This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sluggish Start Time [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, whenever I start my computer now it seems to take a long time to get booted up to where I can actually use anything. Sometimes the computer just freezes and I have to to a reset on it. I've ran AVG, Malware Bytes, and Spybot already and it seems to have the same issue. Here are the scans that were requested.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-02-04 02:01:17
—————————–
02:01:17.059    OS Version: Windows x64 6.2.9200 
02:01:17.059    Number of processors: 8 586 0x1E05
02:01:17.059    ComputerName: DANIELPC  UserName: Daniel
02:01:17.502    Initialze error C000010E - driver not loaded
02:03:45.422    AVAST engine defs: 16020301
02:04:55.212    Service scanning
02:05:23.315    Modules scanning
02:05:23.317    Disk 0 trace - called modules:
02:05:23.318    
02:05:23.937    AVAST engine scan C:\Windows
02:05:25.409    AVAST engine scan C:\Windows\system32
02:08:30.729    AVAST engine scan C:\Windows\system32\drivers
02:08:44.473    AVAST engine scan C:\Users\Daniel
02:16:27.705    AVAST engine scan C:\ProgramData
02:25:59.148    Scan finished successfully
02:26:08.323    The log file has been saved successfully to "C:\Users\Daniel\Desktop\aswMBR.txt"
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
Ran by [removed] (administrator) on DANIELPC (04-02-2016 02:27:33)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8 Pro (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.2.0\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.2.0\loggingserver.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.17280_none_6224eed751126779\TiWorker.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SpeedFan] => C:\\Program Files (x86)\\SpeedFan\\speedfan.exe [4679672 2012-09-12] (Almico Software (www.almico.com))
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-06] (Apple Inc.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3874216 2016-01-08] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2586696 2016-01-31] ()
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [179624 2016-01-12] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\Run: [ROC_ROC_APR2013_AV] => C:\Users\Daniel\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT –mid d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68 –CMPID ROC_APR2013_AV –CM (the data entry has 13 more characters).
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\Run: [CmTray] => C:\Program Files (x86)\Content Manager\launchCM.exe [94208 2011-12-28] ()
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\MountPoints2: {b50e853e-77ea-11e3-bec3-6cf049053bc7} - "G:\MyKey.exe" 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:27-01-2016
Ran by [removed] (2016-02-04 02:28:13)
Running from C:\Users\[removed]\Desktop
Windows 8 Pro (X64) (2012-12-20 01:19:57)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3047707618-2994375693-2628713888-500 - Administrator - Disabled)
Daniel (S-1-5-21-3047707618-2994375693-2628713888-1001 - Administrator - Enabled) => C:\Users\Daniel
Guest (S-1-5-21-3047707618-2994375693-2628713888-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3047707618-2994375693-2628713888-1003 - Limited - Enabled)
Mallory (S-1-5-21-3047707618-2994375693-2628713888-1004 - Limited - Enabled) => C:\Users\Mallory
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 20 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 20.0.0.286 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.13) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG (HKLM\…\AvgZen) (Version: 1.31.1.48846 - AVG Technologies)
AVG (Version: 16.31.7357 - AVG Technologies) Hidden
AVG 2013 (Version: 13.0.2904 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4522 - AVG Technologies) Hidden
AVG Protection (HKLM\…\AVG) (Version: 2016.31.7357 - AVG Technologies)
AVG SafeGuard toolbar (HKLM-x32\…\AVG SafeGuard toolbar) (Version: 19.2.0.326 - AVG Technologies)
AVG Zen (Version: 1.31.9 - AVG Technologies) Hidden
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Chivalry: Medieval Warfare (HKLM-x32\…\Steam App 219640) (Version:  - Torn Banner Studios)
Company of Heroes (HKLM-x32\…\Steam App 4560) (Version:  - Relic)
Company of Heroes: Tales of Valor (HKLM-x32\…\Steam App 20540) (Version:  - Relic)
Content Manager (HKLM-x32\…\{B64BC516-2406-43AE-A21A-1E387A2343B1}) (Version: 2.70 - Magellan)
Counter-Strike (HKLM-x32\…\Steam App 10) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\…\Steam App 240) (Version:  - Valve)
CPUID CPU-Z 1.62.0 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
Darksiders (HKLM-x32\…\Steam App 50620) (Version:  - Vigil Games)
Darksiders II (HKLM-x32\…\Steam App 50650) (Version:  - Vigil Games)
FMW 1 (Version: 1.52.1 - AVG Technologies) Hidden
Free Documents Opener (HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\Free Documents Opener) (Version: 1.0 - Free Documents Opener)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.97 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Homefront (HKLM-x32\…\Steam App 55100) (Version:  - THQ)
HP ENVY 5530 series Basic Device Software (HKLM\…\{CE838BCA-A2CA-4E8E-88C3-C2D4ECA150D1}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP ENVY 5530 series Help (HKLM-x32\…\{97EAE055-1BE8-4775-8101-453E9715EC3F}) (Version: 30.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\…\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
iTunes (HKLM\…\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Metro 2033 (HKLM-x32\…\Steam App 43110) (Version:  - THQ)
Microsoft Games for Windows - LIVE (HKLM-x32\…\{F112F66E-25CA-42DD-983C-6118EB38F606}) (Version: 3.0.89.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\…\{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}) (Version: 3.0.19.0 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 15.0.4787.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mp3tag v2.58 (HKLM-x32\…\Mp3tag) (Version: v2.58 - Florian Heidenreich)
MSI Afterburner 2.3.0 (HKLM-x32\…\Afterburner) (Version: 2.3.0 - MSI Co., LTD)
MX vs ATV Reflex (HKLM-x32\…\Steam App 55140) (Version:  - Rainbow\Double Helix)
Nexuiz (HKLM-x32\…\Steam App 96800) (Version:  - IllFonic)
NVIDIA PhysX (HKLM-x32\…\{54194F60-988C-4D03-B922-C2B00EFDA39A}) (Version: 9.10.0222 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4787.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4787.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4787.1002 - Microsoft Corporation) Hidden
OpenOffice.org 3.4.1 (HKLM-x32\…\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
Orbit Downloader (HKLM-x32\…\Orbit_is1) (Version:  - www.orbitdownloader.com)
Portal (HKLM-x32\…\Steam App 400) (Version:  - Valve)
Portal 2 (HKLM-x32\…\Steam App 620) (Version:  - Valve)
Product Improvement Study for HP ENVY 5530 series (HKLM\…\{693E1B07-E7A7-4744-9B06-DBDFEED23704}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
Project64 1.6 (HKLM-x32\…\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64)
Red Faction (HKLM-x32\…\Steam App 20530) (Version:  - )
Red Faction II (HKLM-x32\…\Steam App 20550) (Version:  - )
Red Faction: Armageddon (HKLM-x32\…\Steam App 55110) (Version:  - Volition)
Retrovirus (HKLM-x32\…\Steam App 227800) (Version:  - Cadenza Interactive)
Saints Row 2 (HKLM-x32\…\Steam App 9480) (Version:  - Volition)
Saints Row: The Third (HKLM-x32\…\Steam App 55230) (Version:  - Volition)
Smite (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 2.7.2766.1 - Hi-Rez Studios)
Sol Survivor (HKLM-x32\…\Steam App 45000) (Version:  - Cadenza Interactive)
SpeedFan (remove only) (HKLM-x32\…\SpeedFan) (Version:  - )
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.)
StarCraft (HKLM-x32\…\StarCraft) (Version:  - Blizzard Entertainment)
StarCraft II (HKLM-x32\…\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Supreme Commander (HKLM-x32\…\Steam App 9350) (Version:  - )
Supreme Commander: Forged Alliance (HKLM-x32\…\Steam App 9420) (Version:  - )
Titan Quest (HKLM-x32\…\Steam App 4540) (Version:  - IronLore)
Visual Studio 2010 x64 Redistributables (HKLM\…\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.0.5 (HKLM-x32\…\VLC media player) (Version: 2.0.5 - VideoLAN)
Warhammer 40,000 Space Marine (HKLM-x32\…\Steam App 55150) (Version:  - Relic)
Warhammer 40,000: Dawn of War – Dark Crusade (HKLM-x32\…\Steam App 4580) (Version:  - Relic)
Warhammer 40,000: Dawn of War - Game of the Year Edition (HKLM-x32\…\Steam App 4570) (Version:  - Relic)
Warhammer 40,000: Dawn of War – Soulstorm (HKLM-x32\…\Steam App 9450) (Version:  - Relic)
Warhammer 40,000: Dawn of War – Winter Assault (HKLM-x32\…\Steam App 9310) (Version:  - Relic)
Warhammer® 40,000™: Dawn of War® II - Chaos Rising™ (HKLM-x32\…\Steam App 20570) (Version:  - Relic)
Warhammer® 40,000™: Dawn of War® II – Retribution™ (HKLM-x32\…\Steam App 56400) (Version:  - Relic)
Warhammer® 40,000™: Dawn of War® II (HKLM-x32\…\Steam App 15620) (Version:  - Relic)
XCOM: Enemy Unknown (HKLM-x32\…\Steam App 200510) (Version:  - Firaxis Games)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {020D663E-47E0-46ED-8064-92314CC03B2E} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-01-23] (Microsoft Corporation)
Task: {04FBA78A-D866-4B6C-8296-AF494BA4DEF3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {1FFD9128-0F09-48C1-A5ED-55EE2065398B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-12-22] (Microsoft Corporation)
Task: {2262048E-862D-4219-A6E4-1C80CE6ABB83} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-23] (Adobe Systems Incorporated)
Task: {263F25A6-8B41-429A-9D0D-CFCF1DB7FAB8} - System32\Tasks\UAC pass\speedfan => C:\Program Files (x86)\SpeedFan\speedfan.exe [2012-09-12] (Almico Software (www.almico.com))
Task: {43AC406F-50B0-465C-84DE-2A95289CFFC2} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {6ED84942-0214-4B13-8A9E-328E0B8593C5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {77B31222-0C47-45D7-93EA-61CC538C6565} - System32\Tasks\HP AR Program Upload - 14c1b268bcbe452fb0008704e02708194befd9ba8afc4b6c81c5512742e8dbe5 => C:\Program Files\HP\HP ENVY 5530 series\bin\HPRewards.exe [2014-03-06] (TODO: )
Task: {9F1578F2-3470-4928-BC4F-310518E1E9D8} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
Task: {C62F2368-5B52-4508-A3C8-842DAB352A47} - \Updater26278.exe -> No File <==== ATTENTION
Task: {D7226742-FAC2-4D05-B03B-FB2F0809BE42} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-11-07] (Microsoft Corporation)
Task: {DCE7E0D8-D6E6-43C9-8B99-523FAD728BAC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-11-07] (Microsoft Corporation)
Task: {DF68E119-3818-46F3-9EB6-3E3D21036ED3} - System32\Tasks\HPCustParticipation HP ENVY 5530 series => C:\Program Files\HP\HP ENVY 5530 series\Bin\HPCustPartic.exe [2014-03-06] (Hewlett-Packard Co.)
Task: {E2846F54-A82E-40AF-9919-9E1BD414B6B2} - System32\Tasks\HP AR Program Upload - 3f646ed8a7f64eb39beb5568b47144a71df672adc5df495fbd467e52018476cf => C:\Program Files\HP\HP ENVY 5530 series\bin\HPRewards.exe [2014-03-06] (TODO: )
Task: {E303C1DF-7624-4B56-B3A0-38FD9EFB6BA3} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-12-22] (Microsoft Corporation)
Task: {E83ECA39-05CC-4859-9621-D7D704D6C240} - System32\Tasks\1114tbUpdateInfo => C:\ProgramData\Avg_Update_1114tb\1114tb_{DE097EFE-998A-4584-AC25-56CFEA6F596E}.exe [2014-11-10] ()
Task: {EBFB44CF-4611-46AF-88CC-26A34FB893E5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-13] (Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\1114tbUpdateInfo.job => C:\ProgramData\Avg_Update_1114tb\1114tb_{DE097EFE-998A-4584-AC25-56CFEA6F596E}.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-20 17:12 - 2015-03-20 17:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-10-10 16:16 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-01-31 16:12 - 2016-01-31 16:12 - 00168008 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.2.0\loggingserver.exe
2015-11-07 17:52 - 2015-09-01 10:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-09-10 16:33 - 2016-01-31 16:12 - 02586696 _____ () C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
2016-01-31 16:12 - 2016-01-31 16:12 - 00527944 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.2.0\log4cplusU.dll
2014-10-23 14:38 - 2016-02-03 21:16 - 00158720 _____ () C:\Users\Daniel\AppData\Local\Temp\sfareca00001.dll
2012-12-20 00:19 - 2016-02-03 21:16 - 00192512 _____ () C:\Users\Daniel\AppData\Local\Temp\sfamcc00001.dll
2013-10-25 08:21 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-10-25 08:21 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2012-08-10 16:51 - 2012-08-10 16:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
2015-11-19 19:06 - 2015-11-19 19:06 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2013-10-25 08:21 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-10-25 08:21 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-10-25 08:21 - 2012-04-03 16:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2015-11-07 17:52 - 2015-09-01 06:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2016-01-31 15:41 - 2016-01-27 11:39 - 01632584 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.97\libglesv2.dll
2016-01-31 15:41 - 2016-01-27 11:39 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.97\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
 
There are 7781 more sites.
 
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\123simsen.com -> www.123simsen.com
 
There are 7872 more sites.
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2012-07-25 23:26 - 2013-01-12 15:32 - 00445034 ____R C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
 
There are 15276 more lines.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-3047707618-2994375693-2628713888-1004\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{BFC364A6-923B-451F-94B8-D4DD4684DF0A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{0730BF4A-0E87-4733-A8D0-9D9EB38B6949}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{BF0BEA50-BE0D-47DB-A35A-7B10F3DD88F7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{1142BF9C-5BF7-4B98-9E52-7294023282B6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe
FirewallRules: [{F0C85F74-B0DE-4B4F-A7CE-9014B7C1E55F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
FirewallRules: [{B40637C8-9045-4693-80AF-9757A2F9F085}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe
FirewallRules: [{12EB4652-73EE-4A11-91B5-A5534AD517CA}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{D82654A4-5272-412C-BDE1-D8EB56F7732A}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{2D282198-6C4A-43C2-89AF-54A4BEC6F994}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{09EE2FB2-A875-4E23-B656-C64CA505C04C}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [TCP Query User{0C148C10-A497-411D-B406-C04E574EB520}C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe
FirewallRules: [UDP Query User{65934E67-FF69-4090-B67F-6BB66BACEF4A}C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe
FirewallRules: [{4B785499-A2A5-43C1-A726-27DBCDDE3AFD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dawn of war 2\DOW2.exe
FirewallRules: [{716671D5-2C7A-437E-A46B-E95103861DC6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dawn of war 2\DOW2.exe
FirewallRules: [{4CB16EBD-4629-4113-80FA-2B0F48A84CCB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\red faction armageddon\rf4_launcher.exe
FirewallRules: [{AA58A670-55A5-4003-8E7F-772A7D13D27D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\red faction armageddon\rf4_launcher.exe
FirewallRules: [TCP Query User{83FA0999-C7B0-41C0-B5C5-392D3CC1B21A}D:\steamlibrary\steamapps\common\dawn of war ii - retribution\dow2.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war ii - retribution\dow2.exe
FirewallRules: [UDP Query User{AB04D121-17CC-4104-9F2E-51408890BD0F}D:\steamlibrary\steamapps\common\dawn of war ii - retribution\dow2.exe] => (Allow) D:\steamlibrary\steamapps\common\dawn of war ii - retribution\dow2.exe
FirewallRules: [TCP Query User{582AD26B-01B6-4E15-8DF9-064D466E0C11}D:\steamlibrary\steamapps\common\portal 2\portal2.exe] => (Allow) D:\steamlibrary\steamapps\common\portal 2\portal2.exe
FirewallRules: [UDP Query User{FBCE3283-A34A-444D-9D69-C69BA98E10FB}D:\steamlibrary\steamapps\common\portal 2\portal2.exe] => (Allow) D:\steamlibrary\steamapps\common\portal 2\portal2.exe
FirewallRules: [{40020B5F-C27D-4E67-90C3-48EC8DF0A932}] => (Allow) D:\Program Files\Steam\steamapps\common\Titan Quest\Titan Quest.exe
FirewallRules: [{A37AECF9-B595-4121-A88A-6D97D7DA4982}] => (Allow) D:\Program Files\Steam\steamapps\common\Titan Quest\Titan Quest.exe
FirewallRules: [{53285927-9147-4910-9DB5-C9C8A504F030}] => (Allow) D:\Program Files\Steam\steamapps\common\Nexuiz\Bin32\Nexuiz.exe
FirewallRules: [{904FE5A2-6EDC-4441-865A-983E80431D3F}] => (Allow) D:\Program Files\Steam\steamapps\common\Nexuiz\Bin32\Nexuiz.exe
FirewallRules: [{374C88B5-AEAA-448E-B851-5496D41282ED}] => (Allow) D:\Program Files\Steam\steamapps\common\Nexuiz\Bin32\Editor.exe
FirewallRules: [{18492CDB-D7AA-4E5E-8984-BC9326898924}] => (Allow) D:\Program Files\Steam\steamapps\common\Nexuiz\Bin32\Editor.exe
FirewallRules: [{2BB2E0CC-269F-46D9-9F06-3B0EAC075284}] => (Allow) D:\Program Files\Steam\steamapps\common\homefront\Binaries\HOMEFRONT.exe
FirewallRules: [{2B077BDC-A2B5-43C9-AC73-44290C6D5A83}] => (Allow) D:\Program Files\Steam\steamapps\common\homefront\Binaries\HOMEFRONT.exe
FirewallRules: [{33F5A5C4-DE8A-4A3F-9F92-3609187D6D01}] => (Allow) D:\Program Files\Steam\steamapps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{3517C56F-77B0-4445-94AD-4661648989F3}] => (Allow) D:\Program Files\Steam\steamapps\common\Darksiders\DarksidersPC.exe
FirewallRules: [{780EB66A-8FA8-4718-863F-7D9DA85FDFCF}] => (Allow) D:\Program Files\Steam\steamapps\common\Darksiders 2\Darksiders2.exe
FirewallRules: [{F3C66F73-D05A-4051-BA1C-48BF2AAD93DE}] => (Allow) D:\Program Files\Steam\steamapps\common\Darksiders 2\Darksiders2.exe
FirewallRules: [{9ACEEED0-90E2-42E2-B31D-9A5FF2142DEC}] => (Allow) D:\Program Files\Steam\steamapps\common\Metro 2033\metro2033.exe
FirewallRules: [{41AD9F57-5919-4CDF-82FC-4028D9AF5A66}] => (Allow) D:\Program Files\Steam\steamapps\common\Metro 2033\metro2033.exe
FirewallRules: [TCP Query User{25E63CCD-A0EF-42EB-9366-8371DC9E622C}D:\steamlibrary\steamapps\common\red faction\rf.exe] => (Block) D:\steamlibrary\steamapps\common\red faction\rf.exe
FirewallRules: [UDP Query User{9DAB1F47-6BC9-44EE-9CE8-906B82556FCB}D:\steamlibrary\steamapps\common\red faction\rf.exe] => (Block) D:\steamlibrary\steamapps\common\red faction\rf.exe
FirewallRules: [TCP Query User{E807AF3D-1DFD-4B33-9FEC-4426BF9B6B0D}D:\program files\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe] => (Allow) D:\program files\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe
FirewallRules: [UDP Query User{406AB152-FCE7-45E0-B44A-FBB464A99E57}D:\program files\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe] => (Allow) D:\program files\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe
FirewallRules: [{12351D18-10D0-4076-B295-424E21CAB1EC}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Soulstorm\soulstorm.exe
FirewallRules: [{BEB01D57-4B32-4D97-AB27-FF395B93EE75}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Soulstorm\soulstorm.exe
FirewallRules: [{48DAC3D5-BAD2-47D0-8291-7DC83B683CF5}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Dark Crusade\darkcrusade.exe
FirewallRules: [{AC519B0B-8140-4EEB-A7E8-EFF2CE503C05}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Dark Crusade\darkcrusade.exe
FirewallRules: [{BC4D166B-43BB-422E-9B4E-6F5B88F02D36}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Gold\W40k.exe
FirewallRules: [{A569E3DB-50B2-4FE5-9C29-3A66B6A4BCD9}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Gold\W40k.exe
FirewallRules: [TCP Query User{2A5749EC-94A9-43DA-9E7F-4776F2E58BAC}D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe
FirewallRules: [UDP Query User{B9CDB669-7473-4FF2-8590-F010D64090BE}D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe
FirewallRules: [{55C0CC2C-5345-443E-9155-1E8D1715598D}] => (Allow) D:\Program Files\StarCraft II\StarCraft II.exe
FirewallRules: [{FC7BBD36-4B85-4312-84F5-ED25E8C4FE6C}] => (Allow) D:\Program Files\StarCraft II\StarCraft II.exe
FirewallRules: [{CDE8C724-3245-4AF4-AAD5-DBD24F8853CA}] => (Allow) D:\Program Files\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{E775BC69-77F5-4E38-846E-85AF31D796B0}] => (Allow) D:\Program Files\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{53F98D62-DE25-4185-98EF-030C9BD6C0FD}] => (Allow) D:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe
FirewallRules: [{6C1E773C-2A33-450E-8EC8-41F8019BAA9D}] => (Allow) D:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe
FirewallRules: [TCP Query User{DA288B50-25C8-42F4-9602-FA207349313E}D:\program files\starcraft ii\versions\base23260\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base23260\sc2.exe
FirewallRules: [UDP Query User{E6EC933A-BE4E-4D79-A6C6-6F32B01C4534}D:\program files\starcraft ii\versions\base23260\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base23260\sc2.exe
FirewallRules: [TCP Query User{F9D47240-8AB7-4C10-9DD9-17326C5227CF}D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe
FirewallRules: [UDP Query User{FC7A228D-D0BB-4661-99C8-CD52D705AAE3}D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe] => (Allow) D:\program files\steam\steamapps\common\dawn of war gold\w40kwa.exe
FirewallRules: [TCP Query User{D891868C-96CD-4008-A72E-5AC58C2665E5}C:\program files (x86)\orbitdownloader\orbitnet.exe] => (Allow) C:\program files (x86)\orbitdownloader\orbitnet.exe
FirewallRules: [UDP Query User{9C46EC5F-FBD7-46E3-AB22-7150791C6684}C:\program files (x86)\orbitdownloader\orbitnet.exe] => (Allow) C:\program files (x86)\orbitdownloader\orbitnet.exe
FirewallRules: [TCP Query User{E1785D6D-A76B-4C8F-87B6-15080CD4017C}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{AD8E7A46-974C-4DDF-A592-07CB9EA09FE4}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [TCP Query User{252A7CCE-35BC-4EBE-A65F-26CA333D9B03}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{E0B66909-A5E1-4249-98ED-BE5E35934970}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{EC4465E9-D1D3-41F2-ACCF-0CE302C37DFD}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{D8385171-6C52-4BBC-BE7A-33B5B6A895D6}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{D071E8AF-37A3-4A85-BD7D-62D20067F9E0}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [{10213D53-02CC-4B3E-B036-FBA11358C867}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe
FirewallRules: [{6D9BEA55-65D7-4AB7-8F03-EF1D8C5D2D44}] => (Allow) D:\Program Files\Steam\steamapps\common\company of heroes\RelicCOH.exe
FirewallRules: [{E47BCA69-B549-43C1-B3AA-A1C018AABDFC}] => (Allow) D:\Program Files\Steam\steamapps\common\company of heroes\RelicCOH.exe
FirewallRules: [{D924D279-F9D7-4DB5-8048-DE48BFE777C6}] => (Allow) D:\Program Files\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{C0F9BB2B-0E9F-4497-AC59-5FF6A59495B1}] => (Allow) D:\Program Files\Steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [TCP Query User{0142C5B7-1895-450B-8D9D-B506E7478138}C:\programdata\battle.net\agent\agent.2045\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.2045\agent.exe
FirewallRules: [UDP Query User{2895018B-BD62-4B2F-943E-1865F982D112}C:\programdata\battle.net\agent\agent.2045\agent.exe] => (Block) C:\programdata\battle.net\agent\agent.2045\agent.exe
FirewallRules: [TCP Query User{E1DF62E7-758B-4FDD-A08A-5856C989C2BA}F:\starcraft ii us\versions\base26490\sc2.exe] => (Block) F:\starcraft ii us\versions\base26490\sc2.exe
FirewallRules: [UDP Query User{D96E6441-985D-4294-8847-B628EACEB706}F:\starcraft ii us\versions\base26490\sc2.exe] => (Block) F:\starcraft ii us\versions\base26490\sc2.exe
FirewallRules: [{41434BC8-AB15-4218-8672-C3F966E6E6BD}] => (Allow) D:\Program Files\Steam\steamapps\common\SolSurvivor\SolSurvivor.exe
FirewallRules: [{B23A969F-00FA-4906-A430-B5719F51C780}] => (Allow) D:\Program Files\Steam\steamapps\common\SolSurvivor\SolSurvivor.exe
FirewallRules: [{31DBED7E-DEA8-404B-8169-CB27E31A0CEB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2B665ADA-AC1D-4BC4-8AFD-FA9187993FC9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{48CC1ABB-06EF-4778-84A6-8ADA1E747994}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DB4EE4D6-C51F-48CA-8596-04A4F7D91524}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{2D19CDB4-C1CA-4115-BC09-FD36859A390B}D:\program files\steam\steam.exe] => (Allow) D:\program files\steam\steam.exe
FirewallRules: [UDP Query User{800CC0C8-D50F-485B-8A6D-2DFCB688B570}D:\program files\steam\steam.exe] => (Allow) D:\program files\steam\steam.exe
FirewallRules: [{FF115663-4673-4FC5-B4AC-AAE42EB25FAF}] => (Allow) D:\SteamLibrary\SteamApps\common\Red Faction II\Red Faction II.exe
FirewallRules: [{D6EDC1FA-2A00-4333-9320-458CABAFFE86}] => (Allow) D:\SteamLibrary\SteamApps\common\Red Faction II\Red Faction II.exe
FirewallRules: [{6305BAA8-466C-43DE-8973-1291036B7B79}] => (Allow) D:\Program Files\Steam\steamapps\common\MX vs ATV Reflex\MXReflex.exe
FirewallRules: [{2C2399C1-9535-4397-B72F-FA4CCB1925B4}] => (Allow) D:\Program Files\Steam\steamapps\common\MX vs ATV Reflex\MXReflex.exe
FirewallRules: [{2C3D361B-3113-4FB0-8396-4042952446B5}] => (Allow) D:\Program Files\Steam\steamapps\common\MX vs ATV Reflex\MXSettings.exe
FirewallRules: [{3DB84999-7C12-43EE-B0ED-3ADB922CA9BD}] => (Allow) D:\Program Files\Steam\steamapps\common\MX vs ATV Reflex\MXSettings.exe
FirewallRules: [{83B85A2E-2DEC-46E2-80C1-D588D9C596E4}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
FirewallRules: [{959B2107-9B72-4EB5-AC4E-DC0D85863B4B}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
FirewallRules: [{F56B0F47-ED8A-4B9A-B24C-CDDFB31CB055}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgdiagex.exe
FirewallRules: [{770D2D66-699D-4380-89D7-076E3C6C8642}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgdiagex.exe
FirewallRules: [{0627611F-F7B7-4CAE-A9A4-308F8FC84467}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
FirewallRules: [{201F82FA-4BBB-49FE-AB6A-8A823AF1EDCF}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
FirewallRules: [TCP Query User{59C15833-79F6-4C1F-B1B7-BFD43DAF8508}D:\steamlibrary\steamapps\common\portal 2\portal2.exe] => (Allow) D:\steamlibrary\steamapps\common\portal 2\portal2.exe
FirewallRules: [UDP Query User{DADC50E6-5C78-4C19-8D51-97B4769A397C}D:\steamlibrary\steamapps\common\portal 2\portal2.exe] => (Allow) D:\steamlibrary\steamapps\common\portal 2\portal2.exe
FirewallRules: [TCP Query User{D4F1E371-65B7-4E78-81E3-2D6B6E5C3450}D:\steamlibrary\steamapps\common\red faction\rf.exe] => (Allow) D:\steamlibrary\steamapps\common\red faction\rf.exe
FirewallRules: [UDP Query User{E30D84FC-71DC-4A41-AE76-584F8D7C349A}D:\steamlibrary\steamapps\common\red faction\rf.exe] => (Allow) D:\steamlibrary\steamapps\common\red faction\rf.exe
FirewallRules: [{FA93C616-903D-4503-AE4F-9E30E56E9766}] => (Allow) D:\Program Files\Steam\steamapps\common\red faction armageddon\RedFactionArmageddon.exe
FirewallRules: [{B337B4C4-0547-402F-BF60-0373AC7772DF}] => (Allow) D:\Program Files\Steam\steamapps\common\red faction armageddon\RedFactionArmageddon.exe
FirewallRules: [{50141359-0CEA-40A3-9CEA-A0C0E00BCC2C}] => (Allow) D:\Program Files\Steam\steamapps\common\red faction armageddon\RedFactionArmageddon_DX11.exe
FirewallRules: [{08CB8907-1C98-48A1-B450-7F5E532739CE}] => (Allow) D:\Program Files\Steam\steamapps\common\red faction armageddon\RedFactionArmageddon_DX11.exe
FirewallRules: [{F0E49AA3-0A15-4651-ADED-566ADD40B3C8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe
FirewallRules: [{76669F22-EB0B-458B-8D01-117E95464D52}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe
FirewallRules: [{83188C0C-79BC-45D2-87CE-D485579981D9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{0CB2D742-FA05-4DE9-9CC2-ED7F4317C384}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [TCP Query User{126DA209-15F4-4E83-81E9-B3BB68ED3A6C}D:\program files\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base28667\sc2.exe
FirewallRules: [UDP Query User{5B2B0DCC-7D0B-40FD-B495-7D7F9D4341E8}D:\program files\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base28667\sc2.exe
FirewallRules: [TCP Query User{2FEC2C80-FE97-420A-95ED-319F8394D7A2}D:\program files\steam\steamapps\common\half-life\hl.exe] => (Block) D:\program files\steam\steamapps\common\half-life\hl.exe
FirewallRules: [UDP Query User{123D8CF0-3B87-4E88-BBE3-48A562F94699}D:\program files\steam\steamapps\common\half-life\hl.exe] => (Block) D:\program files\steam\steamapps\common\half-life\hl.exe
FirewallRules: [{258DEFE2-AB47-44B1-9FC0-80396E69B69D}] => (Allow) D:\Program Files\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{BD2D741B-EC9B-45D1-933C-81783433CD88}] => (Allow) D:\Program Files\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{122603B9-1AE8-4914-90D1-9DD70874F2C3}] => (Allow) D:\Program Files\Steam\steamapps\common\Saints Row 2\SR2_pc.exe
FirewallRules: [{69C6EFBA-3782-49E9-8495-4BC16CEDC9F7}] => (Allow) D:\Program Files\Steam\steamapps\common\Saints Row 2\SR2_pc.exe
FirewallRules: [{9D21AF19-3621-4199-8734-D43039F3E47E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{6E2540FF-DF20-4628-B457-F9A3708361DE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe
FirewallRules: [{3EA25AE0-9140-49FD-A065-F400C07F6A12}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [{FFD3B992-316D-4131-B0EE-488146EBA143}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3023\Agent.exe
FirewallRules: [TCP Query User{8A2431B0-79A8-44DD-ACE6-C9BAE7F718DD}D:\program files\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base28667\sc2.exe
FirewallRules: [UDP Query User{CE81BD36-9925-4D81-8973-E71D09C1E9C8}D:\program files\starcraft ii\versions\base28667\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base28667\sc2.exe
FirewallRules: [{CF28BBE9-A367-4A2B-87DA-5101844A394B}] => (Allow) C:\Program Files\HP\HP ENVY 5530 series\Bin\DeviceSetup.exe
FirewallRules: [{80887BC5-9054-488C-BC10-9026F62869C7}] => (Allow) LPort=5357
FirewallRules: [{28A1301E-8B6F-4672-9630-14CCB003D63B}] => (Allow) C:\Program Files\HP\HP ENVY 5530 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{8A617811-1C22-4B1B-9B3B-7ADBA9FC8C42}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Gold\W40k.exe
FirewallRules: [{477BCC36-E951-457F-B09D-66BA3F08EDF6}] => (Allow) D:\Program Files\Steam\steamapps\common\Dawn of War Gold\W40k.exe
FirewallRules: [{94CD9405-F6FF-4F15-87FA-429BDB612833}] => (Allow) D:\Program Files\Steam\steamapps\common\saints row the third\game_launcher.exe
FirewallRules: [{88B3C9AE-E1AF-41B4-87CD-5EE7355DF6A2}] => (Allow) D:\Program Files\Steam\steamapps\common\saints row the third\game_launcher.exe
FirewallRules: [{BE90A5DF-A762-4B67-8DA0-7F340163C638}] => (Allow) D:\Program Files\Steam\steamapps\common\saints row the third\SaintsRowTheThird.exe
FirewallRules: [{8688204D-BF5E-4EC0-9448-179B1B9F755F}] => (Allow) D:\Program Files\Steam\steamapps\common\saints row the third\SaintsRowTheThird.exe
FirewallRules: [{B8E7B173-A65D-4563-BF5B-FD269F872C6C}] => (Allow) D:\Program Files\Steam\steamapps\common\saints row the third\SaintsRowTheThird_DX11.exe
FirewallRules: [{A889CA3F-154D-4541-BCDA-DA7F2270A6E3}] => (Allow) D:\Program Files\Steam\steamapps\common\saints row the third\SaintsRowTheThird_DX11.exe
FirewallRules: [{6C5598C5-7550-44C8-9B3F-92F1EC20C0CA}] => (Allow) D:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{1EF61594-5D28-4375-B8FB-A9469AA1AA8F}] => (Allow) D:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{6513B535-A424-4064-9784-429D84E6FC73}] => (Allow) D:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe
FirewallRules: [{0BECD3C4-36DE-49D9-BB42-B8AE2366A834}] => (Allow) D:\Program Files\Steam\steamapps\common\dawn of war 2\DOW2.exe
FirewallRules: [TCP Query User{87424581-1959-4035-B63E-64B1E01F0302}D:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) D:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{F3B3B867-D613-4D73-81E1-858B7076E7F3}D:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) D:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe
FirewallRules: [TCP Query User{24CA8ED9-E116-4833-AAA0-ABF4BB736DEE}D:\starcraft\starcraft.exe] => (Allow) D:\starcraft\starcraft.exe
FirewallRules: [UDP Query User{CC2B7CC9-EC24-4A66-825E-0E3140FB6889}D:\starcraft\starcraft.exe] => (Allow) D:\starcraft\starcraft.exe
FirewallRules: [{28357834-C8DD-4EFB-9477-4C8225C1A3F7}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{BB8C2400-DF3B-4FB0-8BE9-664AF5E057C3}] => (Allow) D:\SteamLibrary\SteamApps\common\Warhammer 40,000 Space Marine\SpaceMarine.exe
FirewallRules: [{0DA27D16-C3EC-4140-908F-2AC2C12A836D}] => (Allow) D:\SteamLibrary\SteamApps\common\Warhammer 40,000 Space Marine\SpaceMarine.exe
FirewallRules: [TCP Query User{977F89DC-534D-428D-B14C-0B5E69ED45CF}D:\program files\starcraft ii\versions\base32283\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base32283\sc2.exe
FirewallRules: [UDP Query User{7DF4A0BE-C342-4FBC-94F9-50BB104B49CB}D:\program files\starcraft ii\versions\base32283\sc2.exe] => (Allow) D:\program files\starcraft ii\versions\base32283\sc2.exe
FirewallRules: [TCP Query User{865D811C-660D-46B7-9F50-F421210F5C73}D:\program files\starcraft ii\versions\base38215\sc2_x64.exe] => (Block) D:\program files\starcraft ii\versions\base38215\sc2_x64.exe
FirewallRules: [UDP Query User{E5E61B94-31D1-463B-94BC-45F00C0D24A5}D:\program files\starcraft ii\versions\base38215\sc2_x64.exe] => (Block) D:\program files\starcraft ii\versions\base38215\sc2_x64.exe
FirewallRules: [{6434B403-8CF2-4473-A060-E74633B03F53}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{B784CAA5-CDC9-4162-846C-A5D3FBEBAD21}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{475CBB15-D56F-4711-9D3D-82D7CA76B428}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{563AC8D0-D2D6-467E-B956-1610C44617D6}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{C33F302B-FE08-461A-BF79-E195BAC70DD8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{5F72CEDE-FCBF-42A0-8891-46B21206885D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{2E3715E7-1150-48B1-A871-0DF6ED697A45}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{5B470A59-3BC1-41CB-850F-E41678C2621A}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{649F17E6-7F67-4A23-B01C-041BD27271DA}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{3A2376C5-7BAE-4D8B-BDA1-82DABAEA034B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{E9DC6322-2B12-467C-A34F-EB63487AC671}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{93F4C4C7-82F0-4A5B-82CC-38E2947024FA}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{44687CEF-2B38-46EC-A068-36976047F2E2}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{7F521858-DD64-43C4-8532-3921665950F6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{4E993BFC-50FC-4920-BD7F-1CB1A611FC37}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe] => (Allow) C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe
FirewallRules: [UDP Query User{BA8EA635-7C0A-4475-9E42-20D8B74625A0}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe] => (Allow) C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Orbitdownloader\orbitdm.exe] => Enabled:Orbit
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Orbitdownloader\orbitnet.exe] => Enabled:Orbit
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D; 2 Tray Icon
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
 
==================== Restore Points =========================
 
04-02-2016 00:58:29 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (02/03/2016 10:10:40 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -2143485946
 
Error: (02/03/2016 10:10:40 PM) (Source: Microsoft Office 15) (EventID: 2011) (User: )
Description: Office Subscription licensing exception: Error Code: 0x803D0006; CorrelationId: {9C96A99C-DDEE-4533-94C5-A89C44CB1EEB}
 
Error: (02/02/2016 07:40:24 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15585
 
Error: (02/02/2016 07:40:24 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15585
 
Error: (02/02/2016 07:40:24 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (02/02/2016 03:00:47 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1".Error in manifest or policy file "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" on line UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (02/01/2016 06:04:04 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1".Error in manifest or policy file "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" on line UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (01/31/2016 04:29:49 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1".Error in manifest or policy file "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" on line UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (01/26/2016 06:46:23 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15584
 
Error: (01/26/2016 06:46:23 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15584
 
 
System errors:
=============
Error: (02/04/2016 01:03:20 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
Error: (02/04/2016 01:02:48 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
Error: (02/04/2016 12:29:34 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
Error: (02/04/2016 12:27:56 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
Error: (02/03/2016 09:12:16 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
Error: (02/03/2016 09:11:46 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
Error: (02/03/2016 09:10:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Hi-Rez Studios Authenticate and Update Service service to connect.
 
Error: (02/03/2016 09:10:03 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:30:24 PM on ‎2/‎2/‎2016 was unexpected.
 
Error: (02/02/2016 07:40:08 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
Error: (02/02/2016 07:39:38 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgsvc service.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7 CPU 860 @ 2.80GHz
Percentage of memory in use: 45%
Total physical RAM: 8183.49 MB
Available physical RAM: 4480.84 MB
Total Virtual: 9511.49 MB
Available Virtual: 6165.43 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:74.53 GB) (Free:3.52 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Programs) (Fixed) (Total:465.75 GB) (Free:254.26 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:111.78 GB) (Free:111.61 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: EC4DEC4D)
Partition 1: (Not Active) - (Size=111.8 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: 8D399BC0)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: 88DD92D7)
Partition 1: (Active) - (Size=74.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 

:welcome:

 

I need to see the complete FRST log please, you posted the Additions log just fine but most of the main FRST log is missing . All the logs from the tools we run will open in Notepad, when they open go to the top left and under Format, make sure Wordwrap is checked.  Then under EDIT, click SELECT ALL.    THEN EDIT…COPY , then come back to this thread and paste it in.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-01-2016
Ran by [removed] (administrator) on DANIELPC (04-02-2016 02:27:33)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8 Pro (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.2.0\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.2.0\loggingserver.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.17280_none_6224eed751126779\TiWorker.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SpeedFan] => C:\\Program Files (x86)\\SpeedFan\\speedfan.exe [4679672 2012-09-12] (Almico Software (www.almico.com))
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-06] (Apple Inc.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3874216 2016-01-08] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2586696 2016-01-31] ()
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [179624 2016-01-12] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\Run: [ROC_ROC_APR2013_AV] => C:\Users\Daniel\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT –mid d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68 –CMPID ROC_APR2013_AV –CM (the data entry has 13 more characters).
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\Run: [CmTray] => C:\Program Files (x86)\Content Manager\launchCM.exe [94208 2011-12-28] ()
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\MountPoints2: {b50e853e-77ea-11e3-bec3-6cf049053bc7} - "G:\MyKey.exe" 
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\…\MountPoints2: {cb8bdaf6-c1a6-11e3-bef3-806e6f6e6963} - "I:\windows\AutoRun.exe" {430A8AE3-8898-4DAB-8C5B-5E8ADA7D571E} 3.0.0.02 VID_19D2&PID_0358 {9B00E99F-83A4-40d4-B987-7EB04F722BB7}
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [241664 2012-07-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\speedfan.lnk [2012-12-20]
ShortcutTarget: speedfan.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP ENVY 5530 series.lnk [2016-02-03]
ShortcutTarget: Monitor Ink Alerts - HP ENVY 5530 series.lnk -> C:\Program Files\HP\HP ENVY 5530 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2013-01-06]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Mallory\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2015-05-31]
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{48206C4B-4D63-4EA5-92C4-82242E620B6A}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{CDEF6C1B-172B-4683-8615-1249918DAD17}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=0715tb&pr=fr&d=2013-08-29 22:08:44&v=19.2.0.326&pid=safeguard&sg=0&sap=hp
HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.msn.com/
HKU\S-1-5-21-3047707618-2994375693-2628713888-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=0715tb&pr=fr&d=2013-08-29 22:08:44&v=19.2.0.326&pid=safeguard&sg=0&sap=hp
SearchScopes: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=0915tb&pr=fr&d=2013-08-29 22:08:44&v=18.8.0.179&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3047707618-2994375693-2628713888-1004 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=0715tb&pr=fr&d=2013-08-29 22:08:44&v=18.8.0.179&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-01-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-01-23] (Microsoft Corporation)
BHO-x32: Octh Class -> {000123B4-9B42-4900-B3F7-F4B073EFC214} -> C:\Program Files (x86)\Orbitdownloader\orbitcth.dll [2013-02-01] (Orbitdownloader.com)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-01-10] (Microsoft Corporation)
BHO-x32: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG SafeGuard toolbar\19.2.0.326\AVG SafeGuard toolbar_toolbar.dll [2016-01-31] (AVG Secure Search)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23] (Microsoft Corporation)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll [2013-02-01] ()
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\19.2.0.326\AVG SafeGuard toolbar_toolbar.dll [2016-01-31] (AVG Secure Search)
Toolbar: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} -  No File
Toolbar: HKU\S-1-5-21-3047707618-2994375693-2628713888-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKU\S-1-5-21-3047707618-2994375693-2628713888-1004 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} -  No File
Toolbar: HKU\S-1-5-21-3047707618-2994375693-2628713888-1004 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-10-10] (Microsoft Corporation)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\19.2.0\ViProtocol.dll [2016-01-31] (AVG Secure Search)
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-23] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-23] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\19.2.0\\npsitesafety.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-10-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-12-12] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
FF HKLM-x32\…\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014-01-07] [not signed]
 
Chrome: 
=======
CHR HomePage: Default -> hxxps://mysearch.avg.com?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2013-08-29 22:08:44&v=18.1.9.799&pid=safeguard&sg=0&sap=hp
CHR StartupUrls: Default -> "hxxps://mysearch.avg.com?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2013-08-29 22:08:44&v=18.1.9.799&pid=safeguard&sg=0&sap=hp"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.97\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.97\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.97\pdf.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll => No File
CHR Profile: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-31]
CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-30]
CHR Extension: (Google Cast) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-01-31]
CHR Extension: (Google Search) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-31]
CHR Extension: (Google Docs Offline) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-31]
CHR Extension: (AdBlock) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-31]
CHR Extension: (FVD Video Downloader) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2015-04-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-10]
CHR Extension: (Gmail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-14]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [627544 2016-01-08] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3906568 2016-01-08] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1048488 2016-01-12] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [583936 2016-01-08] (AVG Technologies CZ, s.r.o.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2787512 2015-12-22] (Microsoft Corporation)
S2 HiPatchService; d:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2015-03-12] (Hi-Rez Studios) [File not signed]
S2 MBAMService; e:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R3 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 vToolbarUpdater19.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.2.0\ToolbarUpdater.exe [1875528 2016-01-31] (AVG Secure Search)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16024 2015-01-31] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [23152 2015-09-09] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [298416 2015-08-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [258480 2015-12-04] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-12-04] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [315840 2015-12-16] (AVG Technologies CZ, s.r.o.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3265256 2012-09-20] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44024 2015-01-31] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [275712 2015-01-30] (Microsoft Corporation)
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X]
U3 aswMBR; \??\C:\Users\Daniel\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Daniel\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-04 02:27 - 2016-02-04 02:28 - 00021219 _____ C:\Users\Daniel\Desktop\FRST.txt
2016-02-04 02:26 - 2016-02-04 02:27 - 00000000 ____D C:\FRST
2016-02-04 02:26 - 2016-02-04 02:26 - 00000934 _____ C:\Users\Daniel\Desktop\aswMBR.txt
2016-02-04 01:40 - 2016-02-04 01:40 - 02370560 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2016-02-04 01:38 - 2016-02-04 01:38 - 05198336 _____ (AVAST Software) C:\Users\Daniel\Desktop\aswMBR.exe
2016-02-04 00:50 - 2016-02-04 00:50 - 00000941 _____ C:\Windows\wininit.ini
2016-02-03 22:02 - 2016-02-03 22:02 - 00000000 ____D C:\Users\Daniel\Documents\ProcAlyzer Dumps
2016-02-03 21:54 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2016-01-31 15:24 - 2016-01-31 15:24 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\AVG
2016-01-31 15:23 - 2016-01-31 21:15 - 00000000 ____D C:\Users\Daniel\AppData\Local\Avg
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-02-04 01:56 - 2012-12-25 18:38 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-02-04 01:45 - 2012-12-22 22:57 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-04 01:30 - 2014-04-23 11:18 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-04 00:25 - 2012-12-19 19:26 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3047707618-2994375693-2628713888-1001
2016-02-03 22:01 - 2013-01-12 15:29 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-02-03 21:56 - 2013-01-12 15:29 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-02-03 21:54 - 2015-07-25 14:41 - 00000000 ____D C:\Program Files\Common Files\AV
2016-02-03 21:17 - 2012-07-26 01:59 - 00000000 ____D C:\Windows\CbsTemp
2016-02-03 21:15 - 2012-12-19 19:49 - 00000000 ____D C:\ProgramData\MFAData
2016-02-03 21:13 - 2012-12-20 00:19 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2016-02-03 21:12 - 2012-12-22 22:57 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-03 21:10 - 2012-07-26 01:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-03 21:09 - 2012-07-26 02:12 - 00000000 ____D C:\Windows\Vss
2016-02-01 17:40 - 2012-12-22 22:57 - 00003896 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-01 17:40 - 2012-12-22 22:57 - 00003660 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-01-31 16:12 - 2015-09-10 16:33 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2016-01-31 16:12 - 2013-05-03 11:38 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2016-01-31 15:54 - 2012-07-26 02:12 - 00000000 ___HD C:\Program Files\WindowsApps
2016-01-31 15:54 - 2012-07-26 02:12 - 00000000 ____D C:\Windows\AUInstallAgent
2016-01-31 15:42 - 2012-12-22 22:58 - 00002219 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-01-31 15:40 - 2014-04-23 11:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-01-31 15:40 - 2013-10-24 21:20 - 00000817 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-01-31 15:34 - 2015-06-25 18:31 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-01-31 15:26 - 2012-07-25 23:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2016-01-31 15:24 - 2015-09-16 11:23 - 00003542 _____ C:\Windows\System32\Tasks\HP AR Program Upload - 14c1b268bcbe452fb0008704e02708194befd9ba8afc4b6c81c5512742e8dbe5
2016-01-25 21:57 - 2014-07-07 11:03 - 00000000 ____D C:\Users\Mallory\AppData\Local\Packages
2016-01-25 20:29 - 2015-11-19 19:08 - 00000862 _____ C:\Users\Public\Desktop\AVG.lnk
2016-01-25 20:29 - 2015-11-19 19:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2016-01-25 20:28 - 2015-11-07 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-01-25 20:28 - 2012-12-19 19:53 - 00000000 ____D C:\ProgramData\AVG2013
2016-01-25 20:28 - 2012-12-19 19:52 - 00000000 ____D C:\Program Files (x86)\AVG
2016-01-25 20:24 - 2015-11-19 19:15 - 00000000 ____D C:\Users\Mallory\AppData\Local\Avg
2016-01-25 20:23 - 2012-07-26 01:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-25 20:23 - 2012-07-25 23:37 - 00000000 ____D C:\Windows\Inf
2016-01-23 15:57 - 2012-12-25 18:38 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-01-23 15:50 - 2012-07-26 02:12 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-01-23 15:46 - 2015-10-10 16:16 - 00000000 ____D C:\Program Files\Microsoft Office 15
 
==================== Files in the root of some directories =======
 
2014-07-08 12:22 - 2014-07-08 12:22 - 0000057 _____ () C:\ProgramData\Ament.ini
 
Some files in TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Daniel\AppData\Local\Temp\sfamcc00002.dll
C:\Users\Daniel\AppData\Local\Temp\sfareca00001.dll
C:\Users\Mallory\AppData\Local\Temp\avguirn_081253013690.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-01-31 15:52
 
==================== End of FRST.txt ============================

Much better , Thank you

 

Not much earth shattering that I can see. Lets run some general clean up tools and see what they find. I see you have the latest version of Malwarebytes installed so with my instructions just bypass the download and install part

 

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: 0841859c-1a35-4dbd-b41a-e720629e3e22_zps]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • # AdwCleaner v5.032 - Logfile created 04/02/2016 at 19:20:03
          # Updated 31/01/2016 by Xplode
          # Database : 2016-02-02.1 [Server]
          # Operating system : Windows 8 Pro  (x64)
          # Username : Daniel - DANIELPC
          # Running from : C:\Users\Daniel\Desktop\AdwCleaner.exe
          # Option : Cleaning
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
          [-] Service Deleted : vToolbarUpdater19.2.0
           
          ***** [ Folders ] *****
           
          [-] Folder Deleted : C:\Program Files (x86)\AVG SafeGuard toolbar
          [-] Folder Deleted : C:\Program Files (x86)\AVG Security Toolbar
          [-] Folder Deleted : C:\Program Files (x86)\orbitdownloader
          [-] Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
          [-] Folder Deleted : C:\ProgramData\AVG SafeGuard toolbar
          [-] Folder Deleted : C:\ProgramData\AVG Secure Search
          [-] Folder Deleted : C:\ProgramData\AVG Security Toolbar
          [-] Folder Deleted : C:\Users\Daniel\AppData\Local\AVG SafeGuard toolbar
          [-] Folder Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp
          [-] Folder Deleted : C:\Users\Daniel\AppData\LocalLow\AVG SafeGuard toolbar
          [-] Folder Deleted : C:\Users\Daniel\AppData\Roaming\GrabPro
          [-] Folder Deleted : C:\Users\Daniel\AppData\Roaming\ProgSense
          [-] Folder Deleted : C:\Users\Mallory\AppData\Local\AVG SafeGuard toolbar
          [-] Folder Deleted : C:\Users\Mallory\AppData\LocalLow\AVG SafeGuard toolbar
          [-] Folder Deleted : C:\Users\Mallory\AppData\Roaming\ProgSense
           
          ***** [ Files ] *****
           
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lfmhcpmkbdkbgbmkjoiopeeegenkdikp_0.localstorage
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lfmhcpmkbdkbgbmkjoiopeeegenkdikp_0.localstorage-journal
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_mysearch.avg.com_0.localstorage
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_mysearch.avg.com_0.localstorage-journal
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.yourtango.com_0.localstorage
          [-] File Deleted : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.yourtango.com_0.localstorage-journal
           
          ***** [ DLLs ] *****
           
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Scheduled tasks ] *****
           
           
          ***** [ Registry ] *****
           
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Download by Orbit
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Grab video by Orbit
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Do&wnload selected by Orbit
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Down&load all by Orbit
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
          [-] Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\handler\viprotocol
          [-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
          [-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
          [-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{000123B4-9B42-4900-B3F7-F4B073EFC214}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3F1D494B-0CEF-4468-96C9-386E2E4DEC90}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0880527-DC28-4EBB-BA27-D22102F22A9F}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BCDDE143-FAE3-4C57-B22B-C4E8678CFDC0}
          [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000123B4-9B42-4900-B3F7-F4B073EFC214}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7854F00C-DC77-477E-A10E-603F48442D3B}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{000123B4-9B42-4900-B3F7-F4B073EFC214}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C55BBCD6-41AD-48AD-9953-3609C48EACC7}]
          [-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key Deleted : HKCU\Software\APN PIP
          [-] Key Deleted : HKCU\Software\AVG Security Toolbar
          [-] Key Deleted : HKCU\Software\InstalledBrowserExtensions
          [-] Key Deleted : HKCU\Software\Orbit
          [-] Key Deleted : HKCU\Software\powerpack
          [-] Key Deleted : HKCU\Software\ProgSense
          [-] Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
          [-] Key Deleted : HKLM\SOFTWARE\Orbit
          [-] Key Deleted : HKLM\SOFTWARE\PIP
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Orbit_is1
          [!] Key Not Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\APN PIP
          [!] Key Not Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\AVG Security Toolbar
          [!] Key Not Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\InstalledBrowserExtensions
          [!] Key Not Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\Orbit
          [!] Key Not Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\powerpack
          [!] Key Not Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\ProgSense
          [-] Key Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1004\Software\Orbit
          [-] Key Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1004\Software\ProgSense
          [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
          [-] Data Restored : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
          [-] Data Restored : HKU\S-1-5-21-3047707618-2994375693-2628713888-1004\Software\Microsoft\Internet Explorer\Main [Start Page]
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [!] Key Not Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key Deleted : HKU\S-1-5-21-3047707618-2994375693-2628713888-1004\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
          [-] Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
           
          ***** [ Web browsers ] *****
           
          [-] [C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxps://mysearch.avg.com?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2013-08-29 22:08:44&v=18.1.9.799&pid=safeguard&sg=0&sap=hp
          [-] [C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : booedmolknjekdopkepjjeckmjkdpfgl
          [-] [C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : cijeeimilokkhlfjombmalgpabbonmah
          [-] [C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : flpcjncodpafbgdpnkljologafpionhb
          [-] [C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : lfmhcpmkbdkbgbmkjoiopeeegenkdikp
          [-] [C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ndibdjnfmopecpmkdieinmbadjfpblof
          [-] [C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Deleted : hxxps://mysearch.avg.com?cid={33CD71AD-603C-404D-AED2-D4CE48902982}&mid=d6d9df0b7c5a47d09dddbdb90fe1d234-bc2aa931443946544f29d11d5bc96756e8e24d68&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2013-08-29 22:08:44&v=18.1.9.799&pid=safeguard&sg=0&sap=hp
          [-] [C:\Users\Mallory\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
          [-] [C:\Users\Mallory\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
           
          *************************
           
          :: "Tracing" keys removed
          :: Winsock settings cleared
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [13236 bytes] ##########
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 8.0.2 (01.06.2016)
          Operating System: Windows 8 Pro x64 
          Ran by [removed] (Administrator) on Thu 02/04/2016 at 20:24:16.35
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
           
           
          File System: 14 
           
          Successfully deleted: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal (File) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage (File) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.lyricsmode.com_0.localstorage-journal (File) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.lyricsmode.com_0.localstorage (File) 
          Successfully deleted: C:\Windows\wininit.ini (File) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\59DMNQYB (Folder) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6643TMDY (Folder) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\93NZF9HH (Folder) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FN873354 (Folder) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H4UK4QLI (Folder) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q6KR62XK (Folder) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SDGL8W9F (Folder) 
          Successfully deleted: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SGIPA4U2 (Folder) 
          Successfully deleted: C:\Windows\prefetch\AVG SAFEGUARD TOOLBAR-60F142EC.pf (File) 
           
           
           
          Registry: 1 
           
          Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Value) 
           
           
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Thu 02/04/2016 at 20:27:25.57
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
          Malwarebytes Anti-Malware
          www.malwarebytes.org
           
          Scan Date: 2/4/2016
          Scan Time: 8:35 PM
          Logfile: malwarebytes.txt
          Administrator: Yes
           
          Version: 2.2.0.1024
          Malware Database: v2016.02.04.06
          Rootkit Database: v2016.01.20.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled
           
          OS: Windows 8
          CPU: x64
          File System: NTFS
          User: Daniel
           
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 381884
          Time Elapsed: 25 min, 20 sec
           
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Enabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
           
          Processes: 0
          (No malicious items detected)
           
          Modules: 0
          (No malicious items detected)
           
          Registry Keys: 0
          (No malicious items detected)
           
          Registry Values: 0
          (No malicious items detected)
           
          Registry Data: 0
          (No malicious items detected)
           
          Folders: 0
          (No malicious items detected)
           
          Files: 0
          (No malicious items detected)
           
          Physical Sectors: 0
          (No malicious items detected)
           
           
          (end)
           

          Good Morning,

           

           

          When you installed AVG, you let it install a lot of there programs with it and most of them are not needed, there considered Bloatware.

           

           

          Are things running any better ??  

           

          Open up FRST64 by right clicking on the icon and select RUN AS ADMINISTRATOR , make sure there is a checkmark in Additions, leave everything else as is, then run a new scan and post both the new FRST64 and Additions logs please

          Hey just thought I'd let you know that I'm on duty for 12 to 13 hours and work overnights so it will probably be Monday night at the earliest before I can make a meaningful response

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI