This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow computer [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys

same old story I am afraid web pages are very slow in loading up

poste a scan log not sure if I have done it correctly?

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-01-30 15:08:15
—————————–
15:08:15.875    OS Version: Windows x64 6.1.7601 Service Pack 1
15:08:15.876    Number of processors: 2 586 0x170A
15:08:15.877    ComputerName: SHARON-PC  UserName: Sharon
15:08:18.109    Initialize success
15:08:18.189    VM: initialized successfully
15:08:18.189    VM: Intel CPU virtualization not supported
15:10:43.753    AVAST engine defs: 16012900
15:10:46.899    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:10:46.909    Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 3
15:10:47.169    Disk 0 MBR read successfully
15:10:47.179    Disk 0 MBR scan
15:10:47.189    Disk 0 Windows VISTA default MBR code
15:10:47.189    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0       39 MB offset 63
15:10:47.239    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        15000 MB offset 81920
15:10:47.239    Disk 0 default boot code
15:10:47.269    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       290204 MB offset 30801920
15:10:47.329    Disk 0 scanning C:\Windows\system32\drivers
15:11:03.303    Service scanning
15:11:37.286    Modules scanning
15:11:37.306    Disk 0 trace - called modules:
15:11:37.326    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys
15:11:37.336    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800439d5a0]
15:11:37.344    3 CLASSPNP.SYS[fffff88001dbf43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004111050]
15:11:38.898    AVAST engine scan C:\Windows
15:11:42.244    AVAST engine scan C:\Windows\system32
15:19:11.016    AVAST engine scan C:\Windows\system32\drivers
15:19:28.160    AVAST engine scan C:\Users\Sharon
16:31:50.767    Disk 0 MBR has been saved successfully to "C:\Users\Sharon\Desktop\MBR.dat"
16:31:50.787    The log file has been saved successfully to "C:\Users\Sharon\Desktop\aswMBR.txt"

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-01-30 16:35:34
—————————–
16:35:34.122    OS Version: Windows x64 6.1.7601 Service Pack 1
16:35:34.122    Number of processors: 2 586 0x170A
16:35:34.122    ComputerName: SHARON-PC  UserName: Sharon
16:35:35.339    Initialize success
16:35:35.417    VM: initialized successfully
16:35:35.417    VM: Intel CPU virtualization not supported
16:36:26.258    AVAST engine defs: 16012900
16:37:07.192    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:37:07.192    Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 3
16:37:07.379    Disk 0 MBR read successfully
16:37:07.395    Disk 0 MBR scan
16:37:07.395    Disk 0 Windows VISTA default MBR code
16:37:07.411    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0       39 MB offset 63
16:37:07.504    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        15000 MB offset 81920
16:37:07.520    Disk 0 default boot code
16:37:07.551    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       290204 MB offset 30801920
16:37:07.769    Disk 0 scanning C:\Windows\system32\drivers
16:37:41.024    Service scanning
16:38:14.992    Modules scanning
16:38:15.007    Disk 0 trace - called modules:
16:38:15.054    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
16:38:15.070    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800439d5a0]
16:38:15.070    3 CLASSPNP.SYS[fffff88001dbf43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004111050]
16:38:16.598    AVAST engine scan C:\Windows
16:38:26.802    AVAST engine scan C:\Windows\system32
16:43:19.990    AVAST engine scan C:\Windows\system32\drivers
16:43:37.352    AVAST engine scan C:\Users\Sharon
17:29:40.660    AVAST engine scan C:\ProgramData
17:45:28.259    Disk 0 statistics 5255155/0/0 @ 0.77 MB/s
17:45:28.290    Scan finished successfully
17:45:52.655    Disk 0 MBR has been saved successfully to "C:\Users\Sharon\Desktop\MBR.dat"
17:45:52.686    The log file has been saved successfully to "C:\Users\Sharon\Desktop\aswMBR.txt"

:welcome:

 

Log looks fine, but lets run another scan so we can see whats going on .

 

It looks like you need the 64 bit version, be sure to download it to your DESKTOP

 

Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
  • Hi Ken545

     

    can result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
    Ran by [removed] (administrator) on SHARON-PC (30-01-2016 19:22:46)
    Running from C:\Users\[removed]\Desktop
    [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe
    (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
    () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
    (McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    ( ) C:\Windows\System32\lxdicoms.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_20_0_0_286_ActiveX.exe
    (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\…\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
    HKLM\…\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.)
    HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
    HKLM-x32\…\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1484856 2010-06-30] (McAfee, Inc.)
    HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Run: [WinPatrol] => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [496192 2014-02-25] (BillP Studios)
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\MountPoints2: {75e4e796-5a75-11e3-b617-a4badb95f61e} - F:\DTVP_Launcher.exe
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation)
    Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-12-24]
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
    Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-12-24]
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
    Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk [2010-02-04]
    ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{0352CE31-0851-421A-AAA8-FFFECAAAF602}: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{8CEF2A2E-C861-4D28-B4C8-D9F096CE09D4}: [DhcpNameServer] 192.168.0.1

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.co.uk/
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {6112FDEF-4523-4643-8B16-45CF4E18157F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
    BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\McAfee\MSK\mskapbho64.dll [2010-05-03] ()
    BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
    BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100828145747.dll [2010-05-31] (McAfee, Inc.)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
    BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
    BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\McAfee\MSK\mskapbho.dll [2010-05-03] ()
    BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22] (Microsoft Corporation)
    BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-03] (Oracle Corporation)
    BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100828145747.dll [2010-05-31] (McAfee, Inc.)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
    BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-03] (Oracle Corporation)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
    Toolbar: HKU\S-1-5-21-1603844925-2173046804-925170645-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
    DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: HKLM-x32 {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
    DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
    DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
    Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe

    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1218158.dll [2015-04-27] (Adobe Systems, Inc.)
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
    FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-03] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-03] (Oracle Corporation)
    FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [2015-02-22] (Reto-Moto ApS)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @nsroblox.roblox.com/launcher -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\\NPRobloxProxy.dll [2012-12-31] ( ROBLOX Corporation)
    FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @nsroblox.roblox.com/launcher64 -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\\NPRobloxProxy64.dll [2012-12-31] ( ROBLOX Corporation)
    FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Sharon\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-05] (Unity Technologies ApS)

    Chrome:
    =======
    CHR HKLM-x32\…\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx

    ==================== Services (Whitelisted) ========================

     

     

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:27-01-2016
    Ran by [removed] (2016-01-30 19:24:07)
    Running from C:\Users\[removed]\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2010-02-04 22:00:14)
    Boot Mode: Normal
    ==========================================================

    ==================== Accounts: =============================

    Administrator (S-1-5-21-1603844925-2173046804-925170645-500 - Administrator - Disabled)
    Guest (S-1-5-21-1603844925-2173046804-925170645-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-1603844925-2173046804-925170645-1002 - Limited - Enabled)
    Sharon (S-1-5-21-1603844925-2173046804-925170645-1000 - Administrator - Enabled) => C:\Users\Sharon

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {86355677-4064-3EA7-ABB3-1B136EB04637}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {3D54B793-665E-3129-9103-206115370C8A}
    FW: McAfee Firewall (Enabled) {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
    Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
    Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.)
    Adobe Flash Player 20 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
    Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.8.158 - Adobe Systems, Inc.)
    Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
    Apple Application Support (32-bit) (HKLM-x32\…\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\…\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
    AviSynth 2.5 (HKLM-x32\…\AviSynth) (Version:  - )
    AVS Image Converter 1.2.1.100 (HKLM-x32\…\AVS Image Converter_is1) (Version:  - Online Media Technologies Ltd.)
    AVS Update Manager 1.0 (HKLM-x32\…\AVS Update Manager_is1) (Version:  - Online Media Technologies Ltd.)
    Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
    Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
    Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
    Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dell Dock (HKLM\…\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell)
    Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
    Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
    Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 13.2.3.0 - Synaptics Incorporated)
    Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
    Dell Wireless WLAN Card Utility (HKLM\…\Dell Wireless WLAN Card Utility) (Version: 5.30.21.0 - Dell Inc.)
    Digital Photo Navigator 1.0 (HKLM-x32\…\{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}) (Version:  - )
    Disk Cleaner (remove only) (HKLM-x32\…\DiskCleaner) (Version:  - )
    ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
    EZ Software Updater version 1.0.0.0 (HKLM-x32\…\EZ Software Updater_is1) (Version: 1.0.0.0 - )
    ffdshow v1.1.3572 [2010-09-13] (HKLM-x32\…\ffdshow_is1) (Version: 1.1.3572.0 - )
    Free Audio CD to MP3 Converter version 1.3.12.1228 (HKLM-x32\…\Free Audio CD to MP3 Converter_is1) (Version: 1.3.12.1228 - DVDVideoSoft Ltd.)
    Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    Haali Media Splitter (HKLM-x32\…\HaaliMkx) (Version:  - )
    Heroes & Generals (HKLM-x32\…\Heroes & Generals) (Version: 1.0.6.1 - Reto-Moto)
    iCloud (HKLM\…\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
    iCopyBot for Windows 7.9.8 (HKLM-x32\…\iCopyBot for Windows) (Version: 7.9.8 - VOWSoft, Ltd.)
    Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002 - Brice Lambson) Hidden
    Image Resizer for Windows (HKLM-x32\…\{9dfff2f7-5cd7-4fd4-9b75-7d53b042d94b}) (Version: 3.0.4442.6002 - Brice Lambson)
    inSSIDer Home (HKLM-x32\…\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
    InstallConverter (HKLM-x32\…\InstallConverter) (Version: 1.0 - InstallConverter)
    Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1029 - Intel Corporation)
    Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
    iTunes (HKLM\…\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
    Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    LAV Filters 0.51.3 (HKLM-x32\…\lavfilters_is1) (Version: 0.51.3 - Hendrik Leppkes)
    Lexmark 3500-4500 Series (HKLM\…\Lexmark 3500-4500 Series) (Version:  - Lexmark International, Inc.)
    Live! Cam Avatar Creator (HKLM-x32\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.3009.1 - Creative Technology Ltd)
    McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 10.5.195 - McAfee, Inc.)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
    Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
    Mount&Blade; Warband (HKLM-x32\…\Mount&Blade; Warband) (Version:  - )
    PassShow (HKLM-x32\…\0AADCD53-E02F-9B5A-5431-BAACC6D75585) (Version:  - PassShow-software) <==== ATTENTION
    PowerDVD DX (HKLM-x32\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.3.5424 - CyberLink Corp.)
    Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 9.6.6 - Dell Inc.)
    QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
    ROBLOX Player for Sharon (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
    Roxio Burn (HKLM-x32\…\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.0 - Roxio)
    Skype Click to Call (HKLM-x32\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
    Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
    Sothink Movie DVD Maker (HKLM-x32\…\{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1) (Version: 3.8 - SourceTec Software Co., LTD)
    Spotify (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Spotify) (Version: 0.9.4.185.g7545a404 - Spotify AB)
    Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    Unity Web Player (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
    Verdun (HKLM-x32\…\Steam App 242860) (Version:  - M2H)
    Virgin Media Cloud (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Virgin Media Cloud) (Version: 2.4.4435 - F-Secure Corporation)
    VLC media player 2.1.2 (HKLM-x32\…\VLC media player) (Version: 2.1.2 - VideoLAN)
    Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
    WinPatrol (HKLM\…\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.1.2014 - BillP Studios)
    WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-1603844925-2173046804-925170645-1000_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\RobloxProxy64.dll (ROBLOX Corporation)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {039DD88D-3DDE-408C-8A5A-55F7121590DB} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-02-10] (Oracle Corporation)
    Task: {16B97E37-3B14-4027-A65E-72E301F80F1A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {2FE1DE7F-DDC3-42E3-BD3E-4667BF17AED2} - System32\Tasks\{8D06BC15-F5B6-4AC0-8233-9F0ADAA4DD1D} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
    Task: {327AFB33-C66D-4C6D-8B23-10B01570B775} - \PassShow Update -> No File <==== ATTENTION
    Task: {3C6C326B-CD9B-4D58-925C-C7811B8E52D1} - \Feven 2.2-updater -> No File <==== ATTENTION
    Task: {3CFB5768-E431-47D0-A3BD-F30C37D424C3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
    Task: {47180107-64DE-431E-97CC-F1EC25F0881E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
    Task: {4E87D8BF-C0DE-45DE-910D-861B71EAAB88} - \Feven 2.2-enabler -> No File <==== ATTENTION
    Task: {55870B00-CB28-4ACC-9AAB-11A5DDE0BBB0} - \Feven 2.2-firefoxinstaller -> No File <==== ATTENTION
    Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
    Task: {5CC024D9-88E3-4817-A1B2-67C20F19ADFF} - \Feven 2.2-validator -> No File <==== ATTENTION
    Task: {66B6E2DE-37EF-40A4-A29A-1499E3ACC54D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
    Task: {6DEE93CC-4A2E-49D3-B1FF-35E50C2B2309} - System32\Tasks\DJNJ8SJ1\Administrator - Start WLAN Tray Applet => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE [2009-07-17] (Dell Inc.)
    Task: {8335C703-0DFD-4F5A-8D7B-CF11E9336803} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
    Task: {87589C5E-C1AE-4503-87BC-76B273547797} - System32\Tasks\{A3FDA8D8-F1E0-49A9-AC99-A04158C023A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsBing
    Task: {A16B56B1-CACA-4C8E-957D-63C1895450B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {A367EA33-4598-400B-9BC0-C8CB941BE71E} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
    Task: {C7ADECB6-B5C1-4EC4-8D00-965492898B02} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated)
    Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc
    Task: {E828258C-E94D-4A65-9F31-5F74DC09DA34} - \Feven 2.2-codedownloader -> No File <==== ATTENTION
    Task: {EBD1FDC5-D5BB-4090-81DD-7B336A22F2CE} - System32\Tasks\{39320917-C1DD-477D-A6D2-463E786AB835} => pcalua.exe -a C:\PROGRA~2\SearchProtect\Main\bin\uninstall.exe -c /S <==== ATTENTION
    Task: {F4214C36-6660-4F72-BDC8-98F2C55B6D6A} - System32\Tasks\{46EF662D-9A7C-4B91-A664-490EC3CA199D} => pcalua.exe -a C:\JVC\UsbSTGE.exe -d C:\JVC

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2009-12-24 15:30 - 2009-07-17 01:06 - 00033280 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
    2009-12-24 15:30 - 2009-07-17 01:06 - 00058368 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll
    2012-11-11 10:58 - 2007-03-15 23:11 - 00138240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdidrpp.dll
    2010-01-09 20:17 - 2010-01-09 20:17 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
    2010-01-21 01:40 - 2010-01-21 01:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
    2010-12-20 21:59 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
    2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-10-13 05:45 - 2015-10-13 05:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2015-12-13 19:46 - 2015-12-13 19:46 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\ad2fbbd746bb143008adb984541da686\VistaBridgeLibrary.ni.dll
    2014-02-19 20:53 - 2014-02-18 03:46 - 00643948 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
    2015-10-13 05:46 - 2015-10-13 05:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-10-13 05:45 - 2015-10-13 05:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
    2010-01-09 20:18 - 2010-01-09 20:18 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
    2010-01-21 01:34 - 2010-01-21 01:34 - 08793952 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 02:34 - 2009-06-10 21:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.0.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
    MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{0332E39C-D700-4178-897A-91BD7C9FC3AD}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PowerDVD.exe
    FirewallRules: [{9241A141-1C7D-401C-86FF-68DC3C733D89}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    FirewallRules: [{E511FE26-5850-40F8-8BE9-369B466129B8}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{25E1DDAA-1275-43E2-B0D5-CA0A038762C1}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
    FirewallRules: [{DA5B37A1-E998-4461-801B-885310A70C65}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{4448837A-8A45-4DCF-80EA-018CCABB0152}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    FirewallRules: [{8B5C7515-5E52-4B14-8615-C5CFE1DF0492}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    FirewallRules: [{579303C5-7A83-499E-9059-9FFC90A94E4F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{B292AF1D-BDDF-4862-A319-63627591A6D9}] => (Allow) LPort=2869
    FirewallRules: [{DCA207F2-8A87-4052-8AFF-D08D9ABE6225}] => (Allow) LPort=1900
    FirewallRules: [{525A5E41-73B4-46E1-A5DE-2A156D737B6D}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
    FirewallRules: [{18ADDB25-AE21-433A-88B0-DED508680E27}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{40BC477C-361A-49EC-B674-DF8C4F7549D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{1FD7A359-3662-44EB-9527-46ED6EC10CC4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{879B9977-27F7-4A07-A959-ACA27B6D2E65}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{49E791C3-7A74-4EB9-B960-1874CB2A5BB8}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
    FirewallRules: [{AAFE46BE-7A06-4B2B-AAA0-84AC3D110836}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
    FirewallRules: [{9AEA2DC4-DAC2-4341-994C-DF13AF827FB0}] => (Allow) C:\Windows\System32\lxdicoms.exe
    FirewallRules: [{B911FD92-BABC-4726-8DB7-CA322C099DB8}] => (Allow) C:\Windows\System32\lxdicoms.exe
    FirewallRules: [{CF986128-AD4D-45F2-B22E-E3E16E4E9FDA}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
    FirewallRules: [{7D535C64-78C0-4E0C-A596-6C0621DBE66B}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
    FirewallRules: [{13D9AB9D-4990-49F7-B640-F6F067B2219F}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
    FirewallRules: [{B4DB37E7-E205-4B03-8206-BAE9398D3102}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
    FirewallRules: [{7FFE1605-CD9B-4AC5-9763-6BEE75155F10}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
    FirewallRules: [{156A3780-BFB6-408D-A8F4-AE3FE8F659ED}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
    FirewallRules: [{E39C41EC-5187-4A43-91D4-D2B7947FE7A4}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
    FirewallRules: [{DEC501C9-836F-4D67-A90B-166B23F3A457}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
    FirewallRules: [{5C050647-43F3-4455-84BF-DED1B647757E}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
    FirewallRules: [{C31D4F77-42C9-4606-97F8-227BD727E95D}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
    FirewallRules: [{7789B22F-ADB1-496E-BEAF-8DF913B284EC}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
    FirewallRules: [{5666A10E-8B52-4A11-A734-780A14E2E741}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
    FirewallRules: [TCP Query User{9168E047-A0A1-4A11-8667-9CA820EE5996}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
    FirewallRules: [UDP Query User{29D328A2-FF65-424E-A7E0-67335D03F7AB}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
    FirewallRules: [TCP Query User{6360F2DA-6D0B-4185-B133-BE5E59007308}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
    FirewallRules: [UDP Query User{8A59EF6B-447A-47B6-A552-603CCDA903EE}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
    FirewallRules: [TCP Query User{73A65667-7085-4958-9E4A-6152E28DED93}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [UDP Query User{28FA0E79-DF6D-4F3B-B13E-C7F1C475C938}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [TCP Query User{0EBA448B-CC42-4C3A-BF11-F4DCF379ECFC}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [UDP Query User{2E599A0A-1FB4-433B-94E7-A4EFA2A9C6B3}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [{5B729769-EA93-49A3-A943-D1E779C827A7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{5A93EF4D-8CD9-4E01-8672-BAD5D0977553}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{1AC5BF7C-6BA2-4173-9BE3-AEC003FA37BE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{5EB56F86-F386-4653-9FE9-C2228C140A73}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{3A3866BF-862C-4BFC-85D5-67E8566107F0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
    FirewallRules: [{404848F1-16D8-4889-AED5-D44B705ECAC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
    FirewallRules: [{8BE2350B-9A46-4ADB-8591-73131CC6D1C1}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
    FirewallRules: [{4FDE0FE9-FD52-4355-B9B0-0D4D6C284B44}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
    FirewallRules: [{276C002B-73A7-4115-9DC5-0749C294700E}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    FirewallRules: [{981D43F0-86A7-41F9-A3BD-A043E041AAD7}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    FirewallRules: [{923BFEDE-A25D-4D7A-8254-E1BA21F960D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{34313D66-7655-48F5-8B3A-7F1A9A42025C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{CDB443C1-333D-4266-9532-5C77AF3AC89F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{14781C1E-CB3B-4B77-A3D4-036A23F6472F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{54BFECE4-53A3-4C5D-BD67-FC93971152EF}] => (Allow) C:\Program Files\iTunes\iTunes.exe

    ==================== Restore Points =========================

    30-01-2016 18:11:10 Scheduled Checkpoint

    ==================== Faulty Device Manager Devices =============

    Name:
    Description:
    Class Guid:
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (01/30/2016 03:45:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 7347

    Error: (01/30/2016 03:45:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 7347

    Error: (01/30/2016 03:45:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (01/30/2016 02:42:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    Error: (01/30/2016 02:42:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
    Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

    Error: (01/30/2016 12:41:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    Error: (01/30/2016 12:41:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
    Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

    Error: (01/27/2016 05:46:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    Error: (01/27/2016 05:46:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
    Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

    Error: (01/26/2016 09:38:12 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    System errors:
    =============
    Error: (01/30/2016 07:18:20 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:18:20 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:18:20 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:45 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:45 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:45 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:06:13 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 43. The internal error state is 252.

    CodeIntegrity:
    ===================================
      Date: 2015-10-12 13:46:54.850
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2015-10-12 13:46:54.357
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    ==================== Memory info ===========================

    Processor: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
    Percentage of memory in use: 56%
    Total physical RAM: 4056.36 MB
    Available physical RAM: 1757.77 MB
    Total Virtual: 8110.93 MB
    Available Virtual: 5356.07 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:102.82 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 298.1 GB) (Disk ID: 086F8F0B)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=283.4 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

    Not sure why your txt is so small, its hard to read. When you posted the aswMBR log it was fine. Anyway you did not post the entire FRST log, I need to see the complete log.

    Hi Ken

    not sure why it went like that anyway hope this is better

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
    Ran by [removed] (administrator) on SHARON-PC (30-01-2016 19:22:46)
    Running from C:\Users\[removed]\Desktop
    [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe
    (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
    () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
    (McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    ( ) C:\Windows\System32\lxdicoms.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_20_0_0_286_ActiveX.exe
    (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\…\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
    HKLM\…\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.)
    HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
    HKLM-x32\…\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1484856 2010-06-30] (McAfee, Inc.)
    HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Run: [WinPatrol] => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [496192 2014-02-25] (BillP Studios)
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\MountPoints2: {75e4e796-5a75-11e3-b617-a4badb95f61e} - F:\DTVP_Launcher.exe
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation)
    Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-12-24]
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
    Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-12-24]
    ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
    Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk [2010-02-04]
    ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{0352CE31-0851-421A-AAA8-FFFECAAAF602}: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{8CEF2A2E-C861-4D28-B4C8-D9F096CE09D4}: [DhcpNameServer] 192.168.0.1

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.co.uk/
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {6112FDEF-4523-4643-8B16-45CF4E18157F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
    BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\McAfee\MSK\mskapbho64.dll [2010-05-03] ()
    BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
    BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100828145747.dll [2010-05-31] (McAfee, Inc.)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
    BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
    BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\McAfee\MSK\mskapbho.dll [2010-05-03] ()
    BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22] (Microsoft Corporation)
    BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-03] (Oracle Corporation)
    BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100828145747.dll [2010-05-31] (McAfee, Inc.)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
    BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-03] (Oracle Corporation)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
    Toolbar: HKU\S-1-5-21-1603844925-2173046804-925170645-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
    DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: HKLM-x32 {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
    DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
    DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
    Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe

    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1218158.dll [2015-04-27] (Adobe Systems, Inc.)
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
    FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-03] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-03] (Oracle Corporation)
    FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [2015-02-22] (Reto-Moto ApS)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @nsroblox.roblox.com/launcher -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\\NPRobloxProxy.dll [2012-12-31] ( ROBLOX Corporation)
    FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @nsroblox.roblox.com/launcher64 -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\\NPRobloxProxy64.dll [2012-12-31] ( ROBLOX Corporation)
    FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Sharon\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-05] (Unity Technologies ApS)

    Chrome:
    =======
    CHR HKLM-x32\…\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
    R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation) [File not signed]
    S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2011-02-10] () [File not signed]
    R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
    R2 lxdi_device; C:\Windows\SysWOW64\lxdicoms.exe [517040 2007-06-11] ( )
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
    R2 mcmscsvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
    R2 McNASvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
    S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [509416 2010-04-15] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
    R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199032 2010-05-31] (McAfee, Inc.)
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [244840 2010-05-31] (McAfee, Inc.)
    R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [148520 2010-05-31] (McAfee, Inc.)
    R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
    R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe [240128 2009-06-29] (IDT, Inc.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe [3417088 2009-07-17] (Dell Inc.) [File not signed]

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [62416 2010-05-31] (McAfee, Inc.)
    S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [121504 2010-05-31] (McAfee, Inc.)
    R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [189880 2010-05-31] (McAfee, Inc.)
    U3 mfeavfk01; no ImagePath
    R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [440688 2010-05-31] (McAfee, Inc.)
    R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [528616 2010-05-31] (McAfee, Inc.)
    R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75288 2010-05-31] (McAfee, Inc.)
    S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93840 2010-05-31] (McAfee, Inc.)
    R1 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [279752 2010-05-31] (McAfee, Inc.)
    R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
    S3 cpuz134; \??\C:\Users\Sharon\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
    S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
    U3 aswMBR; \??\C:\Users\Sharon\AppData\Local\Temp\aswMBR.sys [X]
    U3 aswVmm; \??\C:\Users\Sharon\AppData\Local\Temp\aswVmm.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-01-30 19:22 - 2016-01-30 19:23 - 00018229 _____ C:\Users\Sharon\Desktop\FRST.txt
    2016-01-30 19:22 - 2016-01-30 19:22 - 00000000 ____D C:\FRST
    2016-01-30 19:18 - 2016-01-30 19:18 - 02370560 _____ (Farbar) C:\Users\Sharon\Desktop\FRST64.exe
    2016-01-30 16:31 - 2016-01-30 17:45 - 00004071 _____ C:\Users\Sharon\Desktop\aswMBR.txt
    2016-01-30 16:31 - 2016-01-30 17:45 - 00000512 _____ C:\Users\Sharon\Desktop\MBR.dat
    2016-01-30 15:07 - 2016-01-30 15:07 - 05198336 _____ (AVAST Software) C:\Users\Sharon\Desktop\aswMBR.exe
    2016-01-30 12:34 - 2016-01-30 12:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2016-01-13 20:53 - 2015-12-11 18:57 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2016-01-13 20:53 - 2015-12-08 21:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
    2016-01-13 20:53 - 2015-12-08 19:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
    2016-01-13 20:53 - 2015-11-17 01:11 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
    2016-01-13 20:53 - 2015-11-17 01:08 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2016-01-13 20:53 - 2015-11-17 01:08 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2016-01-13 20:53 - 2015-11-17 01:08 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2016-01-13 20:53 - 2015-11-17 01:08 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2016-01-13 20:53 - 2015-11-17 01:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2016-01-13 20:53 - 2015-11-16 20:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
    2016-01-13 20:53 - 2015-11-13 23:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
    2016-01-13 20:53 - 2015-11-13 23:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
    2016-01-13 20:53 - 2015-11-13 23:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
    2016-01-13 20:53 - 2015-11-13 22:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
    2016-01-13 20:53 - 2015-11-13 22:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
    2016-01-13 20:53 - 2015-11-13 22:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe
    2016-01-13 20:52 - 2015-12-23 23:13 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2016-01-13 20:52 - 2015-12-23 22:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2016-01-13 20:52 - 2015-12-12 18:54 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2016-01-13 20:52 - 2015-12-12 18:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2016-01-13 20:52 - 2015-12-12 18:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2016-01-13 20:52 - 2015-12-12 18:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2016-01-13 20:52 - 2015-12-12 18:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2016-01-13 20:52 - 2015-12-12 18:15 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2016-01-13 20:52 - 2015-12-12 18:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2016-01-13 20:52 - 2015-12-12 18:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2016-01-13 20:52 - 2015-12-12 18:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2016-01-13 20:52 - 2015-12-12 18:07 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2016-01-13 20:52 - 2015-12-12 18:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2016-01-13 20:52 - 2015-12-12 18:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2016-01-13 20:52 - 2015-12-12 18:03 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2016-01-13 20:52 - 2015-12-12 18:02 - 20367360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2016-01-13 20:52 - 2015-12-12 18:02 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2016-01-13 20:52 - 2015-12-12 18:02 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2016-01-13 20:52 - 2015-12-12 18:02 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2016-01-13 20:52 - 2015-12-12 18:02 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2016-01-13 20:52 - 2015-12-12 17:55 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2016-01-13 20:52 - 2015-12-12 17:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2016-01-13 20:52 - 2015-12-12 17:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2016-01-13 20:52 - 2015-12-12 17:44 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2016-01-13 20:52 - 2015-12-12 17:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2016-01-13 20:52 - 2015-12-12 17:39 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2016-01-13 20:52 - 2015-12-12 17:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2016-01-13 20:52 - 2015-12-12 17:37 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2016-01-13 20:52 - 2015-12-12 17:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2016-01-13 20:52 - 2015-12-12 17:37 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2016-01-13 20:52 - 2015-12-12 17:36 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2016-01-13 20:52 - 2015-12-12 17:36 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2016-01-13 20:52 - 2015-12-12 17:35 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2016-01-13 20:52 - 2015-12-12 17:33 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2016-01-13 20:52 - 2015-12-12 17:31 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2016-01-13 20:52 - 2015-12-12 17:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2016-01-13 20:52 - 2015-12-12 17:28 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2016-01-13 20:52 - 2015-12-12 17:27 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2016-01-13 20:52 - 2015-12-12 17:27 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2016-01-13 20:52 - 2015-12-12 17:27 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2016-01-13 20:52 - 2015-12-12 17:25 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2016-01-13 20:52 - 2015-12-12 17:23 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2016-01-13 20:52 - 2015-12-12 17:22 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2016-01-13 20:52 - 2015-12-12 17:21 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2016-01-13 20:52 - 2015-12-12 17:20 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2016-01-13 20:52 - 2015-12-12 17:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2016-01-13 20:52 - 2015-12-12 17:18 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2016-01-13 20:52 - 2015-12-12 17:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2016-01-13 20:52 - 2015-12-12 17:12 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2016-01-13 20:52 - 2015-12-12 17:10 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2016-01-13 20:52 - 2015-12-12 17:10 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2016-01-13 20:52 - 2015-12-12 17:09 - 04610560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2016-01-13 20:52 - 2015-12-12 17:08 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2016-01-13 20:52 - 2015-12-12 17:06 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2016-01-13 20:52 - 2015-12-12 17:02 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2016-01-13 20:52 - 2015-12-12 17:00 - 12856320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2016-01-13 20:52 - 2015-12-12 17:00 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2016-01-13 20:52 - 2015-12-12 17:00 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2016-01-13 20:52 - 2015-12-12 17:00 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2016-01-13 20:52 - 2015-12-12 16:54 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2016-01-13 20:52 - 2015-12-12 16:42 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2016-01-13 20:52 - 2015-12-12 16:41 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2016-01-13 20:52 - 2015-12-12 16:38 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2016-01-13 20:52 - 2015-12-12 16:36 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2016-01-13 20:52 - 2015-12-08 21:54 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
    2016-01-13 20:52 - 2015-12-08 21:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
    2016-01-13 20:52 - 2015-12-08 21:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
    2016-01-13 20:52 - 2015-12-08 21:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
    2016-01-13 20:52 - 2015-12-08 21:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
    2016-01-13 20:52 - 2015-12-08 21:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
    2016-01-13 20:52 - 2015-12-08 21:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
    2016-01-13 20:52 - 2015-12-08 21:53 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
    2016-01-13 20:52 - 2015-12-08 21:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll
    2016-01-13 20:52 - 2015-12-08 21:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
    2016-01-13 20:52 - 2015-12-08 19:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
    2016-01-13 20:52 - 2015-12-08 19:07 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
    2016-01-13 20:52 - 2015-12-08 19:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll
    2016-01-13 20:52 - 2015-12-08 19:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
    2016-01-13 20:52 - 2015-12-08 19:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
    2016-01-13 20:52 - 2015-12-08 19:04 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
    2016-01-13 20:52 - 2015-12-08 18:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
    2016-01-13 20:52 - 2015-12-08 18:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
    2016-01-13 20:52 - 2015-12-08 18:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
    2016-01-13 20:52 - 2015-12-08 17:58 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2016-01-13 20:51 - 2015-12-08 21:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
    2016-01-13 20:51 - 2015-12-08 21:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2016-01-13 20:51 - 2015-12-08 19:07 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2016-01-13 20:51 - 2015-12-08 19:07 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2016-01-13 20:50 - 2015-12-30 19:08 - 05572544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2016-01-13 20:50 - 2015-12-30 19:08 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2016-01-13 20:50 - 2015-12-30 19:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2016-01-13 20:50 - 2015-12-30 19:05 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2016-01-13 20:50 - 2015-12-30 19:02 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2016-01-13 20:50 - 2015-12-30 19:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2016-01-13 20:50 - 2015-12-30 19:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2016-01-13 20:50 - 2015-12-30 19:02 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2016-01-13 20:50 - 2015-12-30 19:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2016-01-13 20:50 - 2015-12-30 19:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2016-01-13 20:50 - 2015-12-30 19:01 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2016-01-13 20:50 - 2015-12-30 19:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2016-01-13 20:50 - 2015-12-30 19:01 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2016-01-13 20:50 - 2015-12-30 19:01 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2016-01-13 20:50 - 2015-12-30 19:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2016-01-13 20:50 - 2015-12-30 19:01 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2016-01-13 20:50 - 2015-12-30 19:01 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2016-01-13 20:50 - 2015-12-30 19:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2016-01-13 20:50 - 2015-12-30 18:59 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2016-01-13 20:50 - 2015-12-30 18:59 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2016-01-13 20:50 - 2015-12-30 18:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2016-01-13 20:50 - 2015-12-30 18:58 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2016-01-13 20:50 - 2015-12-30 18:58 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2016-01-13 20:50 - 2015-12-30 18:57 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2016-01-13 20:50 - 2015-12-30 18:57 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2016-01-13 20:50 - 2015-12-30 18:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2016-01-13 20:50 - 2015-12-30 18:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2016-01-13 20:50 - 2015-12-30 18:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
    2016-01-13 20:50 - 2015-12-30 18:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:47 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2016-01-13 20:50 - 2015-12-30 18:47 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2016-01-13 20:50 - 2015-12-30 18:44 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2016-01-13 20:50 - 2015-12-30 18:41 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2016-01-13 20:50 - 2015-12-30 18:40 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2016-01-13 20:50 - 2015-12-30 18:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2016-01-13 20:50 - 2015-12-30 18:39 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2016-01-13 20:50 - 2015-12-30 18:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2016-01-13 20:50 - 2015-12-30 18:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2016-01-13 20:50 - 2015-12-30 18:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2016-01-13 20:50 - 2015-12-30 18:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2016-01-13 20:50 - 2015-12-30 18:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 17:57 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2016-01-13 20:50 - 2015-12-30 17:50 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2016-01-13 20:50 - 2015-12-30 17:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2016-01-13 20:50 - 2015-12-30 17:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2016-01-13 20:50 - 2015-12-30 17:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
    2016-01-13 20:50 - 2015-12-30 17:42 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2016-01-13 20:50 - 2015-12-30 17:42 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
    2016-01-13 20:50 - 2015-12-30 17:41 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2016-01-13 20:50 - 2015-12-30 17:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2016-01-13 20:50 - 2015-12-30 17:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2016-01-13 20:50 - 2015-12-30 17:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2016-01-13 20:50 - 2015-12-30 17:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2016-01-13 20:50 - 2015-12-30 17:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2016-01-13 20:50 - 2015-12-30 17:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
    2016-01-13 20:50 - 2015-12-30 17:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 17:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 17:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2016-01-13 20:50 - 2015-12-30 17:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-01-30 19:23 - 2009-07-14 04:45 - 00022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-01-30 19:23 - 2009-07-14 04:45 - 00022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-01-30 18:56 - 2015-06-21 08:50 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2016-01-30 18:43 - 2012-04-01 17:57 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2016-01-30 15:34 - 2015-06-21 08:50 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2016-01-30 14:42 - 2009-07-14 05:13 - 00006210 _____ C:\Windows\system32\PerfStringBackup.INI
    2016-01-30 12:33 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2016-01-27 17:42 - 2009-07-14 05:08 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
    2016-01-25 20:11 - 2013-04-21 17:08 - 00000000 ____D C:\Users\Sharon\Desktop\Sharon
    2016-01-20 20:43 - 2012-04-01 17:57 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2016-01-20 20:43 - 2012-04-01 17:57 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2016-01-20 20:43 - 2011-05-14 15:03 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-01-19 12:45 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\system32\NDF
    2016-01-16 12:31 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\rescache
    2016-01-15 19:42 - 2009-07-14 04:45 - 00418328 _____ C:\Windows\system32\FNTCACHE.DAT
    2016-01-15 19:38 - 2014-12-12 20:23 - 00000000 ____D C:\Windows\system32\appraiser
    2016-01-15 19:38 - 2014-05-07 19:00 - 00000000 ___SD C:\Windows\system32\CompatTel
    2016-01-15 19:36 - 2013-03-12 21:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2016-01-13 21:25 - 2013-03-12 21:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2016-01-13 21:25 - 2013-03-12 21:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2016-01-13 21:24 - 2013-08-14 19:01 - 00000000 ____D C:\Windows\system32\MRT
    2016-01-13 21:18 - 2010-02-06 16:14 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2016-01-12 16:06 - 2015-10-25 19:45 - 00000000 ____D C:\Users\Sharon\Desktop\Matthew Folder
    2016-01-11 18:58 - 2011-09-12 18:33 - 00541334 _____ C:\Windows\ntbtlog.txt

    ==================== Files in the root of some directories =======

    2010-02-07 14:06 - 2010-02-07 14:06 - 0000014 _____ () C:\Users\Sharon\AppData\Roaming\licence.txt
    2010-09-09 17:52 - 2010-09-09 17:52 - 0000000 _____ () C:\Users\Sharon\AppData\Roaming\wklnhst.dat
    2011-09-12 18:26 - 2012-08-07 20:52 - 0106070 _____ () C:\Users\Sharon\AppData\Local\ars.cache
    2011-09-12 18:26 - 2012-08-07 20:52 - 0853856 _____ () C:\Users\Sharon\AppData\Local\census.cache
    2011-06-10 20:29 - 2011-06-10 20:29 - 0000036 _____ () C:\Users\Sharon\AppData\Local\housecall.guid.cache
    2010-04-06 17:15 - 2010-04-06 17:15 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

    Some files in TEMP:
    ====================
    C:\Users\Sharon\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
    C:\Users\Sharon\AppData\Local\Temp\jre-8u40-windows-au.exe
    C:\Users\Sharon\AppData\Local\Temp\pcspeedup_6e75c22604454eb0bf27d89570f83ac4_.exe
    C:\Users\Sharon\AppData\Local\Temp\Quarantine.exe

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2016-01-30 18:04

    ==================== End of FRST.txt ============================

     

     

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:27-01-2016
    Ran by [removed] (2016-01-30 19:24:07)
    Running from C:\Users\[removed]\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2010-02-04 22:00:14)
    Boot Mode: Normal
    ==========================================================

    ==================== Accounts: =============================

    Administrator (S-1-5-21-1603844925-2173046804-925170645-500 - Administrator - Disabled)
    Guest (S-1-5-21-1603844925-2173046804-925170645-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-1603844925-2173046804-925170645-1002 - Limited - Enabled)
    Sharon (S-1-5-21-1603844925-2173046804-925170645-1000 - Administrator - Enabled) => C:\Users\Sharon

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {86355677-4064-3EA7-ABB3-1B136EB04637}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {3D54B793-665E-3129-9103-206115370C8A}
    FW: McAfee Firewall (Enabled) {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
    Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
    Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.)
    Adobe Flash Player 20 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
    Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.8.158 - Adobe Systems, Inc.)
    Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
    Apple Application Support (32-bit) (HKLM-x32\…\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\…\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
    AviSynth 2.5 (HKLM-x32\…\AviSynth) (Version:  - )
    AVS Image Converter 1.2.1.100 (HKLM-x32\…\AVS Image Converter_is1) (Version:  - Online Media Technologies Ltd.)
    AVS Update Manager 1.0 (HKLM-x32\…\AVS Update Manager_is1) (Version:  - Online Media Technologies Ltd.)
    Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
    Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
    Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
    Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dell Dock (HKLM\…\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell)
    Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
    Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
    Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 13.2.3.0 - Synaptics Incorporated)
    Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
    Dell Wireless WLAN Card Utility (HKLM\…\Dell Wireless WLAN Card Utility) (Version: 5.30.21.0 - Dell Inc.)
    Digital Photo Navigator 1.0 (HKLM-x32\…\{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}) (Version:  - )
    Disk Cleaner (remove only) (HKLM-x32\…\DiskCleaner) (Version:  - )
    ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
    EZ Software Updater version 1.0.0.0 (HKLM-x32\…\EZ Software Updater_is1) (Version: 1.0.0.0 - )
    ffdshow v1.1.3572 [2010-09-13] (HKLM-x32\…\ffdshow_is1) (Version: 1.1.3572.0 - )
    Free Audio CD to MP3 Converter version 1.3.12.1228 (HKLM-x32\…\Free Audio CD to MP3 Converter_is1) (Version: 1.3.12.1228 - DVDVideoSoft Ltd.)
    Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    Haali Media Splitter (HKLM-x32\…\HaaliMkx) (Version:  - )
    Heroes & Generals (HKLM-x32\…\Heroes & Generals) (Version: 1.0.6.1 - Reto-Moto)
    iCloud (HKLM\…\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
    iCopyBot for Windows 7.9.8 (HKLM-x32\…\iCopyBot for Windows) (Version: 7.9.8 - VOWSoft, Ltd.)
    Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002 - Brice Lambson) Hidden
    Image Resizer for Windows (HKLM-x32\…\{9dfff2f7-5cd7-4fd4-9b75-7d53b042d94b}) (Version: 3.0.4442.6002 - Brice Lambson)
    inSSIDer Home (HKLM-x32\…\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
    InstallConverter (HKLM-x32\…\InstallConverter) (Version: 1.0 - InstallConverter)
    Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1029 - Intel Corporation)
    Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
    iTunes (HKLM\…\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
    Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    LAV Filters 0.51.3 (HKLM-x32\…\lavfilters_is1) (Version: 0.51.3 - Hendrik Leppkes)
    Lexmark 3500-4500 Series (HKLM\…\Lexmark 3500-4500 Series) (Version:  - Lexmark International, Inc.)
    Live! Cam Avatar Creator (HKLM-x32\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.3009.1 - Creative Technology Ltd)
    McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 10.5.195 - McAfee, Inc.)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
    Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
    Mount&Blade; Warband (HKLM-x32\…\Mount&Blade; Warband) (Version:  - )
    PassShow (HKLM-x32\…\0AADCD53-E02F-9B5A-5431-BAACC6D75585) (Version:  - PassShow-software) <==== ATTENTION
    PowerDVD DX (HKLM-x32\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.3.5424 - CyberLink Corp.)
    Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 9.6.6 - Dell Inc.)
    QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
    ROBLOX Player for Sharon (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
    Roxio Burn (HKLM-x32\…\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.0 - Roxio)
    Skype Click to Call (HKLM-x32\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
    Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
    Sothink Movie DVD Maker (HKLM-x32\…\{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1) (Version: 3.8 - SourceTec Software Co., LTD)
    Spotify (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Spotify) (Version: 0.9.4.185.g7545a404 - Spotify AB)
    Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    Unity Web Player (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
    Verdun (HKLM-x32\…\Steam App 242860) (Version:  - M2H)
    Virgin Media Cloud (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Virgin Media Cloud) (Version: 2.4.4435 - F-Secure Corporation)
    VLC media player 2.1.2 (HKLM-x32\…\VLC media player) (Version: 2.1.2 - VideoLAN)
    Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
    WinPatrol (HKLM\…\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.1.2014 - BillP Studios)
    WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-1603844925-2173046804-925170645-1000_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\RobloxProxy64.dll (ROBLOX Corporation)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {039DD88D-3DDE-408C-8A5A-55F7121590DB} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-02-10] (Oracle Corporation)
    Task: {16B97E37-3B14-4027-A65E-72E301F80F1A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {2FE1DE7F-DDC3-42E3-BD3E-4667BF17AED2} - System32\Tasks\{8D06BC15-F5B6-4AC0-8233-9F0ADAA4DD1D} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
    Task: {327AFB33-C66D-4C6D-8B23-10B01570B775} - \PassShow Update -> No File <==== ATTENTION
    Task: {3C6C326B-CD9B-4D58-925C-C7811B8E52D1} - \Feven 2.2-updater -> No File <==== ATTENTION
    Task: {3CFB5768-E431-47D0-A3BD-F30C37D424C3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
    Task: {47180107-64DE-431E-97CC-F1EC25F0881E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
    Task: {4E87D8BF-C0DE-45DE-910D-861B71EAAB88} - \Feven 2.2-enabler -> No File <==== ATTENTION
    Task: {55870B00-CB28-4ACC-9AAB-11A5DDE0BBB0} - \Feven 2.2-firefoxinstaller -> No File <==== ATTENTION
    Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
    Task: {5CC024D9-88E3-4817-A1B2-67C20F19ADFF} - \Feven 2.2-validator -> No File <==== ATTENTION
    Task: {66B6E2DE-37EF-40A4-A29A-1499E3ACC54D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
    Task: {6DEE93CC-4A2E-49D3-B1FF-35E50C2B2309} - System32\Tasks\DJNJ8SJ1\Administrator - Start WLAN Tray Applet => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE [2009-07-17] (Dell Inc.)
    Task: {8335C703-0DFD-4F5A-8D7B-CF11E9336803} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
    Task: {87589C5E-C1AE-4503-87BC-76B273547797} - System32\Tasks\{A3FDA8D8-F1E0-49A9-AC99-A04158C023A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsBing
    Task: {A16B56B1-CACA-4C8E-957D-63C1895450B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {A367EA33-4598-400B-9BC0-C8CB941BE71E} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
    Task: {C7ADECB6-B5C1-4EC4-8D00-965492898B02} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated)
    Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc
    Task: {E828258C-E94D-4A65-9F31-5F74DC09DA34} - \Feven 2.2-codedownloader -> No File <==== ATTENTION
    Task: {EBD1FDC5-D5BB-4090-81DD-7B336A22F2CE} - System32\Tasks\{39320917-C1DD-477D-A6D2-463E786AB835} => pcalua.exe -a C:\PROGRA~2\SearchProtect\Main\bin\uninstall.exe -c /S <==== ATTENTION
    Task: {F4214C36-6660-4F72-BDC8-98F2C55B6D6A} - System32\Tasks\{46EF662D-9A7C-4B91-A664-490EC3CA199D} => pcalua.exe -a C:\JVC\UsbSTGE.exe -d C:\JVC

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2009-12-24 15:30 - 2009-07-17 01:06 - 00033280 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
    2009-12-24 15:30 - 2009-07-17 01:06 - 00058368 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll
    2012-11-11 10:58 - 2007-03-15 23:11 - 00138240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdidrpp.dll
    2010-01-09 20:17 - 2010-01-09 20:17 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
    2010-01-21 01:40 - 2010-01-21 01:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
    2010-12-20 21:59 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
    2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-10-13 05:45 - 2015-10-13 05:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2015-12-13 19:46 - 2015-12-13 19:46 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\ad2fbbd746bb143008adb984541da686\VistaBridgeLibrary.ni.dll
    2014-02-19 20:53 - 2014-02-18 03:46 - 00643948 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
    2015-10-13 05:46 - 2015-10-13 05:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-10-13 05:45 - 2015-10-13 05:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
    2010-01-09 20:18 - 2010-01-09 20:18 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
    2010-01-21 01:34 - 2010-01-21 01:34 - 08793952 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 02:34 - 2009-06-10 21:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.0.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
    MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{0332E39C-D700-4178-897A-91BD7C9FC3AD}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PowerDVD.exe
    FirewallRules: [{9241A141-1C7D-401C-86FF-68DC3C733D89}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    FirewallRules: [{E511FE26-5850-40F8-8BE9-369B466129B8}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{25E1DDAA-1275-43E2-B0D5-CA0A038762C1}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
    FirewallRules: [{DA5B37A1-E998-4461-801B-885310A70C65}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{4448837A-8A45-4DCF-80EA-018CCABB0152}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    FirewallRules: [{8B5C7515-5E52-4B14-8615-C5CFE1DF0492}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    FirewallRules: [{579303C5-7A83-499E-9059-9FFC90A94E4F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{B292AF1D-BDDF-4862-A319-63627591A6D9}] => (Allow) LPort=2869
    FirewallRules: [{DCA207F2-8A87-4052-8AFF-D08D9ABE6225}] => (Allow) LPort=1900
    FirewallRules: [{525A5E41-73B4-46E1-A5DE-2A156D737B6D}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
    FirewallRules: [{18ADDB25-AE21-433A-88B0-DED508680E27}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{40BC477C-361A-49EC-B674-DF8C4F7549D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{1FD7A359-3662-44EB-9527-46ED6EC10CC4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{879B9977-27F7-4A07-A959-ACA27B6D2E65}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{49E791C3-7A74-4EB9-B960-1874CB2A5BB8}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
    FirewallRules: [{AAFE46BE-7A06-4B2B-AAA0-84AC3D110836}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
    FirewallRules: [{9AEA2DC4-DAC2-4341-994C-DF13AF827FB0}] => (Allow) C:\Windows\System32\lxdicoms.exe
    FirewallRules: [{B911FD92-BABC-4726-8DB7-CA322C099DB8}] => (Allow) C:\Windows\System32\lxdicoms.exe
    FirewallRules: [{CF986128-AD4D-45F2-B22E-E3E16E4E9FDA}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
    FirewallRules: [{7D535C64-78C0-4E0C-A596-6C0621DBE66B}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
    FirewallRules: [{13D9AB9D-4990-49F7-B640-F6F067B2219F}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
    FirewallRules: [{B4DB37E7-E205-4B03-8206-BAE9398D3102}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
    FirewallRules: [{7FFE1605-CD9B-4AC5-9763-6BEE75155F10}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
    FirewallRules: [{156A3780-BFB6-408D-A8F4-AE3FE8F659ED}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
    FirewallRules: [{E39C41EC-5187-4A43-91D4-D2B7947FE7A4}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
    FirewallRules: [{DEC501C9-836F-4D67-A90B-166B23F3A457}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
    FirewallRules: [{5C050647-43F3-4455-84BF-DED1B647757E}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
    FirewallRules: [{C31D4F77-42C9-4606-97F8-227BD727E95D}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
    FirewallRules: [{7789B22F-ADB1-496E-BEAF-8DF913B284EC}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
    FirewallRules: [{5666A10E-8B52-4A11-A734-780A14E2E741}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
    FirewallRules: [TCP Query User{9168E047-A0A1-4A11-8667-9CA820EE5996}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
    FirewallRules: [UDP Query User{29D328A2-FF65-424E-A7E0-67335D03F7AB}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
    FirewallRules: [TCP Query User{6360F2DA-6D0B-4185-B133-BE5E59007308}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
    FirewallRules: [UDP Query User{8A59EF6B-447A-47B6-A552-603CCDA903EE}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
    FirewallRules: [TCP Query User{73A65667-7085-4958-9E4A-6152E28DED93}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [UDP Query User{28FA0E79-DF6D-4F3B-B13E-C7F1C475C938}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [TCP Query User{0EBA448B-CC42-4C3A-BF11-F4DCF379ECFC}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [UDP Query User{2E599A0A-1FB4-433B-94E7-A4EFA2A9C6B3}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
    FirewallRules: [{5B729769-EA93-49A3-A943-D1E779C827A7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{5A93EF4D-8CD9-4E01-8672-BAD5D0977553}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{1AC5BF7C-6BA2-4173-9BE3-AEC003FA37BE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{5EB56F86-F386-4653-9FE9-C2228C140A73}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{3A3866BF-862C-4BFC-85D5-67E8566107F0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
    FirewallRules: [{404848F1-16D8-4889-AED5-D44B705ECAC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
    FirewallRules: [{8BE2350B-9A46-4ADB-8591-73131CC6D1C1}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
    FirewallRules: [{4FDE0FE9-FD52-4355-B9B0-0D4D6C284B44}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
    FirewallRules: [{276C002B-73A7-4115-9DC5-0749C294700E}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    FirewallRules: [{981D43F0-86A7-41F9-A3BD-A043E041AAD7}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    FirewallRules: [{923BFEDE-A25D-4D7A-8254-E1BA21F960D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{34313D66-7655-48F5-8B3A-7F1A9A42025C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{CDB443C1-333D-4266-9532-5C77AF3AC89F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{14781C1E-CB3B-4B77-A3D4-036A23F6472F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{54BFECE4-53A3-4C5D-BD67-FC93971152EF}] => (Allow) C:\Program Files\iTunes\iTunes.exe

    ==================== Restore Points =========================

    30-01-2016 18:11:10 Scheduled Checkpoint

    ==================== Faulty Device Manager Devices =============

    Name:
    Description:
    Class Guid:
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (01/30/2016 03:45:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 7347

    Error: (01/30/2016 03:45:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 7347

    Error: (01/30/2016 03:45:37 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (01/30/2016 02:42:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    Error: (01/30/2016 02:42:32 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
    Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

    Error: (01/30/2016 12:41:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    Error: (01/30/2016 12:41:38 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
    Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

    Error: (01/27/2016 05:46:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    Error: (01/27/2016 05:46:49 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
    Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

    Error: (01/26/2016 09:38:12 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
    Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

    System errors:
    =============
    Error: (01/30/2016 07:18:20 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:18:20 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:18:20 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:47 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:45 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:45 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:17:45 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 10. The internal error state is 10.

    Error: (01/30/2016 07:06:13 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: The following fatal alert was generated: 43. The internal error state is 252.

    CodeIntegrity:
    ===================================
      Date: 2015-10-12 13:46:54.850
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2015-10-12 13:46:54.357
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    ==================== Memory info ===========================

    Processor: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
    Percentage of memory in use: 56%
    Total physical RAM: 4056.36 MB
    Available physical RAM: 1757.77 MB
    Total Virtual: 8110.93 MB
    Available Virtual: 5356.07 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:102.82 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 298.1 GB) (Disk ID: 086F8F0B)
    Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
    Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=283.4 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

    Ahhh, much better THANK YOU. These old eyes are not as good as they used to be :)

     

    Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
    Please copy the entire contents Inside of the code box below beginning with START and ending with END
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
    Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
     
    Start
    CloseProcesses:
    CreateRestorePoint: 
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe
    Task: {327AFB33-C66D-4C6D-8B23-10B01570B775} - \PassShow Update -> No File <==== ATTENTION
    Task: {3C6C326B-CD9B-4D58-925C-C7811B8E52D1} - \Feven 2.2-updater -> No File <==== ATTENTION
    Task: {4E87D8BF-C0DE-45DE-910D-861B71EAAB88} - \Feven 2.2-enabler -> No File <==== ATTENTION
    Task: {55870B00-CB28-4ACC-9AAB-11A5DDE0BBB0} - \Feven 2.2-firefoxinstaller -> No File <==== ATTENTION
    Task: {5CC024D9-88E3-4817-A1B2-67C20F19ADFF} - \Feven 2.2-validator -> No File <==== ATTENTION
    Task: {E828258C-E94D-4A65-9F31-5F74DC09DA34} - \Feven 2.2-codedownloader -> No File <==== ATTENTION
    Task: {EBD1FDC5-D5BB-4090-81DD-7B336A22F2CE} - System32\Tasks\{39320917-C1DD-477D-A6D2-463E786AB835} => pcalua.exe -a C:\PROGRA~2\SearchProtect\Main\bin\uninstall.exe -c /S <==== ATTENTION
    C:\PROGRA~2\SearchProtect
    FirewallRules: [{276C002B-73A7-4115-9DC5-0749C294700E}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    FirewallRules: [{981D43F0-86A7-41F9-A3BD-A043E041AAD7}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    Hosts:
    CMD: ipconfig /flushdns
    EmptyTemp:
    End
    
     
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Hi Ken

    thanks for the quick replies

    new log

     

     

    Fix result of Farbar Recovery Scan Tool (x64) Version:27-01-2016
    Ran by [removed] (2016-01-30 22:37:01) Run:1
    Running from C:\Users\[removed]\Desktop
    [removed] Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Start
    CloseProcesses:
    CreateRestorePoint:
    StartMenuInternet: IEXPLORE.EXE - iexplore.exe
    Task: {327AFB33-C66D-4C6D-8B23-10B01570B775} - \PassShow Update -> No File <==== ATTENTION
    Task: {3C6C326B-CD9B-4D58-925C-C7811B8E52D1} - \Feven 2.2-updater -> No File <==== ATTENTION
    Task: {4E87D8BF-C0DE-45DE-910D-861B71EAAB88} - \Feven 2.2-enabler -> No File <==== ATTENTION
    Task: {55870B00-CB28-4ACC-9AAB-11A5DDE0BBB0} - \Feven 2.2-firefoxinstaller -> No File <==== ATTENTION
    Task: {5CC024D9-88E3-4817-A1B2-67C20F19ADFF} - \Feven 2.2-validator -> No File <==== ATTENTION
    Task: {E828258C-E94D-4A65-9F31-5F74DC09DA34} - \Feven 2.2-codedownloader -> No File <==== ATTENTION
    Task: {EBD1FDC5-D5BB-4090-81DD-7B336A22F2CE} - System32\Tasks\{39320917-C1DD-477D-A6D2-463E786AB835} => pcalua.exe -a C:\PROGRA~2\SearchProtect\Main\bin\uninstall.exe -c /S <==== ATTENTION
    C:\PROGRA~2\SearchProtect
    FirewallRules: [{276C002B-73A7-4115-9DC5-0749C294700E}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    FirewallRules: [{981D43F0-86A7-41F9-A3BD-A043E041AAD7}] => (Allow) C:\Users\Sharon\AppData\Local\Temp\nsw361E.tmp\CnetInstaller-10969873.exe
    Hosts:
    CMD: ipconfig /flushdns
    EmptyTemp:
    End
    *****************

    Processes closed successfully.
    Restore point was successfully created.
    HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => value restored successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{327AFB33-C66D-4C6D-8B23-10B01570B775}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{327AFB33-C66D-4C6D-8B23-10B01570B775}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PassShow Update" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3C6C326B-CD9B-4D58-925C-C7811B8E52D1}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C6C326B-CD9B-4D58-925C-C7811B8E52D1}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Feven 2.2-updater" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4E87D8BF-C0DE-45DE-910D-861B71EAAB88}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E87D8BF-C0DE-45DE-910D-861B71EAAB88}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Feven 2.2-enabler" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{55870B00-CB28-4ACC-9AAB-11A5DDE0BBB0}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55870B00-CB28-4ACC-9AAB-11A5DDE0BBB0}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Feven 2.2-firefoxinstaller" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5CC024D9-88E3-4817-A1B2-67C20F19ADFF}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5CC024D9-88E3-4817-A1B2-67C20F19ADFF}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Feven 2.2-validator" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E828258C-E94D-4A65-9F31-5F74DC09DA34}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E828258C-E94D-4A65-9F31-5F74DC09DA34}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Feven 2.2-codedownloader" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EBD1FDC5-D5BB-4090-81DD-7B336A22F2CE}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EBD1FDC5-D5BB-4090-81DD-7B336A22F2CE}" => key removed successfully
    C:\Windows\System32\Tasks\{39320917-C1DD-477D-A6D2-463E786AB835} => moved successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{39320917-C1DD-477D-A6D2-463E786AB835}" => key removed successfully
    "C:\PROGRA~2\SearchProtect" => not found.
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{276C002B-73A7-4115-9DC5-0749C294700E} => value removed successfully
    HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{981D43F0-86A7-41F9-A3BD-A043E041AAD7} => value removed successfully
    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.

    =========  ipconfig /flushdns =========

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========= End of CMD: =========

    EmptyTemp: => 5.1 GB temporary data Removed.

    The system needed a reboot.

    ==== End of Fixlog 22:39:19 ====

     

    Good,

     

    Run these programs and lets see if the find and remove anything

     

     
    -AdwCleaner-by Xplode
     
    Click on this link to download : ADWCleaner TO YOUR DESKTOP
     
    Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
     
     
    [external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
     
    • Close all open programs and internet browsers.
    • Double click on AdwCleaner.exe to run the tool.
    • Click on Scan.
    • After the scan is complete click on "Clean"
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the content of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
    •  
       
      ===============================================================================
       
       
       
      [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
      • Download the one from Bleeping Computer
      • Shut down your protection software now to avoid potential conflicts.
      • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
      • The tool will open and start scanning your system.
      • Please be patient as this can take a while to complete depending on your system's specifications.
      • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
      • Post the contents of JRT.txt into your next message.
      •  
         
         
        ===============================================================================
         
        Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
         
        • Windows XP : Double click on the icon to run it.
        • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
        •  
          [external image: 0841859c-1a35-4dbd-b41a-e720629e3e22_zps]
           
          • On the Dashboard click on Update Now
          • Go to the Setting Tab
          • Under Setting go to Detection and Protection
          • Under PUP and PUM make sure both are set to show Treat Detections as Malware
          • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
          • Then on the Dashboard click on Scan
          • Make sure to select THREAT SCAN
          • Then click on Scan
          • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
          • Please paste the log back into this thread for review
          • Exit Malwarebytes
          • Hi Ken

            please see logfiles below

             

             

            # AdwCleaner v5.031 - Logfile created 31/01/2016 at 11:05:46
            # Updated 25/01/2016 by Xplode
            # Database : 2016-01-25.3 [Server]
            # Operating system : Windows 7 Home Premium Service Pack 1 (x64)
            # Username : Sharon - SHARON-PC
            # Running from : C:\Users\Sharon\Desktop\AdwCleaner.exe
            # Option : Cleaning
            # Support : http://toolslib.net/forum

            ***** [ Services ] *****

            ***** [ Folders ] *****

            [-] Folder Deleted : C:\Users\Sharon\AppData\Roaming\rightbackup
            [-] Folder Deleted : C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Systweak

            ***** [ Files ] *****

            [-] File Deleted : C:\Windows\Reimage.ini

            ***** [ DLLs ] *****

            ***** [ Shortcuts ] *****

            ***** [ Scheduled tasks ] *****

            ***** [ Registry ] *****

            [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
            [-] Key Deleted : HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
            [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B49F7AB3-3AA3-2AE4-FCCD-0A65F094F67D}
            [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fcda872c-4de4-443f-a003-b0ef57eb2fe7}
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fcda872c-4de4-443f-a003-b0ef57eb2fe7}
            [-] Key Deleted : HKCU\Software\OB
            [-] Key Deleted : HKCU\Software\Reimage
            [-] Key Deleted : HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
            [-] Key Deleted : HKCU\Software\AppDataLow\Software\PassShow
            [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EZ Software Updater_is1
            [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\0AADCD53-E02F-9B5A-5431-BAACC6D75585
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Reimage
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited
            [-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
            [-] Key Deleted : HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
            [-] Key Deleted : HKU\S-1-5-20\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
            [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
            [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com

            ***** [ Web browsers ] *****

            *************************

            :: "Tracing" keys removed
            :: Winsock settings cleared

            ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4166 bytes] ##########

             

             

            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Junkware Removal Tool (JRT) by Malwarebytes
            Version: 8.0.2 (01.06.2016)
            Operating System: Windows 7 Home Premium x64
            Ran by [removed] (Administrator) on 31/01/2016 at 11:14:01.44
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

             

            File System: 4

            Successfully deleted: C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1C1M0HQL (Folder)
            Successfully deleted: C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\276RCSJM (Folder)
            Successfully deleted: C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SP1TTNGW (Folder)
            Successfully deleted: C:\Users\Sharon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XHR1YPGE (Folder)

             

            Registry: 0

             

             

            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            Scan was completed on 31/01/2016 at 11:17:33.78
            End of JRT log
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

             

             

            Malwarebytes Anti-Malware
            www.malwarebytes.org

            Scan Date: 31/01/2016
            Scan Time: 11:22
            Logfile: malware.txt
            Administrator: Yes

            Version: 2.2.0.1024
            Malware Database: v2016.01.31.01
            Rootkit Database: v2016.01.20.01
            License: Free
            Malware Protection: Disabled
            Malicious Website Protection: Disabled
            Self-protection: Disabled

            OS: Windows 7 Service Pack 1
            CPU: x64
            File System: NTFS
            User: Sharon

            Scan Type: Threat Scan
            Result: Completed
            Objects Scanned: 397617
            Time Elapsed: 3 hr, 56 min, 0 sec

            Memory: Enabled
            Startup: Enabled
            Filesystem: Enabled
            Archives: Enabled
            Rootkits: Disabled
            Heuristics: Enabled
            PUP: Enabled
            PUM: Enabled

            Processes: 0
            (No malicious items detected)

            Modules: 0
            (No malicious items detected)

            Registry Keys: 16
            PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE9B20D-BC9D-4F0F-BF46-D8C9BDE6FF6D}, , [8ba255ebdfbabc7ae46d27a3de259f61],
            PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE9B20D-BC9D-4F0F-BF46-D8C9BDE6FF6D}, , [ab8289b76a2fb97d074a03c73ec5e61a],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{137D55A5-1DFC-4752-93D2-E69A31EC25D3}, , [38f54af6762310261819be0c18ebf808],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{178183DB-ABA9-4CDF-BBD7-BEC3E9F7B7A2}, , [ef3e58e8e1b8b284c270e8e236cd4bb5],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{183A0F40-1320-4704-ABC4-626EC46DE766}, , [002df8482178191d1919e2e8d231eb15],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{224437DC-C0F0-4F10-8274-C6889DBE462E}, , [8e9f72ce475278be84ae01c946bd9c64],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A28B0B4-9CFC-4B4C-AC13-D9AF1817F128}, , [ae7fb88874252c0a6ec34189e61d629e],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7AC28169-EDCE-4850-A0A5-1EFDA7DAD0B1}, , [1e0f5be53a5f67cfb77b06c4679cb947],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FBD4984-43E2-4F14-89BB-7C39848FD214}, , [31fcca761f7aa88ec46e10ba60a335cb],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE9B20D-BC9D-4F0F-BF46-D8C9BDE6FF6D}, , [ab82a9973564c86e8ca4daf02ad9a45c],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0856D1F-7E66-4523-968B-89CF5CAAB9AC}, , [58d5eb558f0a092d9e940dbdb54ea957],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8327152-D04F-42E5-AB9C-CAEC5D27BEF2}, , [1f0e76cad9c074c2ce649b2ff013817f],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2678F97-E501-402D-B5D0-983EB2961D7C}, , [6dc03a068712b0860c25bf0b719251af],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB59012C-1E59-40AC-8612-BC479D6DB299}, , [b37a56ead9c0e452db5727a338cbc23e],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EEC94827-F6DC-4FB7-B298-729FA173BAEE}, , [a08d0f316f2afe386fc229a1c83bb947],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FCDA872C-4DE4-443F-A003-B0EF57EB2FE7}, , [57d69ca45445eb4bea48903a50b3ea16],

            Registry Values: 16
            PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9fe9b20d-bc9d-4f0f-bf46-d8c9bde6ff6d}|AppName, Feven 2.2-bg.exe, , [8ba255ebdfbabc7ae46d27a3de259f61]
            PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9fe9b20d-bc9d-4f0f-bf46-d8c9bde6ff6d}|AppName, Feven 2.2-bg.exe, , [ab8289b76a2fb97d074a03c73ec5e61a]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{137D55A5-1DFC-4752-93D2-E69A31EC25D3}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, , [38f54af6762310261819be0c18ebf808]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{178183DB-ABA9-4CDF-BBD7-BEC3E9F7B7A2}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [ef3e58e8e1b8b284c270e8e236cd4bb5]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{183A0F40-1320-4704-ABC4-626EC46DE766}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [002df8482178191d1919e2e8d231eb15]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{224437DC-C0F0-4F10-8274-C6889DBE462E}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [8e9f72ce475278be84ae01c946bd9c64]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A28B0B4-9CFC-4B4C-AC13-D9AF1817F128}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, , [ae7fb88874252c0a6ec34189e61d629e]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7AC28169-EDCE-4850-A0A5-1EFDA7DAD0B1}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [1e0f5be53a5f67cfb77b06c4679cb947]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FBD4984-43E2-4F14-89BB-7C39848FD214}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [31fcca761f7aa88ec46e10ba60a335cb]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9fe9b20d-bc9d-4f0f-bf46-d8c9bde6ff6d}|AppName, Feven 2.2-bg.exe, , [ab82a9973564c86e8ca4daf02ad9a45c]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0856D1F-7E66-4523-968B-89CF5CAAB9AC}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [58d5eb558f0a092d9e940dbdb54ea957]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8327152-D04F-42E5-AB9C-CAEC5D27BEF2}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [1f0e76cad9c074c2ce649b2ff013817f]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2678F97-E501-402D-B5D0-983EB2961D7C}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, , [6dc03a068712b0860c25bf0b719251af]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB59012C-1E59-40AC-8612-BC479D6DB299}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, , [b37a56ead9c0e452db5727a338cbc23e]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EEC94827-F6DC-4FB7-B298-729FA173BAEE}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, , [a08d0f316f2afe386fc229a1c83bb947]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{fcda872c-4de4-443f-a003-b0ef57eb2fe7}|AppName, Feven 2.2-codedownloader.exe, , [57d69ca45445eb4bea48903a50b3ea16]

            Registry Data: 0
            (No malicious items detected)

            Folders: 0
            (No malicious items detected)

            Files: 1
            PUP.Optional.OutBrowse, C:\Users\Sharon\Downloads\Installation.exe, , [929b52ee29700e28baf04cd2b84a748c],

            Physical Sectors: 0
            (No malicious items detected)

            (end)

             

            Looking good, but let me ask you , did you have Malwarebytes remove all those bad entries, it should show them as Quarantined and it does not ??

             

            This is from another user, not you, its just an example, see how it says those entries are Quarantined

             

            PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}, Quarantined, [d8771a9c444610265bd9f3af73904ab6],
            PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}, Quarantined, [d8771a9c444610265bd9f3af73904ab6],

             

            If you need to run it again you can do this

             

            •  
            • You can highlight one of the detections by left clicking on it.
            • Then, right click on the highlighted detection, and select 'Check All Items'.
            • Next, click 'Remove Selected'. That should remove them all
             
             
             
             
             

            Hi Ken

            was not sure if I had to remove or not so erred on the side of caution and lefts it. I have now rerun the scan and removed the affected files hopefully this logfile looks better

             

            Malwarebytes Anti-Malware
            www.malwarebytes.org

            Scan Date: 31/01/2016
            Scan Time: 16:02
            Logfile: malware.txt
            Administrator: Yes

            Version: 2.2.0.1024
            Malware Database: v2016.01.31.03
            Rootkit Database: v2016.01.20.01
            License: Free
            Malware Protection: Disabled
            Malicious Website Protection: Disabled
            Self-protection: Disabled

            OS: Windows 7 Service Pack 1
            CPU: x64
            File System: NTFS
            User: Sharon

            Scan Type: Threat Scan
            Result: Completed
            Objects Scanned: 397709
            Time Elapsed: 40 min, 56 sec

            Memory: Enabled
            Startup: Enabled
            Filesystem: Enabled
            Archives: Enabled
            Rootkits: Disabled
            Heuristics: Enabled
            PUP: Enabled
            PUM: Enabled

            Processes: 0
            (No malicious items detected)

            Modules: 0
            (No malicious items detected)

            Registry Keys: 16
            PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE9B20D-BC9D-4F0F-BF46-D8C9BDE6FF6D}, Quarantined, [4be4e957fb9e4ee8a4344c7e35ce8878],
            PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE9B20D-BC9D-4F0F-BF46-D8C9BDE6FF6D}, Quarantined, [81ae1030d8c1fb3b10c807c3a75c05fb],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{137D55A5-1DFC-4752-93D2-E69A31EC25D3}, Quarantined, [ce61a49c049575c17a3e606a6a992ad6],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{178183DB-ABA9-4CDF-BBD7-BEC3E9F7B7A2}, Quarantined, [56d9da66a4f59d9943768446d62d2cd4],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{183A0F40-1320-4704-ABC4-626EC46DE766}, Quarantined, [73bc95ab4d4c3bfb9d1cf4d6ce35b34d],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{224437DC-C0F0-4F10-8274-C6889DBE462E}, Quarantined, [6ac54cf4b5e4999d86338c3e10f338c8],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A28B0B4-9CFC-4B4C-AC13-D9AF1817F128}, Quarantined, [45eaa49c396069cd8a2eb4165da66c94],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7AC28169-EDCE-4850-A0A5-1EFDA7DAD0B1}, Quarantined, [63cc5ee2f5a48bab71488d3dd13203fd],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FBD4984-43E2-4F14-89BB-7C39848FD214}, Quarantined, [2807d868d4c560d6fabf3e8cf60d1ae6],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9FE9B20D-BC9D-4F0F-BF46-D8C9BDE6FF6D}, Quarantined, [250a8bb549506dc95f58fad08d76a759],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0856D1F-7E66-4523-968B-89CF5CAAB9AC}, Quarantined, [cc6374ccc5d4181eb702a72372914bb5],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8327152-D04F-42E5-AB9C-CAEC5D27BEF2}, Quarantined, [002f053bb6e321157049b91106fd8a76],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2678F97-E501-402D-B5D0-983EB2961D7C}, Quarantined, [8ea10d33b5e4f93d388023a7838023dd],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB59012C-1E59-40AC-8612-BC479D6DB299}, Quarantined, [49e66cd4bedbf046baffe2e830d354ac],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EEC94827-F6DC-4FB7-B298-729FA173BAEE}, Quarantined, [74bb0838e8b1c4724b6d4585d72c1fe1],
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FCDA872C-4DE4-443F-A003-B0EF57EB2FE7}, Quarantined, [63ccf7498118c2747742e5e5748f966a],

            Registry Values: 16
            PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9fe9b20d-bc9d-4f0f-bf46-d8c9bde6ff6d}|AppName, Feven 2.2-bg.exe, Quarantined, [4be4e957fb9e4ee8a4344c7e35ce8878]
            PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9fe9b20d-bc9d-4f0f-bf46-d8c9bde6ff6d}|AppName, Feven 2.2-bg.exe, Quarantined, [81ae1030d8c1fb3b10c807c3a75c05fb]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{137D55A5-1DFC-4752-93D2-E69A31EC25D3}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, Quarantined, [ce61a49c049575c17a3e606a6a992ad6]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{178183DB-ABA9-4CDF-BBD7-BEC3E9F7B7A2}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [56d9da66a4f59d9943768446d62d2cd4]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{183A0F40-1320-4704-ABC4-626EC46DE766}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [73bc95ab4d4c3bfb9d1cf4d6ce35b34d]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{224437DC-C0F0-4F10-8274-C6889DBE462E}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [6ac54cf4b5e4999d86338c3e10f338c8]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A28B0B4-9CFC-4B4C-AC13-D9AF1817F128}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, Quarantined, [45eaa49c396069cd8a2eb4165da66c94]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7AC28169-EDCE-4850-A0A5-1EFDA7DAD0B1}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [63cc5ee2f5a48bab71488d3dd13203fd]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7FBD4984-43E2-4F14-89BB-7C39848FD214}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [2807d868d4c560d6fabf3e8cf60d1ae6]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9fe9b20d-bc9d-4f0f-bf46-d8c9bde6ff6d}|AppName, Feven 2.2-bg.exe, Quarantined, [250a8bb549506dc95f58fad08d76a759]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A0856D1F-7E66-4523-968B-89CF5CAAB9AC}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [cc6374ccc5d4181eb702a72372914bb5]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A8327152-D04F-42E5-AB9C-CAEC5D27BEF2}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [002f053bb6e321157049b91106fd8a76]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C2678F97-E501-402D-B5D0-983EB2961D7C}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, Quarantined, [8ea10d33b5e4f93d388023a7838023dd]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB59012C-1E59-40AC-8612-BC479D6DB299}|AppName, Feven 2.2-enabler.exe-codedownloader.exe, Quarantined, [49e66cd4bedbf046baffe2e830d354ac]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EEC94827-F6DC-4FB7-B298-729FA173BAEE}|AppName, Feven 2.2-enabler.exe-buttonutil.exe, Quarantined, [74bb0838e8b1c4724b6d4585d72c1fe1]
            PUP.Optional.CrossRider, HKU\S-1-5-21-1603844925-2173046804-925170645-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{fcda872c-4de4-443f-a003-b0ef57eb2fe7}|AppName, Feven 2.2-codedownloader.exe, Quarantined, [63ccf7498118c2747742e5e5748f966a]

            Registry Data: 0
            (No malicious items detected)

            Folders: 0
            (No malicious items detected)

            Files: 1
            PUP.Optional.OutBrowse, C:\Users\Sharon\Downloads\Installation.exe, Quarantined, [bb74e759f8a1ce6846b4a27c9e640cf4],

            Physical Sectors: 0
            (No malicious items detected)

            (end)

            :thumbup:

             

            How is your system behaving now, any better ? You had a lot of junk that was removed.

             

            Open up FRST64 by right clicking on the icon and select RUN AS ADMINISTRATOR.  Make sure to checkmark Additions, leave everything else as is, run a new scan and post both the FRST64 and Additions logs and lets see if there is anything else to do

            Hi Ken

             

            yeah web pages seem to be loading much quicker now I always noticed eBay was always very slow to load with all the pictures etc,just went on to see how it is now and seems to be loading much quicker

             

            Additional scan result of Farbar Recovery Scan Tool (x64) Version:27-01-2016
            Ran by [removed] (2016-01-31 17:42:57)
            Running from C:\Users\[removed]\Desktop
            Windows 7 Home Premium Service Pack 1 (X64) (2010-02-04 22:00:14)
            Boot Mode: Normal
            ==========================================================

            ==================== Accounts: =============================

            Administrator (S-1-5-21-1603844925-2173046804-925170645-500 - Administrator - Disabled)
            Guest (S-1-5-21-1603844925-2173046804-925170645-501 - Limited - Disabled)
            HomeGroupUser$ (S-1-5-21-1603844925-2173046804-925170645-1002 - Limited - Enabled)
            Sharon (S-1-5-21-1603844925-2173046804-925170645-1000 - Administrator - Enabled) => C:\Users\Sharon

            ==================== Security Center ========================

            (If an entry is included in the fixlist, it will be removed.)

            AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {86355677-4064-3EA7-ABB3-1B136EB04637}
            AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
            AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {3D54B793-665E-3129-9103-206115370C8A}
            FW: McAfee Firewall (Enabled) {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

            ==================== Installed Programs ======================

            (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

            Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
            Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
            Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.)
            Adobe Flash Player 20 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated)
            Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
            Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.8.158 - Adobe Systems, Inc.)
            Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
            Apple Application Support (32-bit) (HKLM-x32\…\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
            Apple Application Support (64-bit) (HKLM\…\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
            Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
            Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
            AviSynth 2.5 (HKLM-x32\…\AviSynth) (Version:  - )
            AVS Image Converter 1.2.1.100 (HKLM-x32\…\AVS Image Converter_is1) (Version:  - Online Media Technologies Ltd.)
            AVS Update Manager 1.0 (HKLM-x32\…\AVS Update Manager_is1) (Version:  - Online Media Technologies Ltd.)
            Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
            Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
            Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
            Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
            Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
            D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
            Dell Dock (HKLM\…\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell)
            Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
            Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
            Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 13.2.3.0 - Synaptics Incorporated)
            Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
            Dell Wireless WLAN Card Utility (HKLM\…\Dell Wireless WLAN Card Utility) (Version: 5.30.21.0 - Dell Inc.)
            Digital Photo Navigator 1.0 (HKLM-x32\…\{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}) (Version:  - )
            Disk Cleaner (remove only) (HKLM-x32\…\DiskCleaner) (Version:  - )
            ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
            ffdshow v1.1.3572 [2010-09-13] (HKLM-x32\…\ffdshow_is1) (Version: 1.1.3572.0 - )
            Free Audio CD to MP3 Converter version 1.3.12.1228 (HKLM-x32\…\Free Audio CD to MP3 Converter_is1) (Version: 1.3.12.1228 - DVDVideoSoft Ltd.)
            Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
            Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
            Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
            Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
            Haali Media Splitter (HKLM-x32\…\HaaliMkx) (Version:  - )
            Heroes & Generals (HKLM-x32\…\Heroes & Generals) (Version: 1.0.6.1 - Reto-Moto)
            iCloud (HKLM\…\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
            iCopyBot for Windows 7.9.8 (HKLM-x32\…\iCopyBot for Windows) (Version: 7.9.8 - VOWSoft, Ltd.)
            Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002 - Brice Lambson) Hidden
            Image Resizer for Windows (HKLM-x32\…\{9dfff2f7-5cd7-4fd4-9b75-7d53b042d94b}) (Version: 3.0.4442.6002 - Brice Lambson)
            inSSIDer Home (HKLM-x32\…\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
            InstallConverter (HKLM-x32\…\InstallConverter) (Version: 1.0 - InstallConverter)
            Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)
            Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1029 - Intel Corporation)
            Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
            iTunes (HKLM\…\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
            Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
            Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
            LAV Filters 0.51.3 (HKLM-x32\…\lavfilters_is1) (Version: 0.51.3 - Hendrik Leppkes)
            Lexmark 3500-4500 Series (HKLM\…\Lexmark 3500-4500 Series) (Version:  - Lexmark International, Inc.)
            Live! Cam Avatar Creator (HKLM-x32\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.3009.1 - Creative Technology Ltd)
            Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
            McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 10.5.195 - McAfee, Inc.)
            Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
            Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
            Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
            Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
            Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
            Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
            Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
            Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
            Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
            Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
            Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
            Mount&Blade; Warband (HKLM-x32\…\Mount&Blade; Warband) (Version:  - )
            PowerDVD DX (HKLM-x32\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.3.5424 - CyberLink Corp.)
            Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 9.6.6 - Dell Inc.)
            QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
            ROBLOX Player for Sharon (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
            Roxio Burn (HKLM-x32\…\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.0 - Roxio)
            Skype Click to Call (HKLM-x32\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
            Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
            Sothink Movie DVD Maker (HKLM-x32\…\{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1) (Version: 3.8 - SourceTec Software Co., LTD)
            Spotify (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Spotify) (Version: 0.9.4.185.g7545a404 - Spotify AB)
            Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
            swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
            Unity Web Player (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
            Verdun (HKLM-x32\…\Steam App 242860) (Version:  - M2H)
            Virgin Media Cloud (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Virgin Media Cloud) (Version: 2.4.4435 - F-Secure Corporation)
            VLC media player 2.1.2 (HKLM-x32\…\VLC media player) (Version: 2.1.2 - VideoLAN)
            Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
            Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
            Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
            WinPatrol (HKLM\…\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.1.2014 - BillP Studios)
            WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )

            ==================== Custom CLSID (Whitelisted): ==========================

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            CustomCLSID: HKU\S-1-5-21-1603844925-2173046804-925170645-1000_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\RobloxProxy64.dll (ROBLOX Corporation)

            ==================== Scheduled Tasks (Whitelisted) =============

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            Task: {039DD88D-3DDE-408C-8A5A-55F7121590DB} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-02-10] (Oracle Corporation)
            Task: {16B97E37-3B14-4027-A65E-72E301F80F1A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
            Task: {2FE1DE7F-DDC3-42E3-BD3E-4667BF17AED2} - System32\Tasks\{8D06BC15-F5B6-4AC0-8233-9F0ADAA4DD1D} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
            Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
            Task: {66B6E2DE-37EF-40A4-A29A-1499E3ACC54D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
            Task: {6DEE93CC-4A2E-49D3-B1FF-35E50C2B2309} - System32\Tasks\DJNJ8SJ1\Administrator - Start WLAN Tray Applet => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE [2009-07-17] (Dell Inc.)
            Task: {8335C703-0DFD-4F5A-8D7B-CF11E9336803} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
            Task: {87589C5E-C1AE-4503-87BC-76B273547797} - System32\Tasks\{A3FDA8D8-F1E0-49A9-AC99-A04158C023A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsBing
            Task: {9840521E-672C-4758-9464-F18B350D8626} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
            Task: {A16B56B1-CACA-4C8E-957D-63C1895450B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
            Task: {A367EA33-4598-400B-9BC0-C8CB941BE71E} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
            Task: {C7ADECB6-B5C1-4EC4-8D00-965492898B02} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated)
            Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc
            Task: {E65FA14B-11F8-416C-9A7E-995E9CD6D566} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
            Task: {F4214C36-6660-4F72-BDC8-98F2C55B6D6A} - System32\Tasks\{46EF662D-9A7C-4B91-A664-490EC3CA199D} => pcalua.exe -a C:\JVC\UsbSTGE.exe -d C:\JVC

            (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

            Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

            ==================== Shortcuts =============================

            (The entries could be listed to be restored or removed.)

            ==================== Loaded Modules (Whitelisted) ==============

            2009-12-24 15:30 - 2009-07-17 01:06 - 00033280 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
            2009-12-24 15:30 - 2009-07-17 01:06 - 00058368 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll
            2012-11-11 10:58 - 2007-03-15 23:11 - 00138240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdidrpp.dll
            2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
            2015-10-13 05:45 - 2015-10-13 05:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
            2010-01-09 20:17 - 2010-01-09 20:17 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
            2010-01-21 01:40 - 2010-01-21 01:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
            2010-12-20 21:59 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
            2015-12-13 19:46 - 2015-12-13 19:46 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\ad2fbbd746bb143008adb984541da686\VistaBridgeLibrary.ni.dll
            2014-02-19 20:53 - 2014-02-18 03:46 - 00643948 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
            2015-10-13 05:46 - 2015-10-13 05:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
            2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
            2015-10-13 05:45 - 2015-10-13 05:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
            2010-01-09 20:18 - 2010-01-09 20:18 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
            2010-01-21 01:34 - 2010-01-21 01:34 - 08793952 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

            ==================== Alternate Data Streams (Whitelisted) =========

            (If an entry is included in the fixlist, only the ADS will be removed.)

            ==================== Safe Mode (Whitelisted) ===================

            (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

            ==================== EXE Association (Whitelisted) ===============

            (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

            ==================== Internet Explorer trusted/restricted ===============

            (If an entry is included in the fixlist, it will be removed from the registry.)

            ==================== Hosts content: ===============================

            (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

            2009-07-14 02:34 - 2016-01-30 22:37 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

            ==================== Other Areas ============================

            (Currently there is no automatic fix for this section.)

            HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
            DNS Servers: 192.168.0.1
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
            Windows Firewall is enabled.

            ==================== MSCONFIG/TASK MANAGER disabled items ==

            (Currently there is no automatic fix for this section.)

            MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
            MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
            MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
            MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

            ==================== FirewallRules (Whitelisted) ===============

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            FirewallRules: [{0332E39C-D700-4178-897A-91BD7C9FC3AD}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PowerDVD.exe
            FirewallRules: [{9241A141-1C7D-401C-86FF-68DC3C733D89}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
            FirewallRules: [{E511FE26-5850-40F8-8BE9-369B466129B8}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
            FirewallRules: [{25E1DDAA-1275-43E2-B0D5-CA0A038762C1}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
            FirewallRules: [{DA5B37A1-E998-4461-801B-885310A70C65}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
            FirewallRules: [{4448837A-8A45-4DCF-80EA-018CCABB0152}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
            FirewallRules: [{8B5C7515-5E52-4B14-8615-C5CFE1DF0492}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
            FirewallRules: [{579303C5-7A83-499E-9059-9FFC90A94E4F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
            FirewallRules: [{B292AF1D-BDDF-4862-A319-63627591A6D9}] => (Allow) LPort=2869
            FirewallRules: [{DCA207F2-8A87-4052-8AFF-D08D9ABE6225}] => (Allow) LPort=1900
            FirewallRules: [{525A5E41-73B4-46E1-A5DE-2A156D737B6D}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
            FirewallRules: [{18ADDB25-AE21-433A-88B0-DED508680E27}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{40BC477C-361A-49EC-B674-DF8C4F7549D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{1FD7A359-3662-44EB-9527-46ED6EC10CC4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{879B9977-27F7-4A07-A959-ACA27B6D2E65}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{49E791C3-7A74-4EB9-B960-1874CB2A5BB8}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
            FirewallRules: [{AAFE46BE-7A06-4B2B-AAA0-84AC3D110836}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
            FirewallRules: [{9AEA2DC4-DAC2-4341-994C-DF13AF827FB0}] => (Allow) C:\Windows\System32\lxdicoms.exe
            FirewallRules: [{B911FD92-BABC-4726-8DB7-CA322C099DB8}] => (Allow) C:\Windows\System32\lxdicoms.exe
            FirewallRules: [{CF986128-AD4D-45F2-B22E-E3E16E4E9FDA}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
            FirewallRules: [{7D535C64-78C0-4E0C-A596-6C0621DBE66B}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
            FirewallRules: [{13D9AB9D-4990-49F7-B640-F6F067B2219F}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
            FirewallRules: [{B4DB37E7-E205-4B03-8206-BAE9398D3102}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
            FirewallRules: [{7FFE1605-CD9B-4AC5-9763-6BEE75155F10}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
            FirewallRules: [{156A3780-BFB6-408D-A8F4-AE3FE8F659ED}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
            FirewallRules: [{E39C41EC-5187-4A43-91D4-D2B7947FE7A4}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
            FirewallRules: [{DEC501C9-836F-4D67-A90B-166B23F3A457}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
            FirewallRules: [{5C050647-43F3-4455-84BF-DED1B647757E}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
            FirewallRules: [{C31D4F77-42C9-4606-97F8-227BD727E95D}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
            FirewallRules: [{7789B22F-ADB1-496E-BEAF-8DF913B284EC}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
            FirewallRules: [{5666A10E-8B52-4A11-A734-780A14E2E741}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
            FirewallRules: [TCP Query User{9168E047-A0A1-4A11-8667-9CA820EE5996}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
            FirewallRules: [UDP Query User{29D328A2-FF65-424E-A7E0-67335D03F7AB}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
            FirewallRules: [TCP Query User{6360F2DA-6D0B-4185-B133-BE5E59007308}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
            FirewallRules: [UDP Query User{8A59EF6B-447A-47B6-A552-603CCDA903EE}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
            FirewallRules: [TCP Query User{73A65667-7085-4958-9E4A-6152E28DED93}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [UDP Query User{28FA0E79-DF6D-4F3B-B13E-C7F1C475C938}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [TCP Query User{0EBA448B-CC42-4C3A-BF11-F4DCF379ECFC}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [UDP Query User{2E599A0A-1FB4-433B-94E7-A4EFA2A9C6B3}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [{5B729769-EA93-49A3-A943-D1E779C827A7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
            FirewallRules: [{5A93EF4D-8CD9-4E01-8672-BAD5D0977553}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
            FirewallRules: [{1AC5BF7C-6BA2-4173-9BE3-AEC003FA37BE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
            FirewallRules: [{5EB56F86-F386-4653-9FE9-C2228C140A73}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
            FirewallRules: [{3A3866BF-862C-4BFC-85D5-67E8566107F0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
            FirewallRules: [{404848F1-16D8-4889-AED5-D44B705ECAC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
            FirewallRules: [{8BE2350B-9A46-4ADB-8591-73131CC6D1C1}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
            FirewallRules: [{4FDE0FE9-FD52-4355-B9B0-0D4D6C284B44}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
            FirewallRules: [{923BFEDE-A25D-4D7A-8254-E1BA21F960D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{34313D66-7655-48F5-8B3A-7F1A9A42025C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{CDB443C1-333D-4266-9532-5C77AF3AC89F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{14781C1E-CB3B-4B77-A3D4-036A23F6472F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{54BFECE4-53A3-4C5D-BD67-FC93971152EF}] => (Allow) C:\Program Files\iTunes\iTunes.exe

            ==================== Restore Points =========================

            30-01-2016 18:11:10 Scheduled Checkpoint
            30-01-2016 22:37:03 Restore Point Created by FRST
            31-01-2016 11:14:04 JRT Pre-Junkware Removal

            ==================== Faulty Device Manager Devices =============

            Name:
            Description:
            Class Guid:
            Manufacturer:
            Service:
            Problem: : The drivers for this device are not installed. (Code 28)
            Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

            ==================== Event log errors: =========================

            Application errors:
            ==================
            Error: (01/31/2016 05:03:46 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/31/2016 05:03:46 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            Error: (01/31/2016 02:51:20 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/31/2016 02:51:20 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            Error: (01/31/2016 11:12:09 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/31/2016 11:12:09 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            Error: (01/31/2016 10:47:02 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/31/2016 10:47:02 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            Error: (01/30/2016 11:14:52 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/30/2016 11:14:52 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            System errors:
            =============
            Error: (01/31/2016 04:57:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
            Description: The lxdiCATSCustConnectService service failed to start due to the following error:
            %%1053

            Error: (01/31/2016 04:57:37 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
            Description: A timeout was reached (30000 milliseconds) while waiting for the lxdiCATSCustConnectService service to connect.

            Error: (01/31/2016 11:07:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
            Description: The lxdiCATSCustConnectService service failed to start due to the following error:
            %%1053

            Error: (01/31/2016 11:07:01 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
            Description: A timeout was reached (30000 milliseconds) while waiting for the lxdiCATSCustConnectService service to connect.

            Error: (01/31/2016 11:06:04 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
            Description: WLAN Extensibility Module has stopped unexpectedly.

            Module Path: C:\Windows\System32\bcmihvsrv64.dll

            Error: (01/31/2016 11:06:04 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
            Description: WLAN Extensibility Module has stopped unexpectedly.

            Module Path: C:\Windows\System32\bcmihvsrv64.dll

            Error: (01/31/2016 11:06:02 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
            Description: WLAN Extensibility Module has stopped unexpectedly.

            Module Path: C:\Windows\System32\bcmihvsrv64.dll

            Error: (01/31/2016 11:05:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
            Description: The Software Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

            Error: (01/31/2016 11:05:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
            Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

            Error: (01/31/2016 11:05:46 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
            Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

            CodeIntegrity:
            ===================================
              Date: 2015-10-12 13:46:54.850
              Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

              Date: 2015-10-12 13:46:54.357
              Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

            ==================== Memory info ===========================

            Processor: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
            Percentage of memory in use: 33%
            Total physical RAM: 4056.36 MB
            Available physical RAM: 2699.53 MB
            Total Virtual: 8110.93 MB
            Available Virtual: 6326.52 MB

            ==================== Drives ================================

            Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:107.18 GB) NTFS

            ==================== MBR & Partition Table ==================

            ========================================================
            Disk: 0 (Size: 298.1 GB) (Disk ID: 086F8F0B)
            Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
            Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
            Partition 3: (Not Active) - (Size=283.4 GB) - (Type=07 NTFS)

            ==================== End of Addition.txt ============================

             

             

             

             

            LastRegBack: 2016-01-30 18:04

            ==================== End of FRST.txt ============================

             

            Hi Ken

            not sure what happened there

             

            Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
            Ran by [removed] (administrator) on SHARON-PC (31-01-2016 19:45:24)
            Running from C:\Users\[removed]\Desktop
            [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
            Internet Explorer Version 11 (Default browser: IE)
            Boot Mode: Normal
            Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

            ==================== Processes (Whitelisted) =================

            (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

            (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe
            (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
            () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
            (Microsoft Corporation) C:\Windows\System32\wlanext.exe
            (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE
            (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
            (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
            ( ) C:\Windows\System32\lxdicoms.exe
            (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
            (Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
            (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
            (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
            (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
            (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
            (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
            (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
            (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
            (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
            (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
            (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
            (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
            (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
            (McAfee, Inc.) C:\Program Files\McAfee.com\Agent\mcagent.exe
            (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
            (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
            (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
            (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_20_0_0_286_ActiveX.exe
            (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
            (Microsoft Corporation) C:\Windows\System32\dllhost.exe

            ==================== Registry (Whitelisted) ===========================

            (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

            HKLM\…\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
            HKLM\…\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.)
            HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
            HKLM-x32\…\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1484856 2010-06-30] (McAfee, Inc.)
            HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
            Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
            HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Run: [WinPatrol] => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [496192 2014-02-25] (BillP Studios)
            HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
            HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\MountPoints2: {75e4e796-5a75-11e3-b617-a4badb95f61e} - F:\DTVP_Launcher.exe
            HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation)
            Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-12-24]
            ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
            Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2009-12-24]
            ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
            Startup: C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk [2010-02-04]
            ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)

            ==================== Internet (Whitelisted) ====================

            (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

            Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
            Tcpip\..\Interfaces\{0352CE31-0851-421A-AAA8-FFFECAAAF602}: [DhcpNameServer] 192.168.0.1
            Tcpip\..\Interfaces\{8CEF2A2E-C861-4D28-B4C8-D9F096CE09D4}: [DhcpNameServer] 192.168.0.1

            Internet Explorer:
            ==================
            HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
            HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
            HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.co.uk/
            SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
            SearchScopes: HKLM-x32 -> {6112FDEF-4523-4643-8B16-45CF4E18157F} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
            BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\McAfee\MSK\mskapbho64.dll [2010-05-03] ()
            BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
            BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100828145747.dll [2010-05-31] (McAfee, Inc.)
            BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
            BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
            BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
            BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
            BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\Program Files\McAfee\MSK\mskapbho.dll [2010-05-03] ()
            BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22] (Microsoft Corporation)
            BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-01-21] (Microsoft Corporation)
            BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-03] (Oracle Corporation)
            BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100828145747.dll [2010-05-31] (McAfee, Inc.)
            BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
            BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
            BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
            BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
            BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-03] (Oracle Corporation)
            Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
            Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-22] (Google Inc.)
            Toolbar: HKU\S-1-5-21-1603844925-2173046804-925170645-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-22] (Google Inc.)
            DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
            DPF: HKLM-x32 {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
            DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
            DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework/microsoft/wrc32.ocx
            DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
            Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
            Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)

            FireFox:
            ========
            FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
            FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
            FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
            FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1218158.dll [2015-04-27] (Adobe Systems, Inc.)
            FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
            FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-03] (Oracle Corporation)
            FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-03] (Oracle Corporation)
            FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [2015-02-22] (Reto-Moto ApS)
            FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
            FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
            FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
            FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
            FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
            FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
            FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
            FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
            FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @nsroblox.roblox.com/launcher -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\\NPRobloxProxy.dll [2012-12-31] ( ROBLOX Corporation)
            FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @nsroblox.roblox.com/launcher64 -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\\NPRobloxProxy64.dll [2012-12-31] ( ROBLOX Corporation)
            FF Plugin HKU\S-1-5-21-1603844925-2173046804-925170645-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Sharon\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-05] (Unity Technologies ApS)

            Chrome:
            =======
            CHR HKLM-x32\…\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx

            ==================== Services (Whitelisted) ========================

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
            R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-12-18] (Stardock Corporation) [File not signed]
            S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2011-02-10] () [File not signed]
            R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
            R2 lxdi_device; C:\Windows\SysWOW64\lxdicoms.exe [517040 2007-06-11] ( )
            S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
            R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
            R2 mcmscsvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
            R2 McNaiAnn; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
            R2 McNASvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
            S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [509416 2010-04-15] (McAfee, Inc.)
            R2 McProxy; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
            R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199032 2010-05-31] (McAfee, Inc.)
            R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [244840 2010-05-31] (McAfee, Inc.)
            R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [148520 2010-05-31] (McAfee, Inc.)
            R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [355440 2010-03-10] (McAfee, Inc.)
            R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe [240128 2009-06-29] (IDT, Inc.)
            S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
            R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe [3417088 2009-07-17] (Dell Inc.) [File not signed]

            ===================== Drivers (Whitelisted) ==========================

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [62416 2010-05-31] (McAfee, Inc.)
            S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
            R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
            S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
            R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [121504 2010-05-31] (McAfee, Inc.)
            R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [189880 2010-05-31] (McAfee, Inc.)
            U3 mfeavfk01; no ImagePath
            R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [440688 2010-05-31] (McAfee, Inc.)
            R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [528616 2010-05-31] (McAfee, Inc.)
            R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75288 2010-05-31] (McAfee, Inc.)
            S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [93840 2010-05-31] (McAfee, Inc.)
            R1 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [279752 2010-05-31] (McAfee, Inc.)
            R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
            S3 cpuz134; \??\C:\Users\Sharon\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]

            ==================== NetSvcs (Whitelisted) ===================

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            ==================== One Month Created files and folders ========

            (If an entry is included in the fixlist, the file/folder will be moved.)

            2016-01-31 17:43 - 2016-01-31 19:45 - 00018440 _____ C:\Users\Sharon\Desktop\FRST.txt
            2016-01-31 16:58 - 2016-01-31 16:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
            2016-01-31 11:20 - 2016-01-31 16:59 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
            2016-01-31 11:20 - 2016-01-31 11:20 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
            2016-01-31 11:20 - 2016-01-31 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
            2016-01-31 11:20 - 2016-01-31 11:20 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
            2016-01-31 11:20 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
            2016-01-31 11:20 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
            2016-01-31 11:20 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
            2016-01-31 10:50 - 2016-01-31 11:05 - 00000000 ____D C:\AdwCleaner
            2016-01-31 10:47 - 2016-01-31 10:47 - 01609032 _____ (Malwarebytes) C:\Users\Sharon\Desktop\JRT.exe
            2016-01-31 10:45 - 2016-01-31 10:46 - 01507840 _____ C:\Users\Sharon\Desktop\AdwCleaner.exe
            2016-01-30 19:22 - 2016-01-31 19:45 - 00000000 ____D C:\FRST
            2016-01-30 19:18 - 2016-01-30 19:18 - 02370560 _____ (Farbar) C:\Users\Sharon\Desktop\FRST64.exe
            2016-01-30 15:07 - 2016-01-30 15:07 - 05198336 _____ (AVAST Software) C:\Users\Sharon\Desktop\aswMBR.exe
            2016-01-13 20:53 - 2015-12-11 18:57 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
            2016-01-13 20:53 - 2015-12-08 21:53 - 00509952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
            2016-01-13 20:53 - 2015-12-08 19:07 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
            2016-01-13 20:53 - 2015-11-17 01:11 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
            2016-01-13 20:53 - 2015-11-17 01:08 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
            2016-01-13 20:53 - 2015-11-17 01:08 - 00792064 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
            2016-01-13 20:53 - 2015-11-17 01:08 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
            2016-01-13 20:53 - 2015-11-17 01:08 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
            2016-01-13 20:53 - 2015-11-17 01:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
            2016-01-13 20:53 - 2015-11-16 20:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
            2016-01-13 20:53 - 2015-11-13 23:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
            2016-01-13 20:53 - 2015-11-13 23:09 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
            2016-01-13 20:53 - 2015-11-13 23:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\fixmapi.exe
            2016-01-13 20:53 - 2015-11-13 22:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapistub.dll
            2016-01-13 20:53 - 2015-11-13 22:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mapi32.dll
            2016-01-13 20:53 - 2015-11-13 22:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fixmapi.exe
            2016-01-13 20:52 - 2015-12-23 23:13 - 00387784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
            2016-01-13 20:52 - 2015-12-23 22:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
            2016-01-13 20:52 - 2015-12-12 18:54 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
            2016-01-13 20:52 - 2015-12-12 18:31 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
            2016-01-13 20:52 - 2015-12-12 18:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
            2016-01-13 20:52 - 2015-12-12 18:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
            2016-01-13 20:52 - 2015-12-12 18:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
            2016-01-13 20:52 - 2015-12-12 18:15 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
            2016-01-13 20:52 - 2015-12-12 18:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
            2016-01-13 20:52 - 2015-12-12 18:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
            2016-01-13 20:52 - 2015-12-12 18:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
            2016-01-13 20:52 - 2015-12-12 18:07 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
            2016-01-13 20:52 - 2015-12-12 18:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
            2016-01-13 20:52 - 2015-12-12 18:07 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
            2016-01-13 20:52 - 2015-12-12 18:03 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
            2016-01-13 20:52 - 2015-12-12 18:02 - 20367360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
            2016-01-13 20:52 - 2015-12-12 18:02 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
            2016-01-13 20:52 - 2015-12-12 18:02 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
            2016-01-13 20:52 - 2015-12-12 18:02 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
            2016-01-13 20:52 - 2015-12-12 18:02 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
            2016-01-13 20:52 - 2015-12-12 17:55 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
            2016-01-13 20:52 - 2015-12-12 17:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
            2016-01-13 20:52 - 2015-12-12 17:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
            2016-01-13 20:52 - 2015-12-12 17:44 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
            2016-01-13 20:52 - 2015-12-12 17:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
            2016-01-13 20:52 - 2015-12-12 17:39 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
            2016-01-13 20:52 - 2015-12-12 17:37 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
            2016-01-13 20:52 - 2015-12-12 17:37 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
            2016-01-13 20:52 - 2015-12-12 17:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
            2016-01-13 20:52 - 2015-12-12 17:37 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
            2016-01-13 20:52 - 2015-12-12 17:36 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
            2016-01-13 20:52 - 2015-12-12 17:36 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
            2016-01-13 20:52 - 2015-12-12 17:35 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
            2016-01-13 20:52 - 2015-12-12 17:33 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
            2016-01-13 20:52 - 2015-12-12 17:31 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
            2016-01-13 20:52 - 2015-12-12 17:30 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
            2016-01-13 20:52 - 2015-12-12 17:28 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
            2016-01-13 20:52 - 2015-12-12 17:27 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
            2016-01-13 20:52 - 2015-12-12 17:27 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
            2016-01-13 20:52 - 2015-12-12 17:27 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
            2016-01-13 20:52 - 2015-12-12 17:25 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
            2016-01-13 20:52 - 2015-12-12 17:23 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
            2016-01-13 20:52 - 2015-12-12 17:22 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
            2016-01-13 20:52 - 2015-12-12 17:21 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
            2016-01-13 20:52 - 2015-12-12 17:20 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
            2016-01-13 20:52 - 2015-12-12 17:19 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
            2016-01-13 20:52 - 2015-12-12 17:18 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
            2016-01-13 20:52 - 2015-12-12 17:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
            2016-01-13 20:52 - 2015-12-12 17:12 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
            2016-01-13 20:52 - 2015-12-12 17:10 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
            2016-01-13 20:52 - 2015-12-12 17:10 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
            2016-01-13 20:52 - 2015-12-12 17:09 - 04610560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
            2016-01-13 20:52 - 2015-12-12 17:08 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
            2016-01-13 20:52 - 2015-12-12 17:06 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
            2016-01-13 20:52 - 2015-12-12 17:02 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
            2016-01-13 20:52 - 2015-12-12 17:00 - 12856320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
            2016-01-13 20:52 - 2015-12-12 17:00 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
            2016-01-13 20:52 - 2015-12-12 17:00 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
            2016-01-13 20:52 - 2015-12-12 17:00 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
            2016-01-13 20:52 - 2015-12-12 16:54 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
            2016-01-13 20:52 - 2015-12-12 16:42 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
            2016-01-13 20:52 - 2015-12-12 16:41 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
            2016-01-13 20:52 - 2015-12-12 16:38 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
            2016-01-13 20:52 - 2015-12-12 16:36 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
            2016-01-13 20:52 - 2015-12-08 21:54 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
            2016-01-13 20:52 - 2015-12-08 21:54 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 01568768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 01325056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOE.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 00902144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOD.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 00815616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMADMOE.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 00740352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
            2016-01-13 20:52 - 2015-12-08 21:54 - 00739328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMSPDMOD.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVXENCD.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSDECD.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
            2016-01-13 20:52 - 2015-12-08 21:54 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VIDRESZR.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00970240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2adec.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPEG2ENC.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFWMAAEC.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00415744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MPG4DECD.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP43DECD.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RESAMPLEDMO.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qasf.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksproxy.ax
            2016-01-13 20:52 - 2015-12-08 21:53 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COLORCNV.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP3DMOD.DLL
            2016-01-13 20:52 - 2015-12-08 21:53 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devenum.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfvdsp.dll
            2016-01-13 20:52 - 2015-12-08 21:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
            2016-01-13 20:52 - 2015-12-08 21:53 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
            2016-01-13 20:52 - 2015-12-08 21:53 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ksuser.dll
            2016-01-13 20:52 - 2015-12-08 21:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 01955328 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 01575424 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOE.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 01307136 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2adec.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 01232896 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 01153024 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOE.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 01026048 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 01010688 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\MFWMAAEC.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\WMVSENCD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00292352 _____ (Microsoft Corporation) C:\Windows\system32\VIDRESZR.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\RESAMPLEDMO.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00224768 _____ (Microsoft Corporation) C:\Windows\system32\MPG4DECD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\MP43DECD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\COLORCNV.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MP3DMOD.DLL
            2016-01-13 20:52 - 2015-12-08 19:07 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\mfvdsp.dll
            2016-01-13 20:52 - 2015-12-08 19:07 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
            2016-01-13 20:52 - 2015-12-08 19:07 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\ksuser.dll
            2016-01-13 20:52 - 2015-12-08 19:06 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
            2016-01-13 20:52 - 2015-12-08 19:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
            2016-01-13 20:52 - 2015-12-08 19:04 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
            2016-01-13 20:52 - 2015-12-08 18:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
            2016-01-13 20:52 - 2015-12-08 18:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
            2016-01-13 20:52 - 2015-12-08 18:11 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
            2016-01-13 20:52 - 2015-12-08 17:58 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
            2016-01-13 20:51 - 2015-12-08 21:53 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
            2016-01-13 20:51 - 2015-12-08 21:52 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
            2016-01-13 20:51 - 2015-12-08 19:07 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
            2016-01-13 20:51 - 2015-12-08 19:07 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
            2016-01-13 20:50 - 2015-12-30 19:08 - 05572544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
            2016-01-13 20:50 - 2015-12-30 19:08 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
            2016-01-13 20:50 - 2015-12-30 19:08 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
            2016-01-13 20:50 - 2015-12-30 19:05 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
            2016-01-13 20:50 - 2015-12-30 19:02 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
            2016-01-13 20:50 - 2015-12-30 19:02 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
            2016-01-13 20:50 - 2015-12-30 19:02 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
            2016-01-13 20:50 - 2015-12-30 19:02 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
            2016-01-13 20:50 - 2015-12-30 19:02 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
            2016-01-13 20:50 - 2015-12-30 19:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
            2016-01-13 20:50 - 2015-12-30 19:01 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
            2016-01-13 20:50 - 2015-12-30 19:01 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
            2016-01-13 20:50 - 2015-12-30 19:01 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
            2016-01-13 20:50 - 2015-12-30 19:01 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
            2016-01-13 20:50 - 2015-12-30 19:01 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
            2016-01-13 20:50 - 2015-12-30 19:01 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
            2016-01-13 20:50 - 2015-12-30 19:01 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
            2016-01-13 20:50 - 2015-12-30 19:00 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
            2016-01-13 20:50 - 2015-12-30 18:59 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
            2016-01-13 20:50 - 2015-12-30 18:59 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
            2016-01-13 20:50 - 2015-12-30 18:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
            2016-01-13 20:50 - 2015-12-30 18:58 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
            2016-01-13 20:50 - 2015-12-30 18:58 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
            2016-01-13 20:50 - 2015-12-30 18:57 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
            2016-01-13 20:50 - 2015-12-30 18:57 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
            2016-01-13 20:50 - 2015-12-30 18:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
            2016-01-13 20:50 - 2015-12-30 18:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
            2016-01-13 20:50 - 2015-12-30 18:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
            2016-01-13 20:50 - 2015-12-30 18:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:54 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:47 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
            2016-01-13 20:50 - 2015-12-30 18:47 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
            2016-01-13 20:50 - 2015-12-30 18:44 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
            2016-01-13 20:50 - 2015-12-30 18:41 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
            2016-01-13 20:50 - 2015-12-30 18:40 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
            2016-01-13 20:50 - 2015-12-30 18:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
            2016-01-13 20:50 - 2015-12-30 18:39 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
            2016-01-13 20:50 - 2015-12-30 18:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
            2016-01-13 20:50 - 2015-12-30 18:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
            2016-01-13 20:50 - 2015-12-30 18:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
            2016-01-13 20:50 - 2015-12-30 18:38 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
            2016-01-13 20:50 - 2015-12-30 18:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 18:37 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 17:57 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
            2016-01-13 20:50 - 2015-12-30 17:50 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
            2016-01-13 20:50 - 2015-12-30 17:49 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
            2016-01-13 20:50 - 2015-12-30 17:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
            2016-01-13 20:50 - 2015-12-30 17:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
            2016-01-13 20:50 - 2015-12-30 17:42 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
            2016-01-13 20:50 - 2015-12-30 17:42 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
            2016-01-13 20:50 - 2015-12-30 17:41 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
            2016-01-13 20:50 - 2015-12-30 17:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
            2016-01-13 20:50 - 2015-12-30 17:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
            2016-01-13 20:50 - 2015-12-30 17:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
            2016-01-13 20:50 - 2015-12-30 17:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
            2016-01-13 20:50 - 2015-12-30 17:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
            2016-01-13 20:50 - 2015-12-30 17:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
            2016-01-13 20:50 - 2015-12-30 17:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 17:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 17:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
            2016-01-13 20:50 - 2015-12-30 17:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll

            ==================== One Month Modified files and folders ========

            (If an entry is included in the fixlist, the file/folder will be moved.)

            2016-01-31 19:43 - 2012-04-01 17:57 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
            2016-01-31 19:25 - 2009-07-14 04:45 - 00022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
            2016-01-31 19:25 - 2009-07-14 04:45 - 00022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
            2016-01-31 18:56 - 2015-06-21 08:50 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
            2016-01-31 17:03 - 2009-07-14 05:13 - 00006210 _____ C:\Windows\system32\PerfStringBackup.INI
            2016-01-31 16:57 - 2015-06-21 08:50 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
            2016-01-31 16:57 - 2009-07-14 05:37 - 00000000 ____D C:\Windows\DigitalLocker
            2016-01-31 16:57 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
            2016-01-27 17:42 - 2009-07-14 05:08 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
            2016-01-25 20:11 - 2013-04-21 17:08 - 00000000 ____D C:\Users\Sharon\Desktop\Sharon
            2016-01-20 20:43 - 2012-04-01 17:57 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
            2016-01-20 20:43 - 2012-04-01 17:57 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
            2016-01-20 20:43 - 2011-05-14 15:03 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
            2016-01-19 12:45 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\system32\NDF
            2016-01-16 12:31 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\rescache
            2016-01-15 19:42 - 2009-07-14 04:45 - 00418328 _____ C:\Windows\system32\FNTCACHE.DAT
            2016-01-15 19:38 - 2014-12-12 20:23 - 00000000 ____D C:\Windows\system32\appraiser
            2016-01-15 19:38 - 2014-05-07 19:00 - 00000000 ___SD C:\Windows\system32\CompatTel
            2016-01-15 19:36 - 2013-03-12 21:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
            2016-01-13 21:25 - 2013-03-12 21:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
            2016-01-13 21:25 - 2013-03-12 21:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
            2016-01-13 21:24 - 2013-08-14 19:01 - 00000000 ____D C:\Windows\system32\MRT
            2016-01-13 21:18 - 2010-02-06 16:14 - 143671360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
            2016-01-12 16:06 - 2015-10-25 19:45 - 00000000 ____D C:\Users\Sharon\Desktop\Matthew Folder
            2016-01-11 18:58 - 2011-09-12 18:33 - 00541334 _____ C:\Windows\ntbtlog.txt

            ==================== Files in the root of some directories =======

            2010-02-07 14:06 - 2010-02-07 14:06 - 0000014 _____ () C:\Users\Sharon\AppData\Roaming\licence.txt
            2010-09-09 17:52 - 2010-09-09 17:52 - 0000000 _____ () C:\Users\Sharon\AppData\Roaming\wklnhst.dat
            2011-09-12 18:26 - 2012-08-07 20:52 - 0106070 _____ () C:\Users\Sharon\AppData\Local\ars.cache
            2011-09-12 18:26 - 2012-08-07 20:52 - 0853856 _____ () C:\Users\Sharon\AppData\Local\census.cache
            2011-06-10 20:29 - 2011-06-10 20:29 - 0000036 _____ () C:\Users\Sharon\AppData\Local\housecall.guid.cache
            2010-04-06 17:15 - 2010-04-06 17:15 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

            Some files in TEMP:
            ====================
            C:\Users\Sharon\AppData\Local\Temp\sqlite3.dll

            ==================== Bamital & volsnap =================

            (There is no automatic fix for files that do not pass verification.)

            C:\Windows\system32\winlogon.exe => File is digitally signed
            C:\Windows\system32\wininit.exe => File is digitally signed
            C:\Windows\SysWOW64\wininit.exe => File is digitally signed
            C:\Windows\explorer.exe => File is digitally signed
            C:\Windows\SysWOW64\explorer.exe => File is digitally signed
            C:\Windows\system32\svchost.exe => File is digitally signed
            C:\Windows\SysWOW64\svchost.exe => File is digitally signed
            C:\Windows\system32\services.exe => File is digitally signed
            C:\Windows\system32\User32.dll => File is digitally signed
            C:\Windows\SysWOW64\User32.dll => File is digitally signed
            C:\Windows\system32\userinit.exe => File is digitally signed
            C:\Windows\SysWOW64\userinit.exe => File is digitally signed
            C:\Windows\system32\rpcss.dll => File is digitally signed
            C:\Windows\system32\dnsapi.dll => File is digitally signed
            C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
            C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

            LastRegBack: 2016-01-30 18:04

            ==================== End of FRST.txt ============================

             

             

             

            Additional scan result of Farbar Recovery Scan Tool (x64) Version:27-01-2016
            Ran by [removed] (2016-01-31 19:46:01)
            Running from C:\Users\[removed]\Desktop
            Windows 7 Home Premium Service Pack 1 (X64) (2010-02-04 22:00:14)
            Boot Mode: Normal
            ==========================================================

            ==================== Accounts: =============================

            Administrator (S-1-5-21-1603844925-2173046804-925170645-500 - Administrator - Disabled)
            Guest (S-1-5-21-1603844925-2173046804-925170645-501 - Limited - Disabled)
            HomeGroupUser$ (S-1-5-21-1603844925-2173046804-925170645-1002 - Limited - Enabled)
            Sharon (S-1-5-21-1603844925-2173046804-925170645-1000 - Administrator - Enabled) => C:\Users\Sharon

            ==================== Security Center ========================

            (If an entry is included in the fixlist, it will be removed.)

            AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {86355677-4064-3EA7-ABB3-1B136EB04637}
            AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
            AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {3D54B793-665E-3129-9103-206115370C8A}
            FW: McAfee Firewall (Enabled) {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

            ==================== Installed Programs ======================

            (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

            Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
            Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
            Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.)
            Adobe Flash Player 20 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 20.0.0.286 - Adobe Systems Incorporated)
            Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
            Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.8.158 - Adobe Systems, Inc.)
            Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
            Apple Application Support (32-bit) (HKLM-x32\…\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)
            Apple Application Support (64-bit) (HKLM\…\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)
            Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
            Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
            AviSynth 2.5 (HKLM-x32\…\AviSynth) (Version:  - )
            AVS Image Converter 1.2.1.100 (HKLM-x32\…\AVS Image Converter_is1) (Version:  - Online Media Technologies Ltd.)
            AVS Update Manager 1.0 (HKLM-x32\…\AVS Update Manager_is1) (Version:  - Online Media Technologies Ltd.)
            Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
            Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
            Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
            Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
            Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
            D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
            Dell Dock (HKLM\…\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell)
            Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
            Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
            Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 13.2.3.0 - Synaptics Incorporated)
            Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)
            Dell Wireless WLAN Card Utility (HKLM\…\Dell Wireless WLAN Card Utility) (Version: 5.30.21.0 - Dell Inc.)
            Digital Photo Navigator 1.0 (HKLM-x32\…\{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}) (Version:  - )
            Disk Cleaner (remove only) (HKLM-x32\…\DiskCleaner) (Version:  - )
            ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
            ffdshow v1.1.3572 [2010-09-13] (HKLM-x32\…\ffdshow_is1) (Version: 1.1.3572.0 - )
            Free Audio CD to MP3 Converter version 1.3.12.1228 (HKLM-x32\…\Free Audio CD to MP3 Converter_is1) (Version: 1.3.12.1228 - DVDVideoSoft Ltd.)
            Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
            Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
            Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden
            Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
            Haali Media Splitter (HKLM-x32\…\HaaliMkx) (Version:  - )
            Heroes & Generals (HKLM-x32\…\Heroes & Generals) (Version: 1.0.6.1 - Reto-Moto)
            iCloud (HKLM\…\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
            iCopyBot for Windows 7.9.8 (HKLM-x32\…\iCopyBot for Windows) (Version: 7.9.8 - VOWSoft, Ltd.)
            Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002 - Brice Lambson) Hidden
            Image Resizer for Windows (HKLM-x32\…\{9dfff2f7-5cd7-4fd4-9b75-7d53b042d94b}) (Version: 3.0.4442.6002 - Brice Lambson)
            inSSIDer Home (HKLM-x32\…\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
            InstallConverter (HKLM-x32\…\InstallConverter) (Version: 1.0 - InstallConverter)
            Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - Intel Corporation)
            Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1029 - Intel Corporation)
            Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version:  - Intel Corporation)
            iTunes (HKLM\…\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
            Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
            Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
            LAV Filters 0.51.3 (HKLM-x32\…\lavfilters_is1) (Version: 0.51.3 - Hendrik Leppkes)
            Lexmark 3500-4500 Series (HKLM\…\Lexmark 3500-4500 Series) (Version:  - Lexmark International, Inc.)
            Live! Cam Avatar Creator (HKLM-x32\…\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.3009.1 - Creative Technology Ltd)
            Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
            McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 10.5.195 - McAfee, Inc.)
            Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
            Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
            Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
            Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
            Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
            Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
            Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
            Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
            Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\…\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
            Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
            Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\…\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
            Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
            Microsoft Works (HKLM-x32\…\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
            Mount&Blade; Warband (HKLM-x32\…\Mount&Blade; Warband) (Version:  - )
            PowerDVD DX (HKLM-x32\…\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.3.5424 - CyberLink Corp.)
            Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 9.6.6 - Dell Inc.)
            QuickTime 7 (HKLM-x32\…\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
            ROBLOX Player for Sharon (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
            Roxio Burn (HKLM-x32\…\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.0 - Roxio)
            Skype Click to Call (HKLM-x32\…\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
            Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
            Sothink Movie DVD Maker (HKLM-x32\…\{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1) (Version: 3.8 - SourceTec Software Co., LTD)
            Spotify (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Spotify) (Version: 0.9.4.185.g7545a404 - Spotify AB)
            Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
            swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
            Unity Web Player (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
            Verdun (HKLM-x32\…\Steam App 242860) (Version:  - M2H)
            Virgin Media Cloud (HKU\S-1-5-21-1603844925-2173046804-925170645-1000\…\Virgin Media Cloud) (Version: 2.4.4435 - F-Secure Corporation)
            VLC media player 2.1.2 (HKLM-x32\…\VLC media player) (Version: 2.1.2 - VideoLAN)
            Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
            Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
            Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
            WinPatrol (HKLM\…\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 30.1.2014 - BillP Studios)
            WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )

            ==================== Custom CLSID (Whitelisted): ==========================

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            CustomCLSID: HKU\S-1-5-21-1603844925-2173046804-925170645-1000_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Sharon\AppData\Local\Roblox\Versions\version-465ca0bcd6b344c3\RobloxProxy64.dll (ROBLOX Corporation)

            ==================== Scheduled Tasks (Whitelisted) =============

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            Task: {039DD88D-3DDE-408C-8A5A-55F7121590DB} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-02-10] (Oracle Corporation)
            Task: {16B97E37-3B14-4027-A65E-72E301F80F1A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
            Task: {2FE1DE7F-DDC3-42E3-BD3E-4667BF17AED2} - System32\Tasks\{8D06BC15-F5B6-4AC0-8233-9F0ADAA4DD1D} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
            Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
            Task: {66B6E2DE-37EF-40A4-A29A-1499E3ACC54D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
            Task: {6DEE93CC-4A2E-49D3-B1FF-35E50C2B2309} - System32\Tasks\DJNJ8SJ1\Administrator - Start WLAN Tray Applet => C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE [2009-07-17] (Dell Inc.)
            Task: {8335C703-0DFD-4F5A-8D7B-CF11E9336803} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
            Task: {87589C5E-C1AE-4503-87BC-76B273547797} - System32\Tasks\{A3FDA8D8-F1E0-49A9-AC99-A04158C023A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?page=tsBing
            Task: {9840521E-672C-4758-9464-F18B350D8626} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
            Task: {A16B56B1-CACA-4C8E-957D-63C1895450B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
            Task: {A367EA33-4598-400B-9BC0-C8CB941BE71E} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
            Task: {C7ADECB6-B5C1-4EC4-8D00-965492898B02} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-20] (Adobe Systems Incorporated)
            Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc
            Task: {E65FA14B-11F8-416C-9A7E-995E9CD6D566} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe [2015-12-05] (Microsoft Corporation)
            Task: {F4214C36-6660-4F72-BDC8-98F2C55B6D6A} - System32\Tasks\{46EF662D-9A7C-4B91-A664-490EC3CA199D} => pcalua.exe -a C:\JVC\UsbSTGE.exe -d C:\JVC

            (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

            Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
            Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

            ==================== Shortcuts =============================

            (The entries could be listed to be restored or removed.)

            ==================== Loaded Modules (Whitelisted) ==============

            2009-12-24 15:30 - 2009-07-17 01:06 - 00033280 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
            2009-12-24 15:30 - 2009-07-17 01:06 - 00058368 _____ () C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll
            2012-11-11 10:58 - 2007-03-15 23:11 - 00138240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdidrpp.dll
            2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
            2015-10-13 05:45 - 2015-10-13 05:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
            2010-01-09 20:17 - 2010-01-09 20:17 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
            2010-01-21 01:40 - 2010-01-21 01:40 - 08794464 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
            2010-12-20 21:59 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
            2015-12-13 19:46 - 2015-12-13 19:46 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\ad2fbbd746bb143008adb984541da686\VistaBridgeLibrary.ni.dll
            2014-02-19 20:53 - 2014-02-18 03:46 - 00643948 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
            2015-10-13 05:46 - 2015-10-13 05:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
            2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
            2015-10-13 05:45 - 2015-10-13 05:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
            2010-01-09 20:18 - 2010-01-09 20:18 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
            2010-01-21 01:34 - 2010-01-21 01:34 - 08793952 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

            ==================== Alternate Data Streams (Whitelisted) =========

            (If an entry is included in the fixlist, only the ADS will be removed.)

            ==================== Safe Mode (Whitelisted) ===================

            (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
            HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

            ==================== EXE Association (Whitelisted) ===============

            (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

            ==================== Internet Explorer trusted/restricted ===============

            (If an entry is included in the fixlist, it will be removed from the registry.)

            ==================== Hosts content: ===============================

            (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

            2009-07-14 02:34 - 2016-01-30 22:37 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

            ==================== Other Areas ============================

            (Currently there is no automatic fix for this section.)

            HKU\S-1-5-21-1603844925-2173046804-925170645-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sharon\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
            DNS Servers: 192.168.0.1
            HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
            Windows Firewall is enabled.

            ==================== MSCONFIG/TASK MANAGER disabled items ==

            (Currently there is no automatic fix for this section.)

            MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
            MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
            MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
            MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

            ==================== FirewallRules (Whitelisted) ===============

            (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

            FirewallRules: [{0332E39C-D700-4178-897A-91BD7C9FC3AD}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PowerDVD.exe
            FirewallRules: [{9241A141-1C7D-401C-86FF-68DC3C733D89}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
            FirewallRules: [{E511FE26-5850-40F8-8BE9-369B466129B8}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
            FirewallRules: [{25E1DDAA-1275-43E2-B0D5-CA0A038762C1}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
            FirewallRules: [{DA5B37A1-E998-4461-801B-885310A70C65}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
            FirewallRules: [{4448837A-8A45-4DCF-80EA-018CCABB0152}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
            FirewallRules: [{8B5C7515-5E52-4B14-8615-C5CFE1DF0492}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
            FirewallRules: [{579303C5-7A83-499E-9059-9FFC90A94E4F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
            FirewallRules: [{B292AF1D-BDDF-4862-A319-63627591A6D9}] => (Allow) LPort=2869
            FirewallRules: [{DCA207F2-8A87-4052-8AFF-D08D9ABE6225}] => (Allow) LPort=1900
            FirewallRules: [{525A5E41-73B4-46E1-A5DE-2A156D737B6D}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
            FirewallRules: [{18ADDB25-AE21-433A-88B0-DED508680E27}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{40BC477C-361A-49EC-B674-DF8C4F7549D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{1FD7A359-3662-44EB-9527-46ED6EC10CC4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{879B9977-27F7-4A07-A959-ACA27B6D2E65}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{49E791C3-7A74-4EB9-B960-1874CB2A5BB8}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
            FirewallRules: [{AAFE46BE-7A06-4B2B-AAA0-84AC3D110836}] => (Allow) C:\Windows\SysWOW64\lxdicoms.exe
            FirewallRules: [{9AEA2DC4-DAC2-4341-994C-DF13AF827FB0}] => (Allow) C:\Windows\System32\lxdicoms.exe
            FirewallRules: [{B911FD92-BABC-4726-8DB7-CA322C099DB8}] => (Allow) C:\Windows\System32\lxdicoms.exe
            FirewallRules: [{CF986128-AD4D-45F2-B22E-E3E16E4E9FDA}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
            FirewallRules: [{7D535C64-78C0-4E0C-A596-6C0621DBE66B}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
            FirewallRules: [{13D9AB9D-4990-49F7-B640-F6F067B2219F}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
            FirewallRules: [{B4DB37E7-E205-4B03-8206-BAE9398D3102}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.exe
            FirewallRules: [{7FFE1605-CD9B-4AC5-9763-6BEE75155F10}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
            FirewallRules: [{156A3780-BFB6-408D-A8F4-AE3FE8F659ED}] => (Allow) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
            FirewallRules: [{E39C41EC-5187-4A43-91D4-D2B7947FE7A4}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
            FirewallRules: [{DEC501C9-836F-4D67-A90B-166B23F3A457}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdipswx.exe
            FirewallRules: [{5C050647-43F3-4455-84BF-DED1B647757E}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
            FirewallRules: [{C31D4F77-42C9-4606-97F8-227BD727E95D}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxditime.exe
            FirewallRules: [{7789B22F-ADB1-496E-BEAF-8DF913B284EC}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
            FirewallRules: [{5666A10E-8B52-4A11-A734-780A14E2E741}] => (Allow) C:\Windows\System32\spool\drivers\x64\3\lxdijswx.exe
            FirewallRules: [TCP Query User{9168E047-A0A1-4A11-8667-9CA820EE5996}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
            FirewallRules: [UDP Query User{29D328A2-FF65-424E-A7E0-67335D03F7AB}C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdiamon.exe
            FirewallRules: [TCP Query User{6360F2DA-6D0B-4185-B133-BE5E59007308}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
            FirewallRules: [UDP Query User{8A59EF6B-447A-47B6-A552-603CCDA903EE}C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe] => (Allow) C:\program files (x86)\lexmark 3500-4500 series\lxdimon.exe
            FirewallRules: [TCP Query User{73A65667-7085-4958-9E4A-6152E28DED93}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [UDP Query User{28FA0E79-DF6D-4F3B-B13E-C7F1C475C938}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [TCP Query User{0EBA448B-CC42-4C3A-BF11-F4DCF379ECFC}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [UDP Query User{2E599A0A-1FB4-433B-94E7-A4EFA2A9C6B3}C:\users\sharon\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\sharon\appdata\roaming\spotify\spotify.exe
            FirewallRules: [{5B729769-EA93-49A3-A943-D1E779C827A7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
            FirewallRules: [{5A93EF4D-8CD9-4E01-8672-BAD5D0977553}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
            FirewallRules: [{1AC5BF7C-6BA2-4173-9BE3-AEC003FA37BE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
            FirewallRules: [{5EB56F86-F386-4653-9FE9-C2228C140A73}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
            FirewallRules: [{3A3866BF-862C-4BFC-85D5-67E8566107F0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
            FirewallRules: [{404848F1-16D8-4889-AED5-D44B705ECAC8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Verdun\Verdun.exe
            FirewallRules: [{8BE2350B-9A46-4ADB-8591-73131CC6D1C1}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
            FirewallRules: [{4FDE0FE9-FD52-4355-B9B0-0D4D6C284B44}] => (Allow) C:\Program Files (x86)\Heroes & Generals\live\hng.exe
            FirewallRules: [{923BFEDE-A25D-4D7A-8254-E1BA21F960D5}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{34313D66-7655-48F5-8B3A-7F1A9A42025C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
            FirewallRules: [{CDB443C1-333D-4266-9532-5C77AF3AC89F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{14781C1E-CB3B-4B77-A3D4-036A23F6472F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
            FirewallRules: [{54BFECE4-53A3-4C5D-BD67-FC93971152EF}] => (Allow) C:\Program Files\iTunes\iTunes.exe

            ==================== Restore Points =========================

            30-01-2016 18:11:10 Scheduled Checkpoint
            30-01-2016 22:37:03 Restore Point Created by FRST
            31-01-2016 11:14:04 JRT Pre-Junkware Removal

            ==================== Faulty Device Manager Devices =============

            Name:
            Description:
            Class Guid:
            Manufacturer:
            Service:
            Problem: : The drivers for this device are not installed. (Code 28)
            Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

            ==================== Event log errors: =========================

            Application errors:
            ==================
            Error: (01/31/2016 07:36:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
            Description: Task Scheduling Error: m->NextScheduledSPRetry 3182

            Error: (01/31/2016 07:36:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
            Description: Task Scheduling Error: m->NextScheduledEvent 3182

            Error: (01/31/2016 07:36:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
            Description: Task Scheduling Error: Continuously busy for more than a second

            Error: (01/31/2016 05:03:46 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/31/2016 05:03:46 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            Error: (01/31/2016 02:51:20 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/31/2016 02:51:20 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            Error: (01/31/2016 11:12:09 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            Error: (01/31/2016 11:12:09 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
            Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

            Error: (01/31/2016 10:47:02 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
            Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

            System errors:
            =============
            Error: (01/31/2016 07:00:18 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 43. The internal error state is 252.

            Error: (01/31/2016 07:00:18 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 43. The internal error state is 252.

            Error: (01/31/2016 06:57:30 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            Error: (01/31/2016 06:57:30 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            Error: (01/31/2016 06:57:30 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            Error: (01/31/2016 06:25:31 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            Error: (01/31/2016 06:25:31 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            Error: (01/31/2016 06:25:31 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            Error: (01/31/2016 06:20:44 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            Error: (01/31/2016 06:20:44 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
            Description: The following fatal alert was generated: 10. The internal error state is 10.

            CodeIntegrity:
            ===================================
              Date: 2015-10-12 13:46:54.850
              Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

              Date: 2015-10-12 13:46:54.357
              Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

            ==================== Memory info ===========================

            Processor: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
            Percentage of memory in use: 37%
            Total physical RAM: 4056.36 MB
            Available physical RAM: 2523.31 MB
            Total Virtual: 8110.93 MB
            Available Virtual: 6139.73 MB

            ==================== Drives ================================

            Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:106.91 GB) NTFS

            ==================== MBR & Partition Table ==================

            ========================================================
            Disk: 0 (Size: 298.1 GB) (Disk ID: 086F8F0B)
            Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
            Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
            Partition 3: (Not Active) - (Size=283.4 GB) - (Type=07 NTFS)

            ==================== End of Addition.txt ============================

             

             

             

             

            Ask AI

            AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

            Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI