05 08:31 - 00000000 ____D C:\Program Files (x86)\Consumer Input
    2015-12-05 08:30 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files\Faster Web
    2015-12-05 08:30 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\Faster Web
    Task: {469026FE-68F5-48BD-B29A-4D4AD6422F69} - System32\Tasks\MyDailyBackup => C:\Windows\system32\winupd.exe <==== ATTENTION
    Task: {55168871-DE97-4CF0-BB01-B7E68DB49571} - \impo -> No File <==== ATTENTION
    Task: {D116B680-9F38-44DB-90AF-7A8C7A77DFC6} - System32\Tasks\Biain => C:\PROGRA~1\SHOPPE~1\Mennulw.bat
    Task: {DD434CB0-D0FE-450E-A70F-731EC66B31E6} - \bvxvhxvh -> No File <==== ATTENTION
    FirewallRules: [{5214CAD3-2A8C-4F4D-ADF0-98B30BDED6CB}] => (Allow) C:\Users\Dykes family\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{08A06DE6-E9A0-4ED3-80A9-893501D45650}] => (Allow) C:\Users\Dykes family\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{9B137C5F-00C6-47CF-B259-7EA940886FF3}] => (Allow) ???????????????????????
    FirewallRules: [{581F08B8-7B32-45FF-91F6-AAE9AD367F32}] => (Allow) ???????????????????????e
    Hosts:
    CMD: ipconfig /flushdns
    EmptyTemp:
    End
    
     
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
     
     
     
    =======================================================================
     
     

     
    -AdwCleaner-by Xplode
     
    Click on this link to download : ADWCleaner TO YOUR DESKTOP
    Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
    Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
     
     
    Do not click on any links in the top Advertisment.
     
    [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
     
    •  
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
     
     
     
    ===============================================================================
     
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
    •  
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
     
     
     
    ===============================================================================
     
    Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
     
    •  
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
     
     
    [external image: 0841859c-1a35-4dbd-b41a-e720629e3e22_zps]
     
    •  
    • On the Dashboard click on Update Now
    • Go to the Setting Tab
    • Under Setting go to Detection and Protection
    • Under PUP and PUM make sure both are set to show Treat Detections as Malware
    • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
    • Then on the Dashboard click on Scan
    • Make sure to select THREAT SCAN
    • Then click on Scan
    • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
    • Please paste the log back into this thread for review
    • Exit Malwarebytes
     
     

     

    Results of the FRST scan:

     

    Fix result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
    Ran by [removed] (2015-12-05 14:54:47) Run:1
    Running from C:\Users\[removed]\Desktop
    [removed] Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start
    CloseProcesses:
    CreateRestorePoint:
    HKLM\…\Run: [] => [X]
    HKLM\…\Policies\Explorer: [NoFolderOptions] 0
    HKLM\…\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\Run: [kdapll] => rundll32.exe "C:\Users\Dykes family\AppData\Local\kdapll.dll",kdapll <===== ATTENTION
    AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC64LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [247056 2015-11-15] ()
    AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219920 2015-11-15] ()
    Winsock: Catalog9 01 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 02 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 03 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 04 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9 17 C:\Windows\SysWOW64\Pajhunoour.dll [289136 2015-12-05] ()
    Winsock: Catalog9-x64 01 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 02 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 03 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 04 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    Winsock: Catalog9-x64 17 C:\Windows\system32\Pajhunoour64.dll [375152 2015-12-05] ()
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> DefaultScope {E87B3EAC-41A7-4ECB-A37A-761A3EF860B2} URL =
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=M3BCD1F74-8D9A-4738-ACD0-BB13B3ED1F63&SearchSource=58&CUI=&UM=8&UP=SP24C44E74-9150-4124-B00A-94C809105872&D=120515&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {8364220B-8A5F-4522-938F-CCF2F039BD0B} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=FC5zftpbl2,6bc8c4ff-6b73-422f-92dc-567c954134f5,
    SearchScopes: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> {E87B3EAC-41A7-4ECB-A37A-761A3EF860B2} URL =
    FF NewTab: hxxp://www.trovi.com/?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=M3BCD1F74-8D9A-4738-ACD0-BB13B3ED1F63&SearchSource=69&CUI=&SSPV=&Lay=1&UM=8&UP=SP24C44E74-9150-4124-B00A-94C809105872&D=120515
    FF Extension: AdBeaver - C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\Extensions\[removed] [2015-11-24]
    2015-12-05 08:42 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\Documents\PCSpeedUp
    2015-12-05 08:40 - 2015-12-05 11:00 - 00000000 ____D C:\Users\Dykes family\AppData\Local\bvxvhxvh
    2015-12-05 08:40 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\SearchProtect
    2015-12-05 08:40 - 2015-12-05 08:40 - 00000000 ____D C:\Users\Dykes family\AppData\Local\SearchProtect
    2015-12-05 08:33 - 2015-12-05 11:06 - 00000000 ____D C:\Program Files\shopperz051220150818
    2015-12-05 08:33 - 2015-12-05 08:33 - 00003582 _____ C:\Windows\System32\Tasks\MyDailyBackup
    2015-12-05 08:33 - 2015-12-05 08:33 - 00004800 _____ C:\Windows\SysWOW64\Pajhunoour.ini
    2015-12-05 08:33 - 2015-12-05 08:33 - 00002520 _____ C:\Windows\SysWOW64\PajhunoourOff.ini
    2015-12-05 08:33 - 2015-12-05 08:33 - 00002520 _____ C:\Windows\system32\PajhunoourOff.ini
    2015-12-05 08:33 - 2015-12-05 06:13 - 00375152 ____N C:\Windows\system32\Pajhunoour64.dll
    2015-12-05 08:33 - 2015-12-05 06:12 - 00289136 ____N C:\Windows\SysWOW64\Pajhunoour.dll
    2015-12-05 08:31 - 2015-12-05 11:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up
    2015-12-05 08:31 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\PC Speed Up
    2015-12-05 08:31 - 2015-12-05 08:31 - 00000000 ____D C:\Program Files (x86)\Consumer Input
    2015-12-05 08:30 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files\Faster Web
    2015-12-05 08:30 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\Faster Web
    Task: {469026FE-68F5-48BD-B29A-4D4AD6422F69} - System32\Tasks\MyDailyBackup => C:\Windows\system32\winupd.exe <==== ATTENTION
    Task: {55168871-DE97-4CF0-BB01-B7E68DB49571} - \impo -> No File <==== ATTENTION
    Task: {D116B680-9F38-44DB-90AF-7A8C7A77DFC6} - System32\Tasks\Biain => C:\PROGRA~1\SHOPPE~1\Mennulw.bat
    Task: {DD434CB0-D0FE-450E-A70F-731EC66B31E6} - \bvxvhxvh -> No File <==== ATTENTION
    FirewallRules: [{5214CAD3-2A8C-4F4D-ADF0-98B30BDED6CB}] => (Allow) C:\Users\Dykes family\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{08A06DE6-E9A0-4ED3-80A9-893501D45650}] => (Allow) C:\Users\Dykes family\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{9B137C5F-00C6-47CF-B259-7EA940886FF3}] => (Allow) ???????????????????????
    FirewallRules: [{581F08B8-7B32-45FF-91F6-AAE9AD367F32}] => (Allow) ???????????????????????e
    Hosts:
    CMD: ipconfig /flushdns
    EmptyTemp:
    End
    *****************

    Processes closed successfully.
    Restore point was successfully created.
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value removed successfully
    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value removed successfully
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\Software\Microsoft\Windows\CurrentVersion\Run\\kdapll => value removed successfully
    "C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC64LO~1.DLL" => Value data removed successfully.
    "C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL" => Value data removed successfully.
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004" => key removed successfully
    "HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000017" => key removed successfully
    HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
    HKU\S-1-5-21-843202709-3289130475-90754708-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
    "HKU\S-1-5-21-843202709-3289130475-90754708-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => key removed successfully
    HKCR\CLSID\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found.
    "HKU\S-1-5-21-843202709-3289130475-90754708-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8364220B-8A5F-4522-938F-CCF2F039BD0B}" => key removed successfully
    HKCR\CLSID\{8364220B-8A5F-4522-938F-CCF2F039BD0B} => key not found.
    "HKU\S-1-5-21-843202709-3289130475-90754708-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E87B3EAC-41A7-4ECB-A37A-761A3EF860B2}" => key removed successfully
    HKCR\CLSID\{E87B3EAC-41A7-4ECB-A37A-761A3EF860B2} => key not found.
    Firefox "newtab" removed successfully
    C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\Extensions\[removed] => moved successfully
    C:\Users\Dykes family\Documents\PCSpeedUp => moved successfully
    C:\Users\Dykes family\AppData\Local\bvxvhxvh => moved successfully
    C:\Program Files (x86)\SearchProtect => moved successfully
    C:\Users\Dykes family\AppData\Local\SearchProtect => moved successfully
    C:\Program Files\shopperz051220150818 => moved successfully
    C:\Windows\System32\Tasks\MyDailyBackup => moved successfully
    C:\Windows\SysWOW64\Pajhunoour.ini => moved successfully
    C:\Windows\SysWOW64\PajhunoourOff.ini => moved successfully
    C:\Windows\system32\PajhunoourOff.ini => moved successfully
    C:\Windows\system32\Pajhunoour64.dll => moved successfully
    C:\Windows\SysWOW64\Pajhunoour.dll => moved successfully
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up => moved successfully
    C:\Program Files (x86)\PC Speed Up => moved successfully
    C:\Program Files (x86)\Consumer Input => moved successfully
    C:\Program Files\Faster Web => moved successfully
    C:\Program Files (x86)\Faster Web => moved successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{469026FE-68F5-48BD-B29A-4D4AD6422F69}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{469026FE-68F5-48BD-B29A-4D4AD6422F69}" => key removed successfully
    C:\Windows\System32\Tasks\MyDailyBackup => not found.
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MyDailyBackup" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{55168871-DE97-4CF0-BB01-B7E68DB49571}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55168871-DE97-4CF0-BB01-B7E68DB49571}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\impo" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D116B680-9F38-44DB-90AF-7A8C7A77DFC6}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D116B680-9F38-44DB-90AF-7A8C7A77DFC6}" => key removed successfully
    C:\Windows\System32\Tasks\Biain => moved successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Biain" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DD434CB0-D0FE-450E-A70F-731EC66B31E6}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD434CB0-D0FE-450E-A70F-731EC66B31E6}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvhxvh" => key removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5214CAD3-2A8C-4F4D-ADF0-98B30BDED6CB} => value not found.
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{08A06DE6-E9A0-4ED3-80A9-893501D45650} => value not found.
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9B137C5F-00C6-47CF-B259-7EA940886FF3} => value removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{581F08B8-7B32-45FF-91F6-AAE9AD367F32} => value removed successfully
    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.

    =========  ipconfig /flushdns =========


    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========

    EmptyTemp: => 2 GB temporary data Removed.


    The system needed a reboot.

    ==== End of Fixlog 14:55:18 ====

     

     

     

     

    Results of the Adware cleaner scan:

     

    # AdwCleaner v5.023 - Logfile created 05/12/2015 at 15:09:22
    # Updated 30/11/2015 by Xplode
    # Database : 2015-12-03.1 [Server]
    # Operating system : Windows 10 Home  (x64)
    # Username : Dykes family - LAPTOP-L02074TA
    # Running from : C:\Users\Dykes family\Desktop\AdwCleaner.exe
    # Option : Cleaning
    # Support : http://toolslib.net/forum

    ***** [ Services ] *****

    [-] Service Deleted : bsdriver
    [-] Service Deleted : CltMngSvc

    ***** [ Folders ] *****

    [-] Folder Deleted : C:\Program Files\WNEn
    [-] Folder Deleted : C:\Program Files (x86)\410000EC-1449321552-2044-2020-202020202020
    [-] Folder Deleted : C:\Program Files (x86)\gmsd_us_005010167
    [-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
    [-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WNEn
    [-] Folder Deleted : C:\Users\Dykes family\AppData\Local\Microsoft\Silverlight\OutOfBrowser\Speedchecker.PCSpeedUp
    [-] Folder Deleted : C:\Users\Dykes family\AppData\Local\gmsd_us_005010167
    [-] Folder Deleted : C:\Users\Dykes family\AppData\Local\410000EC-1449303607-2044-2020-202020202020
    [-] Folder Deleted : C:\Users\Dykes family\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
    [-] Folder Deleted : C:\Users\Dykes family\AppData\Roaming\NUIns

    ***** [ Files ] *****

    [-] File Deleted : C:\END
    [-] File Deleted : C:\Windows\SysNative\drivers\bsdriver.sys
    [-] File Deleted : C:\Windows\SysNative\drivers\cherimoya.sys

    ***** [ DLLs ] *****

    [-] File Disinfected : C:\Windows\SysNative\dnsapi.dll
    [-] File Disinfected : C:\Windows\SysWOW64\dnsapi.dll

    ***** [ Shortcuts ] *****


    ***** [ Scheduled tasks ] *****


    ***** [ Registry ] *****

    [-] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Itibiti.exe]
    [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{79F768ED-0B12-42EF-8257-36751A0ECF3A}]
    [-] Key Deleted : HKCU\Software\SearchProtect
    [-] Key Deleted : HKCU\Software\Tutorials
    [-] Key Deleted : HKCU\Software\tstamptoken
    [-] Key Deleted : HKCU\Software\{DF9F804D-8E89-446E-8861-B3CFA5EB226C}
    [-] Key Deleted : HKLM\SOFTWARE\SearchProtect
    [-] Key Deleted : HKLM\SOFTWARE\SPPDCOM
    [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
    [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater
    [-] Key Deleted : HKU\.DEFAULT\Software\{DF9F804D-8E89-446E-8861-B3CFA5EB226C}
    [-] Key Deleted : HKU\S-1-5-19\Software\{DF9F804D-8E89-446E-8861-B3CFA5EB226C}
    [-] Key Deleted : HKU\S-1-5-20\Software\{DF9F804D-8E89-446E-8861-B3CFA5EB226C}
    [-] Key Deleted : HKU\S-1-5-21-843202709-3289130475-90754708-1001_Classes\Software\{DF9F804D-8E89-446E-8861-B3CFA5EB226C}
    [-] Data Restored : HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{26b11a49-585f-4b43-a90c-9af3c3d7b25b} [NameServer]
    [-] Data Restored : HKLM\SYSTEM\ControlSet001\services\Tcpip\Parameters\Interfaces\{26b11a49-585f-4b43-a90c-9af3c3d7b25b} [NameServer]

    ***** [ Web browsers ] *****

    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_executeCode", "not set");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_ga_redirected", "not set");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_ga_redirectedUrl", "not set");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_lastUpdate", "14493300480858641449330048086");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_redirectURL", "not set");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_referer", "not set");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_status", "active");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_VBATES_whiteList", "not set");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_installer_name", "vbates_clkmusex_.exe");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_pxl_VBATES_dailyPing", "dailyPing1449409736598");
    [-] [C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default\prefs.js] [Preference] Deleted : user_pref("{41986BD2-6C8C-4C9C-b8FE-33C58E88C4C9}.ScriptData_temp_installer_name", "vbates_clkmusex_.exe");

    *************************

    :: "Tracing" keys removed
    :: Winsock settings cleared

    ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [5553 bytes] ##########
     

     

     

    Results of the JRT scan. Not much, probably because my laptop hardly has anything on it:

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.0.1 (11.24.2015)
    Operating System: Windows 10 Home x64
    Ran by [removed] (Administrator) on Sat 12/05/2015 at 15:17:52.61
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    File System: 1

    Successfully deleted: C:\Users\Dykes family\Appdata\LocalLow\company (Folder)



    Registry: 0





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Sat 12/05/2015 at 15:19:41.63
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     

     

     

    Results of the Malwarebytes Antimalware scan. I didn't delete anything yet:

     

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 12/5/2015
    Scan Time: 3:24 PM
    Logfile: MBAM-scan-results.txt
    Administrator: Yes

    Version: 2.2.0.1024
    Malware Database: v2015.12.05.04
    Rootkit Database: v2015.11.26.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled

    OS: Windows 10
    CPU: x64
    File System: NTFS
    User: Dykes family

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 321671
    Time Elapsed: 24 min, 40 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 6
    PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\A7BD54B233B5B2F70AF86F5BD1A0C0A772A59FC6, , [90e81190acdf10268029029be41ea35d],
    PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\D830B6B8939ACB4928401060203BB648456BB4F8, , [3e3a3869c5c67abc7337603d669c45bb],
    PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\F53E693DDABF57A88A9B12B608B09B26C0608B74, , [4137188986056ccaeac14855dd2525db],
    PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\A7BD54B233B5B2F70AF86F5BD1A0C0A772A59FC6, , [93e5346d117a2115ddcc7726e71b7888],
    PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\D830B6B8939ACB4928401060203BB648456BB4F8, , [cbad1d84880396a0901a7b22e61c9b65],
    PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\F53E693DDABF57A88A9B12B608B09B26C0608B74, , [5424c8d91a71a195affcc1dc788a46ba],

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 1
    PUP.Optional.SimpleMediaPlayer, C:\Users\Dykes family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Simple Media Player, , [7602326f44474ee8b096d2cb34ce06fa],

    Files: 1
    PUP.Optional.HijackHosts.Gen, C:\Windows\System32\jike\faze\nid.dat, , [ff793d647e0d013538b603987f855ca4],

    Physical Sectors: 0
    (No malicious items detected)


    (end)

    I see you are around Castleberry, lived in Orlando and Winter Park for many years, currently in Brevard County, Florida's Spacecoast

     

    When you ran Malwarebytes did you have it remove what it found, your log should show those items Quarantined and it does not, you may have to run it again

     

    • You can highlight one of the detections by left clicking on it.
    • Then, right click on the highlighted detection, and select 'Check All Items'.
    • Next, click 'Remove Selected'. That should remove them all
    •  
       
      When  your done open up FRST and put a checkmark in Additions, run a new scan and post both the new FRST and Additions logs

      I deleted the items that Malwarebytes Antimalware found, btw. Thanks! I saw many "error" and "unable to verify" items. I hope those aren't problems.

       

      Here is the new FRST log file:

       

      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
      Ran by [removed] (administrator) on LAPTOP-L02074TA (05-12-2015 17:39:37)
      Running from C:\Users\[removed]\Desktop
      [removed] Platform: Windows 10 Home (X64) Language: English (United States)
      Internet Explorer Version 11 (Default browser: IE)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

      ==================== Processes (Whitelisted) =================

      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

      (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
      (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
      (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
      (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
      (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
      (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
      (TOSHIBA Corporation) C:\Program Files\TOSHIBA\System Setting\TCrdMain_Win8.exe
      (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
      (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
      (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
      (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
      () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
      (Microsoft Corporation) C:\Windows\System32\msiexec.exe
      (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16384_none_115fd2f761f7c508\TiWorker.exe
      (Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\eea27c0af0ca0ed43b6ca32b9a0d1077\WindowsUpdateBox.exe
      (Microsoft Corporation) C:\$WINDOWS.~BT\Sources\SetupHost.exe
      (Microsoft Corporation) C:\Windows\System32\rundll32.exe


      ==================== Registry (Whitelisted) ===========================

      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

      HKLM\…\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [599384 2015-06-05] (Conexant Systems, Inc.)
      HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
      HKLM\…\Run: [TCrdMain] => C:\Program Files\Toshiba\System Setting\TCrdMain_Win8.exe [511280 2015-06-23] (TOSHIBA Corporation)
      HKLM-x32\…\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [516976 2015-06-09] (TOSHIBA)
      HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\RunOnce: [Uninstall C:\Users\Dykes family\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes family\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"

      ==================== Internet (Whitelisted) ====================

      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

      Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
      Tcpip\..\Interfaces\{e79ab54d-b855-47b9-b876-73cdf5a0204e}: [DhcpNameServer] [removed]
      Tcpip\..\Interfaces\{efd1cb4d-c480-4627-af71-4f51f9ea6777}: [DhcpNameServer] 192.168.1.1

      Internet Explorer:
      ==================
      HKU\S-1-5-21-843202709-3289130475-90754708-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba15.msn.com/?pc=TBTE

      Edge:
      ======
      Edge HomeButtonPage: HKU\S-1-5-21-843202709-3289130475-90754708-1001 -> hxxp://www.google.com/

      FireFox:
      ========
      FF ProfilePath: C:\Users\Dykes family\AppData\Roaming\Mozilla\Firefox\Profiles\kjsbf1ya.default
      FF DefaultSearchEngine.US: Google
      FF Homepage: hxxps://www.google.com/
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
      FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)

      ==================== Services (Whitelisted) ========================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2278152 2015-09-25] (Broadcom Corporation.)
      R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [382312 2015-11-27] (Digital Wave Ltd.)
      R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-11-30] (Intel Corporation)
      S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
      R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation)
      S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
      R2 TOSRMService; C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\RMService.exe [326960 2015-06-24] (TOSHIBA)
      S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
      S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
      S2 Omobuvh; "C:\Users\Dykes family\AppData\Roaming\FijaeDejka\Avetde.exe" -cms [X]

      ===================== Drivers (Whitelisted) ==========================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [199472 2015-09-25] (Broadcom Corporation.)
      R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7593176 2015-07-10] (Broadcom Corporation)
      S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
      S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
      R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation)
      R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [301784 2015-06-01] (Realtek Semiconductor Corp.)
      R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-16] (Realtek                                            )
      R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-08-03] (Synaptics Incorporated)
      R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [45720 2015-06-13] (Toshiba Corporation)
      S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
      S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
      S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
      S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
      S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

      ==================== NetSvcs (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


      ==================== One Month Created files and folders ========

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2015-12-05 17:39 - 2015-12-05 17:39 - 00000000 ___HD C:\$WINDOWS.~BT
      2015-12-05 17:38 - 2015-12-05 17:39 - 00000000 ____D C:\Windows\system32\MRT
      2015-12-05 17:38 - 2015-10-27 18:43 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
      2015-12-05 17:37 - 2015-12-05 17:37 - 00016148 _____ C:\Windows\system32\LAPTOP-L02074TA_Dykes family_HistoryPrediction.bin
      2015-12-05 15:19 - 2015-12-05 15:19 - 00000642 _____ C:\Users\Dykes family\Desktop\JRT.txt
      2015-12-05 15:07 - 2015-12-05 15:09 - 00000000 ____D C:\AdwCleaner
      2015-12-05 15:04 - 2015-12-05 15:04 - 22908888 _____ (Malwarebytes ) C:\Users\Dykes family\Desktop\mbam-setup-2.2.0.1024.exe
      2015-12-05 15:03 - 2015-12-05 15:03 - 01599336 _____ (Malwarebytes) C:\Users\Dykes family\Desktop\JRT.exe
      2015-12-05 15:02 - 2015-12-05 15:02 - 01736704 _____ C:\Users\Dykes family\Desktop\AdwCleaner.exe
      2015-12-05 14:54 - 2015-12-05 14:55 - 00012549 _____ C:\Users\Dykes family\Desktop\Fixlog.txt
      2015-12-05 14:48 - 2015-12-05 14:48 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
      2015-12-05 13:17 - 2015-12-05 13:17 - 00022583 _____ C:\Users\Dykes family\Desktop\Addition.txt
      2015-12-05 13:16 - 2015-12-05 17:39 - 00007844 _____ C:\Users\Dykes family\Desktop\FRST.txt
      2015-12-05 13:11 - 2015-12-05 17:39 - 00000000 ____D C:\FRST
      2015-12-05 13:09 - 2015-12-05 13:09 - 02369024 _____ (Farbar) C:\Users\Dykes family\Desktop\FRST64.exe
      2015-12-05 11:06 - 2015-12-05 11:06 - 00000000 ____D C:\Windows\system32\jike
      2015-12-05 08:33 - 2015-12-05 11:00 - 00000000 ____D C:\uninst
      2015-12-05 08:33 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\Simple Media Player
      2015-12-05 08:33 - 2015-12-05 08:33 - 00003698 _____ C:\Windows\System32\Tasks\GoogleUp
      2015-12-05 08:33 - 2015-12-05 08:33 - 00003686 _____ C:\Windows\System32\Tasks\import
      2015-12-05 08:33 - 2015-12-05 08:33 - 00003592 _____ C:\Windows\System32\Tasks\Googleuptodate
      2015-12-05 08:33 - 2015-12-05 08:33 - 00003558 _____ C:\Windows\System32\Tasks\win
      2015-12-05 08:33 - 2015-12-05 08:33 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Tempfolder
      2015-12-05 08:31 - 2015-12-05 08:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
      2015-12-05 08:31 - 2015-12-05 08:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
      2015-12-05 08:30 - 2015-12-05 08:30 - 00009216 _____ C:\Users\Dykes family\AppData\Local\kdapll.dll
      2015-12-05 08:30 - 2015-12-05 08:30 - 00002560 _____ C:\Users\Dykes family\AppData\Local\uninstall.exe
      2015-12-05 08:29 - 2015-12-05 08:29 - 00000000 ____D C:\Users\Dykes family\AppData\Local\CEF
      2015-12-05 08:28 - 2015-12-05 11:00 - 00000000 ____D C:\Program Files (x86)\winnetuse
      2015-12-04 20:56 - 2015-12-04 20:56 - 00000000 ____D C:\Program Files\Synaptics
      2015-12-04 20:16 - 2015-12-04 20:16 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Synaptics
      2015-12-04 19:53 - 2015-12-05 11:13 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\.minecraft
      2015-12-04 19:53 - 2015-12-04 19:53 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\java
      2015-12-04 19:51 - 2015-12-04 19:51 - 00001030 _____ C:\Users\Public\Desktop\Minecraft.lnk
      2015-12-04 19:51 - 2015-12-04 19:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
      2015-12-04 19:51 - 2015-12-04 19:51 - 00000000 ____D C:\Program Files (x86)\Minecraft
      2015-12-04 19:30 - 2015-12-04 19:30 - 00000000 ____D C:\Users\Dykes family\AppData\Local\NetworkTiles
      2015-12-01 18:57 - 2015-12-05 11:04 - 00000000 ____D C:\Windows\System32\Tasks\McAfee
      2015-12-01 02:02 - 2015-12-01 07:35 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Comms
      2015-11-30 22:31 - 2015-11-30 22:31 - 00001577 _____ C:\Users\Public\Desktop\Free Video to DVD Converter.lnk
      2015-11-30 22:31 - 2015-11-30 22:31 - 00001376 _____ C:\Users\Public\Desktop\Free DVD Video Burner.lnk
      2015-11-30 22:31 - 2015-11-30 22:31 - 00001310 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
      2015-11-30 22:31 - 2015-11-30 22:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
      2015-11-30 22:31 - 2015-11-30 22:31 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
      2015-11-30 22:28 - 2015-11-30 22:30 - 26601640 _____ (DVDVideoSoft Ltd. ) C:\Users\Dykes family\Downloads\FreeVideoToDVDConverter.exe
      2015-11-30 22:25 - 2015-11-30 22:31 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\DVDVideoSoft
      2015-11-30 22:18 - 2015-11-30 22:18 - 00000013 __RSH C:\Windows\system32\Drivers\fbd.sys
      2015-11-30 22:17 - 2015-11-30 22:18 - 01388432 _____ C:\Users\Public\VOIP.dat
      2015-11-30 22:17 - 2015-11-30 22:17 - 00000000 ____D C:\Users\Dykes family\Tracing
      2015-11-30 22:10 - 2015-12-04 19:32 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Skype
      2015-11-30 22:10 - 2015-11-30 22:10 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
      2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ___RD C:\Program Files (x86)\Skype
      2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Skype
      2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ____D C:\ProgramData\Skype
      2015-11-30 22:10 - 2015-11-30 22:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
      2015-11-30 22:05 - 2015-11-30 22:05 - 01504384 _____ (Skype Technologies S.A.) C:\Users\Dykes family\Downloads\SkypeSetup.exe
      2015-11-30 22:04 - 2015-11-30 22:04 - 00003328 _____ C:\Windows\System32\Tasks\{5236EBB1-7687-40F3-95D6-10FB965F7948}
      2015-11-30 22:02 - 2015-12-05 14:25 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\uTorrent
      2015-11-30 21:59 - 2015-11-30 22:00 - 00000000 ____D C:\ProgramData\KMSAuto
      2015-11-30 21:59 - 2013-08-22 03:40 - 00040664 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tap0901.sys
      2015-11-30 21:58 - 2015-11-30 22:00 - 00000000 ____D C:\Users\Dykes family\AppData\Local\MSfree Inc
      2015-11-30 21:54 - 2015-12-05 14:24 - 00000000 ____D C:\Program Files\Microsoft Office
      2015-11-30 21:54 - 2015-11-30 21:54 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Microsoft Help
      2015-11-30 21:44 - 2015-12-05 15:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
      2015-11-30 21:44 - 2015-12-05 15:22 - 00001167 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
      2015-11-30 21:44 - 2015-12-05 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
      2015-11-30 21:44 - 2015-12-05 15:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
      2015-11-30 21:44 - 2015-11-30 21:44 - 00000000 ____D C:\ProgramData\Malwarebytes
      2015-11-30 21:44 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
      2015-11-30 21:44 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
      2015-11-30 21:44 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
      2015-11-30 21:40 - 2015-11-30 21:40 - 00000200 _____ C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
      2015-11-30 21:39 - 2015-11-30 21:39 - 35768808 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumdim32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 30404056 _____ (Intel Corporation) C:\Windows\system32\igd11dxva64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 29613040 _____ (Intel Corporation) C:\Windows\SysWOW64\igd11dxva32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 29084160 _____ (Intel Corporation) C:\Windows\system32\common_clang64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 19844096 _____ (Intel Corporation) C:\Windows\SysWOW64\common_clang32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 13211648 _____ (Intel Corporation) C:\Windows\system32\ig8icd64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 12880160 _____ (Intel Corporation) C:\Windows\system32\igc64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 10528136 _____ (Intel Corporation) C:\Windows\SysWOW64\igc32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 10032128 _____ (Intel Corporation) C:\Windows\SysWOW64\ig8icd32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 06741482 _____ C:\Windows\system32\igdclbif.bin
      2015-11-30 21:39 - 2015-11-30 21:39 - 05467648 _____ (Intel Corporation) C:\Windows\system32\igdmcl64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 05245440 _____ (Intel Corporation) C:\Windows\system32\GfxResources.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 05121136 _____ (Intel Corporation) C:\Windows\system32\igd12umd64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 05092320 _____ (Intel Corporation) C:\Windows\SysWOW64\igd12umd32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 04443136 _____ (Intel Corporation) C:\Windows\system32\igdrcl64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 03873280 _____ (Intel Corporation) C:\Windows\SysWOW64\igdrcl32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 03801600 _____ (Intel Corporation) C:\Windows\SysWOW64\igdmcl32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01858632 _____ (Intel Corporation) C:\Windows\system32\igdmd64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01767992 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01765408 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01565696 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01456408 _____ (Intel Corporation) C:\Windows\SysWOW64\igdmd32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01216000 _____ (Intel Corporation) C:\Windows\system32\igdfcl64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01156608 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 01008016 _____ C:\Windows\system32\igfxSDK.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00970752 _____ (Intel Corporation) C:\Windows\SysWOW64\igdfcl32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00927120 _____ (Intel Corporation) C:\Windows\system32\Gfxv4_0.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00923536 _____ (Intel Corporation) C:\Windows\system32\Gfxv2_0.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00803113 _____ C:\Windows\system32\DisplayAudiox64.cab
      2015-11-30 21:39 - 2015-11-30 21:39 - 00624128 _____ (Intel Corporation) C:\Windows\system32\MetroIntelGenericUIFramework.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00589712 _____ C:\Windows\system32\IntelCpHDCPSvc.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00519056 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiUMS64.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00511260 _____ C:\Windows\system32\cp_resources.bin
      2015-11-30 21:39 - 2015-11-30 21:39 - 00448912 _____ (Intel Corporation) C:\Windows\system32\GfxUIEx.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00425472 _____ (Intel Corporation) C:\Windows\system32\igdbcl64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00397824 _____ (Intel Corporation) C:\Windows\system32\IntelOpenCL64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00386048 _____ (Intel Corporation) C:\Windows\system32\igfxOSP.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00373248 _____ (Intel Corporation) C:\Windows\SysWOW64\igdbcl32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00331808 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiMCComp64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00313888 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiUtils64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00300032 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelOpenCL32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00284280 _____ (Intel Corporation) C:\Windows\system32\igd10idpp64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00283024 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00269360 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10idpp32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00256000 _____ C:\Windows\system32\igfxCPL.cpl
      2015-11-30 21:39 - 2015-11-30 21:39 - 00243200 _____ (Intel Corporation) C:\Windows\system32\igfxDTCM.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00219024 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00214416 _____ (Intel Corporation) C:\Windows\system32\DPTopologyApp.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00213904 _____ (Intel Corporation) C:\Windows\system32\DPTopologyAppv2_0.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00206848 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v4256.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00200856 _____ (Intel Corporation) C:\Windows\system32\igdde64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00172032 _____ (Intel Corporation) C:\Windows\system32\igdail64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00163776 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00162752 _____ (Intel Corporation) C:\Windows\system32\igfx11cmrt64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00160680 _____ (Intel Corporation) C:\Windows\SysWOW64\igdde32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00157072 _____ (Intel Corporation) C:\Windows\system32\difx64.exe
      2015-11-30 21:39 - 2015-11-30 21:39 - 00153600 _____ (Intel Corporation) C:\Windows\SysWOW64\igdail32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00143904 _____ (Intel Corporation) C:\Windows\system32\IntelWiDiLogServer64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00141080 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00140056 _____ (Intel Corporation) C:\Windows\SysWOW64\igfx11cmrt32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00090112 _____ ( ) C:\Windows\system32\igfxSDKLibv2_0.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00086528 _____ (Khronos Group) C:\Windows\SysWOW64\Intel_OpenCL_ICD32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00086016 _____ C:\Windows\system32\igfxCUIServicePS.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00082944 _____ ( ) C:\Windows\system32\igfxSDKLib.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00082432 _____ (Khronos Group) C:\Windows\system32\Intel_OpenCL_ICD64.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00073728 _____ ( ) C:\Windows\system32\igfxDHLibv2_0.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00064512 _____ ( ) C:\Windows\system32\igfxDHLib.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00036616 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00035328 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00011776 _____ ( ) C:\Windows\system32\igfxDILib.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00011264 _____ ( ) C:\Windows\system32\igfxDILibv2_0.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00010240 _____ ( ) C:\Windows\system32\igfxEMLibv2_0.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00010240 _____ ( ) C:\Windows\system32\igfxEMLib.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00005120 _____ ( ) C:\Windows\system32\igfxLHMLibv2_0.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00005120 _____ ( ) C:\Windows\system32\igfxLHMLib.dll
      2015-11-30 21:39 - 2015-11-30 21:39 - 00004682 _____ C:\Windows\system32\iglhxs64.vp
      2015-11-30 21:37 - 2015-11-30 21:43 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Mozilla
      2015-11-30 21:37 - 2015-11-30 21:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
      2015-11-30 21:37 - 2015-11-30 21:37 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Mozilla
      2015-11-30 21:34 - 2015-11-30 21:34 - 00243656 _____ C:\Users\Dykes family\Downloads\Firefox Setup Stub 42.0.exe
      2015-11-30 21:28 - 2015-11-30 21:28 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Macromedia
      2015-11-30 21:28 - 2015-11-30 21:28 - 00000000 ____D C:\Users\Dykes family\AppData\Local\MicrosoftEdge
      2015-11-30 21:27 - 2015-12-04 19:48 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Toshiba
      2015-11-30 21:27 - 2015-11-30 21:28 - 00002351 _____ C:\Users\Dykes family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
      2015-11-30 21:27 - 2015-11-30 21:28 - 00000000 ___RD C:\Users\Dykes family\OneDrive
      2015-11-30 21:25 - 2015-11-30 21:25 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Publishers
      2015-11-30 21:23 - 2015-12-05 15:13 - 00000000 __SHD C:\Users\Dykes family\IntelGraphicsProfiles
      2015-11-30 21:23 - 2015-12-04 20:08 - 00000000 ____D C:\Users\Dykes family\AppData\Local\Packages
      2015-11-30 21:23 - 2015-12-04 19:52 - 00000000 ____D C:\Users\Dykes family\AppData\Local\VirtualStore
      2015-11-30 21:23 - 2015-12-04 19:45 - 00000000 ____D C:\Users\Dykes family
      2015-11-30 21:23 - 2015-11-30 21:23 - 00016148 _____ C:\Windows\system32\LAPTOP-L02074TA_defaultuser0_HistoryPrediction.bin
      2015-11-30 21:23 - 2015-11-30 21:23 - 00000020 ___SH C:\Users\Dykes family\ntuser.ini
      2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\My Documents
      2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Videos
      2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Pictures
      2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 _SHDL C:\Users\Dykes family\Documents\My Music
      2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\Adobe
      2015-11-30 21:23 - 2015-11-30 21:23 - 00000000 ____D C:\Users\Dykes family\AppData\Local\TileDataLayer
      2015-11-30 21:15 - 2015-12-05 15:13 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
      2015-11-30 21:11 - 2015-08-18 23:50 - 00609592 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
      2015-11-30 21:11 - 2015-07-25 01:29 - 04532304 _____ (Microsoft Corporation) C:\Windows\explorer.exe
      2015-11-30 21:11 - 2015-07-24 23:54 - 04047288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
      2015-11-30 21:11 - 2015-07-21 22:52 - 00988672 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll

      ==================== One Month Modified files and folders ========

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2015-12-05 17:39 - 2015-07-19 04:41 - 00000000 ____D C:\Windows\Panther
      2015-12-05 15:22 - 2015-07-10 05:55 - 00000000 ____D C:\Windows\CbsTemp
      2015-12-05 15:16 - 2015-09-25 07:08 - 00875126 _____ C:\Windows\system32\PerfStringBackup.INI
      2015-12-05 15:16 - 2015-07-10 06:02 - 00000000 ____D C:\Windows\INF
      2015-12-05 15:10 - 2015-07-10 07:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
      2015-12-05 15:10 - 2015-07-10 04:05 - 00262144 ___SH C:\Windows\system32\config\BBI
      2015-12-05 14:56 - 2015-07-10 07:20 - 00221040 _____ C:\Windows\system32\FNTCACHE.DAT
      2015-12-05 14:24 - 2015-07-10 06:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
      2015-12-05 14:24 - 2015-07-10 06:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
      2015-12-05 14:24 - 2015-07-10 04:05 - 00000000 ____D C:\Windows
      2015-12-05 11:22 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\system32\NDF
      2015-12-05 11:08 - 2015-09-25 07:06 - 00000000 __RHD C:\Users\Public\AccountPictures
      2015-12-05 11:07 - 2015-09-25 07:47 - 00000000 ____D C:\ProgramData\McAfee
      2015-12-05 11:07 - 2015-09-25 07:47 - 00000000 ____D C:\Program Files\Common Files\McAfee
      2015-12-05 11:05 - 2015-07-10 06:04 - 00000000 ___HD C:\Windows\ELAMBKUP
      2015-12-05 11:05 - 2015-07-10 04:05 - 00032768 ___SH C:\Windows\system32\config\ELAM
      2015-12-05 08:33 - 2015-09-25 07:23 - 00000000 ____D C:\ProgramData\Conexant
      2015-12-04 20:18 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\LiveKernelReports
      2015-12-04 20:17 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\AppReadiness
      2015-12-04 20:15 - 2015-07-10 06:04 - 00000000 ___HD C:\Program Files\WindowsApps
      2015-12-03 07:52 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\appcompat
      2015-11-30 21:40 - 2015-09-25 07:19 - 00000000 ___HD C:\Intel
      2015-11-30 21:39 - 2015-09-25 07:20 - 00086528 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.DLL
      2015-11-30 21:39 - 2015-09-25 07:20 - 00082432 _____ (Khronos Group) C:\Windows\system32\OpenCL.DLL
      2015-11-30 21:39 - 2015-03-12 01:50 - 36681912 _____ (Intel Corporation) C:\Windows\system32\igdumdim64.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 13727296 _____ (Intel Corporation) C:\Windows\system32\igd10iumd64.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 11276968 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10iumd32.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 06389688 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
      2015-11-30 21:39 - 2015-03-12 01:50 - 06305696 _____ (Intel Corporation) C:\Windows\system32\igdusc64.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 04841488 _____ (Intel Corporation) C:\Windows\SysWOW64\igdusc32.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 02028032 _____ (Intel Corporation) C:\Windows\system32\igfxLHM.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 00723456 _____ (Intel Corporation) C:\Windows\system32\igfxDH.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 00396688 _____ C:\Windows\system32\igfxTray.exe
      2015-11-30 21:39 - 2015-03-12 01:50 - 00353280 _____ (Intel Corporation) C:\Windows\system32\igfxDI.dll
      2015-11-30 21:39 - 2015-03-12 01:50 - 00351120 _____ (Intel Corporation) C:\Windows\system32\igfxCUIService.exe
      2015-11-30 21:39 - 2015-03-12 01:50 - 00328080 _____ (Intel Corporation) C:\Windows\system32\igfxEM.exe
      2015-11-30 21:39 - 2015-03-12 01:50 - 00249232 _____ (Intel Corporation) C:\Windows\system32\igfxHK.exe
      2015-11-30 21:18 - 2015-09-25 07:28 - 00000000 ____D C:\ProgramData\TOSHIBA
      2015-11-30 21:11 - 2015-07-10 06:04 - 00000000 ____D C:\Windows\rescache

      ==================== Files in the root of some directories =======

      2015-12-05 08:30 - 2015-12-05 08:30 - 0009216 _____ () C:\Users\Dykes family\AppData\Local\kdapll.dll
      2015-12-05 08:30 - 2015-12-05 08:30 - 0002560 _____ () C:\Users\Dykes family\AppData\Local\uninstall.exe

      Files to move or delete:
      ====================
      C:\Users\Public\VOIP.dat


      Some files in TEMP:
      ====================
      C:\Users\Dykes family\AppData\Local\Temp\sqlite3.dll


      ==================== Bamital & volsnap =================

      (There is no automatic fix for files that do not pass verification.)

      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\dnsapi.dll => File is digitally signed
      C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


      LastRegBack: 2015-09-25 06:56

      ==================== End of FRST.txt ============================

       

       

       

      Here is the Additions log file:

       

      Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
      Ran by [removed] (2015-12-05 17:40:02)
      Running from C:\Users\[removed]\Desktop
      Windows 10 Home (X64) (2015-12-01 02:14:34)
      Boot Mode: Normal
      ==========================================================


      ==================== Accounts: =============================

      Administrator (S-1-5-21-843202709-3289130475-90754708-500 - Administrator - Disabled)
      DefaultAccount (S-1-5-21-843202709-3289130475-90754708-503 - Limited - Disabled)
      Dykes family (S-1-5-21-843202709-3289130475-90754708-1001 - Administrator - Enabled) => C:\Users\Dykes family
      Guest (S-1-5-21-843202709-3289130475-90754708-501 - Limited - Disabled)

      ==================== Security Center ========================

      (If an entry is included in the fixlist, it will be removed.)

      AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

      ==================== Installed Programs ======================

      (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

      Bluetooth(R) Link (HKLM\…\{3F3DCC8C-2C93-4082-A6DE-BBDC74804FA0}) (Version: 4.3.03 - Toshiba Corporation)
      Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.66.8.52 - Conexant)
      CyberLink PowerDVD 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5509.05 - CyberLink Corp.)
      Free Video to DVD Converter (HKLM-x32\…\Free Video to DVD Converter_is1) (Version: 5.0.69.1127 - DVDVideoSoft Ltd.)
      Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
      Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation)
      Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4112 - Intel Corporation)
      Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
      Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
      Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
      Microsoft Silverlight (HKLM-x32\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Minecraft (HKLM-x32\…\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
      NetStream 1.0 (HKU\S-1-5-21-843202709-3289130475-90754708-1001\…\NetStream 1.0) (Version:  - )
      Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10130.29089 - Realtek Semiconductor Corp.)
      Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
      Skype™ 7.15 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.15.102 - Skype Technologies S.A.)
      TOSHIBA Application Installer (HKLM\…\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.8 - Toshiba Corporation)
      TOSHIBA Audio Enhancement (HKLM\…\{1515F5E3-29EA-4CD1-A981-032D88880F09}) (Version: 3.0.0.9 - Toshiba Corporation)
      TOSHIBA Display Utility (HKLM\…\{0B39C39A-3ECE-4582-9C91-842D22819A24}) (Version: 2.0.1.0 - Toshiba Corporation)
      TOSHIBA Password Utility (HKLM-x32\…\InstallShield_{26BB68BB-CF93-4A12-BC6D-A3B6F53AC8D9}) (Version: 8.1.1.0 - Toshiba Corporation)
      TOSHIBA Service Station (HKLM\…\{0DFA8761-7735-4DE8-A0EB-2286578DCFC6}) (Version: 2.6.14 - Toshiba Corporation)
      TOSHIBA System Driver (HKLM-x32\…\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 2.00.0005 - Toshiba Corporation)
      TOSHIBA System Settings (HKLM\…\{B040D5C9-C9AA-430A-A44E-696656012E61}) (Version: 3.0.0.6406 - Toshiba Corporation)
      TOSHIBA User's Guide (HKLM-x32\…\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)

      ==================== Custom CLSID (Whitelisted): ==========================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      CustomCLSID: HKU\S-1-5-21-843202709-3289130475-90754708-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Dykes family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

      ==================== Restore Points =========================

      30-11-2015 21:11:54 Windows Modules Installer
      30-11-2015 21:48:25 Day 1 of laptop
      04-12-2015 19:50:38 Installed Minecraft
      05-12-2015 15:17:55 JRT Pre-Junkware Removal

      ==================== Hosts content: ===============================

      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

      2015-07-10 06:04 - 2015-12-05 14:54 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts

      127.0.0.1       localhost

      ==================== Scheduled Tasks (Whitelisted) =============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      Task: {02C0A321-FD63-4DE7-8EDB-EB21DB915B0C} - System32\Tasks\{5236EBB1-7687-40F3-95D6-10FB965F7948} => launchwinapp.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver;=4.1.0.166&LastError;=404
      Task: {06EBFEF3-D10F-4C99-ABFE-0E6DD5D2F4B1} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
      Task: {2A49C756-107C-4F3E-AD56-CC0F42EFEEC0} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2015-06-12] (TOSHIBA Corporation)
      Task: {4603A09B-4202-4DFE-8E18-163233E6CECD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe
      Task: {53F06927-DA16-4A76-9CA7-BB66BF0CBD86} - System32\Tasks\win => C:\Windows\system32\win.exe
      Task: {5B554B79-11E1-4622-9A36-63A7CC6C9000} - System32\Tasks\BTSchedulerTask => C:\Program Files (x86)\TOSHIBA\Toshiba Bluetooth Device Profile Utility\TosBt_NotificationScheduler.exe [2015-07-08] (Toshiba Corporation)
      Task: {5F753A44-BB07-47CC-90F9-8D55A51EEF24} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2014-04-03] (TOSHIBA Corporation)
      Task: {632CD2E0-A082-4CB6-A66E-F0D23CB52915} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe
      Task: {6F792032-E46E-4F9F-A51C-66329AF9D144} - System32\Tasks\GoogleUp => C:\Windows\system32\hsysinfo.exe
      Task: {7BCB58D7-FC51-4AAF-95F5-3679D470A307} - System32\Tasks\import => C:\Windows\system32\Mint.exe
      Task: {7E884694-3DEA-4F4D-9586-86D599E51FD8} - System32\Tasks\Googleuptodate => C:\Windows\system32\Wimboldon.exe
      Task: {A0DD6ABF-3542-442D-8992-794423226875} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-10-27] (Microsoft Corporation)

      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


      ==================== Shortcuts =============================

      (The entries could be listed to be restored or removed.)

      ==================== Loaded Modules (Whitelisted) ==============

      2015-07-10 06:00 - 2015-07-10 06:00 - 00032768 _____ () C:\Windows\SYSTEM32\licensemanagerapi.dll
      2015-07-16 09:43 - 2015-07-16 09:43 - 00403968 _____ () C:\Windows\System32\diagtrack_wininternal.dll
      2015-07-10 06:00 - 2015-07-10 06:00 - 02498296 _____ () C:\Windows\system32\CoreUIComponents.dll
      2015-07-10 06:00 - 2015-07-10 06:00 - 02498296 _____ () C:\Windows\System32\CoreUIComponents.dll
      2012-07-18 20:38 - 2012-07-18 20:38 - 00020904 _____ () C:\Program Files\TOSHIBA\System Setting\SmoothView.dll
      2015-07-10 05:59 - 2015-07-10 05:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
      2015-07-10 06:00 - 2015-07-10 08:15 - 06579712 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
      2015-07-10 06:00 - 2015-07-10 08:15 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
      2015-07-10 06:00 - 2015-07-10 08:15 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
      2015-12-04 20:04 - 2015-12-04 20:04 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
      2015-12-04 20:04 - 2015-12-04 20:04 - 11526656 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
      2015-12-04 20:02 - 2015-12-04 20:02 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1201.10020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
      2015-11-30 22:31 - 2015-11-27 19:06 - 00253800 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\collector.dll
      2015-11-30 22:31 - 2015-11-27 19:06 - 00110952 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
      2015-11-30 22:31 - 2015-11-27 19:06 - 00295272 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\stat.dll
      2015-11-30 22:31 - 2015-11-27 19:06 - 00104296 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
      2015-11-30 22:31 - 2015-11-27 19:06 - 00020328 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
      2015-11-30 22:31 - 2015-11-27 19:06 - 00044392 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll

      ==================== Alternate Data Streams (Whitelisted) =========

      (If an entry is included in the fixlist, only the ADS will be removed.)


      ==================== Safe Mode (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Pajhunoour => ""="service"

      ==================== EXE Association (Whitelisted) ===============

      (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


      ==================== Internet Explorer trusted/restricted ===============

      (If an entry is included in the fixlist, it will be removed from the registry.)


      ==================== Other Areas ============================

      (Currently there is no automatic fix for this section.)

      HKU\S-1-5-21-843202709-3289130475-90754708-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Innovation\Bishop Tree.jpg
      DNS Servers: 192.168.1.1
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
      Windows Firewall is enabled.

      ==================== MSCONFIG/TASK MANAGER disabled items ==

      (Currently there is no automatic fix for this section.)

      MSCONFIG\Services: HomeNetSvc => 2
      MSCONFIG\Services: PCSUService => 2
      MSCONFIG\Services: SCService => 2

      ==================== FirewallRules (Whitelisted) ===============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
      FirewallRules: [{96C8546B-32FD-4AC8-8526-130F7848FA16}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
      FirewallRules: [{A0763D73-A490-4EA9-A3E9-FABAC2D73F91}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{B0E073D4-455F-44E3-8476-20A4C39B421C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
      FirewallRules: [{CB0B5FBE-5B3F-4A98-A08C-DFFB10BFE152}] => (Allow) C:\Windows\system32\rundll32.exe

      ==================== Faulty Device Manager Devices =============


      ==================== Event log errors: =========================

      Application errors:
      ==================
      Error: (12/05/2015 05:37:20 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: svchost.exe_LicenseManager, version: 10.0.10240.16384, time stamp: 0x559f38cb
      Faulting module name: LicenseManager.dll, version: 10.0.10240.16387, time stamp: 0x55a1b680
      Exception code: 0xc0000005
      Fault offset: 0x0000000000094fdb
      Faulting process id: 0xec
      Faulting application start time: 0xsvchost.exe_LicenseManager0
      Faulting application path: svchost.exe_LicenseManager1
      Faulting module path: svchost.exe_LicenseManager2
      Report Id: svchost.exe_LicenseManager3
      Faulting package full name: svchost.exe_LicenseManager4
      Faulting package-relative application ID: svchost.exe_LicenseManager5

      Error: (12/05/2015 03:18:05 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

      Details:
      AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

      System Error:
      Access is denied.
      .

      Error: (12/05/2015 02:24:38 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application name: SystemSettings.exe, version: 10.0.10240.16384, time stamp: 0x559f39ae
      Faulting module name: SettingsHandlers_StorageSense.dll, version: 10.0.10240.16384, time stamp: 0x559f3d87
      Exception code: 0xc0000005
      Fault offset: 0x00000000000174b9
      Faulting process id: 0x17c0
      Faulting application start time: 0xSystemSettings.exe0
      Faulting application path: SystemSettings.exe1
      Faulting module path: SystemSettings.exe2
      Report Id: SystemSettings.exe3
      Faulting package full name: SystemSettings.exe4
      Faulting package-relative application ID: SystemSettings.exe5

      Error: (12/05/2015 11:54:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

      Error: (12/05/2015 11:53:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.

      Error: (12/05/2015 11:53:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

      Error: (12/05/2015 11:52:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.

      Error: (12/05/2015 11:52:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.

      Error: (12/05/2015 11:51:53 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:47:53Z. Error Code: 0x80040154.

      Error: (12/05/2015 11:51:23 AM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
      Description: Failed to schedule Software Protection service for re-start at 2015-12-05T17:48:23Z. Error Code: 0x80040154.


      System errors:
      =============
      Error: (12/05/2015 05:39:24 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
      Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Network Store Interface Service service, but this action failed with the following error:
      %%1056

      Error: (12/05/2015 05:38:24 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
      Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Font Cache Service service, but this action failed with the following error:
      %%1056

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Diagnostic Service Host service terminated unexpectedly.  It has done this 1 time(s).

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The Network Store Interface Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The Network List Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 100 milliseconds: Restart the service.

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: The Windows License Manager Service service terminated unexpectedly.  It has done this 1 time(s).

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The Windows Font Cache Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The COM+ Event System service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.

      Error: (12/05/2015 05:37:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: The Bluetooth Support Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.


      CodeIntegrity:
      ===================================
        Date: 2015-12-05 08:37:42.890
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:37:13.044
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:36:04.341
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:35:56.706
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:35:55.000
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:35:54.830
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:35:54.669
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:35:54.462
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:35:54.284
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

        Date: 2015-12-05 08:35:54.126
        Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.


      ==================== Memory info ===========================

      Processor: Intel(R) Core(TM) i5-5200U CPU @ 2.20GHz
      Percentage of memory in use: 21%
      Total physical RAM: 8106.14 MB
      Available physical RAM: 6401.57 MB
      Total Virtual: 16810.14 MB
      Available Virtual: 15251.35 MB

      ==================== Drives ================================

      Drive c: () (Fixed) (Total:930.79 GB) (Free:896.51 GB) NTFS
      Drive e: (KINGSTON) (Removable) (Total:14.53 GB) (Free:5.03 GB) FAT32

      ==================== MBR & Partition Table ==================

      ========================================================
      Disk: 0 (Size: 931.5 GB) (Disk ID: 00000000)

      Partition: GPT.

      ========================================================
      Disk: 1 (MBR Code: Windows XP) (Size: 14.5 GB) (Disk ID: C3072E18)
      Partition 1: (Active) - (Size=14.5 GB) - (Type=0C)

      ==================== End of Addition.txt ============================

      Your log looks so much better  :thumbup:
       
       
      Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
      Please copy the entire contents Inside of the code box below beginning with START and ending with END
      (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
      Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
       
      Start
      CloseProcesses:
      CreateRestorePoint: 
      2015-11-30 22:02 - 2015-12-05 14:25 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\uTorrent
      EmptyTemp:
      End
      
       
      NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
       
       
       
       
       
      How is your system behaving now ??????

      It did everything except post a log after bootup called "FIXLOG.TXT". It's nowhere on the desktop - or anywhere else that I could find.

      Found it. Here it is.

       

      Fix result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
      Ran by [removed] (2015-12-05 19:06:12) Run:3
      Running from C:\Users\[removed]\Desktop
      [removed] Boot Mode: Normal
      ==============================================

      fixlist content:
      *****************
      Start
      CloseProcesses:
      CreateRestorePoint:
      2015-11-30 22:02 - 2015-12-05 14:25 - 00000000 ____D C:\Users\Dykes family\AppData\Roaming\uTorrent
      EmptyTemp:
      End
      *****************

      Processes closed successfully.
      Restore point was successfully created.
      "C:\Users\Dykes family\AppData\Roaming\uTorrent" => not found.
      EmptyTemp: => 2.8 MB temporary data Removed.


      The system needed a reboot.

      ==== End of Fixlog 19:06:15 ====

       

       

      So far things seems to be clear. :woot:  I'm going to re-download Firefox now. Hopefully this won't happen again.

       

      Btw, what program would you suggest to protect my laptop? I heard Microsoft had something free that was good, but I don't know. I'm using Avast for my desktop.

       

      Thanks!

      Windows 10 comes with Windows Defender and this version is very nice, as far as AV its all I use

       

      You can go to C:/ Program Files > Windows Defender and drag MSASCui to your taskbar. Open it and you can check for updates and do regular scans

       

       

      You have Malwarebytes installed, the free version lets you update, run scans and remove threats, the Premium version has a protection module that will block bad sites and downloads, its one of the better Anti Malware programs around and I have it on my PC and all my friends and families PCs. I believe its about $25 a year.

       

      They also have Malwarebytes Anti Exploit that will block the recent wave of ransomware. Cryptolocker will encrypt all your files and photos and the only way to get them back is to pay a ransom, Malwarebytes Anti Exploit will block that from installing, this too is around $25 a year but I believe for 3 PCs

       

      I never had much use for Avast, Windows Defender is free and  more than adequate

       

      So on my system I have Windows Defender, Malwarebytes Premium, Malwarebytes Anti Exploit and I feel its all i need, doing what I do and researching  questionable files and entries these programs have always kept me safe, but whether you want  to purchase these is entirely up to you. As we just recommend programs we are not affiliated with them

       

      I noticed on your logs that someone installed a shopping program, the kind that gives you points for sites you visit, not a good idea as these will bring you numerous adds.

       

      Double click on AdwCleaner.exe to run the tool again.
      •  
      • Click on the Uninstall button.
      • Click Yes when asked are you sure you want to uninstall.
      • Both AdwCleaner.exe, its folder and all logs will be removed.
       
       
       
      ==========================================================
       
       
      Please download DelFix and save the file to your Desktop.
       
      [external image: DelFix_zps139e2ea1.jpg]
       
      •  
      • Windows XP Double Click DelFix.exe to run the program. 
      • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
      • Checkmark " Remove Disinfection Tools"
      • Click the Run button
       
       
      This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
       
       
       
       
      So How did I get infected in the first place <– Some reading for you to keep yourself safe online
       
       
      Safe Surfn
      Ken
       
       
       

      Thanks for the assistance. I've been browsing and I haven't had any issues. I will definitely look into your protection programs suggestions.

       

      I don't recall anyone installing a shopping program on the laptop. How would I remove that?

       

      Thanks again.

      With all the junk that you had on your system it most likely came bundled with something else, but its gone so no need to worry

       

      Take care

       

      Ken :)

      Ask AI

      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI