This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop really weird behavior... Please help [Solved]

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello my friends,

From a couple a month ago I notice my laptop is taking toooooo long to start. Usually the first time after  a long period of time (aprox 10 mins) windows will start the OS crashes and the laptop restart and again takes a long period (aprox 10 mins) to get to the log in windows. It takes toooo long for the latptop to get to the login windows. Most of the time when I hibernate or make my laptop go to sleep and I try to turn it on again the screen will stay black and wont turn on or simply it crashes and I have to wait again a long time for the laptop to restart. Once I Finally reach the start windows and I Log in in windows IT takes a lot to load the initials tools and programs, after that computer seems to run normal. In the task manager laptop from time to time stays on a high percentage disk usage (between 95-99%), and somehow high CPU and memory usage (between 45% and 75%) without doing anything on the laptop…..

 

Thanks a lot for your help… Much appreciated….

 

Here is my FRST log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:02-03-2016

Ran by [removed] (administrator) on VAIO (03-03-2016 14:40:36)

Running from C:\Users\[removed]\Desktop

[removed]

Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: Edge)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe

() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe

(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe

(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe

(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagent.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe

(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe

(Software) C:\Program Files (x86)\Common Files\Hydrup\hydrup.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe

(Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe

(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe

(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\ToolbarUpdater.exe

() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\loggingserver.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe

() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe

(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient.exe

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\igfxEM.exe

(Intel Corporation) C:\Windows\System32\igfxHK.exe

(Intel Corporation) C:\Windows\System32\igfxTray.exe

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

() C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe

(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe

(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe

() C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe

(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe

(Microsoft Corporation) C:\Windows\System32\browser_broker.exe

(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe

(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe

(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe

(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe

(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe

(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe

(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe

(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE

(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.16941.0_x64__8wekyb3d8bbwe\Video.UI.exe

(Microsoft Corporation) C:\Windows\System32\WWAHost.exe

(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe

(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe

(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE

(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\MSOSYNC.EXE

(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe

(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe

 

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-09-20] (Realtek Semiconductor)

HKLM\…\Run: [BtTray] => "C:\Program Files (x86)\Bluetooth Suite\BtTray.exe"

HKLM\…\Run: [BtvStack] => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"

HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3928264 2015-05-27] (Synaptics Incorporated)

HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-15] (Apple Inc.)

HKLM-x32\…\Run: [] => [X]

HKLM-x32\…\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [68776 2012-08-18] (Sony Corporation)

HKLM-x32\…\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [724576 2012-07-27] (Sony Corporation)

HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)

HKLM-x32\…\Run: [ATLauncher] => "C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe" /createshortcuts:1

HKLM-x32\…\Run: [ATUninstallIcon] => "C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe" /createuninstallentry:1

HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)

HKLM-x32\…\Run: [Iminent] => C:\Program Files (x86)\Iminent\Iminent.exe [1074736 2013-06-18] (Iminent)

HKLM-x32\…\Run: [IminentMessenger] => C:\Program Files (x86)\Iminent\Iminent.Messengers.exe [884784 2013-06-18] (Iminent)

HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)

HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [3873704 2016-01-25] (AVG Technologies CZ, s.r.o.)

HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2874440 2016-02-25] ()

HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [179624 2016-01-12] (AVG Technologies CZ, s.r.o.)

Winlogon\Notify\ GbPluginBdv: C:\Program Files (x86)\GbPlugin\gbiehBdv.dll [2015-12-23] (Banco de Venezuela)

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [HP Deskjet 3050 J610 series (NET)] => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Akamai NetSession Interface] => C:\Users\Mohamed\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Dropbox Update] => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [57987712 2015-09-28] (Skype Technologies S.A.)

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [uTorrent] => C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-12-16] (BitTorrent Inc.)

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1382672 2015-10-26] (Lavasoft)

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"

AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => No File

ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399026} - C:\Program Files (x86)\GbPlugin\gbiehbdv.dll [1864800 2015-12-23] (Banco de Venezuela)

ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-09-04]

ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)

Startup: C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-10-27]

ShortcutTarget: Dropbox.lnk -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

Startup: C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk [2015-06-03]

ShortcutTarget: Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk -> C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

BootExecute: autocheck autochk *

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

AutoConfigURL: [S-1-5-21-3844031730-595245587-2132850609-1001] => hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404

Winsock: Catalog9-x64 01 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-10-26] (Lavasoft Limited)

Winsock: Catalog9-x64 02 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-10-26] (Lavasoft Limited)

Winsock: Catalog9-x64 03 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-10-26] (Lavasoft Limited)

Winsock: Catalog9-x64 04 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-10-26] (Lavasoft Limited)

Winsock: Catalog9-x64 05 C:\WINDOWS\system32\LavasoftTcpService64.dll [425744 2015-10-26] (Lavasoft Limited)

Hosts: 0.0.0.1     mssplus.mcafee.com

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

Tcpip\..\Interfaces\{8e600265-fef9-4bc5-915b-46b09da7aa5b}: [DhcpNameServer] [removed] [removed]

Tcpip\..\Interfaces\{95b7ca61-94ac-4fcc-b000-6961f24fe53a}: [DhcpNameServer] 192.168.0.1

ManualProxies: 0hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404

 

Internet Explorer:

==================

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony13.msn.com

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.delta-search.com/?babsrc=HP_ss&mntrId;=A492A41731D66686&affID;=119357&tsp;=4923

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc;=UE01&ocid;=UE01DHP

SearchScopes: HKU\S-1-5-21-3844031730-595245587-2132850609-1001 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}

SearchScopes: HKU\S-1-5-21-3844031730-595245587-2132850609-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&babsrc;=SP_ss&mntrId;=A492A41731D66686&affID;=119357&tsp;=4923

SearchScopes: HKU\S-1-5-21-3844031730-595245587-2132850609-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={3E41C021-620A-4569-9061-5D26BC875617}∣=ee062fba3c1447cd9ca3851aabd0d12b-acb90d7262b26f03626765bc5924a395368b9741⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=1215tb≺=fr&d;=2015-06-03 13:26:46&v;=4.2.1.951&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}

BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)

BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)

BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)

BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)

BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2012-12-11] (Oracle Corporation)

BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-11-05] (Qualcomm Atheros Commnucations)

BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.2.6.552\AVG Web TuneUp.dll [2016-02-25] (AVG)

BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-18] (Kaspersky Lab ZAO)

BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx64.dll [2014-02-19] (SIEN)

BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)

BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)

BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-11-10] (Microsoft Corporation)

BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-12-11] (Oracle Corporation)

BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-18] (Kaspersky Lab ZAO)

BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)

BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)

BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)

BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)

BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-12-11] (Oracle Corporation)

BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.2.6.552\AVG Web TuneUp.dll [2016-02-25] (AVG)

BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-18] (Kaspersky Lab ZAO)

BHO-x32: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx86.dll [2014-02-19] (SIEN)

BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)

BHO-x32: delta Helper Object -> {C1AF5FA5-852C-4C90-812E-A7F75E011D87} -> C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll [2013-05-20] (Delta-search.com)

BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540026} -> C:\Program Files (x86)\GbPlugin\gbiehbdv.dll [2015-12-23] (Banco de Venezuela)

BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-12-11] (Oracle Corporation)

BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-18] (Kaspersky Lab ZAO)

Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)

Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll [2013-05-20] (Delta-search.com)

Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)

DPF: HKLM-x32 {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab

Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)

Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)

 

FireFox:

========

FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll [2012-12-11] (Oracle Corporation)

FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2012-12-11] (Oracle Corporation)

FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()

FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.2.6\\npsitesafety.dll [No File]

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)

FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-11] (Oracle Corporation)

FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-12-11] (Oracle Corporation)

FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)

FF Plugin-x32: @sony.com/ReaderDesktop -> C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll [2012-07-12] (Sony Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-05] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-05] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)

FF Plugin HKU\S-1-5-21-3844031730-595245587-2132850609-1001: gastecnologia.com.br/sf/bdv -> C:\Users\Mohamed\AppData\Local\GAS Tecnologia\GBBD\npsf_bdv.dll [2013-08-16] (GAS Tecnologia)

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]

FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]

FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]

FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]

FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]

FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]

FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]

 

Chrome:

=======

CHR HomePage: Profile 1 -> mysearch.avg.com/?rvt=1

CHR StartupUrls: Profile 1 -> "hxxp://www.yoursearching.com/?type=hp&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx"

CHR NewTab: Profile 1 -> "chrome-extension://chfdnecihphmhljaaejmgoiahnihplgn/pages/newtab.html"

CHR DefaultSearchURL: Profile 1 -> hxxp://yoursearching.com/web/?type=ds&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx&q;={searchTerms}

CHR DefaultSearchKeyword: Profile 1 -> yoursearching

CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Default

CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1

CHR Extension: (Google Docs) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]

CHR Extension: (Google Drive) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]

CHR Extension: (YouTube) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-30]

CHR Extension: (AVG Secure Search) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2015-12-22]

CHR Extension: (Google Search) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]

CHR Extension: (Kaspersky URL Advisor) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2015-01-17]

CHR Extension: (Delta Toolbar) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [2015-01-17]

CHR Extension: (Google Docs Offline) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]

CHR Extension: (Safe Money) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hakdifolhalapjijoafobooafbilfakh [2015-01-17]

CHR Extension: (Content Blocker) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2015-01-17]

CHR Extension: (Virtual Keyboard) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2015-01-17]

CHR Extension: (Skype) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-20]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-26]

CHR Extension: (GBBD Cl@veDefensa del Banco de Venezuela) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\odifdffdmeannfboglpliamjmoggdmci [2015-01-17]

CHR Extension: (Gmail) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]

CHR Extension: (Anti-Banner) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2015-01-17]

CHR HKU\S-1-5-21-3844031730-595245587-2132850609-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx

CHR HKU\S-1-5-21-3844031730-595245587-2132850609-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx

CHR HKU\S-1-5-21-3844031730-595245587-2132850609-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [odifdffdmeannfboglpliamjmoggdmci] - C:\Users\Mohamed\AppData\Local\GAS Tecnologia\GBBD\bdv\sf.crx [2013-10-27]

CHR HKLM-x32\…\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-01]

CHR HKLM-x32\…\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Mohamed\AppData\Roaming\BabSolution\CR\Delta.crx [2013-06-24]

CHR HKLM-x32\…\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-01]

CHR HKLM-x32\…\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-01]

CHR HKLM-x32\…\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-10-01]

CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]

CHR HKLM-x32\…\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-01]

 

==================== Services (Whitelisted) ========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)

S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [615584 2015-12-09] (AVG Technologies CZ, s.r.o.)

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagent.exe [3881696 2016-01-25] (AVG Technologies CZ, s.r.o.)

R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1048488 2016-01-12] (AVG Technologies CZ, s.r.o.)

R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe [561104 2016-01-25] (AVG Technologies CZ, s.r.o.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)

R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)

R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()

R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [102224 2012-08-17] (Condusiv Technologies)

R2 GbpSv; C:\Program Files (x86)\GbPlugin\GbpSv.exe [593120 2015-11-19] (GAS Tecnologia)

R2 Hydrup; C:\Program Files (x86)\Common Files\Hydrup\hydrup.exe [266536 2015-03-28] (Software)

R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)

R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)

R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)

R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751760 2015-10-26] (Lavasoft Limited)

S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [289256 2015-07-31] (McAfee, Inc.)

S3 NetworkSupport; C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe [625240 2013-09-28] (Sony Corporation)

R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [474208 2012-07-27] (Sony Corporation)

R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2266160 2016-02-01] (IBM Corp.)

S4 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [17168 2015-10-26] ()

S4 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2012-09-19] (Sony Corporation) [File not signed]

S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()

S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [964608 2012-09-28] (Sony Corporation) [File not signed]

R2 vToolbarUpdater40.2.6; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\ToolbarUpdater.exe [1949768 2016-02-25] (AVG Secure Search)

R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1653272 2015-07-31] (Sony Corporation)

S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)

S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1215560 2016-02-25] ()

S4 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-11-05] (Atheros) [File not signed]

 

===================== Drivers (Whitelisted) ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.)

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [184240 2015-11-06] (AVG Technologies CZ, s.r.o.)

R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2016-01-05] (AVG Technologies CZ, s.r.o.)

R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [272304 2016-01-08] (AVG Technologies CZ, s.r.o.)

R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [284080 2015-10-21] (AVG Technologies CZ, s.r.o.)

R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [398256 2015-08-14] (AVG Technologies CZ, s.r.o.)

R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [260528 2016-01-22] (AVG Technologies CZ, s.r.o.)

R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [42416 2015-12-04] (AVG Technologies CZ, s.r.o.)

R0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [23472 2016-01-08] (AVG Technologies CZ, s.r.o.)

R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [315840 2015-12-16] (AVG Technologies CZ, s.r.o.)

R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23376 2012-08-17] (Condusiv Technologies)

R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [103248 2012-08-17] (Condusiv Technologies)

R1 RapportCerberus_1507079; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507079.sys [961880 2015-12-02] (IBM Corp.)

R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [514336 2016-02-01] (IBM Corp.)

R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [152320 2016-02-01] (IBM Corp.)

R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [407168 2016-02-01] (IBM Corp.)

R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [507424 2016-02-01] (IBM Corp.)

R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )

R3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [29352 2015-11-17] ()

R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-05-27] (Synaptics Incorporated)

R3 SOWS; C:\Windows\System32\drivers\sows.sys [24280 2012-06-10] (Sony Corporation)

S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-01-14] (Anchorfree Inc.)

S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)

S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)

S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

S3 HTTP; system32\drivers\HTTP.sys [X]

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== Three Months Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-03-03 14:40 - 2016-03-03 14:41 - 00037701 _____ C:\Users\Mohamed\Desktop\FRST.txt

2016-03-03 14:38 - 2016-03-03 14:40 - 00000000 ____D C:\FRST

2016-03-03 14:34 - 2016-03-03 14:38 - 02371584 _____ (Farbar) C:\Users\Mohamed\Desktop\FRST64.exe

2016-03-03 14:34 - 2016-03-03 14:34 - 02371584 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST64.exe

2016-03-03 14:33 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Desktop\FRST.exe

2016-03-03 14:32 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST.exe

2016-03-03 14:32 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST (1).exe

2016-03-03 14:21 - 2016-03-03 14:21 - 00000000 ___HD C:\OneDriveTemp

2016-03-03 14:20 - 2016-03-03 14:20 - 00000000 ___SH C:\DkHyperbootSync

2016-03-03 13:31 - 2016-03-03 13:34 - 00840956 _____ C:\WINDOWS\Minidump\030316-304625-01.dmp

2016-02-29 10:27 - 2016-02-29 10:27 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday (2).xls

2016-02-29 10:26 - 2016-02-29 10:26 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday.xls

2016-02-29 10:26 - 2016-02-29 10:26 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday (1).xls

2016-02-29 10:13 - 2016-02-29 10:15 - 01592300 _____ C:\WINDOWS\Minidump\022916-295703-01.dmp

2016-02-23 11:39 - 2016-02-23 11:39 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

2016-02-23 10:29 - 2016-02-23 10:30 - 00849748 _____ C:\WINDOWS\Minidump\022316-302218-01.dmp

2016-02-07 21:18 - 2016-02-07 21:18 - 09846564 _____ C:\Users\Mohamed\Desktop\3.mp4

2016-02-07 21:10 - 2015-05-08 03:18 - 53059755 _____ C:\Users\Mohamed\Desktop\IMG_4839.MOV

2016-02-07 20:40 - 2016-02-07 20:40 - 10365693 _____ C:\Users\Mohamed\Desktop\Burj 2.mp4

2016-02-07 20:33 - 2016-02-07 20:34 - 08754364 _____ C:\Users\Mohamed\Desktop\Burj 1.mp4

2016-02-07 20:20 - 2016-02-07 20:21 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack

2016-02-07 20:20 - 2016-02-07 20:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack

2016-02-07 20:04 - 2016-02-07 20:19 - 38248161 _____ (KLCP ) C:\Users\Mohamed\Downloads\K-Lite_Codec_Pack_1185_Full.exe

2016-02-07 19:46 - 2016-02-07 19:46 - 00001447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk

2016-02-07 19:46 - 2016-02-07 19:46 - 00001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk

2016-02-07 19:46 - 2016-02-07 19:46 - 00000000 ____D C:\WINDOWS\en

2016-02-07 19:44 - 2016-02-07 19:45 - 00000000 ____D C:\Program Files (x86)\Windows Live

2016-02-07 19:44 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll

2016-02-07 19:44 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll

2016-02-07 19:44 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll

2016-02-07 19:44 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll

2016-02-07 19:44 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll

2016-02-07 19:44 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll

2016-02-07 19:44 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll

2016-02-07 19:44 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll

2016-02-07 19:44 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll

2016-02-07 19:44 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll

2016-02-07 19:44 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll

2016-02-07 19:44 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll

2016-02-07 19:42 - 2016-02-07 19:57 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Windows Live

2016-02-07 19:42 - 2016-02-07 19:42 - 01239752 _____ (Microsoft Corporation) C:\Users\Mohamed\Downloads\wlsetup-web.exe

2016-02-07 19:13 - 2016-02-07 19:13 - 00000000 ____D C:\Program Files (x86)\RayDld

2016-02-07 19:12 - 2016-02-07 19:13 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\yoursearching

2016-02-07 19:12 - 2016-02-07 19:12 - 00000351 _____ C:\prefs.js

2016-02-07 19:10 - 2016-02-07 19:10 - 04458496 _____ C:\Users\Mohamed\Downloads\Movavi_Video_Editor_10_Activation_Key_plus_Crack_Full_Free.iso

2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\VideoEditor

2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Movavi

2016-02-07 17:36 - 2016-02-07 17:36 - 00001189 _____ C:\Users\Public\Desktop\Movavi Video Editor 11.lnk

2016-02-07 17:36 - 2016-02-07 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 11

2016-02-07 17:36 - 2016-02-07 17:36 - 00000000 ____D C:\Program Files (x86)\Movavi Video Editor 11

2016-02-07 17:35 - 2016-02-07 17:35 - 00004881 _____ C:\ProgramData\rxsmznjf.zcp

2016-02-07 17:35 - 2016-02-07 17:35 - 00000016 _____ C:\ProgramData\mntemp

2016-02-07 17:35 - 2016-02-07 17:35 - 00000000 ____D C:\ProgramData\Movavi Video Editor 11

2016-02-07 17:31 - 2016-02-07 17:35 - 73093984 _____ (Movavi) C:\Users\Mohamed\Downloads\MovaviVideoEditorSetupC.exe

2016-02-07 17:24 - 2015-05-10 15:51 - 65098242 _____ C:\Users\Mohamed\Desktop\IMG_4971.MOV

2016-02-07 17:24 - 2015-05-10 15:50 - 130348697 _____ C:\Users\Mohamed\Desktop\IMG_4970.MOV

2016-02-07 17:11 - 2016-02-07 17:12 - 01394860 _____ C:\WINDOWS\Minidump\020716-304281-01.dmp

2016-02-05 22:13 - 2016-02-05 22:14 - 01339012 _____ C:\WINDOWS\Minidump\020516-296562-01.dmp

2016-02-02 23:41 - 2016-02-02 23:42 - 00000000 ____D C:\Users\Mohamed\Desktop\Transferencias en camino

2016-01-31 23:04 - 2016-01-31 23:04 - 00000246 _____ C:\Users\Mohamed\Desktop\note.txt

2016-01-31 14:43 - 2016-01-16 01:50 - 06971752 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll

2016-01-31 14:43 - 2016-01-16 01:50 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll

2016-01-31 14:43 - 2016-01-16 01:50 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll

2016-01-31 14:43 - 2016-01-16 01:49 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll

2016-01-31 14:43 - 2016-01-16 01:47 - 21125400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

2016-01-31 14:43 - 2016-01-16 01:46 - 05238360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll

2016-01-31 14:43 - 2016-01-16 01:38 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll

2016-01-31 14:43 - 2016-01-16 01:06 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll

2016-01-31 14:43 - 2016-01-16 01:05 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll

2016-01-31 14:43 - 2016-01-16 01:04 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll

2016-01-31 14:43 - 2016-01-16 01:03 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll

2016-01-31 14:43 - 2016-01-16 01:02 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe

2016-01-31 14:43 - 2016-01-16 01:01 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe

2016-01-31 14:43 - 2016-01-16 01:00 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll

2016-01-31 14:43 - 2016-01-16 01:00 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll

2016-01-31 14:43 - 2016-01-16 00:59 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll

2016-01-31 14:43 - 2016-01-16 00:58 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll

2016-01-31 14:43 - 2016-01-16 00:58 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll

2016-01-31 14:43 - 2016-01-16 00:57 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll

2016-01-31 14:43 - 2016-01-16 00:56 - 19338752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2016-01-31 14:43 - 2016-01-16 00:56 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll

2016-01-31 14:43 - 2016-01-16 00:55 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll

2016-01-31 14:43 - 2016-01-16 00:54 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll

2016-01-31 14:43 - 2016-01-16 00:54 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll

2016-01-31 14:43 - 2016-01-16 00:54 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll

2016-01-31 14:43 - 2016-01-16 00:53 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl

2016-01-31 14:43 - 2016-01-16 00:53 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll

2016-01-31 14:43 - 2016-01-16 00:51 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll

2016-01-31 14:43 - 2016-01-16 00:50 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll

2016-01-31 14:43 - 2016-01-16 00:50 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll

2016-01-31 14:43 - 2016-01-16 00:49 - 12126208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2016-01-31 14:43 - 2016-01-16 00:49 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll

2016-01-31 14:43 - 2016-01-16 00:49 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll

2016-01-31 14:43 - 2016-01-16 00:49 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll

2016-01-31 14:43 - 2016-01-16 00:46 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll

2016-01-31 14:43 - 2016-01-16 00:41 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll

2016-01-31 14:42 - 2016-01-16 01:50 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll

2016-01-31 14:42 - 2016-01-16 01:49 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll

2016-01-31 14:42 - 2016-01-16 01:05 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

2016-01-31 14:42 - 2016-01-16 00:54 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll

2016-01-31 14:42 - 2016-01-16 00:46 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll

2016-01-31 14:42 - 2016-01-16 00:45 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll

2016-01-31 14:42 - 2016-01-16 00:44 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll

2016-01-31 14:37 - 2016-01-16 01:54 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll

2016-01-31 14:37 - 2016-01-16 01:53 - 08728920 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll

2016-01-31 14:37 - 2016-01-16 01:16 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys

2016-01-31 14:37 - 2016-01-16 01:14 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe

2016-01-31 14:37 - 2016-01-16 01:13 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll

2016-01-31 14:37 - 2016-01-16 01:11 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe

2016-01-31 14:37 - 2016-01-16 01:08 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll

2016-01-31 14:37 - 2016-01-16 01:03 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll

2016-01-31 14:37 - 2016-01-16 01:02 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll

2016-01-31 14:37 - 2016-01-16 01:01 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll

2016-01-31 14:37 - 2016-01-16 00:58 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll

2016-01-31 14:37 - 2016-01-16 00:54 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll

2016-01-31 14:37 - 2016-01-16 00:48 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys

2016-01-31 14:36 - 2016-01-16 02:07 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll

2016-01-31 14:36 - 2016-01-16 01:51 - 22572624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll

2016-01-31 14:36 - 2016-01-16 01:51 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe

2016-01-31 14:36 - 2016-01-16 01:42 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll

2016-01-31 14:36 - 2016-01-16 01:38 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe

2016-01-31 14:36 - 2016-01-16 01:14 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll

2016-01-31 14:36 - 2016-01-16 01:14 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll

2016-01-31 14:36 - 2016-01-16 01:12 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll

2016-01-31 14:36 - 2016-01-16 01:10 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll

2016-01-31 14:36 - 2016-01-16 01:10 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll

2016-01-31 14:36 - 2016-01-16 01:10 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe

2016-01-31 14:36 - 2016-01-16 01:09 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll

2016-01-31 14:36 - 2016-01-16 01:08 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll

2016-01-31 14:36 - 2016-01-16 01:08 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll

2016-01-31 14:36 - 2016-01-16 01:07 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll

2016-01-31 14:36 - 2016-01-16 01:07 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll

2016-01-31 14:36 - 2016-01-16 01:06 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll

2016-01-31 14:36 - 2016-01-16 01:06 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll

2016-01-31 14:36 - 2016-01-16 01:04 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll

2016-01-31 14:36 - 2016-01-16 01:04 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll

2016-01-31 14:36 - 2016-01-16 01:03 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll

2016-01-31 14:36 - 2016-01-16 01:01 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll

2016-01-31 14:36 - 2016-01-16 00:59 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe

2016-01-31 14:36 - 2016-01-16 00:58 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll

2016-01-31 14:36 - 2016-01-16 00:56 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll

2016-01-31 14:36 - 2016-01-16 00:55 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll

2016-01-31 14:36 - 2016-01-16 00:55 - 00235008 _____ C:\WINDOWS\system32\MTF.dll

2016-01-31 14:36 - 2016-01-16 00:50 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll

2016-01-31 14:36 - 2016-01-16 00:49 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll

2016-01-31 14:36 - 2016-01-16 00:39 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll

2016-01-31 14:35 - 2016-01-16 01:53 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll

2016-01-31 14:35 - 2016-01-16 01:50 - 06600904 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll

2016-01-31 14:35 - 2016-01-16 01:43 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys

2016-01-31 14:35 - 2016-01-16 01:43 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys

2016-01-31 14:35 - 2016-01-16 01:14 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll

2016-01-31 14:35 - 2016-01-16 01:12 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll

2016-01-31 14:35 - 2016-01-16 01:08 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll

2016-01-31 14:35 - 2016-01-16 01:07 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll

2016-01-31 14:35 - 2016-01-16 01:06 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe

2016-01-31 14:35 - 2016-01-16 01:05 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll

2016-01-31 14:35 - 2016-01-16 01:01 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll

2016-01-31 14:35 - 2016-01-16 01:00 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2016-01-31 14:35 - 2016-01-16 01:00 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll

2016-01-31 14:35 - 2016-01-16 00:58 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll

2016-01-31 14:35 - 2016-01-16 00:56 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll

2016-01-31 14:35 - 2016-01-16 00:56 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll

2016-01-31 14:35 - 2016-01-16 00:50 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll

2016-01-31 14:34 - 2016-01-16 01:02 - 24602624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2016-01-31 14:33 - 2016-01-16 01:00 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl

2016-01-31 14:30 - 2016-01-16 01:53 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll

2016-01-31 14:30 - 2016-01-16 01:15 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll

2016-01-31 14:30 - 2016-01-16 01:07 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll

2016-01-31 14:30 - 2016-01-16 01:06 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll

2016-01-31 14:30 - 2016-01-16 01:04 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll

2016-01-31 14:30 - 2016-01-16 01:01 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll

2016-01-31 14:30 - 2016-01-16 00:48 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll

2016-01-31 14:30 - 2016-01-16 00:47 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll

2016-01-31 14:30 - 2016-01-16 00:44 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll

2016-01-31 14:29 - 2016-01-16 02:06 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll

2016-01-31 14:29 - 2016-01-16 02:06 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll

2016-01-31 14:29 - 2016-01-16 02:04 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll

2016-01-31 14:29 - 2016-01-16 01:53 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll

2016-01-31 14:29 - 2016-01-16 01:53 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll

2016-01-31 14:29 - 2016-01-16 01:53 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe

2016-01-31 14:29 - 2016-01-16 01:04 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll

2016-01-31 14:29 - 2016-01-16 01:00 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll

2016-01-31 14:28 - 2016-01-16 01:10 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe

2016-01-31 13:39 - 2016-01-31 13:39 - 00003050 _____ C:\WINDOWS\System32\Tasks\0116avUpdateInfo

2016-01-31 13:39 - 2016-01-31 13:39 - 00000000 ____D C:\ProgramData\Avg_Update_0116av

2016-01-31 13:31 - 2016-01-31 13:31 - 00003078 _____ C:\WINDOWS\System32\Tasks\0116tbUpdateInfo

2016-01-31 13:31 - 2016-01-31 13:31 - 00000000 ____D C:\ProgramData\Avg_Update_0116tb

2016-01-31 13:30 - 2016-01-31 13:32 - 01607972 _____ C:\WINDOWS\Minidump\013116-298312-01.dmp

2016-01-22 15:15 - 2016-01-22 15:15 - 00260528 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx64.sys

2016-01-18 16:03 - 2016-01-18 16:05 - 01256884 _____ C:\WINDOWS\Minidump\011816-297265-01.dmp

2016-01-18 09:46 - 2016-01-18 09:46 - 01310972 _____ C:\WINDOWS\Minidump\011816-290046-01.dmp

2016-01-17 15:32 - 2016-01-17 15:35 - 01483188 _____ C:\WINDOWS\Minidump\011716-326625-01.dmp

2016-01-15 15:21 - 2016-01-15 15:21 - 00097525 _____ C:\Users\Mohamed\Downloads\Comprobante_de_Transaccion (104).pdf

2016-01-15 15:20 - 2016-01-15 15:20 - 00097527 _____ C:\Users\Mohamed\Downloads\Comprobante_de_Transaccion (103).pdf

2016-01-12 15:08 - 2016-01-04 22:21 - 07477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe

2016-01-12 15:08 - 2016-01-04 22:20 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll

2016-01-12 15:08 - 2016-01-04 22:15 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll

2016-01-12 15:08 - 2016-01-04 22:12 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll

2016-01-12 15:08 - 2016-01-04 22:07 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll

2016-01-12 15:08 - 2016-01-04 22:07 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll

2016-01-12 15:08 - 2016-01-04 22:07 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll

2016-01-12 15:08 - 2016-01-04 22:06 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe

2016-01-12 15:08 - 2016-01-04 22:03 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll

2016-01-12 15:08 - 2016-01-04 22:03 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll

2016-01-12 15:08 - 2016-01-04 22:03 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll

2016-01-12 15:08 - 2016-01-04 22:01 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe

2016-01-12 15:08 - 2016-01-04 21:57 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll

2016-01-12 15:08 - 2016-01-04 21:54 - 00796352 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll

2016-01-12 15:08 - 2016-01-04 21:53 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll

2016-01-12 15:08 - 2016-01-04 21:53 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL

2016-01-12 15:08 - 2016-01-04 21:51 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll

2016-01-12 15:08 - 2016-01-04 21:47 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL

2016-01-12 15:08 - 2016-01-04 21:24 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe

2016-01-12 15:08 - 2016-01-04 21:18 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL

2016-01-12 15:08 - 2016-01-04 21:15 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll

2016-01-12 15:08 - 2016-01-04 21:13 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll

2016-01-12 15:08 - 2016-01-04 21:10 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL

2016-01-12 15:08 - 2016-01-04 21:09 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll

2016-01-12 15:08 - 2016-01-04 21:08 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll

2016-01-12 15:08 - 2016-01-04 21:00 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll

2016-01-12 15:08 - 2016-01-04 21:00 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll

2016-01-12 15:08 - 2016-01-04 20:59 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2016-01-12 15:08 - 2016-01-04 20:58 - 07826432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll

2016-01-12 15:08 - 2016-01-04 20:58 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2016-01-12 15:08 - 2016-01-04 20:55 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll

2016-01-12 15:08 - 2015-12-07 00:27 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll

2016-01-12 15:08 - 2015-12-07 00:25 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 01155944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 01065080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 01020096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00983464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00884256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00823264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00450904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll

2016-01-12 15:08 - 2015-12-07 00:18 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll

2016-01-12 15:08 - 2015-12-07 00:17 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll

2016-01-12 15:08 - 2015-12-07 00:17 - 00898184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:17 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll

2016-01-12 15:08 - 2015-12-07 00:16 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

2016-01-12 15:08 - 2015-12-07 00:16 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2016-01-12 15:08 - 2015-12-07 00:15 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll

2016-01-12 15:08 - 2015-12-06 23:45 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll

2016-01-12 15:08 - 2015-12-06 23:40 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll

2016-01-12 15:08 - 2015-12-06 23:36 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll

2016-01-12 15:08 - 2015-12-06 23:36 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe

2016-01-12 15:08 - 2015-12-06 23:32 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe

2016-01-12 15:08 - 2015-12-06 23:30 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll

2016-01-12 15:08 - 2015-12-06 23:30 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll

2016-01-12 15:08 - 2015-12-06 23:29 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll

2016-01-12 15:08 - 2015-12-06 23:29 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll

2016-01-12 15:08 - 2015-12-06 23:27 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll

2016-01-12 15:08 - 2015-12-06 23:26 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll

2016-01-12 15:08 - 2015-12-06 23:26 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll

2016-01-12 15:08 - 2015-12-06 23:23 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll

2016-01-12 15:08 - 2015-12-06 23:20 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll

2016-01-12 15:08 - 2015-12-06 23:19 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll

2016-01-12 15:08 - 2015-12-06 23:15 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll

2016-01-12 15:08 - 2015-12-06 23:15 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll

2016-01-12 15:08 - 2015-12-06 23:15 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll

2016-01-12 15:08 - 2015-12-06 23:13 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL

2016-01-12 15:08 - 2015-12-06 23:11 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll

2016-01-12 15:08 - 2015-12-06 23:10 - 01995776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll

2016-01-12 15:08 - 2015-12-06 23:10 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll

2016-01-12 15:08 - 2015-12-06 23:03 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe

2016-01-12 15:08 - 2015-12-06 23:02 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll

2016-01-12 15:07 - 2016-01-04 22:21 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi

2016-01-12 15:07 - 2016-01-04 22:21 - 01141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe

2016-01-12 15:07 - 2016-01-04 22:18 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll

2016-01-12 15:07 - 2016-01-04 22:07 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll

2016-01-12 15:07 - 2016-01-04 22:07 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll

2016-01-12 15:07 - 2016-01-04 22:03 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll

2016-01-12 15:07 - 2016-01-04 22:03 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll

2016-01-12 15:07 - 2016-01-04 21:53 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll

2016-01-12 15:07 - 2016-01-04 21:53 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL

2016-01-12 15:07 - 2016-01-04 21:46 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL

2016-01-12 15:07 - 2016-01-04 21:27 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll

2016-01-12 15:07 - 2016-01-04 21:27 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll

2016-01-12 15:07 - 2016-01-04 21:26 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe

2016-01-12 15:07 - 2016-01-04 21:24 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys

2016-01-12 15:07 - 2016-01-04 21:23 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx

2016-01-12 15:07 - 2016-01-04 21:22 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll

2016-01-12 15:07 - 2016-01-04 21:21 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll

2016-01-12 15:07 - 2016-01-04 21:21 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll

2016-01-12 15:07 - 2016-01-04 21:20 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll

2016-01-12 15:07 - 2016-01-04 21:20 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll

2016-01-12 15:07 - 2016-01-04 21:19 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe

2016-01-12 15:07 - 2016-01-04 21:19 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL

2016-01-12 15:07 - 2016-01-04 21:19 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll

2016-01-12 15:07 - 2016-01-04 21:19 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll

2016-01-12 15:07 - 2016-01-04 21:19 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll

2016-01-12 15:07 - 2016-01-04 21:18 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll

2016-01-12 15:07 - 2016-01-04 21:18 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll

2016-01-12 15:07 - 2016-01-04 21:17 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll

2016-01-12 15:07 - 2016-01-04 21:17 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll

2016-01-12 15:07 - 2016-01-04 21:17 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax

2016-01-12 15:07 - 2016-01-04 21:15 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll

2016-01-12 15:07 - 2016-01-04 21:14 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx

2016-01-12 15:07 - 2016-01-04 21:13 - 00953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys

2016-01-12 15:07 - 2016-01-04 21:13 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll

2016-01-12 15:07 - 2016-01-04 21:13 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe

2016-01-12 15:07 - 2016-01-04 21:12 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll

2016-01-12 15:07 - 2016-01-04 21:11 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL

2016-01-12 15:07 - 2016-01-04 21:11 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll

2016-01-12 15:07 - 2016-01-04 21:10 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll

2016-01-12 15:07 - 2016-01-04 21:09 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll

2016-01-12 15:07 - 2016-01-04 21:09 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll

2016-01-12 15:07 - 2016-01-04 21:09 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax

2016-01-12 15:07 - 2016-01-04 21:06 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll

2016-01-12 15:07 - 2016-01-04 21:06 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

2016-01-12 15:07 - 2015-12-07 00:19 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe

2016-01-12 15:07 - 2015-12-07 00:18 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll

2016-01-12 15:07 - 2015-12-07 00:18 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll

2016-01-12 15:07 - 2015-12-06 23:45 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll

2016-01-12 15:07 - 2015-12-06 23:39 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll

2016-01-12 15:07 - 2015-12-06 23:39 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll

2016-01-12 15:07 - 2015-12-06 23:39 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll

2016-01-12 15:07 - 2015-12-06 23:37 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll

2016-01-12 15:07 - 2015-12-06 23:37 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll

2016-01-12 15:07 - 2015-12-06 23:36 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll

2016-01-12 15:07 - 2015-12-06 23:35 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll

2016-01-12 15:07 - 2015-12-06 23:35 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe

2016-01-12 15:07 - 2015-12-06 23:34 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll

2016-01-12 15:07 - 2015-12-06 23:34 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe

2016-01-12 15:07 - 2015-12-06 23:32 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll

2016-01-12 15:07 - 2015-12-06 23:31 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll

2016-01-12 15:07 - 2015-12-06 23:31 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe

2016-01-12 15:07 - 2015-12-06 23:30 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll

2016-01-12 15:07 - 2015-12-06 23:29 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll

2016-01-12 15:07 - 2015-12-06 23:29 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll

2016-01-12 15:07 - 2015-12-06 23:28 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll

2016-01-12 15:07 - 2015-12-06 23:27 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll

2016-01-12 15:07 - 2015-12-06 23:25 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll

2016-01-12 15:07 - 2015-12-06 23:21 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll

2016-01-12 15:07 - 2015-12-06 23:09 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll

2016-01-12 15:07 - 2015-12-06 23:08 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL

2016-01-12 13:53 - 2016-01-12 13:53 - 01238956 _____ C:\WINDOWS\Minidump\011216-290140-01.dmp

2016-01-11 23:06 - 2016-01-11 23:06 - 01365244 _____ C:\WINDOWS\Minidump\011116-288437-01.dmp

2016-01-10 08:03 - 2016-01-10 08:04 - 01285428 _____ C:\WINDOWS\Minidump\011016-286828-01.dmp

2016-01-09 11:51 - 2016-01-09 11:51 - 01328660 _____ C:\WINDOWS\Minidump\010916-289656-01.dmp

2016-01-08 22:38 - 2016-01-08 22:38 - 01301340 _____ C:\WINDOWS\Minidump\010816-288921-01.dmp

2016-01-08 12:05 - 2016-01-08 12:07 - 01281940 _____ C:\WINDOWS\Minidump\010816-282250-01.dmp

2016-01-08 10:46 - 2016-01-08 10:46 - 00023472 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avguniva.sys

2016-01-07 21:39 - 2016-01-07 21:40 - 01293340 _____ C:\WINDOWS\Minidump\010716-282906-01.dmp

2016-01-07 15:03 - 2016-01-07 15:03 - 00021632 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgboota.sys

2016-01-07 12:41 - 2016-01-07 12:42 - 01782964 _____ C:\WINDOWS\Minidump\010716-291968-01.dmp

2016-01-06 12:59 - 2016-01-06 13:00 - 01274436 _____ C:\WINDOWS\Minidump\010616-294109-01.dmp

2016-01-06 08:46 - 2016-01-06 08:46 - 01249060 _____ C:\WINDOWS\Minidump\010616-291890-01.dmp

2016-01-05 13:10 - 2016-01-05 13:10 - 00983604 _____ C:\WINDOWS\Minidump\010516-294156-01.dmp

2016-01-03 12:19 - 2016-01-03 12:19 - 01285916 _____ C:\WINDOWS\Minidump\010316-282625-01.dmp

2016-01-02 11:49 - 2016-01-02 11:50 - 01415044 _____ C:\WINDOWS\Minidump\010216-286734-01.dmp

2016-01-01 23:30 - 2016-01-01 23:30 - 00027937 _____ C:\Users\Mohamed\Downloads\download (54).htm

2015-12-30 11:33 - 2015-12-30 12:05 - 00000000 ____D C:\Users\Mohamed\Desktop\Mientras 2 - Copy - Copy

2015-12-30 11:24 - 2015-12-30 11:24 - 00000000 ____D C:\Users\Mohamed\Desktop\Mientras 2 - Copy

2015-12-29 23:20 - 2015-12-29 23:20 - 00001875 _____ C:\Users\Mohamed\Desktop\Edge.lnk

2015-12-28 22:00 - 2015-12-30 11:32 - 00000000 ____D C:\Users\Mohamed\Desktop\Mientras 2

2015-12-24 18:28 - 2015-12-24 18:28 - 00153721 _____ C:\Users\Mohamed\Desktop\pila.jpg

2015-12-23 04:30 - 2015-12-23 04:30 - 00119544 _____ C:\Users\Mohamed\Desktop\Gestiona tus reservas - Booking.pdf

2015-12-23 04:27 - 2015-12-23 04:27 - 00198457 _____ C:\Users\Mohamed\Desktop\hotel.pdf

2015-12-22 15:21 - 2015-12-22 15:21 - 00096989 _____ C:\Users\Mohamed\Downloads\EmiratesETicket1.PDF

2015-12-21 11:21 - 2015-12-21 11:21 - 00260003 _____ C:\Users\Mohamed\Desktop\Outlook.pdf

2015-12-20 14:07 - 2015-12-20 14:07 - 00000000 ____D C:\Users\Mohamed\AppData\LocalLow\Temp

2015-12-20 13:00 - 2015-12-20 13:58 - 00013758 _____ C:\Users\Mohamed\Desktop\Autorización.docx

2015-12-19 03:24 - 2015-12-19 03:24 - 01372108 _____ C:\WINDOWS\Minidump\121915-292890-01.dmp

2015-12-16 04:44 - 2015-12-16 04:58 - 00000000 ____D C:\Users\Mohamed\Downloads\Breaking Bad Season 5

2015-12-16 04:44 - 2015-12-16 04:44 - 00022925 _____ C:\Users\Mohamed\Downloads\[torrentmonkey.com].breaking.bad.season.5.1080p.x265.torrent

2015-12-16 04:42 - 2015-12-16 04:42 - 00613731 _____ C:\Users\Mohamed\Downloads\Breaking Bad Season 5 Complete Downloader.rar

2015-12-16 04:41 - 2015-12-16 04:41 - 02724882 _____ C:\Users\Mohamed\Downloads\Breaking+Bad+Season+5+Com.zip

2015-12-16 04:34 - 2015-12-16 04:34 - 00021746 _____ C:\Users\Mohamed\Downloads\breaking bad season 5 kybik v kybe.torrent

2015-12-16 04:30 - 2015-12-16 04:36 - 00000000 ____D C:\Users\Mohamed\Downloads\Breaking Bad Season 4

2015-12-16 04:29 - 2015-12-16 04:29 - 00031351 _____ C:\Users\Mohamed\Downloads\Breaking.Bad.Season.4.torrent

2015-12-16 01:14 - 2015-12-16 01:14 - 00315840 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgwfpa.sys

2015-12-15 04:23 - 2015-12-12 10:39 - 846000994 _____ C:\Users\Mohamed\Desktop\Dope.2015.720p.BluRay.x264.YIFY.mp4

2015-12-14 08:10 - 2015-12-14 08:10 - 00099952 _____ C:\Users\Mohamed\Downloads\Comprobante_de_Transaccion (102).pdf

2015-12-14 06:36 - 2015-12-14 06:36 - 00000000 ___RD C:\Users\Mohamed\3D Objects

2015-12-14 05:19 - 2015-12-14 05:19 - 00100015 _____ C:\Users\Mohamed\Downloads\Comprobante_de_Transaccion (101).pdf

2015-12-12 05:23 - 2015-12-12 05:24 - 01375692 _____ C:\WINDOWS\Minidump\121215-293421-01.dmp

2015-12-09 21:11 - 2015-12-09 21:12 - 01396180 _____ C:\WINDOWS\Minidump\121015-309546-01.dmp

2015-12-09 07:27 - 2015-12-09 07:27 - 00000000 ____D C:\WINDOWS\PCHEALTH

2015-12-09 05:36 - 2015-11-24 05:24 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll

2015-12-09 05:36 - 2015-11-24 05:23 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys

2015-12-09 05:36 - 2015-11-24 04:25 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys

2015-12-09 05:35 - 2015-12-01 02:42 - 02152800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys

2015-12-09 05:35 - 2015-11-24 07:37 - 01817160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll

2015-12-09 05:35 - 2015-11-24 06:36 - 01540768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll

2015-12-09 05:35 - 2015-11-24 05:56 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll

2015-12-09 05:35 - 2015-11-24 05:31 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb

2015-12-09 05:35 - 2015-11-24 05:15 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll

2015-12-09 05:35 - 2015-11-24 05:07 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys

2015-12-09 05:35 - 2015-11-24 04:56 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll

2015-12-09 05:35 - 2015-11-24 04:49 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll

2015-12-09 05:35 - 2015-11-24 04:42 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll

2015-12-09 05:35 - 2015-11-24 04:24 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb

2015-12-09 05:35 - 2015-11-24 04:22 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll

2015-12-09 05:35 - 2015-11-24 04:19 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll

2015-12-09 05:35 - 2015-11-24 03:44 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll

2015-12-09 05:35 - 2015-11-24 03:29 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll

2015-12-09 05:35 - 2015-11-24 03:27 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll

2015-12-09 05:35 - 2015-11-24 02:59 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll

2015-12-09 05:35 - 2015-11-24 02:34 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll

2015-12-08 03:57 - 2015-12-08 03:57 - 01070232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCTL.OCX

2015-12-05 08:05 - 2015-12-05 08:06 - 01343028 _____ C:\WINDOWS\Minidump\120515-282109-01.dmp

2015-12-04 05:31 - 2015-12-04 05:31 - 01094359 _____ C:\Users\Mohamed\Downloads\ns-24 التقرير اليومي.xlsx

2015-12-04 05:31 - 2015-12-04 05:31 - 00033280 _____ C:\Users\Mohamed\Downloads\22-problem.doc

2015-12-04 05:31 - 2015-12-04 05:31 - 00011767 _____ C:\Users\Mohamed\Downloads\9-Mud Materials Consumption.xlsx

2015-12-04 05:30 - 2015-12-04 05:30 - 03170324 _____ C:\Users\Mohamed\Downloads\_____ __ ______ ____ ______-21.xlsx

2015-12-04 05:30 - 2015-12-04 05:30 - 00741293 _____ C:\Users\Mohamed\Downloads\_______ ______ ____ ______ 23 (1).xlsx

2015-12-04 04:13 - 2015-12-04 04:13 - 00741293 _____ C:\Users\Mohamed\Downloads\_______ ______ ____ ______ 23.xlsx

2015-12-04 03:54 - 2015-12-04 03:54 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search

 

==================== Three Months Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-03-03 14:34 - 2015-06-22 15:14 - 00000936 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA.job

2016-03-03 14:30 - 2015-10-30 02:54 - 00000000 ___HD C:\Program Files\WindowsApps

2016-03-03 14:30 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\AppReadiness

2016-03-03 14:21 - 2015-11-18 12:02 - 00000000 ___RD C:\Users\Mohamed\OneDrive

2016-03-03 14:20 - 2014-11-15 08:55 - 00004002 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{AECFECB3-D89E-470B-B66F-3EF265E05FF0}

2016-03-03 14:17 - 2013-09-22 21:12 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2016-03-03 13:39 - 2015-11-18 10:38 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI

2016-03-03 13:39 - 2015-10-30 02:51 - 00000000 ____D C:\WINDOWS\INF

2016-03-03 13:35 - 2015-06-03 11:59 - 00000000 ____D C:\ProgramData\MFAData

2016-03-03 13:35 - 2013-09-22 21:12 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2016-03-03 13:34 - 2014-11-09 11:50 - 00000000 __SHD C:\Users\Mohamed\IntelGraphicsProfiles

2016-03-03 13:31 - 2015-11-19 04:32 - 00000000 ____D C:\WINDOWS\Minidump

2016-03-03 13:31 - 2015-11-18 10:43 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT

2016-03-03 13:31 - 2014-06-22 12:41 - 749243620 _____ C:\WINDOWS\MEMORY.DMP

2016-02-29 19:34 - 2015-06-22 15:14 - 00000884 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core.job

2016-02-29 10:46 - 2013-06-24 12:58 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl

2016-02-26 10:40 - 2015-11-06 09:41 - 00005424 _____ C:\WINDOWS\System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl

2016-02-26 10:25 - 2014-10-11 12:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection

2016-02-26 10:23 - 2015-11-18 12:02 - 00002403 _____ C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk

2016-02-26 10:18 - 2015-11-18 10:12 - 00000000 ____D C:\Users\Mohamed

2016-02-25 20:28 - 2015-06-03 13:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp

2016-02-25 20:27 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp

2016-02-25 20:27 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp

2016-02-25 20:19 - 2015-01-17 12:41 - 00000000 ____D C:\Users\Mohamed\Desktop\Cuenta

2016-02-23 14:35 - 2015-10-30 01:58 - 00008192 ___SH C:\WINDOWS\system32\config\ELAM

2016-02-23 11:39 - 2014-05-14 13:07 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Dropbox

2016-02-23 11:22 - 2013-09-22 21:17 - 00002586 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2016-02-11 20:31 - 2015-10-26 06:37 - 00285956 ____N C:\WINDOWS\Minidump\021116-314203-01.dmp

2016-02-07 21:04 - 2015-10-26 09:29 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\vlc

2016-02-07 19:45 - 2015-10-30 02:54 - 00000000 ____D C:\Program Files\Common Files\microsoft shared

2016-02-07 19:45 - 2013-04-28 00:00 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition

2016-02-07 19:12 - 2015-10-19 04:32 - 00002646 _____ C:\Users\Mohamed\Desktop\Google Chrome.lnk

2016-02-07 19:11 - 2015-10-19 04:32 - 00001247 _____ C:\Users\Mohamed\Desktop\Internet Explorer.lnk

2016-02-05 23:12 - 2013-09-22 21:12 - 00003974 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA

2016-02-05 23:12 - 2013-09-22 21:12 - 00003742 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

2016-02-05 22:51 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\system32\NDF

2016-02-05 22:48 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\rescache

2016-02-02 23:32 - 2015-10-30 02:41 - 00000000 ____D C:\WINDOWS\CbsTemp

2016-02-02 23:20 - 2013-03-19 21:02 - 00000000 __RHD C:\Users\Public\AccountPictures

 

==================== Files in the root of some directories =======

 

2013-10-27 20:34 - 2013-10-27 20:34 - 0011706 _____ () C:\Users\Mohamed\AppData\Roaming\unins000.dat

2013-10-27 20:34 - 2013-10-27 20:34 - 0720465 _____ () C:\Users\Mohamed\AppData\Roaming\unins000.exe

2015-06-03 11:54 - 2015-06-03 11:54 - 0045159 _____ () C:\ProgramData\1433348586.bdinstall.bin

2015-06-03 11:54 - 2015-06-03 11:54 - 0034475 _____ () C:\ProgramData\1433348671.bdinstall.bin

2015-07-23 04:37 - 2015-07-23 04:37 - 0048027 _____ () C:\ProgramData\1437642367.bdinstall.bin

2013-08-25 23:44 - 2013-08-25 23:44 - 0000057 _____ () C:\ProgramData\Ament.ini

2016-02-07 17:35 - 2016-02-07 17:35 - 0000016 _____ () C:\ProgramData\mntemp

2016-02-07 17:35 - 2016-02-07 17:35 - 0004881 _____ () C:\ProgramData\rxsmznjf.zcp

 

Some files in TEMP:

====================

C:\Users\Mohamed\AppData\Local\Temp\avguirn_08448574923.exe

 

 

==================== Bamital & volsnap =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\WINDOWS\system32\winlogon.exe => File is digitally signed

C:\WINDOWS\system32\wininit.exe => File is digitally signed

C:\WINDOWS\explorer.exe => File is digitally signed

C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed

C:\WINDOWS\system32\svchost.exe => File is digitally signed

C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed

C:\WINDOWS\system32\services.exe => File is digitally signed

C:\WINDOWS\system32\User32.dll => File is digitally signed

C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed

C:\WINDOWS\system32\userinit.exe => File is digitally signed

C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed

C:\WINDOWS\system32\rpcss.dll => File is digitally signed

C:\WINDOWS\system32\dnsapi.dll => File is digitally signed

C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed

C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2016-02-26 10:37

 

==================== End of FRST.txt ============================

 

And here it is the Addition.txt log:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:02-03-2016

Ran by [removed] (2016-03-03 14:42:01)

Running from C:\Users\[removed]\Desktop

Windows 10 Home Version 1511 (X64) (2015-11-18 16:25:13)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-3844031730-595245587-2132850609-500 - Administrator - Disabled)

DefaultAccount (S-1-5-21-3844031730-595245587-2132850609-503 - Limited - Disabled)

Guest (S-1-5-21-3844031730-595245587-2132850609-501 - Limited - Disabled)

HomeGroupUser$ (S-1-5-21-3844031730-595245587-2132850609-1005 - Limited - Enabled)

Mohamed (S-1-5-21-3844031730-595245587-2132850609-1001 - Administrator - Enabled) => C:\Users\Mohamed

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

µTorrent (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)

Adobe Reader XI (11.0.13)  MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)

Akamai NetSession Interface (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Akamai) (Version:  - Akamai Technologies, Inc)

Apple Application Support (32-bit) (HKLM-x32\…\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\…\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.)

Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)

Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)

AVG (Version: 16.12.7303 - AVG Technologies) Hidden

AVG (Version: 16.41.7441 - AVG Technologies) Hidden

AVG 2015 (Version: 15.0.4447 - AVG Technologies) Hidden

AVG 2015 (Version: 15.0.6140 - AVG Technologies) Hidden

AVG 2016 (Version: 16.0.4537 - AVG Technologies) Hidden

AVG Protection (HKLM\…\AVG) (Version: 2016.41.7441 - AVG Technologies)

AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.2.6.552 - AVG Technologies)

Bing Bar (HKLM-x32\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)

Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)

Bootstrapper (x32 Version: 1.0.0.0 - Minitab, Inc.) Hidden

Cl@veDefensa del Banco de Venezuela (HKLM-x32\…\{A0753E93-0933-4adc-B357-D60699B143B2}_is1) (Version: 3.2.0.2 - )

Cl@veDefensa del Banco de Venezuela (HKLM-x32\…\Cl@veDefensa del Banco de Venezuela_is1) (Version:  - )

D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

Delta Chrome Toolbar (HKLM-x32\…\Delta Chrome Toolbar) (Version:  - Visual Tools) <==== ATTENTION

Delta toolbar   (HKLM-x32\…\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION

Dropbox (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Dropbox) (Version: 3.14.7 - Dropbox, Inc.)

Eines de correcció del Microsoft Office 2013: català (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden

eMule (HKLM-x32\…\eMule) (Version:  - )

ExpressCache (HKLM\…\{3EA6AB5D-D434-4ACA-9609-48F1319518EF}) (Version: 1.0.94 - Condusiv Technologies)

FDUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

Ferramentas de verificación de Microsoft Office 2013 - Galego (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden

FMW 1 (Version: 1.52.1 - AVG Technologies) Hidden

Garmin MapSource (HKLM-x32\…\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)

Garmin Training Center (HKLM-x32\…\{7D542452-84EB-47C0-97BA-735C523AB555}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)

Garmin USB Drivers (HKLM-x32\…\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries)

Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)

Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden

Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden

HP Deskjet 3050 J610 series Basic Device Software (HKLM\…\{6457BD83-98CF-4267-93D7-F173FF3E7C25}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)

HP Deskjet 3050 J610 series Help (HKLM-x32\…\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)

HP Deskjet 3050 J610 series Product Improvement Study (HKLM\…\{5FB5B723-6B6E-45ED-BA73-F264D52AF916}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)

HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)

HP Update (HKLM-x32\…\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)

Iminent (HKLM-x32\…\IMBoosterARP) (Version: 6.25.21.0 - Iminent) <==== ATTENTION

Iminent (x32 Version: 6.25.21.0 - Iminent) Hidden <==== ATTENTION

Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)

Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation)

Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)

Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)

iTunes (HKLM\…\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.)

Java 7 Update 9 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417009FF}) (Version: 7.0.90 - Oracle)

Java 7 Update 9 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)

Kaspersky Internet Security 2013 (HKLM-x32\…\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)

Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden

K-Lite Codec Pack 11.8.5 Full (HKLM-x32\…\KLiteCodecPack_is1) (Version: 11.8.5 - KLCP)

KUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.11.163.2 - McAfee, Inc.)

Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)

Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

Microsoft Visio Professional 2013 (HKLM-x32\…\Office15.VISPROR) (Version: 15.0.4569.1506 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)

Minitab 16 (HKLM-x32\…\Minitab16) (Version: 16.1.0 - Minitab, Inc.)

Minitab Software Update Manager (HKLM-x32\…\MinitabSoftwareManager) (Version: 1.0.0.0 - Minitab, Inc.)

Minitab16 (x32 Version: 16.1.0.0 - Minitab Inc) Hidden

Minitab16 (x32 Version: 16.1.0.0 - Minitab, Inc.) Hidden

Movavi Video Editor 11 (HKLM-x32\…\Movavi Video Editor 11) (Version: 11.2.0 - Movavi)

Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden

Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden

PlayMemories Home (HKLM-x32\…\{10DD6128-A810-4A90-9523-475D573FBB37}) (Version: 6.3.02.07270 - Sony Corporation)

Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.214 - Qualcomm Atheros Communications)

Rapport (x32 Version: 3.5.1507.109 - Trusteer) Hidden

Reader for PC (HKLM-x32\…\{25340F94-F74E-4CCF-ABDF-ECBCF03911BE}) (Version: 2.0.00.07121 - Sony Corporation)

Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6695 - Realtek Semiconductor Corp.)

Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.28121 - Realtek Semiconductor Corp.)

Restore (x32 Version: 1.0.0 - Sony Corporation) Hidden

Revisores de Texto do Microsoft Office 2013 – Português do Brasil (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden

Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)

Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)

Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)

Skype™ 7.10 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.10.101 - Skype Technologies S.A.)

SoftwareManager (x32 Version: 1.0.0.0 - Minitab, Inc.) Hidden

SSLx64 (Version: 1.0.0 - Sony Corporation ) Hidden

SSLx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden

Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.5.0 - Synaptics Incorporated)

Trusteer Endpoint Protection (HKLM-x32\…\Rapport_msi) (Version: 3.5.1507.109 - Trusteer)

Update for Skype for Business 2015 (KB3114502) 32-Bit Edition (HKLM-x32\…\{90150000-002A-0000-1000-0000000FF1CE}_Office15.VISPROR_{B4DBD8FE-927A-4BAF-9158-D71D2EE4C00F}) (Version:  - Microsoft)

VAIO - Xperia Link (HKLM-x32\…\{D91558BF-D1F3-411F-AEFE-8774CB406512}) (Version: 1.3.3.11280 - Sony Corporation)

VAIO Care (HKLM\…\{036400BD-B717-4D50-ACDC-96480C99EDD3}) (Version: 8.4.4.09186 - Sony Corporation)

VAIO Care Recovery (HKLM\…\{15B9204E-BA09-485E-8F2C-094AC0077664}) (Version: 1.1.2.13230 - Sony Corporation)

VAIO Control Center (HKLM-x32\…\{8E797841-A110-41FD-B17A-3ABC0641187A}) (Version: 6.1.0.10300 - Sony Corporation)

VAIO CPU Fan Diagnostic (HKLM-x32\…\{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}) (Version: 1.1.0.09200 - Sony Corporation)

VAIO Data Restore Tool (HKLM-x32\…\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.10.0.07270 - Sony Corporation)

VAIO Easy Connect (x32 Version: 8.4.4.07220 - Sony Corporation) Hidden

VAIO Gate Default (HKLM-x32\…\{B7546697-2A80-4256-A24B-1C33163F535B}) (Version: 3.1.0.10240 - Sony Corporation)

VAIO Gesture Control (HKLM-x32\…\{692955F2-DE9F-4078-8FAA-858D6F3A1776}) (Version: 2.1.0.10220 - Sony Corporation)

VAIO Gesture Control (x32 Version: 2.1.0.10220 - Sony Corporation) Hidden

VAIO Hardware Diagnostics Plugin for VAIO Care (HKLM-x32\…\{EC153498-00E1-4C9C-89BE-81527C6750BE}) (Version: 4.7.0.11070 - Sony Corporation)

VAIO Health Report (HKLM-x32\…\VAIO Health Report1.0) (Version: 1.0 - Sony Electronics)

VAIO Image Optimizer (HKLM-x32\…\InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}) (Version: 3.0.00.08170 - Sony Corporation)

VAIO Image Optimizer (x32 Version: 3.0.00.08170 - Sony Corporation) Hidden

VAIO Improvement (HKLM-x32\…\{3A26D9BD-0F73-432D-B522-2BA18138F7EF}) (Version: 2.1.0.10220 - Sony Corporation)

VAIO Manual (HKLM-x32\…\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}) (Version: 3.0.0.08100 - Sony Corporation)

VAIO Media Server Settings (HKLM\…\{62A172B2-550E-499D-9A82-5190D18390AA}) (Version: 1.0.1.10170 - Sony Corporation)

VAIO Movie Creator (HKLM-x32\…\InstallShield_{C2CC5822-32E6-4D21-88EA-DE8CED09EE2F}) (Version: 4.0.00.10170 - Sony Corporation)

VAIO Movie Creator (x32 Version: 4.0.00.10170 - Sony Corporation) Hidden

VAIO Movie Creator Template Data (x32 Version: 4.0.00.08170 - Sony Corporation) Hidden

VAIO Transfer Support (HKLM-x32\…\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}) (Version: 1.9.0.11060 - Sony Corporation)

VAIO Update (HKLM-x32\…\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.1.0.08060 - Sony Corporation)

VCCMMX64 (Version: 1.0.0 - Sony Corporation) Hidden

VCCMMX86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

VCCx64 (Version: 1.0.0 - Sony Corporation) Hidden

VCCx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

VHD (x32 Version: 1.0.0 - Sony Corporation) Hidden

Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)

Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)

VIx64 (Version: 1.0.0 - Sony Corporation) Hidden

VIx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)

VMLx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

VPMx64 (Version: 1.0.0 - Sony Corporation ) Hidden

VSSTx64 (Version: 1.0.0 - Sony Corporation ) Hidden

VSSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden

VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden

VWSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

Web Companion (HKLM-x32\…\{dfa2e17c-b3ae-4bd7-97c2-d25a373fe428}) (Version: 2.1.1159.2383 - Lavasoft)

Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (06/03/2009 2.3.0.0) (HKLM\…\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin)

Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)

WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

XperiaLinkx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {01E8C4D3-71CE-4AB9-A841-47602E449CF6} - System32\Tasks\Minitab\Minitab Software Update Manager => C:\Program Files (x86)\Common Files\Minitab Shared\Software Manager\SoftwareManager.exe [2010-03-25] (Minitab)

Task: {059334B1-5D47-4910-9DF2-2E5F1F66F046} - System32\Tasks\Sony Corporation\VHDInformationCheck => C:\Program Files (x86)\Sony\VAIO Recovery\plugins\InformationCheck.exe [2012-11-08] (Sony Corporation)

Task: {0B4DC8FC-BDAD-4064-8529-DC71348B0DA2} - System32\Tasks\AVG_SYS_TASK_0215pit_RUN => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe

Task: {1A614C97-355C-4221-BDC7-D4B9647EF953} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)

Task: {1B1EE405-ADB2-4A32-B8E1-74F6479E1477} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Month => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-09-06] (Sony Corporation)

Task: {23F700F9-3AD6-4D55-ACA6-8790D10C07A6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)

Task: {25903C7C-5BDD-4B55-B241-794BAED09AA0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION

Task: {2BFCBD49-912A-4A29-8E8F-A3DE01FCF636} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION

Task: {307C81B3-23D2-48A4-ABBB-FDEBE609B3D1} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {392E1203-F7DE-4F09-B820-0F421CFD13BB} - System32\Tasks\0116avUpdateInfo => C:\ProgramData\Avg_Update_0116av\0116av_AVG-Secure-Search-Update.exe [2016-01-10] ()

Task: {3CE839B7-48D9-4065-B228-23B51752BE00} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe

Task: {3DCB276A-B18E-40D6-9FCF-DE9164F310AF} - System32\Tasks\ShdUpdate => C:\Users\Mohamed\AppData\Local\ShdUpdate\shupd.exe

Task: {4038D60A-67E7-4CE1-9AE6-15462FA78D59} - System32\Tasks\Sony Corporation\Xperia Link\Xperia Link Logon Start => C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe [2014-11-28] (Sony Corporation)

Task: {43F31D98-ECCC-4363-A7C0-942D92044DDE} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {4796AA0F-637C-4BD9-A388-3D8DF02C3975} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION

Task: {4BB1FE87-4BC9-4EFF-996B-E4D6929FBF68} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-12] (Microsoft Corporation)

Task: {5317E109-EB3F-40A7-9AF1-A90B28DC536F} - System32\Tasks\dlclient Updater => C:\WINDOWS\system32\wscript.exe [2015-10-30] (Microsoft Corporation)

Task: {55D22126-8B2F-4F4E-83DB-6ED20480600A} - System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl => C:\Users\Mohamed\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\MinibarChrome.exe

Task: {56DC05BA-1872-4066-B3A1-35DA3F127A87} - System32\Tasks\EPUpdater => C:\Users\Mohamed\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION

Task: {60B7D15A-169A-427B-A753-67DF2429035D} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {612606F8-A564-4FDD-998F-19F8189CB6C6} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {66321C0C-64E6-4262-8138-24A1A446EAAE} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)

Task: {679BF2BC-B190-459C-B70E-827FC91692DB} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {69993CC2-A246-4F22-93C4-147E66D44A01} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION

Task: {774F71DB-0FC3-4846-B083-F389DF638D80} - System32\Tasks\StPrsSW => C:\Users\Mohamed\AppData\Roaming\StPrsSW\stprss.exe

Task: {778C9C9A-D2F0-438B-949B-163B01C99276} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {7820700A-9B7F-45FF-82E4-C34135218302} - System32\Tasks\0116tbUpdateInfo => C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe [2016-01-31] ()

Task: {7B320197-E3E5-4E55-B31B-0D8B272215EE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION

Task: {7C8E4363-DB51-45E4-A4C7-3A43E49E91F8} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-05-27] (Synaptics Incorporated)

Task: {7CF6E46E-9035-495E-8E20-6FEAE62283E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION

Task: {7ED2A75D-30C8-406E-9F28-E1E95E23EB61} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION

Task: {7ED76DB6-41DF-444D-BBEF-F68114064CD9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION

Task: {817B72B9-1153-4C01-830E-FE168B2B4D95} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION

Task: {83A1F6AD-0A91-46BB-9612-79A0531E8D2C} - System32\Tasks\bdraw Updater => C:\WINDOWS\system32\wscript.exe [2015-10-30] (Microsoft Corporation)

Task: {877B2768-1F74-4A00-A173-57FA87DAF844} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION

Task: {87F67BB8-BDA3-4D67-8998-D147D58D4937} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {8D434BA6-9AE8-44A2-B573-AE3635A38D71} - System32\Tasks\Sony Corporation\VAIO Gesture Control\VCGULogonTask => C:\Program Files (x86)\Sony\VAIO Camera Gesture Utility\VCGU.exe [2012-10-23] (Sony Corporation)

Task: {8F552644-BBED-4F26-9C62-C19ED700296F} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Daily => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-09-06] (Sony Corporation)

Task: {94040B21-D3F3-4E87-B2B5-AD3996115FAE} - System32\Tasks\Sony Corporation\VAIO Care\UpdateConfig => C:\ProgramData\Sony Corporation\VCM Data\UpdateConfig.exe [2015-03-03] (Sony Corporation)

Task: {988CD594-1CA7-4778-A7E1-36F38E7F8BD9} - System32\Tasks\Sony Corporation\VAIO Control Center\VAIOControlCenterUser => C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe [2014-11-17] (Sony Corporation)

Task: {9A89E719-D142-408F-88B7-9930A445F864} - System32\Tasks\HPCustParticipation HP Deskjet 3050 J610 series => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)

Task: {9B7DEB27-1F51-41B5-B71F-762C86BFB579} - \Microsoft\Windows\Setup\xtgt\refreshxtgtconfig -> No File <==== ATTENTION

Task: {9B8E6F2A-7A65-4514-8164-3FDFB10B1923} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2015-02-04] (Sony Corporation)

Task: {A08B941B-5850-4495-8B64-22478DA6A511} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION

Task: {A0D99ED2-9134-4D59-BD69-99FC40A8F7E7} - System32\Tasks\Sony Corporation\VAIO Control Center\NetworkSetting\NetworkSetting Logon Start => C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient

Task: {A72C7826-6850-4A91-99C0-3BA5989BA5B2} - System32\Tasks\Sony Corporation\VAIO Control Center\VAIOControlCenterSystem => C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe [2014-11-17] (Sony Corporation)

Task: {A98A9361-3092-4E73-9EA4-CC380F6797C5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {AAAD10C7-3583-48E6-B177-E3E6574FF4D5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)

Task: {AF781C91-FBB2-4BBE-8E5F-4A84840BBD45} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2015-07-23] (Sony Corporation)

Task: {B6BE1946-EC3D-4489-9210-45886CBEFB02} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2012-10-22] (Sony Corporation)

Task: {C4DB7938-DD4C-4542-9B12-2685E66A4518} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {D421F58A-779C-494D-902D-A62D35688EB6} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2015-08-06] (Sony Corporation)

Task: {DB31E079-DE33-4E3B-9BF2-5499985493F5} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe [2015-07-31] (Sony Corporation)

Task: {DDAAB7F8-3D7F-490E-B3ED-2F5E022B94D0} - System32\Tasks\USER_ESRV_SVC => Wscript.exe //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"

Task: {E282B03A-2F25-4ACC-BB16-8FBD0D44B109} - System32\Tasks\VAIO Health Report => C:\Program Files (x86)\Sony\VAIO Health Report\VAIOHealthReport.exe [2013-06-20] (Sony Electronics)

Task: {E6FE04D1-8BD8-4B33-B4B4-7A604FF955E6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)

Task: {E90C368E-05E9-4A42-8EF1-1321D428AFB8} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)

Task: {E9125151-377A-4DCB-B066-20E63E6470DF} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2015-07-31] (Sony Corporation)

Task: {F3167AEB-B03E-4CAF-9F09-F7DC8FF3448B} - System32\Tasks\Sony Corporation\VAIO Care\ActiveStatusCollect => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

Task: {FEB4F95B-C5B9-4274-A133-09CF447B557A} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core.job => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA.job => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

 

==================== Shortcuts =============================

 

(The entries could be listed to be restored or removed.)

 

ShortcutWithArgument: C:\Users\Mohamed\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx

ShortcutWithArgument: C:\Users\Mohamed\Desktop\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://esurf.biz/?ssid=1454888464&a;=1026405&src;=sh&uuid;=b05a016d-f6f9-4beb-a582-927650f30a8d"

ShortcutWithArgument: C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://esurf.biz/?ssid=1454888464&a;=1026405&src;=sh&uuid;=b05a016d-f6f9-4beb-a582-927650f30a8d"

ShortcutWithArgument: C:\Users\Mohamed\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx

ShortcutWithArgument: C:\Users\Mohamed\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://esurf.biz/?ssid=1454888464&a;=1026405&src;=sh&uuid;=b05a016d-f6f9-4beb-a582-927650f30a8d"

ShortcutWithArgument: C:\Users\Mohamed\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx

ShortcutWithArgument: C:\Users\Mohamed\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://esurf.biz/?ssid=1454888464&a;=1026405&src;=sh&uuid;=b05a016d-f6f9-4beb-a582-927650f30a8d"

ShortcutWithArgument: C:\Users\Mohamed\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx

ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx

 

==================== Loaded Modules (Whitelisted) ==============

 

2015-10-30 02:48 - 2015-10-30 02:48 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll

2015-06-03 13:26 - 2016-02-25 20:27 - 01215560 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe

2015-10-12 23:15 - 2015-10-12 23:15 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-10-12 23:15 - 2015-10-12 23:15 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2016-02-25 20:27 - 2016-02-25 20:27 - 00192584 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\loggingserver.exe

2015-12-03 04:55 - 2015-11-22 06:17 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll

2015-12-03 04:55 - 2015-11-22 06:17 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll

2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

2016-02-02 23:35 - 2016-02-02 23:39 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe

2016-01-12 15:07 - 2015-12-06 23:44 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll

2016-01-12 15:07 - 2015-12-06 23:30 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll

2016-01-12 15:08 - 2016-01-04 20:59 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll

2016-01-12 15:08 - 2016-01-04 20:53 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll

2016-01-31 14:30 - 2016-01-16 00:40 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll

2016-01-31 14:30 - 2016-01-16 00:43 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll

2016-01-12 15:08 - 2016-01-04 20:54 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00413336 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe

2015-08-26 13:11 - 2015-08-26 13:11 - 00709272 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_modeler.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00130712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_process_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00025752 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_system_power_state_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00059544 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_quality_and_reliability_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00194712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\acpi_battery_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00159896 _____ () C:\Program Files\Sony\VAIO Care\ESRV\sema_thermal_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00158360 _____ () C:\Program Files\Sony\VAIO Care\ESRV\wifi_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00050840 _____ () C:\Program Files\Sony\VAIO Care\ESRV\devices_use_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00032920 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_disktrace_input.dll

2015-08-26 13:11 - 2015-08-26 13:11 - 00458904 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe

2015-08-26 13:11 - 2015-08-26 13:11 - 00185496 _____ () C:\Program Files\Sony\VAIO Care\ESRV\foreground_window_input.dll

2016-02-25 20:27 - 2016-02-25 20:27 - 00533576 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.6\log4cplusU.dll

2016-02-02 23:35 - 2016-02-02 23:39 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll

2016-02-02 23:35 - 2016-02-02 23:39 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll

2015-10-27 04:12 - 2015-10-27 04:11 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll

2015-07-21 16:02 - 2015-07-21 16:02 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

 

==================== EXE Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\bancodevenezuela.com -> www.bancodevenezuela.com

IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\banvenez.com -> e-bdv.banvenez.com

IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\banvenez.corp -> e-bdvscn.banvenez.corp

IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\localhost -> localhost

IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\webcompanion.com -> hxxp://webcompanion.com

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2012-07-26 00:56 - 2015-09-04 03:35 - 00000856 ____N C:\WINDOWS\system32\Drivers\etc\hosts

 

0.0.0.1   mssplus.mcafee.com

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Sony\VAIO 11 img1 Wallpaper 1366x768.jpg

DNS Servers: 192.168.0.1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

(Currently there is no automatic fix for this section.)

 

MSCONFIG\Services: RapportMgmtService => 2

MSCONFIG\Services: SampleCollector => 2

MSCONFIG\Services: SearchProtectionService => 2

MSCONFIG\Services: SkypeUpdate => 2

MSCONFIG\Services: SOHCImp => 3

MSCONFIG\Services: SOHDms => 3

MSCONFIG\Services: SOHDs => 3

MSCONFIG\Services: Sony SCSI Helper Service => 3

MSCONFIG\Services: SpfService => 3

MSCONFIG\Services: UNS => 2

MSCONFIG\Services: VAIO Event Service => 2

MSCONFIG\Services: VAIO Power Management => 3

MSCONFIG\Services: VCFw => 3

MSCONFIG\Services: VCService => 3

MSCONFIG\Services: vToolbarUpdater40.1.8 => 2

MSCONFIG\Services: VUAgent => 3

MSCONFIG\Services: WtuSystemSupport => 2

MSCONFIG\Services: ZAtheros Bt and Wlan Coex Agent => 2

HKLM\…\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"

HKLM\…\StartupApproved\Run: => "BtTray"

HKLM\…\StartupApproved\Run: => "BtvStack"

HKLM\…\StartupApproved\Run: => "HotKeysCmds"

HKLM\…\StartupApproved\Run: => "Persistence"

HKLM\…\StartupApproved\Run: => "IgfxTray"

HKLM\…\StartupApproved\Run32: => "Adobe ARM"

HKLM\…\StartupApproved\Run32: => "ATUninstallIcon"

HKLM\…\StartupApproved\Run32: => "ATLauncher"

HKLM\…\StartupApproved\Run32: => "HP Software Update"

HKLM\…\StartupApproved\Run32: => "IminentMessenger"

HKLM\…\StartupApproved\Run32: => "Iminent"

HKLM\…\StartupApproved\Run32: => "ISBMgr.exe"

HKLM\…\StartupApproved\Run32: => "PMBVolumeWatcher"

HKLM\…\StartupApproved\Run32: => "BCSSync"

HKLM\…\StartupApproved\Run32: => "vProt"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\StartupFolder: => "Dropbox.lnk"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\StartupFolder: => "Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Akamai NetSession Interface"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Dropbox Update"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "HP Deskjet 3050 J610 series (NET)"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "uTorrent"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Skype"

HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Web Companion"

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139

FirewallRules: [{5A7B768E-A3B6-45BA-A7EF-BE9A5A78A9BB}] => (Allow) C:\Program Files\Sony\VAIO Care\VAIOShell.exe

FirewallRules: [{5255C25F-CF98-4572-8328-3950CB5DD17A}] => (Allow) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe

FirewallRules: [{83A1058E-99E5-420F-A596-512C714C7ABD}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAdmin.exe

FirewallRules: [{F2550089-5D57-45CE-9B8F-F051F5DB64F9}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAgent.exe

FirewallRules: [{032ED4F2-5FF2-4804-803C-802CD95BAC3F}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe

FirewallRules: [{D5AA685A-C1F6-4CCE-8ACD-69F92417BF5B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe

FirewallRules: [{ECF65DB4-DB74-41E5-BC91-39B4613BF219}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe

FirewallRules: [{9D17CFB5-F059-44F6-B4C2-E84F715D94AF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe

FirewallRules: [{306E741B-0BF4-48B6-8E82-29C1C2305554}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe

FirewallRules: [{7246312F-41FD-492B-9169-A4FE9CE7AD4A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe

FirewallRules: [{B0A13E65-26D7-4A07-A2F1-238AD8403190}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe

FirewallRules: [{A23D1A60-BF7B-43A7-88D5-963D5BD4C588}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe

FirewallRules: [{0C20D46A-89A2-4644-8A82-7593266157D2}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe

FirewallRules: [{D6D027DA-8710-4AA8-BD0A-226F29859DA0}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe

FirewallRules: [{8BBCFE44-A535-40E9-A361-A9515802C70A}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe

FirewallRules: [{7C4685B1-6A2B-4F0E-B9ED-61D9F5317593}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe

FirewallRules: [{F1B5556B-08BF-420F-9C75-E5D78CDE7ABC}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe

FirewallRules: [{75980B65-F094-42C2-AC90-C5E26F87B123}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe

FirewallRules: [UDP Query User{55529703-E018-4A66-AC81-5E8BD86EBC0B}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe

FirewallRules: [TCP Query User{6B042536-B865-48AD-87C2-8587D989830E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe

FirewallRules: [{F7C075B2-86A2-42F2-AFE1-850750B72DA0}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

FirewallRules: [{9B99E1EB-B508-4688-8DCE-637388839E52}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

FirewallRules: [{363ED47E-3CEE-4DEE-9C05-F6E2427304B9}] => (Allow) C:\Program Files (x86)\Iminent\Iminent.exe

FirewallRules: [{E2603D52-3108-47C3-8C1A-7BD1346C4147}] => (Allow) C:\Program Files (x86)\Iminent\Iminent.Messengers.exe

FirewallRules: [{29CB40BD-523F-4F08-9C88-72163697D36B}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe

FirewallRules: [{957EFFE1-4D66-4494-A9EE-213494C5B368}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe

FirewallRules: [{C878EB33-BAF3-4F8B-9CB9-272F994D0A7D}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicatorCom.exe

FirewallRules: [TCP Query User{44127511-CF27-48DE-9583-1958A39F985B}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe

FirewallRules: [UDP Query User{D70CF496-D40E-42A5-BF03-0F7B21155187}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe

FirewallRules: [TCP Query User{880103C5-AA49-492D-9529-BFFBAC464723}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe

FirewallRules: [UDP Query User{D41CCDEE-E619-4455-87DF-0E1813EF630A}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe

FirewallRules: [{8370D6FD-057F-4F0C-BED6-13371AFF45FC}] => (Allow) C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe

FirewallRules: [{8EDEE1C8-2FA5-4A4B-B156-C8608718DA8F}] => (Allow) C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe

FirewallRules: [TCP Query User{B9245E71-B7E3-47A6-B0E6-6B0B3672D62E}C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe

FirewallRules: [UDP Query User{03B456A9-5351-44E6-96C0-FF7312CF541E}C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe

FirewallRules: [TCP Query User{A44FC839-B42D-4D54-ABD7-991622D25887}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe

FirewallRules: [{9F6D9876-3F1A-41A3-A9D4-CDF020EB6753}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe

FirewallRules: [{0C61DA2E-1D6C-4B65-B115-89306A8505DA}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe

FirewallRules: [{2EF696F4-B9CE-4878-A0D7-C674DDEC40DF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{59273D93-240F-47DB-8B8F-D5BB7DFA44EF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{A494D966-54C4-4BC8-9DFD-EA220FC5AB1E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{E46AB6F8-7E00-423E-A86F-E33B617278F9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{F3C639F4-AE6D-4691-AE68-510AE9689708}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{36E8002E-76F0-401F-B1D3-899AB50BD3BF}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe

FirewallRules: [{20B0A966-9BC8-48AA-AB38-8396063A41D8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe

FirewallRules: [{65F8552F-6714-4852-9340-54EE2342AB1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe

FirewallRules: [{E730E30E-580E-475A-9266-C29527C28FD4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe

FirewallRules: [{3296E763-B5E2-464D-A16C-C85793837FAC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe

FirewallRules: [{23A36BF3-185D-4490-8A11-29893A53736D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe

FirewallRules: [{B241DB46-5B3E-4A1F-B6A4-2AA798722CD2}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe

FirewallRules: [{DB5D3643-EA7A-4C6D-952E-3112384F788D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe

FirewallRules: [{18701A33-5F97-416D-859B-A76BE195ED88}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe

FirewallRules: [{00FE0603-F42A-4C79-9F2E-DE8F997C4C31}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe

FirewallRules: [{17F07D65-1176-4321-88BA-6466B9C89351}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe

FirewallRules: [{3A97DA7C-6BEE-4956-A763-01CF376F5855}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe

FirewallRules: [{E1478880-C245-4AB0-BF65-6F31EE28B817}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

FirewallRules: [{9AFC3DD0-BE6C-44B9-A6F5-7D2EE733103C}] => (Allow) LPort=2869

FirewallRules: [{D027D31C-9509-4AD8-9477-463533807A9B}] => (Allow) LPort=1900

FirewallRules: [{661A1F9A-20EC-440B-A585-A1FC1B932DA5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

==================== Restore Points =========================

 

07-02-2016 18:08:51 Scheduled Checkpoint

23-02-2016 11:00:11 Scheduled Checkpoint

26-02-2016 10:22:12 Installed Rapport

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (03/03/2016 02:17:08 PM) (Source: Perflib) (EventID: 1010) (User: )

Description: C:\Windows\System32\winspool.drvSpooler8

 

Error: (02/29/2016 11:01:10 AM) (Source: Perflib) (EventID: 1010) (User: )

Description: C:\Windows\System32\winspool.drvSpooler8

 

Error: (02/29/2016 11:01:08 AM) (Source: Perflib) (EventID: 1008) (User: )

Description: BITSC:\Windows\System32\bitsperf.dll8

 

Error: (02/29/2016 10:40:59 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VAIO)

Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (02/29/2016 10:40:32 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SearchUI.exe, version: 10.0.10586.63, time stamp: 0x568b1fdc

Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.71, time stamp: 0x5699d8e0

Exception code: 0xc000027b

Fault offset: 0x00000000006fce8b

Faulting process id: 0x181c

Faulting application start time: 0xSearchUI.exe0

Faulting application path: SearchUI.exe1

Faulting module path: SearchUI.exe2

Report Id: SearchUI.exe3

Faulting package full name: SearchUI.exe4

Faulting package-relative application ID: SearchUI.exe5

 

Error: (02/29/2016 10:27:49 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: VAIO)

Description: Package Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe+MicrosoftEdge was terminated because it took too long to suspend.

 

Error: (02/29/2016 10:22:21 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.10586.0, time stamp: 0x5632d8f0

Faulting module name: twinapi.appcore.dll, version: 10.0.10586.0, time stamp: 0x5632d2f5

Exception code: 0xc000027b

Fault offset: 0x000000000004b199

Faulting process id: 0x15ec

Faulting application start time: 0xbackgroundTaskHost.exe0

Faulting application path: backgroundTaskHost.exe1

Faulting module path: backgroundTaskHost.exe2

Report Id: backgroundTaskHost.exe3

Faulting package full name: backgroundTaskHost.exe4

Faulting package-relative application ID: backgroundTaskHost.exe5

 

Error: (02/26/2016 10:23:55 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )

Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

 

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

 

System Error:

Access is denied.

.

 

Error: (02/26/2016 10:20:56 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VAIO)

Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.

 

Error: (02/26/2016 10:19:46 AM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SearchUI.exe, version: 10.0.10586.63, time stamp: 0x568b1fdc

Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.71, time stamp: 0x5699d8e0

Exception code: 0xc000027b

Fault offset: 0x00000000006fce8b

Faulting process id: 0x1324

Faulting application start time: 0xSearchUI.exe0

Faulting application path: SearchUI.exe1

Faulting module path: SearchUI.exe2

Report Id: SearchUI.exe3

Faulting package full name: SearchUI.exe4

Faulting package-relative application ID: SearchUI.exe5

 

 

System errors:

=============

Error: (03/03/2016 02:28:40 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:40 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (03/03/2016 02:28:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

 

CodeIntegrity:

===================================

  Date: 2016-03-03 14:39:18.900

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:39:18.886

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:39:18.544

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:39:18.533

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:22:44.876

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:22:44.860

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:20:16.049

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:20:16.034

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:20:16.017

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-03-03 14:20:16.004

  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

 

 

==================== Memory info ===========================

 

Processor: Intel(R) Core(TM) i5-3337U CPU @ 1.80GHz

Percentage of memory in use: 45%

Total physical RAM: 6023.27 MB

Available physical RAM: 3288.2 MB

Total Virtual: 12167.27 MB

Available Virtual: 9151.98 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:441.14 GB) (Free:245.75 GB) NTFS

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (Size: 465.8 GB) (Disk ID: 195C4519)

 

Partition: GPT.

 

==================== End of Addition.txt ============================

 

 

Thanks a lot.

Hello Moe_J_AK and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner
  • when it has finished, select Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Security Check

Download Security Check by screen317 from here or here.

  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

Logs to include with next post:

AdwCleaner log
JRT.txt
checkup.txt


Thanks

Satchfan

 

Hi Satchfan, thank you for your time.

 

Below the logs you asked for (By the way the first time i ran the AdwCleaner it crashed giving a message that "AdwCLeaner has stopped working" so no log was generated so i had to run it one more time)…

 

# AdwCleaner v5.037 - Logfile created 03/03/2016 at 20:18:04
# Updated 28/02/2016 by Xplode
# Database : 2016-03-02.1 [Server]
# Operating system : Windows 10 Home  (x64)
# Username : Mohamed - VAIO
# Running from : C:\Users\Mohamed\Desktop\adwcleaner_5.037.exe
# Option : Clean
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[#] Folder Deleted : C:\ProgramData\mntemp
 
***** [ Files ] *****
 
 
***** [ DLLs ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKCU\Software\DataMngr_Toolbar
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{363ED47E-3CEE-4DEE-9C05-F6E2427304B9}]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{E2603D52-3108-47C3-8C1A-7BD1346C4147}]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\adserver.iminent.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\iminent.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\adserver.iminent.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\iminent.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\videodownloadconverter.dl.tb.ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Iminent]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [IminentMessenger]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
[-] Key Deleted : HKCU\Software\Classes\keepmysearch
 
***** [ Web browsers ] *****
 
 
*************************
 
:: "Tracing" keys removed
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [42351 bytes] - [03/03/2016 20:06:47]
C:\AdwCleaner\AdwCleaner[C2].txt - [2684 bytes] - [03/03/2016 20:18:04]
C:\AdwCleaner\AdwCleaner[S1].txt - [43974 bytes] - [03/03/2016 19:42:17]
C:\AdwCleaner\AdwCleaner[S2].txt - [2759 bytes] - [03/03/2016 20:10:51]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [2904 bytes] ##########
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.3 (02.09.2016)
Operating System: Windows 10 Home x64 
Ran by [removed] (Administrator) on Thu 03/03/2016 at 20:35:08.00
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 10 
 
Failed to delete: C:\Program Files (x86)\lavasoft\web companion (Folder) 
Successfully deleted: C:\ProgramData\1433348586.bdinstall.bin (File) 
Successfully deleted: C:\ProgramData\1433348671.bdinstall.bin (File) 
Successfully deleted: C:\ProgramData\1437642367.bdinstall.bin (File) 
Successfully deleted: C:\ProgramData\lavasoft\web companion (Folder) 
Successfully deleted: C:\Users\Mohamed\AppData\Local\delta (Folder) 
Successfully deleted: C:\Users\Mohamed\AppData\Roaming\delta (Folder) 
Successfully deleted: C:\Users\Mohamed\AppData\Roaming\lavasoft\web companion (Folder) 
Successfully deleted: C:\WINDOWS\system32\Tasks\0116avUpdateInfo (Task)
Successfully deleted: C:\Program Files (x86)\delta (Folder) 
 
 
 
Registry: 2 
 
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540026} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540026} (Registry Key)
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 03/03/2016 at 20:38:56.90
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 Results of screen317's Security Check version 1.014 — 12/23/15  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Windows Defender             
AVG AntiVirus Free Edition   
 Antivirus out of date!  
`````````Anti-malware/Other Utilities Check:````````` 
 AVG Web TuneUp   
 Java 7 Update 9  
 Java version 32-bit out of Date! 
 Adobe Reader XI  
 Google Chrome (48.0.2564.109) 
 Google Chrome (48.0.2564.116) 
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log`````````````````````` 
 
 
 
 

Multiple antiviruses

You have AVG and Windows Defender antivirus programs running.

You can not run two real-time antiviruses at the same time. Although many have different methods of searching for and recognising threats, they will all be 'fighting' in memory to kick each other out, rendering them all ineffective.

I would suggest you uninstall AVG, as Windows Defender is more effective and less intrusive but, it is your choice.

If you uninstalled AVG there will still be some remnants on your computer even after the uninstall so please download and run AVG Removal Tool from here.

================================================

Please run FRST again and make sure there is a checkmark next to "Addition.txt" before you hit “Scan”.

Logs to include with next post:

New Frst.txt
New Addition.txt


Thanks

Satchfan

ok StachFan,

 

I deleted AVG antivirus as suggested.

 

Below the logs you asked for:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:02-03-2016
Ran by [removed] (administrator) on VAIO (04-03-2016 10:24:09)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\MSOSYNC.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-09-20] (Realtek Semiconductor)
HKLM\…\Run: [BtTray] => "C:\Program Files (x86)\Bluetooth Suite\BtTray.exe"
HKLM\…\Run: [BtvStack] => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3928264 2015-05-27] (Synaptics Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-15] (Apple Inc.)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [68776 2012-08-18] (Sony Corporation)
HKLM-x32\…\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [724576 2012-07-27] (Sony Corporation)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [ATLauncher] => "C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe" /createshortcuts:1
HKLM-x32\…\Run: [ATUninstallIcon] => "C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe" /createuninstallentry:1
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
Winlogon\Notify\ GbPluginBdv: C:\Program Files (x86)\GbPlugin\gbiehBdv.dll [2015-12-23] (Banco de Venezuela)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [HP Deskjet 3050 J610 series (NET)] => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Akamai NetSession Interface] => C:\Users\Mohamed\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Dropbox Update] => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [57987712 2015-09-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [uTorrent] => C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-12-16] (BitTorrent Inc.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe –minimize
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399026} - C:\Program Files (x86)\GbPlugin\gbiehbdv.dll [1864800 2015-12-23] (Banco de Venezuela)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-09-04]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-10-27]
ShortcutTarget: Dropbox.lnk -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk [2015-06-03]
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk -> C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
BootExecute: autocheck autochk * 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
AutoConfigURL: [S-1-5-21-3844031730-595245587-2132850609-1001] => hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8e600265-fef9-4bc5-915b-46b09da7aa5b}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{95b7ca61-94ac-4fcc-b000-6961f24fe53a}: [DhcpNameServer] 192.168.0.1
ManualProxies: 0hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
 
Internet Explorer:
==================
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony13.msn.com
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc;=UE01&ocid;=UE01DHP
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2012-12-11] (Oracle Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-11-05] (Qualcomm Atheros Commnucations)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-18] (Kaspersky Lab ZAO)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-11-10] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-12-11] (Oracle Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-18] (Kaspersky Lab ZAO)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-18] (Kaspersky Lab ZAO)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-12-11] (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-18] (Kaspersky Lab ZAO)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540026} -> C:\Program Files (x86)\GbPlugin\gbiehbdv.dll [2015-12-23] (Banco de Venezuela)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-12-11] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-18] (Kaspersky Lab ZAO)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-11] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-11] (Microsoft Corporation.)
DPF: HKLM-x32 {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll [2012-12-11] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2012-12-11] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-12-11] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @sony.com/ReaderDesktop -> C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll [2012-07-12] (Sony Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3844031730-595245587-2132850609-1001: gastecnologia.com.br/sf/bdv -> C:\Users\Mohamed\AppData\Local\GAS Tecnologia\GBBD\npsf_bdv.dll [2013-08-16] (GAS Tecnologia)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013-03-22] [not signed]
 
Chrome: 
=======
CHR HomePage: Profile 1 -> hxxp://www.yoursearching.com/?type=hp&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx
CHR StartupUrls: Profile 1 -> "hxxp://www.yoursearching.com/?type=hp&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx"
CHR DefaultSearchURL: Profile 1 -> hxxp://yoursearching.com/web/?type=ds&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx&q;={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> yoursearching
CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Docs) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-30]
CHR Extension: (Google Search) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2015-01-17]
CHR Extension: (Google Docs Offline) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Safe Money) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hakdifolhalapjijoafobooafbilfakh [2015-01-17]
CHR Extension: (Content Blocker) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2015-01-17]
CHR Extension: (Virtual Keyboard) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2015-01-17]
CHR Extension: (Skype) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-26]
CHR Extension: (GBBD Cl@veDefensa del Banco de Venezuela) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\odifdffdmeannfboglpliamjmoggdmci [2015-01-17]
CHR Extension: (Gmail) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Anti-Banner) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2015-01-17]
CHR HKU\S-1-5-21-3844031730-595245587-2132850609-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3844031730-595245587-2132850609-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [odifdffdmeannfboglpliamjmoggdmci] - C:\Users\Mohamed\AppData\Local\GAS Tecnologia\GBBD\bdv\sf.crx [2013-10-27]
CHR HKLM-x32\…\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-01]
CHR HKLM-x32\…\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-01]
CHR HKLM-x32\…\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-01]
CHR HKLM-x32\…\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-10-01]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
CHR HKLM-x32\…\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-01]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [102224 2012-08-17] (Condusiv Technologies)
R2 GbpSv; C:\Program Files (x86)\GbPlugin\GbpSv.exe [593120 2015-11-19] (GAS Tecnologia)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751760 2015-10-26] (Lavasoft Limited)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [289256 2015-07-31] (McAfee, Inc.)
S3 NetworkSupport; C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe [625240 2013-09-28] (Sony Corporation)
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [474208 2012-07-27] (Sony Corporation)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2266160 2016-02-01] (IBM Corp.)
S4 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2012-09-19] (Sony Corporation) [File not signed]
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [964608 2012-09-28] (Sony Corporation) [File not signed]
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1653272 2015-07-31] (Sony Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S4 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-11-05] (Atheros) [File not signed]
S4 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [X]
S2 WtuSystemSupport; "C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe" [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23376 2012-08-17] (Condusiv Technologies)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [103248 2012-08-17] (Condusiv Technologies)
R1 RapportCerberus_1507079; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507079.sys [961880 2015-12-02] (IBM Corp.)
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [514336 2016-02-01] (IBM Corp.)
R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [152320 2016-02-01] (IBM Corp.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [407168 2016-02-01] (IBM Corp.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [507424 2016-02-01] (IBM Corp.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [29352 2015-11-17] ()
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-05-27] (Synaptics Incorporated)
R3 SOWS; C:\Windows\System32\drivers\sows.sys [24280 2012-06-10] (Sony Corporation)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-01-14] (Anchorfree Inc.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 HTTP; system32\drivers\HTTP.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-04 10:24 - 2016-03-04 10:24 - 00030364 _____ C:\Users\Mohamed\Desktop\FRST.txt
2016-03-04 10:05 - 2016-03-04 10:05 - 00000000 ___HD C:\OneDriveTemp
2016-03-04 09:51 - 2016-03-04 10:21 - 00000000 ____D C:\AVG_Remover
2016-03-04 09:51 - 2016-03-04 09:51 - 08065568 _____ ( ) C:\Users\Mohamed\Downloads\AVG_Remover.exe
2016-03-04 08:58 - 2016-03-04 08:59 - 01294460 _____ C:\WINDOWS\Minidump\030416-302093-01.dmp
2016-03-03 20:57 - 2016-03-03 20:57 - 00000842 _____ C:\Users\Mohamed\Desktop\checkup.txt
2016-03-03 20:54 - 2016-03-03 20:55 - 00852798 _____ C:\Users\Mohamed\Desktop\SecurityCheck.exe
2016-03-03 20:54 - 2016-03-03 20:54 - 00852798 _____ C:\Users\Mohamed\Downloads\SecurityCheck.exe
2016-03-03 20:38 - 2016-03-03 20:38 - 00001607 _____ C:\Users\Mohamed\Desktop\JRT.txt
2016-03-03 20:29 - 2016-03-03 20:33 - 01609216 _____ (Malwarebytes) C:\Users\Mohamed\Desktop\JRT.exe
2016-03-03 20:28 - 2016-03-03 20:28 - 01609216 _____ (Malwarebytes) C:\Users\Mohamed\Downloads\JRT.exe
2016-03-03 20:26 - 2016-03-03 20:26 - 00002987 _____ C:\Users\Mohamed\Desktop\AdwCleaner[C2].txt
2016-03-03 19:41 - 2016-03-03 20:18 - 00000000 ____D C:\AdwCleaner
2016-03-03 19:41 - 2016-03-03 19:41 - 01518592 _____ C:\Users\Mohamed\Desktop\adwcleaner_5.037.exe
2016-03-03 19:40 - 2016-03-03 19:40 - 01518592 _____ C:\Users\Mohamed\Downloads\adwcleaner_5.037.exe
2016-03-03 19:40 - 2016-03-03 19:40 - 01518592 _____ C:\Users\Mohamed\Downloads\adwcleaner_5.037 (1).exe
2016-03-03 14:38 - 2016-03-04 10:24 - 00000000 ____D C:\FRST
2016-03-03 14:34 - 2016-03-03 14:38 - 02371584 _____ (Farbar) C:\Users\Mohamed\Desktop\FRST64.exe
2016-03-03 14:34 - 2016-03-03 14:34 - 02371584 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST64.exe
2016-03-03 14:33 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Desktop\FRST.exe
2016-03-03 14:32 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST.exe
2016-03-03 14:32 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST (1).exe
2016-03-03 13:31 - 2016-03-03 13:34 - 00840956 _____ C:\WINDOWS\Minidump\030316-304625-01.dmp
2016-02-29 10:27 - 2016-02-29 10:27 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday (2).xls
2016-02-29 10:26 - 2016-02-29 10:26 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday.xls
2016-02-29 10:26 - 2016-02-29 10:26 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday (1).xls
2016-02-29 10:13 - 2016-02-29 10:15 - 01592300 _____ C:\WINDOWS\Minidump\022916-295703-01.dmp
2016-02-23 11:39 - 2016-02-23 11:39 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-02-23 10:29 - 2016-02-23 10:30 - 00849748 _____ C:\WINDOWS\Minidump\022316-302218-01.dmp
2016-02-07 21:18 - 2016-02-07 21:18 - 09846564 _____ C:\Users\Mohamed\Desktop\3.mp4
2016-02-07 21:10 - 2015-05-08 03:18 - 53059755 _____ C:\Users\Mohamed\Desktop\IMG_4839.MOV
2016-02-07 20:40 - 2016-02-07 20:40 - 10365693 _____ C:\Users\Mohamed\Desktop\Burj 2.mp4
2016-02-07 20:33 - 2016-02-07 20:34 - 08754364 _____ C:\Users\Mohamed\Desktop\Burj 1.mp4
2016-02-07 20:20 - 2016-02-07 20:21 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2016-02-07 20:20 - 2016-02-07 20:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2016-02-07 20:04 - 2016-02-07 20:19 - 38248161 _____ (KLCP ) C:\Users\Mohamed\Downloads\K-Lite_Codec_Pack_1185_Full.exe
2016-02-07 19:46 - 2016-02-07 19:46 - 00001447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2016-02-07 19:46 - 2016-02-07 19:46 - 00001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2016-02-07 19:46 - 2016-02-07 19:46 - 00000000 ____D C:\WINDOWS\en
2016-02-07 19:44 - 2016-02-07 19:45 - 00000000 ____D C:\Program Files (x86)\Windows Live
2016-02-07 19:44 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2016-02-07 19:44 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2016-02-07 19:44 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2016-02-07 19:44 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2016-02-07 19:44 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2016-02-07 19:44 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2016-02-07 19:44 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2016-02-07 19:44 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2016-02-07 19:42 - 2016-02-07 19:57 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Windows Live
2016-02-07 19:42 - 2016-02-07 19:42 - 01239752 _____ (Microsoft Corporation) C:\Users\Mohamed\Downloads\wlsetup-web.exe
2016-02-07 19:12 - 2016-02-07 19:12 - 00000351 _____ C:\prefs.js
2016-02-07 19:10 - 2016-02-07 19:10 - 04458496 _____ C:\Users\Mohamed\Downloads\Movavi_Video_Editor_10_Activation_Key_plus_Crack_Full_Free.iso
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\VideoEditor
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Movavi
2016-02-07 17:36 - 2016-02-07 17:36 - 00001189 _____ C:\Users\Public\Desktop\Movavi Video Editor 11.lnk
2016-02-07 17:36 - 2016-02-07 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 11
2016-02-07 17:36 - 2016-02-07 17:36 - 00000000 ____D C:\Program Files (x86)\Movavi Video Editor 11
2016-02-07 17:35 - 2016-02-07 17:35 - 00004881 _____ C:\ProgramData\rxsmznjf.zcp
2016-02-07 17:35 - 2016-02-07 17:35 - 00000000 ____D C:\ProgramData\Movavi Video Editor 11
2016-02-07 17:31 - 2016-02-07 17:35 - 73093984 _____ (Movavi) C:\Users\Mohamed\Downloads\MovaviVideoEditorSetupC.exe
2016-02-07 17:24 - 2015-05-10 15:51 - 65098242 _____ C:\Users\Mohamed\Desktop\IMG_4971.MOV
2016-02-07 17:24 - 2015-05-10 15:50 - 130348697 _____ C:\Users\Mohamed\Desktop\IMG_4970.MOV
2016-02-07 17:11 - 2016-02-07 17:12 - 01394860 _____ C:\WINDOWS\Minidump\020716-304281-01.dmp
2016-02-05 22:13 - 2016-02-05 22:14 - 01339012 _____ C:\WINDOWS\Minidump\020516-296562-01.dmp
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-04 10:20 - 2015-11-18 12:02 - 00000000 ___RD C:\Users\Mohamed\OneDrive
2016-03-04 10:20 - 2014-11-09 11:50 - 00000000 __SHD C:\Users\Mohamed\IntelGraphicsProfiles
2016-03-04 10:20 - 2013-09-22 21:12 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-04 10:17 - 2015-11-18 10:38 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-04 10:17 - 2015-10-30 02:51 - 00000000 ____D C:\WINDOWS\INF
2016-03-04 10:17 - 2013-09-22 21:12 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-04 10:10 - 2015-11-18 10:43 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-04 10:05 - 2015-10-30 01:58 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2016-03-04 10:05 - 2015-10-27 04:12 - 00000000 ____D C:\ProgramData\Avg
2016-03-04 10:03 - 2015-06-19 03:57 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Avg
2016-03-04 10:01 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-03-04 10:01 - 2015-06-03 12:39 - 00000000 ____D C:\Program Files (x86)\AVG
2016-03-04 09:55 - 2015-10-30 02:54 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-03-04 09:55 - 2015-10-27 04:24 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\AVG
2016-03-04 09:55 - 2015-06-21 05:23 - 00000000 ____D C:\Program Files\Common Files\AV
2016-03-04 09:34 - 2015-06-22 15:14 - 00000936 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA.job
2016-03-04 09:03 - 2014-11-15 08:55 - 00004002 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{AECFECB3-D89E-470B-B66F-3EF265E05FF0}
2016-03-04 08:58 - 2015-11-19 04:32 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-04 08:58 - 2014-06-22 12:41 - 523749988 _____ C:\WINDOWS\MEMORY.DMP
2016-03-03 21:59 - 2015-11-18 10:12 - 00000000 ____D C:\Users\Mohamed
2016-03-03 20:37 - 2015-10-26 07:54 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Lavasoft
2016-03-03 20:37 - 2015-10-26 07:52 - 00000000 ____D C:\ProgramData\Lavasoft
2016-03-03 20:30 - 2015-10-30 01:58 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-03-03 20:10 - 2015-10-19 04:32 - 00001424 _____ C:\Users\Mohamed\Desktop\Google Chrome.lnk
2016-03-03 20:07 - 2015-10-19 04:32 - 00001057 _____ C:\Users\Mohamed\Desktop\Internet Explorer.lnk
2016-03-03 20:07 - 2013-09-22 21:17 - 00001375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-03 19:34 - 2015-06-22 15:14 - 00000884 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core.job
2016-03-03 17:36 - 2013-06-24 12:58 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
2016-03-03 14:30 - 2015-10-30 02:54 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-03 14:30 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-26 10:25 - 2014-10-11 12:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2016-02-26 10:23 - 2015-11-18 12:02 - 00002403 _____ C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-25 20:28 - 2015-06-03 13:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-02-25 20:27 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-02-25 20:19 - 2015-01-17 12:41 - 00000000 ____D C:\Users\Mohamed\Desktop\Cuenta
2016-02-23 11:39 - 2014-05-14 13:07 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Dropbox
2016-02-11 20:31 - 2015-10-26 06:37 - 00285956 ____N C:\WINDOWS\Minidump\021116-314203-01.dmp
2016-02-07 21:04 - 2015-10-26 09:29 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\vlc
2016-02-07 19:45 - 2015-10-30 02:54 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-02-07 19:45 - 2013-04-28 00:00 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-02-05 23:12 - 2013-09-22 21:12 - 00003974 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-05 23:12 - 2013-09-22 21:12 - 00003742 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-05 22:51 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-05 22:48 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\rescache
 
==================== Files in the root of some directories =======
 
2013-10-27 20:34 - 2013-10-27 20:34 - 0011706 _____ () C:\Users\Mohamed\AppData\Roaming\unins000.dat
2013-10-27 20:34 - 2013-10-27 20:34 - 0720465 _____ () C:\Users\Mohamed\AppData\Roaming\unins000.exe
2013-08-25 23:44 - 2013-08-25 23:44 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-02-07 17:35 - 2016-02-07 17:35 - 0004881 _____ () C:\ProgramData\rxsmznjf.zcp
 
Some files in TEMP:
====================
C:\Users\Mohamed\AppData\Local\Temp\avguirn_08448574923.exe
C:\Users\Mohamed\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-02-26 10:37
 
==================== End of FRST.txt ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:02-03-2016
Ran by [removed] (2016-03-04 10:26:05)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1511 (X64) (2015-11-18 16:25:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3844031730-595245587-2132850609-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3844031730-595245587-2132850609-503 - Limited - Disabled)
Guest (S-1-5-21-3844031730-595245587-2132850609-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3844031730-595245587-2132850609-1005 - Limited - Enabled)
Mohamed (S-1-5-21-3844031730-595245587-2132850609-1001 - Administrator - Enabled) => C:\Users\Mohamed
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
Adobe Reader XI (11.0.13)  MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Akamai) (Version:  - Akamai Technologies, Inc)
Apple Application Support (32-bit) (HKLM-x32\…\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.2.6.552 - AVG Technologies)
Bing Bar (HKLM-x32\…\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Bootstrapper (x32 Version: 1.0.0.0 - Minitab, Inc.) Hidden
Cl@veDefensa del Banco de Venezuela (HKLM-x32\…\{A0753E93-0933-4adc-B357-D60699B143B2}_is1) (Version: 3.2.0.2 - )
Cl@veDefensa del Banco de Venezuela (HKLM-x32\…\Cl@veDefensa del Banco de Venezuela_is1) (Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Delta toolbar   (HKLM-x32\…\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION
Dropbox (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Dropbox) (Version: 3.14.7 - Dropbox, Inc.)
Eines de correcció del Microsoft Office 2013: català (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
eMule (HKLM-x32\…\eMule) (Version:  - )
ExpressCache (HKLM\…\{3EA6AB5D-D434-4ACA-9609-48F1319518EF}) (Version: 1.0.94 - Condusiv Technologies)
FDUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
Ferramentas de verificación de Microsoft Office 2013 - Galego (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Garmin MapSource (HKLM-x32\…\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin Training Center (HKLM-x32\…\{7D542452-84EB-47C0-97BA-735C523AB555}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\…\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
HP Deskjet 3050 J610 series Basic Device Software (HKLM\…\{6457BD83-98CF-4267-93D7-F173FF3E7C25}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Help (HKLM-x32\…\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Deskjet 3050 J610 series Product Improvement Study (HKLM\…\{5FB5B723-6B6E-45ED-BA73-F264D52AF916}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\…\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
Iminent (x32 Version: 6.25.21.0 - Iminent) Hidden <==== ATTENTION
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
iTunes (HKLM\…\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.)
Java 7 Update 9 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417009FF}) (Version: 7.0.90 - Oracle)
Java 7 Update 9 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
Kaspersky Internet Security 2013 (HKLM-x32\…\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)
Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden
K-Lite Codec Pack 11.8.5 Full (HKLM-x32\…\KLiteCodecPack_is1) (Version: 11.8.5 - KLCP)
KUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.11.163.2 - McAfee, Inc.)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visio Professional 2013 (HKLM-x32\…\Office15.VISPROR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Minitab 16 (HKLM-x32\…\Minitab16) (Version: 16.1.0 - Minitab, Inc.)
Minitab Software Update Manager (HKLM-x32\…\MinitabSoftwareManager) (Version: 1.0.0.0 - Minitab, Inc.)
Minitab16 (x32 Version: 16.1.0.0 - Minitab Inc) Hidden
Minitab16 (x32 Version: 16.1.0.0 - Minitab, Inc.) Hidden
Movavi Video Editor 11 (HKLM-x32\…\Movavi Video Editor 11) (Version: 11.2.0 - Movavi)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PlayMemories Home (HKLM-x32\…\{10DD6128-A810-4A90-9523-475D573FBB37}) (Version: 6.3.02.07270 - Sony Corporation)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.214 - Qualcomm Atheros Communications)
Rapport (x32 Version: 3.5.1507.109 - Trusteer) Hidden
Reader for PC (HKLM-x32\…\{25340F94-F74E-4CCF-ABDF-ECBCF03911BE}) (Version: 2.0.00.07121 - Sony Corporation)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6695 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.28121 - Realtek Semiconductor Corp.)
Restore (x32 Version: 1.0.0 - Sony Corporation) Hidden
Revisores de Texto do Microsoft Office 2013 – Português do Brasil (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.10 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.10.101 - Skype Technologies S.A.)
SoftwareManager (x32 Version: 1.0.0.0 - Minitab, Inc.) Hidden
SSLx64 (Version: 1.0.0 - Sony Corporation ) Hidden
SSLx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.5.0 - Synaptics Incorporated)
Trusteer Endpoint Protection (HKLM-x32\…\Rapport_msi) (Version: 3.5.1507.109 - Trusteer)
Update for Skype for Business 2015 (KB3114502) 32-Bit Edition (HKLM-x32\…\{90150000-002A-0000-1000-0000000FF1CE}_Office15.VISPROR_{B4DBD8FE-927A-4BAF-9158-D71D2EE4C00F}) (Version:  - Microsoft)
VAIO - Xperia Link (HKLM-x32\…\{D91558BF-D1F3-411F-AEFE-8774CB406512}) (Version: 1.3.3.11280 - Sony Corporation)
VAIO Care (HKLM\…\{036400BD-B717-4D50-ACDC-96480C99EDD3}) (Version: 8.4.4.09186 - Sony Corporation)
VAIO Care Recovery (HKLM\…\{15B9204E-BA09-485E-8F2C-094AC0077664}) (Version: 1.1.2.13230 - Sony Corporation)
VAIO Control Center (HKLM-x32\…\{8E797841-A110-41FD-B17A-3ABC0641187A}) (Version: 6.1.0.10300 - Sony Corporation)
VAIO CPU Fan Diagnostic (HKLM-x32\…\{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}) (Version: 1.1.0.09200 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\…\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.10.0.07270 - Sony Corporation)
VAIO Easy Connect (x32 Version: 8.4.4.07220 - Sony Corporation) Hidden
VAIO Gate Default (HKLM-x32\…\{B7546697-2A80-4256-A24B-1C33163F535B}) (Version: 3.1.0.10240 - Sony Corporation)
VAIO Gesture Control (HKLM-x32\…\{692955F2-DE9F-4078-8FAA-858D6F3A1776}) (Version: 2.1.0.10220 - Sony Corporation)
VAIO Gesture Control (x32 Version: 2.1.0.10220 - Sony Corporation) Hidden
VAIO Hardware Diagnostics Plugin for VAIO Care (HKLM-x32\…\{EC153498-00E1-4C9C-89BE-81527C6750BE}) (Version: 4.7.0.11070 - Sony Corporation)
VAIO Health Report (HKLM-x32\…\VAIO Health Report1.0) (Version: 1.0 - Sony Electronics)
VAIO Image Optimizer (HKLM-x32\…\InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}) (Version: 3.0.00.08170 - Sony Corporation)
VAIO Image Optimizer (x32 Version: 3.0.00.08170 - Sony Corporation) Hidden
VAIO Improvement (HKLM-x32\…\{3A26D9BD-0F73-432D-B522-2BA18138F7EF}) (Version: 2.1.0.10220 - Sony Corporation)
VAIO Manual (HKLM-x32\…\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}) (Version: 3.0.0.08100 - Sony Corporation)
VAIO Media Server Settings (HKLM\…\{62A172B2-550E-499D-9A82-5190D18390AA}) (Version: 1.0.1.10170 - Sony Corporation)
VAIO Movie Creator (HKLM-x32\…\InstallShield_{C2CC5822-32E6-4D21-88EA-DE8CED09EE2F}) (Version: 4.0.00.10170 - Sony Corporation)
VAIO Movie Creator (x32 Version: 4.0.00.10170 - Sony Corporation) Hidden
VAIO Movie Creator Template Data (x32 Version: 4.0.00.08170 - Sony Corporation) Hidden
VAIO Transfer Support (HKLM-x32\…\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}) (Version: 1.9.0.11060 - Sony Corporation)
VAIO Update (HKLM-x32\…\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.1.0.08060 - Sony Corporation)
VCCMMX64 (Version: 1.0.0 - Sony Corporation) Hidden
VCCMMX86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VCCx64 (Version: 1.0.0 - Sony Corporation) Hidden
VCCx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VHD (x32 Version: 1.0.0 - Sony Corporation) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VIx64 (Version: 1.0.0 - Sony Corporation) Hidden
VIx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
VMLx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VPMx64 (Version: 1.0.0 - Sony Corporation ) Hidden
VSSTx64 (Version: 1.0.0 - Sony Corporation ) Hidden
VSSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden
VWSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
Web Companion (HKLM-x32\…\{dfa2e17c-b3ae-4bd7-97c2-d25a373fe428}) (Version: 2.1.1159.2383 - Lavasoft)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (06/03/2009 2.3.0.0) (HKLM\…\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
XperiaLinkx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01E8C4D3-71CE-4AB9-A841-47602E449CF6} - System32\Tasks\Minitab\Minitab Software Update Manager => C:\Program Files (x86)\Common Files\Minitab Shared\Software Manager\SoftwareManager.exe [2010-03-25] (Minitab)
Task: {059334B1-5D47-4910-9DF2-2E5F1F66F046} - System32\Tasks\Sony Corporation\VHDInformationCheck => C:\Program Files (x86)\Sony\VAIO Recovery\plugins\InformationCheck.exe [2012-11-08] (Sony Corporation)
Task: {0B4DC8FC-BDAD-4064-8529-DC71348B0DA2} - System32\Tasks\AVG_SYS_TASK_0215pit_RUN => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
Task: {1A614C97-355C-4221-BDC7-D4B9647EF953} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {1B1EE405-ADB2-4A32-B8E1-74F6479E1477} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Month => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-09-06] (Sony Corporation)
Task: {23F700F9-3AD6-4D55-ACA6-8790D10C07A6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
Task: {25903C7C-5BDD-4B55-B241-794BAED09AA0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2BFCBD49-912A-4A29-8E8F-A3DE01FCF636} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {307C81B3-23D2-48A4-ABBB-FDEBE609B3D1} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {3CE839B7-48D9-4065-B228-23B51752BE00} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {4038D60A-67E7-4CE1-9AE6-15462FA78D59} - System32\Tasks\Sony Corporation\Xperia Link\Xperia Link Logon Start => C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe [2014-11-28] (Sony Corporation)
Task: {43F31D98-ECCC-4363-A7C0-942D92044DDE} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {4796AA0F-637C-4BD9-A388-3D8DF02C3975} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {60B7D15A-169A-427B-A753-67DF2429035D} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {612606F8-A564-4FDD-998F-19F8189CB6C6} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {66321C0C-64E6-4262-8138-24A1A446EAAE} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {679BF2BC-B190-459C-B70E-827FC91692DB} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {69993CC2-A246-4F22-93C4-147E66D44A01} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {774F71DB-0FC3-4846-B083-F389DF638D80} - System32\Tasks\StPrsSW => C:\Users\Mohamed\AppData\Roaming\StPrsSW\stprss.exe
Task: {778C9C9A-D2F0-438B-949B-163B01C99276} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {7820700A-9B7F-45FF-82E4-C34135218302} - System32\Tasks\0116tbUpdateInfo => C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe
Task: {7B320197-E3E5-4E55-B31B-0D8B272215EE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7C8E4363-DB51-45E4-A4C7-3A43E49E91F8} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-05-27] (Synaptics Incorporated)
Task: {7CF6E46E-9035-495E-8E20-6FEAE62283E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7ED2A75D-30C8-406E-9F28-E1E95E23EB61} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7ED76DB6-41DF-444D-BBEF-F68114064CD9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {817B72B9-1153-4C01-830E-FE168B2B4D95} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {877B2768-1F74-4A00-A173-57FA87DAF844} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {87F67BB8-BDA3-4D67-8998-D147D58D4937} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {8D434BA6-9AE8-44A2-B573-AE3635A38D71} - System32\Tasks\Sony Corporation\VAIO Gesture Control\VCGULogonTask => C:\Program Files (x86)\Sony\VAIO Camera Gesture Utility\VCGU.exe [2012-10-23] (Sony Corporation)
Task: {8F552644-BBED-4F26-9C62-C19ED700296F} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Daily => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-09-06] (Sony Corporation)
Task: {94040B21-D3F3-4E87-B2B5-AD3996115FAE} - System32\Tasks\Sony Corporation\VAIO Care\UpdateConfig => C:\ProgramData\Sony Corporation\VCM Data\UpdateConfig.exe [2015-03-03] (Sony Corporation)
Task: {988CD594-1CA7-4778-A7E1-36F38E7F8BD9} - System32\Tasks\Sony Corporation\VAIO Control Center\VAIOControlCenterUser => C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe [2014-11-17] (Sony Corporation)
Task: {9A89E719-D142-408F-88B7-9930A445F864} - System32\Tasks\HPCustParticipation HP Deskjet 3050 J610 series => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {9B7DEB27-1F51-41B5-B71F-762C86BFB579} - \Microsoft\Windows\Setup\xtgt\refreshxtgtconfig -> No File <==== ATTENTION
Task: {9B8E6F2A-7A65-4514-8164-3FDFB10B1923} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2015-02-04] (Sony Corporation)
Task: {9C56FE7C-0E3C-4FC5-A782-5D616C57B364} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-12] (Microsoft Corporation)
Task: {A08B941B-5850-4495-8B64-22478DA6A511} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A0D99ED2-9134-4D59-BD69-99FC40A8F7E7} - System32\Tasks\Sony Corporation\VAIO Control Center\NetworkSetting\NetworkSetting Logon Start => C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient
Task: {A72C7826-6850-4A91-99C0-3BA5989BA5B2} - System32\Tasks\Sony Corporation\VAIO Control Center\VAIOControlCenterSystem => C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe [2014-11-17] (Sony Corporation)
Task: {A98A9361-3092-4E73-9EA4-CC380F6797C5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {AAAD10C7-3583-48E6-B177-E3E6574FF4D5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {AF781C91-FBB2-4BBE-8E5F-4A84840BBD45} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2015-07-23] (Sony Corporation)
Task: {B4C0F183-2EDB-4953-A532-43D190C2EEBD} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2015-08-06] (Sony Corporation)
Task: {B6BE1946-EC3D-4489-9210-45886CBEFB02} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2012-10-22] (Sony Corporation)
Task: {C4DB7938-DD4C-4542-9B12-2685E66A4518} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {DB31E079-DE33-4E3B-9BF2-5499985493F5} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe [2015-07-31] (Sony Corporation)
Task: {DDAAB7F8-3D7F-490E-B3ED-2F5E022B94D0} - System32\Tasks\USER_ESRV_SVC => Wscript.exe //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
Task: {E282B03A-2F25-4ACC-BB16-8FBD0D44B109} - System32\Tasks\VAIO Health Report => C:\Program Files (x86)\Sony\VAIO Health Report\VAIOHealthReport.exe [2013-06-20] (Sony Electronics)
Task: {E6FE04D1-8BD8-4B33-B4B4-7A604FF955E6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {E90C368E-05E9-4A42-8EF1-1321D428AFB8} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {E9125151-377A-4DCB-B066-20E63E6470DF} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2015-07-31] (Sony Corporation)
Task: {F3167AEB-B03E-4CAF-9F09-F7DC8FF3448B} - System32\Tasks\Sony Corporation\VAIO Care\ActiveStatusCollect => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {FEB4F95B-C5B9-4274-A133-09CF447B557A} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core.job => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA.job => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-30 02:48 - 2015-10-30 02:48 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-10-12 23:15 - 2015-10-12 23:15 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-12 23:15 - 2015-10-12 23:15 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00413336 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
2015-08-26 13:11 - 2015-08-26 13:11 - 00709272 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_modeler.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00130712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_process_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00025752 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_system_power_state_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00059544 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_quality_and_reliability_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00194712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\acpi_battery_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00159896 _____ () C:\Program Files\Sony\VAIO Care\ESRV\sema_thermal_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00158360 _____ () C:\Program Files\Sony\VAIO Care\ESRV\wifi_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00050840 _____ () C:\Program Files\Sony\VAIO Care\ESRV\devices_use_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00032920 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_disktrace_input.dll
2015-12-03 04:55 - 2015-11-22 06:17 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 04:55 - 2015-11-22 06:17 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2016-02-02 23:35 - 2016-02-02 23:39 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-01-12 15:07 - 2015-12-06 23:44 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-01-12 15:07 - 2015-12-06 23:30 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-12 15:08 - 2016-01-04 20:59 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-12 15:08 - 2016-01-04 20:53 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-31 14:30 - 2016-01-16 00:40 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-31 14:30 - 2016-01-16 00:43 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-01-12 15:08 - 2016-01-04 20:54 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00458904 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
2015-08-26 13:11 - 2015-08-26 13:11 - 00185496 _____ () C:\Program Files\Sony\VAIO Care\ESRV\foreground_window_input.dll
2016-02-02 23:35 - 2016-02-02 23:39 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-02-02 23:35 - 2016-02-02 23:39 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-07-21 16:02 - 2015-07-21 16:02 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\bancodevenezuela.com -> www.bancodevenezuela.com
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\banvenez.com -> e-bdv.banvenez.com
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\banvenez.corp -> e-bdvscn.banvenez.corp
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\localhost -> localhost
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2012-07-26 00:56 - 2015-09-04 03:35 - 00000856 ____N C:\WINDOWS\system32\Drivers\etc\hosts
 
0.0.0.1 mssplus.mcafee.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Sony\VAIO 11 img1 Wallpaper 1366x768.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: RapportMgmtService => 2
MSCONFIG\Services: SampleCollector => 2
MSCONFIG\Services: SearchProtectionService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: SOHCImp => 3
MSCONFIG\Services: SOHDms => 3
MSCONFIG\Services: SOHDs => 3
MSCONFIG\Services: Sony SCSI Helper Service => 3
MSCONFIG\Services: SpfService => 3
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: VAIO Event Service => 2
MSCONFIG\Services: VAIO Power Management => 3
MSCONFIG\Services: VCFw => 3
MSCONFIG\Services: VCService => 3
MSCONFIG\Services: vToolbarUpdater40.1.8 => 2
MSCONFIG\Services: VUAgent => 3
MSCONFIG\Services: WtuSystemSupport => 2
MSCONFIG\Services: ZAtheros Bt and Wlan Coex Agent => 2
HKLM\…\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
HKLM\…\StartupApproved\Run: => "BtTray"
HKLM\…\StartupApproved\Run: => "BtvStack"
HKLM\…\StartupApproved\Run: => "HotKeysCmds"
HKLM\…\StartupApproved\Run: => "Persistence"
HKLM\…\StartupApproved\Run: => "IgfxTray"
HKLM\…\StartupApproved\Run32: => "Adobe ARM"
HKLM\…\StartupApproved\Run32: => "ATUninstallIcon"
HKLM\…\StartupApproved\Run32: => "ATLauncher"
HKLM\…\StartupApproved\Run32: => "HP Software Update"
HKLM\…\StartupApproved\Run32: => "IminentMessenger"
HKLM\…\StartupApproved\Run32: => "Iminent"
HKLM\…\StartupApproved\Run32: => "ISBMgr.exe"
HKLM\…\StartupApproved\Run32: => "PMBVolumeWatcher"
HKLM\…\StartupApproved\Run32: => "BCSSync"
HKLM\…\StartupApproved\Run32: => "vProt"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\StartupFolder: => "Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Akamai NetSession Interface"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "HP Deskjet 3050 J610 series (NET)"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Web Companion"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5A7B768E-A3B6-45BA-A7EF-BE9A5A78A9BB}] => (Allow) C:\Program Files\Sony\VAIO Care\VAIOShell.exe
FirewallRules: [{5255C25F-CF98-4572-8328-3950CB5DD17A}] => (Allow) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
FirewallRules: [{83A1058E-99E5-420F-A596-512C714C7ABD}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAdmin.exe
FirewallRules: [{F2550089-5D57-45CE-9B8F-F051F5DB64F9}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAgent.exe
FirewallRules: [{ECF65DB4-DB74-41E5-BC91-39B4613BF219}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{9D17CFB5-F059-44F6-B4C2-E84F715D94AF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{306E741B-0BF4-48B6-8E82-29C1C2305554}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{7246312F-41FD-492B-9169-A4FE9CE7AD4A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{0C20D46A-89A2-4644-8A82-7593266157D2}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D6D027DA-8710-4AA8-BD0A-226F29859DA0}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8BBCFE44-A535-40E9-A361-A9515802C70A}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{7C4685B1-6A2B-4F0E-B9ED-61D9F5317593}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F1B5556B-08BF-420F-9C75-E5D78CDE7ABC}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{75980B65-F094-42C2-AC90-C5E26F87B123}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [UDP Query User{55529703-E018-4A66-AC81-5E8BD86EBC0B}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{6B042536-B865-48AD-87C2-8587D989830E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{F7C075B2-86A2-42F2-AFE1-850750B72DA0}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{9B99E1EB-B508-4688-8DCE-637388839E52}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{29CB40BD-523F-4F08-9C88-72163697D36B}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe
FirewallRules: [{957EFFE1-4D66-4494-A9EE-213494C5B368}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{C878EB33-BAF3-4F8B-9CB9-272F994D0A7D}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{44127511-CF27-48DE-9583-1958A39F985B}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{D70CF496-D40E-42A5-BF03-0F7B21155187}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{880103C5-AA49-492D-9529-BFFBAC464723}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{D41CCDEE-E619-4455-87DF-0E1813EF630A}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [{8370D6FD-057F-4F0C-BED6-13371AFF45FC}] => (Allow) C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{8EDEE1C8-2FA5-4A4B-B156-C8608718DA8F}] => (Allow) C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{B9245E71-B7E3-47A6-B0E6-6B0B3672D62E}C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{03B456A9-5351-44E6-96C0-FF7312CF541E}C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{A44FC839-B42D-4D54-ABD7-991622D25887}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe
FirewallRules: [{9F6D9876-3F1A-41A3-A9D4-CDF020EB6753}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{0C61DA2E-1D6C-4B65-B115-89306A8505DA}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{2EF696F4-B9CE-4878-A0D7-C674DDEC40DF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{59273D93-240F-47DB-8B8F-D5BB7DFA44EF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A494D966-54C4-4BC8-9DFD-EA220FC5AB1E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E46AB6F8-7E00-423E-A86F-E33B617278F9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F3C639F4-AE6D-4691-AE68-510AE9689708}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{65F8552F-6714-4852-9340-54EE2342AB1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{E730E30E-580E-475A-9266-C29527C28FD4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{3296E763-B5E2-464D-A16C-C85793837FAC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{23A36BF3-185D-4490-8A11-29893A53736D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{18701A33-5F97-416D-859B-A76BE195ED88}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{00FE0603-F42A-4C79-9F2E-DE8F997C4C31}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{17F07D65-1176-4321-88BA-6466B9C89351}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{3A97DA7C-6BEE-4956-A763-01CF376F5855}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{E1478880-C245-4AB0-BF65-6F31EE28B817}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9AFC3DD0-BE6C-44B9-A6F5-7D2EE733103C}] => (Allow) LPort=2869
FirewallRules: [{D027D31C-9509-4AD8-9477-463533807A9B}] => (Allow) LPort=1900
FirewallRules: [{661A1F9A-20EC-440B-A585-A1FC1B932DA5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
23-02-2016 11:00:11 Scheduled Checkpoint
26-02-2016 10:22:12 Installed Rapport
03-03-2016 20:35:19 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/04/2016 09:28:23 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SkypeHost.exe, version: 10.1.2123.10, time stamp: 0x569054dc
Faulting module name: SkyWrap.dll, version: 10.1.2123.10, time stamp: 0x569054c9
Exception code: 0xc0000005
Fault offset: 0x00ac6197
Faulting process id: 0x163c
Faulting application start time: 0xSkypeHost.exe0
Faulting application path: SkypeHost.exe1
Faulting module path: SkypeHost.exe2
Report Id: SkypeHost.exe3
Faulting package full name: SkypeHost.exe4
Faulting package-relative application ID: SkypeHost.exe5
 
Error: (03/03/2016 08:41:31 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8
 
Error: (03/03/2016 08:35:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/03/2016 08:07:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: adwcleaner_5.037.exe, version: 5.0.3.7, time stamp: 0x56d37200
Faulting module name: adwcleaner_5.037.exe, version: 5.0.3.7, time stamp: 0x56d37200
Exception code: 0xc0000005
Fault offset: 0x00020fea
Faulting process id: 0x36ec
Faulting application start time: 0xadwcleaner_5.037.exe0
Faulting application path: adwcleaner_5.037.exe1
Faulting module path: adwcleaner_5.037.exe2
Report Id: adwcleaner_5.037.exe3
Faulting package full name: adwcleaner_5.037.exe4
Faulting package-relative application ID: adwcleaner_5.037.exe5
 
Error: (03/03/2016 02:17:08 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
 
Error: (02/29/2016 11:01:10 AM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
 
Error: (02/29/2016 11:01:08 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8
 
Error: (02/29/2016 10:40:59 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VAIO)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147023170 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (02/29/2016 10:40:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SearchUI.exe, version: 10.0.10586.63, time stamp: 0x568b1fdc
Faulting module name: Windows.UI.Xaml.dll, version: 10.0.10586.71, time stamp: 0x5699d8e0
Exception code: 0xc000027b
Fault offset: 0x00000000006fce8b
Faulting process id: 0x181c
Faulting application start time: 0xSearchUI.exe0
Faulting application path: SearchUI.exe1
Faulting module path: SearchUI.exe2
Report Id: SearchUI.exe3
Faulting package full name: SearchUI.exe4
Faulting package-relative application ID: SearchUI.exe5
 
Error: (02/29/2016 10:27:49 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: VAIO)
Description: Package Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe+MicrosoftEdge was terminated because it took too long to suspend.
 
 
System errors:
=============
Error: (03/04/2016 10:23:04 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}
 
Error: (03/04/2016 10:22:15 AM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 10:22:15 AM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 10:21:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (03/04/2016 10:20:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: 
%%1068
 
Error: (03/04/2016 10:20:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Function Discovery Resource Publication service depends on the HTTP service which failed to start because of the following error: 
%%2
 
Error: (03/04/2016 10:20:21 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Function Discovery Provider Host service depends on the HTTP service which failed to start because of the following error: 
%%2
 
Error: (03/04/2016 10:20:21 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HTTP service failed to start due to the following error: 
%%2
 
Error: (03/04/2016 10:12:37 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The SSDP Discovery service depends on the HTTP service which failed to start because of the following error: 
%%2
 
Error: (03/04/2016 10:12:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HTTP service failed to start due to the following error: 
%%2
 
 
CodeIntegrity:
===================================
  Date: 2016-03-03 20:27:33.588
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:33.579
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:33.289
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:33.279
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:28.941
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:28.928
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 19:42:37.666
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 19:42:37.638
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 17:37:18.631
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 17:37:18.622
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-3337U CPU @ 1.80GHz
Percentage of memory in use: 33%
Total physical RAM: 6023.27 MB
Available physical RAM: 4013.06 MB
Total Virtual: 12167.27 MB
Available Virtual: 10230.48 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:441.14 GB) (Free:246.74 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 195C4519)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

You still have 2 antiviruses running; Kaspersky Internet Security and Windows Defender.

If you paid for Kaspersky and therefore want to keep it, you need to disable Windows Defender and Windows firewall.

Turn Windows Defender On or Off in Windows 10

Turning Windows 10 Firewall on or off

===================================================

P2P - I see you have P2P software, (uTorrent and emule ), installed on your machine.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

P2P File Sharing Risks.

I would strongly recommend that you uninstall them now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep them, please don’t use them until we have finished up here.

===================================================

You also have illegal software on your system and, as your computer is quite infected, this is probably how it became that way.

 

Besides being illegal, cracks/keygens are the most certain means of infecting your system, as ALL illegal software contains some form of malicious code.

This forum, as well as all the other well-respected malware removal forums, does not condone the use of illegal software and does not offer support unless it is for the removal of it: continuing to help you could be viewed as supporting/condoning illegal software.

Therefore, if you require further help I need you to uninstall all the illegal software that you have downloaded and installed and then do the following:

Download CKScanner by askey127 from here & save it to your Desktop.

  • double-click CKScanner.exe then click Search For Files
  • when the cursor hourglass disappears, click Save List To File
  • a message box will verify the file saved
  • double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply.

If you are unwilling to do this I'm afraid that no more help can be offered.

 

If I don’t hear back from you within 24 hours, this thread will be closed

Satchfan

OK StachFan,

 

I want to clean this laptop. Im not the only one that uses this laptop, I have younger brothers that used it too… SO yes I will like to clean all Illegal software on my system so please can you point out exactly which programs are those…. or what about a hard drive format?… I dodn't reemeber anyone paying for the kaspersky so i will delete it and stay with the window defender, and i will delete the P2P software you mentioned… but again can you please point out the illegal software in my machine so i can delete all of them, or do you think a full format will be a better option? Thank you…

Im not the only one that uses this laptop, I have younger brothers that used it too

 

 

I understand. It's something that you must tell your younger brothers not to do as young people can be the worst offenders when allowing or encouraging infections.

 

do you think a full format will be a better option?

 

That shouldn't be necessary - we'll get it cleaned up.

 

Please uninstall the following:

Movavi Video Editor 11
Bing Bar


When you’ve done that, please run CKScanner and post the log.

 

================================================

Please also run FRST again and make sure there is a checkmark next to "Addition.txt" before you hit “Scan”.

Logs to include with next post:

CKFiles.txt
New Frst.txt
New Addition.txt


Thanks

 

Have to go out for a while now but will check back later.

 

Satchfan

OK Satchfan, thank you for your support and time.

 

I uninstalled KAsperSky since i dont remember anyone paying for it… I turned on Windows defender and firewall…

 

P2P programs Utorrent and Emule, are out…. I also deleted the programs you told me about:  Movavi Video Editor and Bing Bar.

 

Below are the logs you asked for:

 

CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
c:\users\mohamed\downloads\movavi_video_editor_10_activation_key_plus_crack_full_free.iso
scanner sequence 3.NA.11.WMAPXZ
 —– EOF —– 
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:04-03-2016
Ran by [removed] (administrator) on VAIO (04-03-2016 18:06:39)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Lavasoft Limited) C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(IBM Corp.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
() C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe
() C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-09-20] (Realtek Semiconductor)
HKLM\…\Run: [BtTray] => "C:\Program Files (x86)\Bluetooth Suite\BtTray.exe"
HKLM\…\Run: [BtvStack] => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3928264 2015-05-27] (Synaptics Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-15] (Apple Inc.)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [68776 2012-08-18] (Sony Corporation)
HKLM-x32\…\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [724576 2012-07-27] (Sony Corporation)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [ATLauncher] => "C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe" /createshortcuts:1
HKLM-x32\…\Run: [ATUninstallIcon] => "C:\Program Files\McAfeeEx\McAfeeAntiTheft\ATLauncher.exe" /createuninstallentry:1
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
Winlogon\Notify\ GbPluginBdv: C:\Program Files (x86)\GbPlugin\gbiehBdv.dll [2015-12-23] (Banco de Venezuela)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [HP Deskjet 3050 J610 series (NET)] => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Akamai NetSession Interface] => C:\Users\Mohamed\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Dropbox Update] => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-22] (Dropbox, Inc.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [57987712 2015-09-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe –minimize
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\RunOnce: [Uninstall C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399026} - C:\Program Files (x86)\GbPlugin\gbiehbdv.dll [1864800 2015-12-23] (Banco de Venezuela)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-09-04]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-10-27]
ShortcutTarget: Dropbox.lnk -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk [2015-06-03]
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk -> C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
BootExecute: autocheck autochk * 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
AutoConfigURL: [S-1-5-21-3844031730-595245587-2132850609-1001] => hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{8e600265-fef9-4bc5-915b-46b09da7aa5b}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{95b7ca61-94ac-4fcc-b000-6961f24fe53a}: [DhcpNameServer] 192.168.0.1
ManualProxies: 0hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
 
Internet Explorer:
==================
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony13.msn.com
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc;=UE01&ocid;=UE01DHP
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2012-12-11] (Oracle Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-11-05] (Qualcomm Atheros Commnucations)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-11-10] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-12-11] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-12-11] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540026} -> C:\Program Files (x86)\GbPlugin\gbiehbdv.dll [2015-12-23] (Banco de Venezuela)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-12-11] (Oracle Corporation)
DPF: HKLM-x32 {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\system32\npDeployJava1.dll [2012-12-11] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2012-12-11] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-12-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2012-12-11] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @sony.com/ReaderDesktop -> C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll [2012-07-12] (Sony Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3844031730-595245587-2132850609-1001: gastecnologia.com.br/sf/bdv -> C:\Users\Mohamed\AppData\Local\GAS Tecnologia\GBBD\npsf_bdv.dll [2013-08-16] (GAS Tecnologia)
 
Chrome: 
=======
CHR HomePage: Profile 1 -> hxxp://www.yoursearching.com/?type=hp&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx
CHR StartupUrls: Profile 1 -> "hxxp://www.yoursearching.com/?type=hp&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx"
CHR DefaultSearchURL: Profile 1 -> hxxp://yoursearching.com/web/?type=ds&ts;=1454888552&z;=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from;=exp1&uid;=hitachixhts545050a7e380_121026ta85113vj98mnnx&q;={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> yoursearching
CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Docs) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-30]
CHR Extension: (Google Search) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Google Docs Offline) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Skype) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-26]
CHR Extension: (GBBD Cl@veDefensa del Banco de Venezuela) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\odifdffdmeannfboglpliamjmoggdmci [2015-01-17]
CHR Extension: (Gmail) - C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKU\S-1-5-21-3844031730-595245587-2132850609-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3844031730-595245587-2132850609-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [odifdffdmeannfboglpliamjmoggdmci] - C:\Users\Mohamed\AppData\Local\GAS Tecnologia\GBBD\bdv\sf.crx [2013-10-27]
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [102224 2012-08-17] (Condusiv Technologies)
R2 GbpSv; C:\Program Files (x86)\GbPlugin\GbpSv.exe [593120 2015-11-19] (GAS Tecnologia)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation)
R2 LavasoftTcpService; C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751760 2015-10-26] (Lavasoft Limited)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [289256 2015-07-31] (McAfee, Inc.)
S3 NetworkSupport; C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe [625240 2013-09-28] (Sony Corporation)
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [474208 2012-07-27] (Sony Corporation)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2266160 2016-02-01] (IBM Corp.)
S4 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2012-09-19] (Sony Corporation) [File not signed]
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [964608 2012-09-28] (Sony Corporation) [File not signed]
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1653272 2015-07-31] (Sony Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S4 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-11-05] (Atheros) [File not signed]
S4 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [X]
S2 WtuSystemSupport; "C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe" [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23376 2012-08-17] (Condusiv Technologies)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [103248 2012-08-17] (Condusiv Technologies)
R1 RapportCerberus_1507079; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1507079.sys [961880 2015-12-02] (IBM Corp.)
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [514336 2016-02-01] (IBM Corp.)
R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [152320 2016-02-01] (IBM Corp.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [407168 2016-02-01] (IBM Corp.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [507424 2016-02-01] (IBM Corp.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [29352 2015-11-17] ()
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-05-27] (Synaptics Incorporated)
R3 SOWS; C:\Windows\System32\drivers\sows.sys [24280 2012-06-10] (Sony Corporation)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-01-14] (Anchorfree Inc.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 HTTP; system32\drivers\HTTP.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-04 18:06 - 2016-03-04 18:06 - 00000000 ____D C:\Users\Mohamed\Desktop\FRST-OlderVersion
2016-03-04 18:03 - 2016-03-04 18:03 - 00000218 _____ C:\Users\Mohamed\Desktop\ckfiles.txt
2016-03-04 17:57 - 2016-03-04 17:58 - 00468480 _____ () C:\Users\Mohamed\Desktop\CKScanner.exe
2016-03-04 17:57 - 2016-03-04 17:57 - 00468480 _____ () C:\Users\Mohamed\Downloads\CKScanner.exe
2016-03-04 17:54 - 2016-03-04 17:54 - 00000000 ___HD C:\OneDriveTemp
2016-03-04 17:34 - 2016-03-04 17:34 - 00000016 _____ C:\ProgramData\mntemp
2016-03-04 10:24 - 2016-03-04 18:07 - 00024892 _____ C:\Users\Mohamed\Desktop\FRST.txt
2016-03-04 09:51 - 2016-03-04 10:21 - 00000000 ____D C:\AVG_Remover
2016-03-04 09:51 - 2016-03-04 09:51 - 08065568 _____ ( ) C:\Users\Mohamed\Downloads\AVG_Remover.exe
2016-03-04 08:58 - 2016-03-04 08:59 - 01294460 _____ C:\WINDOWS\Minidump\030416-302093-01.dmp
2016-03-03 20:57 - 2016-03-03 20:57 - 00000842 _____ C:\Users\Mohamed\Desktop\checkup.txt
2016-03-03 20:54 - 2016-03-03 20:55 - 00852798 _____ C:\Users\Mohamed\Desktop\SecurityCheck.exe
2016-03-03 20:54 - 2016-03-03 20:54 - 00852798 _____ C:\Users\Mohamed\Downloads\SecurityCheck.exe
2016-03-03 20:38 - 2016-03-03 20:38 - 00001607 _____ C:\Users\Mohamed\Desktop\JRT.txt
2016-03-03 20:29 - 2016-03-03 20:33 - 01609216 _____ (Malwarebytes) C:\Users\Mohamed\Desktop\JRT.exe
2016-03-03 20:28 - 2016-03-03 20:28 - 01609216 _____ (Malwarebytes) C:\Users\Mohamed\Downloads\JRT.exe
2016-03-03 20:26 - 2016-03-03 20:26 - 00002987 _____ C:\Users\Mohamed\Desktop\AdwCleaner[C2].txt
2016-03-03 19:41 - 2016-03-03 20:18 - 00000000 ____D C:\AdwCleaner
2016-03-03 19:41 - 2016-03-03 19:41 - 01518592 _____ C:\Users\Mohamed\Desktop\adwcleaner_5.037.exe
2016-03-03 19:40 - 2016-03-03 19:40 - 01518592 _____ C:\Users\Mohamed\Downloads\adwcleaner_5.037.exe
2016-03-03 19:40 - 2016-03-03 19:40 - 01518592 _____ C:\Users\Mohamed\Downloads\adwcleaner_5.037 (1).exe
2016-03-03 14:38 - 2016-03-04 18:06 - 00000000 ____D C:\FRST
2016-03-03 14:34 - 2016-03-04 18:06 - 02374144 _____ (Farbar) C:\Users\Mohamed\Desktop\FRST64.exe
2016-03-03 14:34 - 2016-03-03 14:34 - 02371584 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST64.exe
2016-03-03 14:32 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST.exe
2016-03-03 14:32 - 2016-03-03 14:32 - 01722368 _____ (Farbar) C:\Users\Mohamed\Downloads\FRST (1).exe
2016-03-03 13:31 - 2016-03-03 13:34 - 00840956 _____ C:\WINDOWS\Minidump\030316-304625-01.dmp
2016-02-29 10:27 - 2016-02-29 10:27 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday (2).xls
2016-02-29 10:26 - 2016-02-29 10:26 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday.xls
2016-02-29 10:26 - 2016-02-29 10:26 - 00038565 _____ C:\Users\Mohamed\Downloads\dolartoday (1).xls
2016-02-29 10:13 - 2016-02-29 10:15 - 01592300 _____ C:\WINDOWS\Minidump\022916-295703-01.dmp
2016-02-23 11:39 - 2016-02-23 11:39 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-02-23 10:29 - 2016-02-23 10:30 - 00849748 _____ C:\WINDOWS\Minidump\022316-302218-01.dmp
2016-02-07 21:18 - 2016-02-07 21:18 - 09846564 _____ C:\Users\Mohamed\Desktop\3.mp4
2016-02-07 21:10 - 2015-05-08 03:18 - 53059755 _____ C:\Users\Mohamed\Desktop\IMG_4839.MOV
2016-02-07 20:40 - 2016-02-07 20:40 - 10365693 _____ C:\Users\Mohamed\Desktop\Burj 2.mp4
2016-02-07 20:33 - 2016-02-07 20:34 - 08754364 _____ C:\Users\Mohamed\Desktop\Burj 1.mp4
2016-02-07 20:20 - 2016-02-07 20:21 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2016-02-07 20:20 - 2016-02-07 20:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2016-02-07 20:04 - 2016-02-07 20:19 - 38248161 _____ (KLCP ) C:\Users\Mohamed\Downloads\K-Lite_Codec_Pack_1185_Full.exe
2016-02-07 19:46 - 2016-02-07 19:46 - 00001447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2016-02-07 19:46 - 2016-02-07 19:46 - 00001378 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2016-02-07 19:46 - 2016-02-07 19:46 - 00000000 ____D C:\WINDOWS\en
2016-02-07 19:44 - 2016-02-07 19:45 - 00000000 ____D C:\Program Files (x86)\Windows Live
2016-02-07 19:44 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2016-02-07 19:44 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2016-02-07 19:44 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2016-02-07 19:44 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2016-02-07 19:44 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2016-02-07 19:44 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2016-02-07 19:44 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2016-02-07 19:44 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2016-02-07 19:44 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2016-02-07 19:42 - 2016-02-07 19:57 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Windows Live
2016-02-07 19:42 - 2016-02-07 19:42 - 01239752 _____ (Microsoft Corporation) C:\Users\Mohamed\Downloads\wlsetup-web.exe
2016-02-07 19:12 - 2016-02-07 19:12 - 00000351 _____ C:\prefs.js
2016-02-07 19:10 - 2016-02-07 19:10 - 04458496 _____ C:\Users\Mohamed\Downloads\Movavi_Video_Editor_10_Activation_Key_plus_Crack_Full_Free.iso
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\VideoEditor
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Movavi
2016-02-07 17:35 - 2016-02-07 17:35 - 00004881 _____ C:\ProgramData\rxsmznjf.zcp
2016-02-07 17:35 - 2016-02-07 17:35 - 00000000 ____D C:\ProgramData\Movavi Video Editor 11
2016-02-07 17:31 - 2016-02-07 17:35 - 73093984 _____ (Movavi) C:\Users\Mohamed\Downloads\MovaviVideoEditorSetupC.exe
2016-02-07 17:24 - 2015-05-10 15:51 - 65098242 _____ C:\Users\Mohamed\Desktop\IMG_4971.MOV
2016-02-07 17:24 - 2015-05-10 15:50 - 130348697 _____ C:\Users\Mohamed\Desktop\IMG_4970.MOV
2016-02-07 17:11 - 2016-02-07 17:12 - 01394860 _____ C:\WINDOWS\Minidump\020716-304281-01.dmp
2016-02-05 22:13 - 2016-02-05 22:14 - 01339012 _____ C:\WINDOWS\Minidump\020516-296562-01.dmp
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-04 17:58 - 2015-11-18 10:38 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-04 17:58 - 2015-10-30 02:51 - 00000000 ____D C:\WINDOWS\INF
2016-03-04 17:56 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-04 17:54 - 2015-11-18 12:02 - 00000000 ___RD C:\Users\Mohamed\OneDrive
2016-03-04 17:53 - 2013-09-22 21:12 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-04 17:52 - 2014-11-09 11:50 - 00000000 __SHD C:\Users\Mohamed\IntelGraphicsProfiles
2016-03-04 17:50 - 2015-11-18 10:43 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-04 17:45 - 2015-10-30 01:58 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2016-03-04 17:42 - 2015-10-30 02:54 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-03-04 17:41 - 2015-11-18 12:00 - 00000000 ____D C:\Users\DefaultAccount
2016-03-04 17:41 - 2015-11-18 06:34 - 00000000 ____D C:\Users\HomeGroupUser$
2016-03-04 17:41 - 2015-11-18 06:34 - 00000000 ____D C:\Users\Guest
2016-03-04 17:41 - 2015-11-18 06:34 - 00000000 ____D C:\Users\Administrator
2016-03-04 17:41 - 2013-08-22 09:06 - 00000000 ____D C:\Users\Default.migrated
2016-03-04 17:38 - 2014-11-05 16:35 - 00000000 ____D C:\ProgramData\eMule
2016-03-04 17:34 - 2015-06-22 15:14 - 00000936 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA.job
2016-03-04 17:17 - 2013-09-22 21:12 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-04 15:05 - 2014-11-15 08:55 - 00004002 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{AECFECB3-D89E-470B-B66F-3EF265E05FF0}
2016-03-04 10:43 - 2014-03-25 23:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-03-04 10:28 - 2015-10-30 02:54 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-04 10:05 - 2015-10-27 04:12 - 00000000 ____D C:\ProgramData\Avg
2016-03-04 10:03 - 2015-06-19 03:57 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Avg
2016-03-04 10:01 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-03-04 10:01 - 2015-06-03 12:39 - 00000000 ____D C:\Program Files (x86)\AVG
2016-03-04 09:55 - 2015-10-27 04:24 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\AVG
2016-03-04 09:55 - 2015-06-21 05:23 - 00000000 ____D C:\Program Files\Common Files\AV
2016-03-04 08:58 - 2015-11-19 04:32 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-04 08:58 - 2014-06-22 12:41 - 523749988 _____ C:\WINDOWS\MEMORY.DMP
2016-03-03 21:59 - 2015-11-18 10:12 - 00000000 ____D C:\Users\Mohamed
2016-03-03 20:37 - 2015-10-26 07:54 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Lavasoft
2016-03-03 20:37 - 2015-10-26 07:52 - 00000000 ____D C:\ProgramData\Lavasoft
2016-03-03 20:30 - 2015-10-30 01:58 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-03-03 20:10 - 2015-10-19 04:32 - 00001424 _____ C:\Users\Mohamed\Desktop\Google Chrome.lnk
2016-03-03 20:07 - 2015-10-19 04:32 - 00001057 _____ C:\Users\Mohamed\Desktop\Internet Explorer.lnk
2016-03-03 20:07 - 2013-09-22 21:17 - 00001375 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-03 19:34 - 2015-06-22 15:14 - 00000884 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core.job
2016-03-03 17:36 - 2013-06-24 12:58 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
2016-02-26 10:25 - 2014-10-11 12:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2016-02-26 10:23 - 2015-11-18 12:02 - 00002403 _____ C:\Users\Mohamed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-25 20:28 - 2015-06-03 13:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-02-25 20:27 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-02-25 20:19 - 2015-01-17 12:41 - 00000000 ____D C:\Users\Mohamed\Desktop\Cuenta
2016-02-23 11:39 - 2014-05-14 13:07 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\Dropbox
2016-02-11 20:31 - 2015-10-26 06:37 - 00285956 ____N C:\WINDOWS\Minidump\021116-314203-01.dmp
2016-02-07 21:04 - 2015-10-26 09:29 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\vlc
2016-02-07 19:45 - 2015-10-30 02:54 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-02-07 19:45 - 2013-04-28 00:00 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-02-05 23:12 - 2013-09-22 21:12 - 00003974 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-05 23:12 - 2013-09-22 21:12 - 00003742 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-05 22:51 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-05 22:48 - 2015-10-30 02:54 - 00000000 ____D C:\WINDOWS\rescache
 
==================== Files in the root of some directories =======
 
2013-10-27 20:34 - 2013-10-27 20:34 - 0011706 _____ () C:\Users\Mohamed\AppData\Roaming\unins000.dat
2013-10-27 20:34 - 2013-10-27 20:34 - 0720465 _____ () C:\Users\Mohamed\AppData\Roaming\unins000.exe
2013-08-25 23:44 - 2013-08-25 23:44 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-03-04 17:34 - 2016-03-04 17:34 - 0000016 _____ () C:\ProgramData\mntemp
2016-02-07 17:35 - 2016-02-07 17:35 - 0004881 _____ () C:\ProgramData\rxsmznjf.zcp
 
Some files in TEMP:
====================
C:\Users\Mohamed\AppData\Local\Temp\avguirn_08448574923.exe
C:\Users\Mohamed\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-02-26 10:37
 
==================== End of FRST.txt ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:04-03-2016
Ran by [removed] (2016-03-04 18:08:04)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1511 (X64) (2015-11-18 16:25:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3844031730-595245587-2132850609-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3844031730-595245587-2132850609-503 - Limited - Disabled)
Guest (S-1-5-21-3844031730-595245587-2132850609-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3844031730-595245587-2132850609-1005 - Limited - Enabled)
Mohamed (S-1-5-21-3844031730-595245587-2132850609-1001 - Administrator - Enabled) => C:\Users\Mohamed
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Reader XI (11.0.13)  MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Akamai) (Version:  - Akamai Technologies, Inc)
Apple Application Support (32-bit) (HKLM-x32\…\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.2.6.552 - AVG Technologies)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Bootstrapper (x32 Version: 1.0.0.0 - Minitab, Inc.) Hidden
Cl@veDefensa del Banco de Venezuela (HKLM-x32\…\{A0753E93-0933-4adc-B357-D60699B143B2}_is1) (Version: 3.2.0.2 - )
Cl@veDefensa del Banco de Venezuela (HKLM-x32\…\Cl@veDefensa del Banco de Venezuela_is1) (Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Delta toolbar   (HKLM-x32\…\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION
Dropbox (HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\Dropbox) (Version: 3.14.7 - Dropbox, Inc.)
Eines de correcció del Microsoft Office 2013: català (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
ExpressCache (HKLM\…\{3EA6AB5D-D434-4ACA-9609-48F1319518EF}) (Version: 1.0.94 - Condusiv Technologies)
FDUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
Ferramentas de verificación de Microsoft Office 2013 - Galego (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Garmin MapSource (HKLM-x32\…\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries)
Garmin Training Center (HKLM-x32\…\{7D542452-84EB-47C0-97BA-735C523AB555}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\…\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
HP Deskjet 3050 J610 series Basic Device Software (HKLM\…\{6457BD83-98CF-4267-93D7-F173FF3E7C25}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3050 J610 series Help (HKLM-x32\…\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}) (Version: 140.0.63.63 - Hewlett Packard)
HP Deskjet 3050 J610 series Product Improvement Study (HKLM\…\{5FB5B723-6B6E-45ED-BA73-F264D52AF916}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\…\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
Iminent (x32 Version: 6.25.21.0 - Iminent) Hidden <==== ATTENTION
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
iTunes (HKLM\…\{E690A491-702F-4DEC-9977-C015D1DBB57C}) (Version: 12.3.1.23 - Apple Inc.)
Java 7 Update 9 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86417009FF}) (Version: 7.0.90 - Oracle)
Java 7 Update 9 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217009FF}) (Version: 7.0.90 - Oracle)
K-Lite Codec Pack 11.8.5 Full (HKLM-x32\…\KLiteCodecPack_is1) (Version: 11.8.5 - KLCP)
KUx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
McAfee Security Scan Plus (HKLM\…\McAfee Security Scan) (Version: 3.11.163.2 - McAfee, Inc.)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visio Professional 2013 (HKLM-x32\…\Office15.VISPROR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Minitab 16 (HKLM-x32\…\Minitab16) (Version: 16.1.0 - Minitab, Inc.)
Minitab Software Update Manager (HKLM-x32\…\MinitabSoftwareManager) (Version: 1.0.0.0 - Minitab, Inc.)
Minitab16 (x32 Version: 16.1.0.0 - Minitab Inc) Hidden
Minitab16 (x32 Version: 16.1.0.0 - Minitab, Inc.) Hidden
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PlayMemories Home (HKLM-x32\…\{10DD6128-A810-4A90-9523-475D573FBB37}) (Version: 6.3.02.07270 - Sony Corporation)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.214 - Qualcomm Atheros Communications)
Rapport (x32 Version: 3.5.1507.109 - Trusteer) Hidden
Reader for PC (HKLM-x32\…\{25340F94-F74E-4CCF-ABDF-ECBCF03911BE}) (Version: 2.0.00.07121 - Sony Corporation)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6695 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.28121 - Realtek Semiconductor Corp.)
Restore (x32 Version: 1.0.0 - Sony Corporation) Hidden
Revisores de Texto do Microsoft Office 2013 – Português do Brasil (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.10 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.10.101 - Skype Technologies S.A.)
SoftwareManager (x32 Version: 1.0.0.0 - Minitab, Inc.) Hidden
SSLx64 (Version: 1.0.0 - Sony Corporation ) Hidden
SSLx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.5.0 - Synaptics Incorporated)
Trusteer Endpoint Protection (HKLM-x32\…\Rapport_msi) (Version: 3.5.1507.109 - Trusteer)
Update for Skype for Business 2015 (KB3114502) 32-Bit Edition (HKLM-x32\…\{90150000-002A-0000-1000-0000000FF1CE}_Office15.VISPROR_{B4DBD8FE-927A-4BAF-9158-D71D2EE4C00F}) (Version:  - Microsoft)
VAIO - Xperia Link (HKLM-x32\…\{D91558BF-D1F3-411F-AEFE-8774CB406512}) (Version: 1.3.3.11280 - Sony Corporation)
VAIO Care (HKLM\…\{036400BD-B717-4D50-ACDC-96480C99EDD3}) (Version: 8.4.4.09186 - Sony Corporation)
VAIO Care Recovery (HKLM\…\{15B9204E-BA09-485E-8F2C-094AC0077664}) (Version: 1.1.2.13230 - Sony Corporation)
VAIO Control Center (HKLM-x32\…\{8E797841-A110-41FD-B17A-3ABC0641187A}) (Version: 6.1.0.10300 - Sony Corporation)
VAIO CPU Fan Diagnostic (HKLM-x32\…\{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}) (Version: 1.1.0.09200 - Sony Corporation)
VAIO Data Restore Tool (HKLM-x32\…\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.10.0.07270 - Sony Corporation)
VAIO Easy Connect (x32 Version: 8.4.4.07220 - Sony Corporation) Hidden
VAIO Gate Default (HKLM-x32\…\{B7546697-2A80-4256-A24B-1C33163F535B}) (Version: 3.1.0.10240 - Sony Corporation)
VAIO Gesture Control (HKLM-x32\…\{692955F2-DE9F-4078-8FAA-858D6F3A1776}) (Version: 2.1.0.10220 - Sony Corporation)
VAIO Gesture Control (x32 Version: 2.1.0.10220 - Sony Corporation) Hidden
VAIO Hardware Diagnostics Plugin for VAIO Care (HKLM-x32\…\{EC153498-00E1-4C9C-89BE-81527C6750BE}) (Version: 4.7.0.11070 - Sony Corporation)
VAIO Health Report (HKLM-x32\…\VAIO Health Report1.0) (Version: 1.0 - Sony Electronics)
VAIO Image Optimizer (HKLM-x32\…\InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}) (Version: 3.0.00.08170 - Sony Corporation)
VAIO Image Optimizer (x32 Version: 3.0.00.08170 - Sony Corporation) Hidden
VAIO Improvement (HKLM-x32\…\{3A26D9BD-0F73-432D-B522-2BA18138F7EF}) (Version: 2.1.0.10220 - Sony Corporation)
VAIO Manual (HKLM-x32\…\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}) (Version: 3.0.0.08100 - Sony Corporation)
VAIO Media Server Settings (HKLM\…\{62A172B2-550E-499D-9A82-5190D18390AA}) (Version: 1.0.1.10170 - Sony Corporation)
VAIO Movie Creator (HKLM-x32\…\InstallShield_{C2CC5822-32E6-4D21-88EA-DE8CED09EE2F}) (Version: 4.0.00.10170 - Sony Corporation)
VAIO Movie Creator (x32 Version: 4.0.00.10170 - Sony Corporation) Hidden
VAIO Movie Creator Template Data (x32 Version: 4.0.00.08170 - Sony Corporation) Hidden
VAIO Transfer Support (HKLM-x32\…\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}) (Version: 1.9.0.11060 - Sony Corporation)
VAIO Update (HKLM-x32\…\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.1.0.08060 - Sony Corporation)
VCCMMX64 (Version: 1.0.0 - Sony Corporation) Hidden
VCCMMX86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VCCx64 (Version: 1.0.0 - Sony Corporation) Hidden
VCCx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VHD (x32 Version: 1.0.0 - Sony Corporation) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VIx64 (Version: 1.0.0 - Sony Corporation) Hidden
VIx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
VMLx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VPMx64 (Version: 1.0.0 - Sony Corporation ) Hidden
VSSTx64 (Version: 1.0.0 - Sony Corporation ) Hidden
VSSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden
VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden
VWSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
Web Companion (HKLM-x32\…\{dfa2e17c-b3ae-4bd7-97c2-d25a373fe428}) (Version: 2.1.1159.2383 - Lavasoft)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (06/03/2009 2.3.0.0) (HKLM\…\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
XperiaLinkx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Mohamed\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3844031730-595245587-2132850609-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01E8C4D3-71CE-4AB9-A841-47602E449CF6} - System32\Tasks\Minitab\Minitab Software Update Manager => C:\Program Files (x86)\Common Files\Minitab Shared\Software Manager\SoftwareManager.exe [2010-03-25] (Minitab)
Task: {059334B1-5D47-4910-9DF2-2E5F1F66F046} - System32\Tasks\Sony Corporation\VHDInformationCheck => C:\Program Files (x86)\Sony\VAIO Recovery\plugins\InformationCheck.exe [2012-11-08] (Sony Corporation)
Task: {0B4DC8FC-BDAD-4064-8529-DC71348B0DA2} - System32\Tasks\AVG_SYS_TASK_0215pit_RUN => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
Task: {1A614C97-355C-4221-BDC7-D4B9647EF953} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {1B1EE405-ADB2-4A32-B8E1-74F6479E1477} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Month => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-09-06] (Sony Corporation)
Task: {23F700F9-3AD6-4D55-ACA6-8790D10C07A6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-26] (Apple Inc.)
Task: {25903C7C-5BDD-4B55-B241-794BAED09AA0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2722471B-95AB-4157-9621-16D3EFB21A93} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-12] (Microsoft Corporation)
Task: {2BFCBD49-912A-4A29-8E8F-A3DE01FCF636} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {307C81B3-23D2-48A4-ABBB-FDEBE609B3D1} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {3CE839B7-48D9-4065-B228-23B51752BE00} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {4038D60A-67E7-4CE1-9AE6-15462FA78D59} - System32\Tasks\Sony Corporation\Xperia Link\Xperia Link Logon Start => C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe [2014-11-28] (Sony Corporation)
Task: {43F31D98-ECCC-4363-A7C0-942D92044DDE} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {4796AA0F-637C-4BD9-A388-3D8DF02C3975} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {48067897-B1A7-402A-89FC-343759A521C8} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2015-08-06] (Sony Corporation)
Task: {60B7D15A-169A-427B-A753-67DF2429035D} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {612606F8-A564-4FDD-998F-19F8189CB6C6} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {66321C0C-64E6-4262-8138-24A1A446EAAE} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {679BF2BC-B190-459C-B70E-827FC91692DB} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {69993CC2-A246-4F22-93C4-147E66D44A01} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {774F71DB-0FC3-4846-B083-F389DF638D80} - System32\Tasks\StPrsSW => C:\Users\Mohamed\AppData\Roaming\StPrsSW\stprss.exe
Task: {778C9C9A-D2F0-438B-949B-163B01C99276} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {7820700A-9B7F-45FF-82E4-C34135218302} - System32\Tasks\0116tbUpdateInfo => C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe
Task: {7B320197-E3E5-4E55-B31B-0D8B272215EE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7C8E4363-DB51-45E4-A4C7-3A43E49E91F8} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-05-27] (Synaptics Incorporated)
Task: {7CF6E46E-9035-495E-8E20-6FEAE62283E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7ED2A75D-30C8-406E-9F28-E1E95E23EB61} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7ED76DB6-41DF-444D-BBEF-F68114064CD9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {817B72B9-1153-4C01-830E-FE168B2B4D95} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {877B2768-1F74-4A00-A173-57FA87DAF844} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {87F67BB8-BDA3-4D67-8998-D147D58D4937} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {8D434BA6-9AE8-44A2-B573-AE3635A38D71} - System32\Tasks\Sony Corporation\VAIO Gesture Control\VCGULogonTask => C:\Program Files (x86)\Sony\VAIO Camera Gesture Utility\VCGU.exe [2012-10-23] (Sony Corporation)
Task: {8F552644-BBED-4F26-9C62-C19ED700296F} - System32\Tasks\Sony Corporation\VAIO Control Center\Level4Daily => C:\Program Files (x86)\Sony\VAIO Control Center\WBCBatteryCare.exe [2012-09-06] (Sony Corporation)
Task: {94040B21-D3F3-4E87-B2B5-AD3996115FAE} - System32\Tasks\Sony Corporation\VAIO Care\UpdateConfig => C:\ProgramData\Sony Corporation\VCM Data\UpdateConfig.exe [2015-03-03] (Sony Corporation)
Task: {988CD594-1CA7-4778-A7E1-36F38E7F8BD9} - System32\Tasks\Sony Corporation\VAIO Control Center\VAIOControlCenterUser => C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe [2014-11-17] (Sony Corporation)
Task: {9A89E719-D142-408F-88B7-9930A445F864} - System32\Tasks\HPCustParticipation HP Deskjet 3050 J610 series => C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {9B7DEB27-1F51-41B5-B71F-762C86BFB579} - \Microsoft\Windows\Setup\xtgt\refreshxtgtconfig -> No File <==== ATTENTION
Task: {9B8E6F2A-7A65-4514-8164-3FDFB10B1923} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2015-02-04] (Sony Corporation)
Task: {A08B941B-5850-4495-8B64-22478DA6A511} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A0D99ED2-9134-4D59-BD69-99FC40A8F7E7} - System32\Tasks\Sony Corporation\VAIO Control Center\NetworkSetting\NetworkSetting Logon Start => C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkClient
Task: {A72C7826-6850-4A91-99C0-3BA5989BA5B2} - System32\Tasks\Sony Corporation\VAIO Control Center\VAIOControlCenterSystem => C:\Program Files (x86)\Sony\VAIO Control Center\vim.exe [2014-11-17] (Sony Corporation)
Task: {A98A9361-3092-4E73-9EA4-CC380F6797C5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {AAAD10C7-3583-48E6-B177-E3E6574FF4D5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {AF781C91-FBB2-4BBE-8E5F-4A84840BBD45} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2015-07-23] (Sony Corporation)
Task: {B6BE1946-EC3D-4489-9210-45886CBEFB02} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2012-10-22] (Sony Corporation)
Task: {C4DB7938-DD4C-4542-9B12-2685E66A4518} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {DB31E079-DE33-4E3B-9BF2-5499985493F5} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe [2015-07-31] (Sony Corporation)
Task: {DDAAB7F8-3D7F-490E-B3ED-2F5E022B94D0} - System32\Tasks\USER_ESRV_SVC => Wscript.exe //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
Task: {E282B03A-2F25-4ACC-BB16-8FBD0D44B109} - System32\Tasks\VAIO Health Report => C:\Program Files (x86)\Sony\VAIO Health Report\VAIOHealthReport.exe [2013-06-20] (Sony Electronics)
Task: {E6FE04D1-8BD8-4B33-B4B4-7A604FF955E6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {E90C368E-05E9-4A42-8EF1-1321D428AFB8} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-22] (Dropbox, Inc.)
Task: {E9125151-377A-4DCB-B066-20E63E6470DF} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2015-07-31] (Sony Corporation)
Task: {F3167AEB-B03E-4CAF-9F09-F7DC8FF3448B} - System32\Tasks\Sony Corporation\VAIO Care\ActiveStatusCollect => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {FEB4F95B-C5B9-4274-A133-09CF447B557A} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001Core.job => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-3844031730-595245587-2132850609-1001UA.job => C:\Users\Mohamed\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-30 02:48 - 2015-10-30 02:48 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-10-12 23:15 - 2015-10-12 23:15 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-12 23:15 - 2015-10-12 23:15 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-12-03 04:55 - 2015-11-22 06:17 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 04:55 - 2015-11-22 06:17 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2016-01-12 15:07 - 2015-12-06 23:44 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-01-12 15:07 - 2015-12-06 23:30 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-12 15:08 - 2016-01-04 20:59 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-12 15:08 - 2016-01-04 20:53 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-31 14:30 - 2016-01-16 00:40 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-31 14:30 - 2016-01-16 00:43 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-01-12 15:08 - 2016-01-04 20:54 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-02-02 23:35 - 2016-02-02 23:39 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-08-26 13:11 - 2015-08-26 13:11 - 00413336 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
2015-08-26 13:11 - 2015-08-26 13:11 - 00709272 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_modeler.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00130712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_process_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00025752 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_system_power_state_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00059544 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_quality_and_reliability_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00194712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\acpi_battery_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00159896 _____ () C:\Program Files\Sony\VAIO Care\ESRV\sema_thermal_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00158360 _____ () C:\Program Files\Sony\VAIO Care\ESRV\wifi_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00050840 _____ () C:\Program Files\Sony\VAIO Care\ESRV\devices_use_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00032920 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_disktrace_input.dll
2015-08-26 13:11 - 2015-08-26 13:11 - 00458904 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv.exe
2015-08-26 13:11 - 2015-08-26 13:11 - 00185496 _____ () C:\Program Files\Sony\VAIO Care\ESRV\foreground_window_input.dll
2016-02-02 23:35 - 2016-02-02 23:39 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-02-02 23:35 - 2016-02-02 23:39 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-07-21 16:02 - 2015-07-21 16:02 - 00557056 _____ () C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll
2016-02-23 11:22 - 2016-02-17 23:44 - 01630360 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libglesv2.dll
2016-02-23 11:22 - 2016-02-17 23:44 - 00085656 _____ () C:\Program Files (x86)\Google\Chrome\Application\48.0.2564.116\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\bancodevenezuela.com -> www.bancodevenezuela.com
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\banvenez.com -> e-bdv.banvenez.com
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\banvenez.corp -> e-bdvscn.banvenez.corp
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\localhost -> localhost
IE trusted site: HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2012-07-26 00:56 - 2015-09-04 03:35 - 00000856 ____N C:\WINDOWS\system32\Drivers\etc\hosts
 
0.0.0.1 mssplus.mcafee.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Sony\VAIO 11 img1 Wallpaper 1366x768.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: RapportMgmtService => 2
MSCONFIG\Services: SampleCollector => 2
MSCONFIG\Services: SearchProtectionService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: SOHCImp => 3
MSCONFIG\Services: SOHDms => 3
MSCONFIG\Services: SOHDs => 3
MSCONFIG\Services: Sony SCSI Helper Service => 3
MSCONFIG\Services: SpfService => 3
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: VAIO Event Service => 2
MSCONFIG\Services: VAIO Power Management => 3
MSCONFIG\Services: VCFw => 3
MSCONFIG\Services: VCService => 3
MSCONFIG\Services: vToolbarUpdater40.1.8 => 2
MSCONFIG\Services: VUAgent => 3
MSCONFIG\Services: WtuSystemSupport => 2
MSCONFIG\Services: ZAtheros Bt and Wlan Coex Agent => 2
HKLM\…\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
HKLM\…\StartupApproved\Run: => "BtTray"
HKLM\…\StartupApproved\Run: => "BtvStack"
HKLM\…\StartupApproved\Run: => "HotKeysCmds"
HKLM\…\StartupApproved\Run: => "Persistence"
HKLM\…\StartupApproved\Run: => "IgfxTray"
HKLM\…\StartupApproved\Run32: => "Adobe ARM"
HKLM\…\StartupApproved\Run32: => "ATUninstallIcon"
HKLM\…\StartupApproved\Run32: => "ATLauncher"
HKLM\…\StartupApproved\Run32: => "HP Software Update"
HKLM\…\StartupApproved\Run32: => "IminentMessenger"
HKLM\…\StartupApproved\Run32: => "Iminent"
HKLM\…\StartupApproved\Run32: => "ISBMgr.exe"
HKLM\…\StartupApproved\Run32: => "PMBVolumeWatcher"
HKLM\…\StartupApproved\Run32: => "BCSSync"
HKLM\…\StartupApproved\Run32: => "vProt"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\StartupFolder: => "Monitor Ink Alerts - HP Deskjet 3050 J610 series (Network).lnk"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Akamai NetSession Interface"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Dropbox Update"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "HP Deskjet 3050 J610 series (NET)"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\…\StartupApproved\Run: => "Web Companion"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5A7B768E-A3B6-45BA-A7EF-BE9A5A78A9BB}] => (Allow) C:\Program Files\Sony\VAIO Care\VAIOShell.exe
FirewallRules: [{5255C25F-CF98-4572-8328-3950CB5DD17A}] => (Allow) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
FirewallRules: [{83A1058E-99E5-420F-A596-512C714C7ABD}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAdmin.exe
FirewallRules: [{F2550089-5D57-45CE-9B8F-F051F5DB64F9}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAgent.exe
FirewallRules: [{ECF65DB4-DB74-41E5-BC91-39B4613BF219}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{9D17CFB5-F059-44F6-B4C2-E84F715D94AF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{306E741B-0BF4-48B6-8E82-29C1C2305554}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{7246312F-41FD-492B-9169-A4FE9CE7AD4A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{D6D027DA-8710-4AA8-BD0A-226F29859DA0}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8BBCFE44-A535-40E9-A361-A9515802C70A}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [UDP Query User{55529703-E018-4A66-AC81-5E8BD86EBC0B}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{6B042536-B865-48AD-87C2-8587D989830E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{F7C075B2-86A2-42F2-AFE1-850750B72DA0}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{9B99E1EB-B508-4688-8DCE-637388839E52}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{29CB40BD-523F-4F08-9C88-72163697D36B}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe
FirewallRules: [{957EFFE1-4D66-4494-A9EE-213494C5B368}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{C878EB33-BAF3-4F8B-9CB9-272F994D0A7D}] => (Allow) C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{44127511-CF27-48DE-9583-1958A39F985B}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{D70CF496-D40E-42A5-BF03-0F7B21155187}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{880103C5-AA49-492D-9529-BFFBAC464723}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{D41CCDEE-E619-4455-87DF-0E1813EF630A}C:\users\mohamed\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\mohamed\appdata\local\akamai\netsession_win.exe
FirewallRules: [{8370D6FD-057F-4F0C-BED6-13371AFF45FC}] => (Allow) C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{8EDEE1C8-2FA5-4A4B-B156-C8608718DA8F}] => (Allow) C:\Users\Mohamed\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{B9245E71-B7E3-47A6-B0E6-6B0B3672D62E}C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{03B456A9-5351-44E6-96C0-FF7312CF541E}C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\mohamed\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{A44FC839-B42D-4D54-ABD7-991622D25887}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe
FirewallRules: [{9F6D9876-3F1A-41A3-A9D4-CDF020EB6753}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{0C61DA2E-1D6C-4B65-B115-89306A8505DA}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{2EF696F4-B9CE-4878-A0D7-C674DDEC40DF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{59273D93-240F-47DB-8B8F-D5BB7DFA44EF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A494D966-54C4-4BC8-9DFD-EA220FC5AB1E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E46AB6F8-7E00-423E-A86F-E33B617278F9}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F3C639F4-AE6D-4691-AE68-510AE9689708}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{65F8552F-6714-4852-9340-54EE2342AB1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{E730E30E-580E-475A-9266-C29527C28FD4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{3296E763-B5E2-464D-A16C-C85793837FAC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{23A36BF3-185D-4490-8A11-29893A53736D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{18701A33-5F97-416D-859B-A76BE195ED88}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{00FE0603-F42A-4C79-9F2E-DE8F997C4C31}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{17F07D65-1176-4321-88BA-6466B9C89351}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{3A97DA7C-6BEE-4956-A763-01CF376F5855}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{E1478880-C245-4AB0-BF65-6F31EE28B817}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9AFC3DD0-BE6C-44B9-A6F5-7D2EE733103C}] => (Allow) LPort=2869
FirewallRules: [{D027D31C-9509-4AD8-9477-463533807A9B}] => (Allow) LPort=1900
FirewallRules: [{661A1F9A-20EC-440B-A585-A1FC1B932DA5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
23-02-2016 11:00:11 Scheduled Checkpoint
26-02-2016 10:22:12 Installed Rapport
03-03-2016 20:35:19 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/04/2016 05:44:24 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: VAIO)
Description: App Microsoft.MicrosoftEdge_25.10586.0.0_neutral__8wekyb3d8bbwe+MicrosoftEdge did not launch within its allotted time.
 
Error: (03/04/2016 02:45:43 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
 
Error: (03/04/2016 12:43:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: VAIO)
Description: Activation of app KasperskyLab.KasperskyNow_8jx5e25qw3tdc!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/04/2016 12:43:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Kav.Metro.exe version 1.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1d7c
 
Start Time: 01d1763913bd0089
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\KasperskyLab.KasperskyNow_1.0.0.43_neutral__8jx5e25qw3tdc\Kav.Metro.exe
 
Report Id: 5bb7fcd4-e22c-11e5-8033-a41731d66686
 
Faulting package full name: KasperskyLab.KasperskyNow_1.0.0.43_neutral__8jx5e25qw3tdc
 
Faulting package-relative application ID: App
 
Error: (03/04/2016 09:28:23 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SkypeHost.exe, version: 10.1.2123.10, time stamp: 0x569054dc
Faulting module name: SkyWrap.dll, version: 10.1.2123.10, time stamp: 0x569054c9
Exception code: 0xc0000005
Fault offset: 0x00ac6197
Faulting process id: 0x163c
Faulting application start time: 0xSkypeHost.exe0
Faulting application path: SkypeHost.exe1
Faulting module path: SkypeHost.exe2
Report Id: SkypeHost.exe3
Faulting package full name: SkypeHost.exe4
Faulting package-relative application ID: SkypeHost.exe5
 
Error: (03/03/2016 08:41:31 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8
 
Error: (03/03/2016 08:35:34 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/03/2016 08:07:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: adwcleaner_5.037.exe, version: 5.0.3.7, time stamp: 0x56d37200
Faulting module name: adwcleaner_5.037.exe, version: 5.0.3.7, time stamp: 0x56d37200
Exception code: 0xc0000005
Fault offset: 0x00020fea
Faulting process id: 0x36ec
Faulting application start time: 0xadwcleaner_5.037.exe0
Faulting application path: adwcleaner_5.037.exe1
Faulting module path: adwcleaner_5.037.exe2
Report Id: adwcleaner_5.037.exe3
Faulting package full name: adwcleaner_5.037.exe4
Faulting package-relative application ID: adwcleaner_5.037.exe5
 
Error: (03/03/2016 02:17:08 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
 
Error: (02/29/2016 11:01:10 AM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
 
 
System errors:
=============
Error: (03/04/2016 06:03:27 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 06:03:27 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 05:55:30 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 05:55:30 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 05:55:30 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 05:55:29 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 05:55:29 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 05:55:28 PM) (Source: DCOM) (EventID: 10016) (User: VAIO)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}VAIOMohamedS-1-5-21-3844031730-595245587-2132850609-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (03/04/2016 05:54:52 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}
 
Error: (03/04/2016 05:54:06 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The SSDP Discovery service depends on the HTTP service which failed to start because of the following error: 
%%2
 
 
CodeIntegrity:
===================================
  Date: 2016-03-04 18:02:27.144
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-04 10:43:41.507
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume5\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:33.588
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:33.579
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:33.289
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:33.279
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:28.941
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 20:27:28.928
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 19:42:37.666
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-03 19:42:37.638
  Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\AVG\Av\avgidsagent.exe) attempted to load \Device\HarddiskVolume5\Program Files (x86)\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-3337U CPU @ 1.80GHz
Percentage of memory in use: 39%
Total physical RAM: 6023.27 MB
Available physical RAM: 3659.82 MB
Total Virtual: 12167.27 MB
Available Virtual: 9859.51 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:441.14 GB) (Free:247.49 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 195C4519)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

There is still a sign of illegal software on your computer.

 

Don't bother about it too much. I'll look at the other logs tomorrow and send instructions as soon as I can.

 

We'll get it dealt with. :)

 

Satchfan

Thanks for your patience.
 

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
AutoConfigURL: [S-1-5-21-3844031730-595245587-2132850609-1001] => hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
ManualProxies: 0hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
CHR HomePage: Profile 1 -> hxxp://www.yoursearching.com/?type=hp&ts=1454888552&z=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from=exp1&uid=hitachixhts545050a7e380_121026ta85113vj98mnnx
CHR StartupUrls: Profile 1 -> "hxxp://www.yoursearching.com/?type=hp&ts=1454888552&z=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from=exp1&uid=hitachixhts545050a7e380_121026ta85113vj98mnnx"
CHR DefaultSearchURL: Profile 1 -> hxxp://yoursearching.com/web/?type=ds&ts=1454888552&z=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from=exp1&uid=hitachixhts545050a7e380_121026ta85113vj98mnnx&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> yoursearching
CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1
S4 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [X]
S2 WtuSystemSupport; "C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe" [X]
S3 HTTP; system32\drivers\HTTP.sys [X]
2016-03-04 09:51 - 2016-03-04 10:21 - 00000000 ____D C:\AVG_Remover
2016-03-04 09:51 - 2016-03-04 09:51 - 08065568 _____ ( ) C:\Users\Mohamed\Downloads\AVG_Remover.exe
2016-02-07 21:10 - 2015-05-08 03:18 - 53059755 _____ C:\Users\Mohamed\Desktop\IMG_4839.MOV
2016-02-07 19:10 - 2016-02-07 19:10 - 04458496 _____ C:\Users\Mohamed\Downloads\Movavi_Video_Editor_10_Activation_Key_plus_Crack_Full_Free.iso
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\VideoEditor
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Movavi
2016-02-07 17:35 - 2016-02-07 17:35 - 00004881 _____ C:\ProgramData\rxsmznjf.zcp
2016-02-07 17:35 - 2016-02-07 17:35 - 00000000 ____D C:\ProgramData\Movavi Video Editor 11
2016-02-07 17:31 - 2016-02-07 17:35 - 73093984 _____ (Movavi) C:\Users\Mohamed\Downloads\MovaviVideoEditorSetupC.exe
2016-02-07 17:24 - 2015-05-10 15:51 - 65098242 _____ C:\Users\Mohamed\Desktop\IMG_4971.MOV
2016-02-07 17:24 - 2015-05-10 15:50 - 130348697 _____ C:\Users\Mohamed\Desktop\IMG_4970.MOV
2016-03-04 17:38 - 2014-11-05 16:35 - 00000000 ____D C:\ProgramData\eMule
2016-03-04 10:05 - 2015-10-27 04:12 - 00000000 ____D C:\ProgramData\Avg
2016-03-04 10:03 - 2015-06-19 03:57 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Avg
2016-03-04 10:01 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-03-04 10:01 - 2015-06-03 12:39 - 00000000 ____D C:\Program Files (x86)\AVG
2016-03-04 09:55 - 2015-10-27 04:24 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\AVG
2016-03-04 09:55 - 2015-06-21 05:23 - 00000000 ____D C:\Program Files\Common Files\AV
2016-03-03 17:36 - 2013-06-24 12:58 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
2016-02-25 20:28 - 2015-06-03 13:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-02-25 20:27 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-03-04 17:34 - 2016-03-04 17:34 - 0000016 _____ () C:\ProgramData\mntemp
2016-02-07 17:35 - 2016-02-07 17:35 - 0004881 _____ () C:\ProgramData\rxsmznjf.zcp
C:\Users\Mohamed\AppData\Local\Temp\avguirn_08448574923.exe
Delta toolbar   (HKLM-x32\…\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION
Iminent (x32 Version: 6.25.21.0 - Iminent) Hidden <==== ATTENTION
Movavi Video Editor 11 (HKLM-x32\…\Movavi Video Editor 11) (Version: 11.2.0 - Movavi)
Task: {0B4DC8FC-BDAD-4064-8529-DC71348B0DA2} - System32\Tasks\AVG_SYS_TASK_0215pit_RUN => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
Task: {25903C7C-5BDD-4B55-B241-794BAED09AA0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2BFCBD49-912A-4A29-8E8F-A3DE01FCF636} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {4796AA0F-637C-4BD9-A388-3D8DF02C3975} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {69993CC2-A246-4F22-93C4-147E66D44A01} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {774F71DB-0FC3-4846-B083-F389DF638D80} - System32\Tasks\StPrsSW => C:\Users\Mohamed\AppData\Roaming\StPrsSW\stprss.exe
Task: {7820700A-9B7F-45FF-82E4-C34135218302} - System32\Tasks\0116tbUpdateInfo => C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe
Task: {7B320197-E3E5-4E55-B31B-0D8B272215EE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7CF6E46E-9035-495E-8E20-6FEAE62283E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7ED2A75D-30C8-406E-9F28-E1E95E23EB61} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7ED76DB6-41DF-444D-BBEF-F68114064CD9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {817B72B9-1153-4C01-830E-FE168B2B4D95} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {877B2768-1F74-4A00-A173-57FA87DAF844} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9B7DEB27-1F51-41B5-B71F-762C86BFB579} - \Microsoft\Windows\Setup\xtgt\refreshxtgtconfig -> No File <==== ATTENTION
Task: {A08B941B-5850-4495-8B64-22478DA6A511} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
FirewallRules: [{ECF65DB4-DB74-41E5-BC91-39B4613BF219}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{9D17CFB5-F059-44F6-B4C2-E84F715D94AF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{306E741B-0BF4-48B6-8E82-29C1C2305554}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{7246312F-41FD-492B-9169-A4FE9CE7AD4A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{D6D027DA-8710-4AA8-BD0A-226F29859DA0}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8BBCFE44-A535-40E9-A361-A9515802C70A}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{A44FC839-B42D-4D54-ABD7-991622D25887}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe
FirewallRules: [{9F6D9876-3F1A-41A3-A9D4-CDF020EB6753}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{0C61DA2E-1D6C-4B65-B115-89306A8505DA}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{65F8552F-6714-4852-9340-54EE2342AB1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{E730E30E-580E-475A-9266-C29527C28FD4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{3296E763-B5E2-464D-A16C-C85793837FAC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{23A36BF3-185D-4490-8A11-29893A53736D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{18701A33-5F97-416D-859B-A76BE195ED88}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{00FE0603-F42A-4C79-9F2E-DE8F997C4C31}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{17F07D65-1176-4321-88BA-6466B9C89351}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{3A97DA7C-6BEE-4956-A763-01CF376F5855}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
C:\Users\Mohamed\AppData\Roaming\StPrsSW
C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe
C:\Users\Mohamed\AppData\Roaming\uTorrent
C:\Users\Mohamed\AppData\Roaming\uTorrent
C:\program files (x86)\emule
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

================================================

Uninstall programs

Uninstall the following programs:


Delta toolbar
Iminent



===================================================

Let’s have a look with a different tool.

Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.

  • on Windows Vista, 7/8, 10 right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    createsrpoint;
    autoclean;
    emptyalltemp;
    CHRdefaults;
    iedefaults;
    FFdefaults;
    resetIEproxy;
    uninstall-list;
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

Logs to include with next post:

Fixlog.txt
zoek-results.log


Thanks

Satchfan

OK Satchfan,

 

I deleted Delta bar, but when I tried to delete Iminent i couldn't, a massage will display saying already a session exists giving me just an 'ok' option….but when finished running all the programs you told me it doesn't appear anymore in the programs list…

 

Below are the logs you asked for:

 

Fix result of Farbar Recovery Scan Tool (x64) Version:04-03-2016
Ran by [removed] (2016-03-05 08:48:14) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe" /lps=fmw
AutoConfigURL: [S-1-5-21-3844031730-595245587-2132850609-1001] => hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
ManualProxies: 0hxxp://stop-block.org/wpad.dat?f04d6d01f43a0374fc9838069f19d5645879404
CHR HomePage: Profile 1 -> hxxp://www.yoursearching.com/?type=hp&ts=1454888552&z=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from=exp1&uid=hitachixhts545050a7e380_121026ta85113vj98mnnx
CHR StartupUrls: Profile 1 -> "hxxp://www.yoursearching.com/?type=hp&ts=1454888552&z=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from=exp1&uid=hitachixhts545050a7e380_121026ta85113vj98mnnx"
CHR DefaultSearchURL: Profile 1 -> hxxp://yoursearching.com/web/?type=ds&ts=1454888552&z=e52d2d9ecf5f7de3a8065bcg8z3wdzbb4b3bcw1weo&from=exp1&uid=hitachixhts545050a7e380_121026ta85113vj98mnnx&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> yoursearching
CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1
S4 SearchProtectionService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.WinService.exe [X]
S2 WtuSystemSupport; "C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe" [X]
S3 HTTP; system32\drivers\HTTP.sys [X]
2016-03-04 09:51 - 2016-03-04 10:21 - 00000000 ____D C:\AVG_Remover
2016-03-04 09:51 - 2016-03-04 09:51 - 08065568 _____ ( ) C:\Users\Mohamed\Downloads\AVG_Remover.exe
2016-02-07 21:10 - 2015-05-08 03:18 - 53059755 _____ C:\Users\Mohamed\Desktop\IMG_4839.MOV
2016-02-07 19:10 - 2016-02-07 19:10 - 04458496 _____ C:\Users\Mohamed\Downloads\Movavi_Video_Editor_10_Activation_Key_plus_Crack_Full_Free.iso
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\VideoEditor
2016-02-07 17:37 - 2016-02-07 17:37 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Movavi
2016-02-07 17:35 - 2016-02-07 17:35 - 00004881 _____ C:\ProgramData\rxsmznjf.zcp
2016-02-07 17:35 - 2016-02-07 17:35 - 00000000 ____D C:\ProgramData\Movavi Video Editor 11
2016-02-07 17:31 - 2016-02-07 17:35 - 73093984 _____ (Movavi) C:\Users\Mohamed\Downloads\MovaviVideoEditorSetupC.exe
2016-02-07 17:24 - 2015-05-10 15:51 - 65098242 _____ C:\Users\Mohamed\Desktop\IMG_4971.MOV
2016-02-07 17:24 - 2015-05-10 15:50 - 130348697 _____ C:\Users\Mohamed\Desktop\IMG_4970.MOV
2016-03-04 17:38 - 2014-11-05 16:35 - 00000000 ____D C:\ProgramData\eMule
2016-03-04 10:05 - 2015-10-27 04:12 - 00000000 ____D C:\ProgramData\Avg
2016-03-04 10:03 - 2015-06-19 03:57 - 00000000 ____D C:\Users\Mohamed\AppData\Local\Avg
2016-03-04 10:01 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-03-04 10:01 - 2015-06-03 12:39 - 00000000 ____D C:\Program Files (x86)\AVG
2016-03-04 09:55 - 2015-10-27 04:24 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\AVG
2016-03-04 09:55 - 2015-06-21 05:23 - 00000000 ____D C:\Program Files\Common Files\AV
2016-03-03 17:36 - 2013-06-24 12:58 - 00000000 ____D C:\Users\Mohamed\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
2016-02-25 20:28 - 2015-06-03 13:26 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-02-25 20:27 - 2015-06-03 13:26 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-03-04 17:34 - 2016-03-04 17:34 - 0000016 _____ () C:\ProgramData\mntemp
2016-02-07 17:35 - 2016-02-07 17:35 - 0004881 _____ () C:\ProgramData\rxsmznjf.zcp
C:\Users\Mohamed\AppData\Local\Temp\avguirn_08448574923.exe
Delta toolbar   (HKLM-x32\…\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION
Iminent (x32 Version: 6.25.21.0 - Iminent) Hidden <==== ATTENTION
Movavi Video Editor 11 (HKLM-x32\…\Movavi Video Editor 11) (Version: 11.2.0 - Movavi)
Task: {0B4DC8FC-BDAD-4064-8529-DC71348B0DA2} - System32\Tasks\AVG_SYS_TASK_0215pit_RUN => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
Task: {25903C7C-5BDD-4B55-B241-794BAED09AA0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {2BFCBD49-912A-4A29-8E8F-A3DE01FCF636} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {4796AA0F-637C-4BD9-A388-3D8DF02C3975} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {69993CC2-A246-4F22-93C4-147E66D44A01} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {774F71DB-0FC3-4846-B083-F389DF638D80} - System32\Tasks\StPrsSW => C:\Users\Mohamed\AppData\Roaming\StPrsSW\stprss.exe
Task: {7820700A-9B7F-45FF-82E4-C34135218302} - System32\Tasks\0116tbUpdateInfo => C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe
Task: {7B320197-E3E5-4E55-B31B-0D8B272215EE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7CF6E46E-9035-495E-8E20-6FEAE62283E2} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7ED2A75D-30C8-406E-9F28-E1E95E23EB61} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7ED76DB6-41DF-444D-BBEF-F68114064CD9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {817B72B9-1153-4C01-830E-FE168B2B4D95} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {877B2768-1F74-4A00-A173-57FA87DAF844} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9B7DEB27-1F51-41B5-B71F-762C86BFB579} - \Microsoft\Windows\Setup\xtgt\refreshxtgtconfig -> No File <==== ATTENTION
Task: {A08B941B-5850-4495-8B64-22478DA6A511} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
FirewallRules: [{ECF65DB4-DB74-41E5-BC91-39B4613BF219}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{9D17CFB5-F059-44F6-B4C2-E84F715D94AF}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{306E741B-0BF4-48B6-8E82-29C1C2305554}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{7246312F-41FD-492B-9169-A4FE9CE7AD4A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{D6D027DA-8710-4AA8-BD0A-226F29859DA0}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8BBCFE44-A535-40E9-A361-A9515802C70A}] => (Allow) C:\Users\Mohamed\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{A44FC839-B42D-4D54-ABD7-991622D25887}C:\program files (x86)\emule\emule.exe] => (Allow) C:\program files (x86)\emule\emule.exe
FirewallRules: [{9F6D9876-3F1A-41A3-A9D4-CDF020EB6753}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{0C61DA2E-1D6C-4B65-B115-89306A8505DA}] => (Allow) %ProgramFiles% (x86)\eMule\emule.exe
FirewallRules: [{65F8552F-6714-4852-9340-54EE2342AB1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{E730E30E-580E-475A-9266-C29527C28FD4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{3296E763-B5E2-464D-A16C-C85793837FAC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{23A36BF3-185D-4490-8A11-29893A53736D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{18701A33-5F97-416D-859B-A76BE195ED88}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{00FE0603-F42A-4C79-9F2E-DE8F997C4C31}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{17F07D65-1176-4321-88BA-6466B9C89351}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{3A97DA7C-6BEE-4956-A763-01CF376F5855}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
C:\Users\Mohamed\AppData\Roaming\StPrsSW
C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe
C:\Users\Mohamed\AppData\Roaming\uTorrent
C:\Users\Mohamed\AppData\Roaming\uTorrent
C:\program files (x86)\emule
EmptyTemp:
*****************
 
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AvgUi => value removed successfully
HKU\S-1-5-21-3844031730-595245587-2132850609-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\\ => value removed successfully
Chrome HomePage => removed successfully
Chrome StartupUrls => removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
CHR Profile: C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1 => Error: No automatic fix found for this entry.
SearchProtectionService => service removed successfully
WtuSystemSupport => service removed successfully
HTTP => service removed successfully
C:\AVG_Remover => moved successfully
C:\Users\Mohamed\Downloads\AVG_Remover.exe => moved successfully
C:\Users\Mohamed\Desktop\IMG_4839.MOV => moved successfully
C:\Users\Mohamed\Downloads\Movavi_Video_Editor_10_Activation_Key_plus_Crack_Full_Free.iso => moved successfully
C:\Users\Mohamed\AppData\Local\VideoEditor => moved successfully
C:\Users\Mohamed\AppData\Local\Movavi => moved successfully
C:\ProgramData\rxsmznjf.zcp => moved successfully
C:\ProgramData\Movavi Video Editor 11 => moved successfully
C:\Users\Mohamed\Downloads\MovaviVideoEditorSetupC.exe => moved successfully
C:\Users\Mohamed\Desktop\IMG_4971.MOV => moved successfully
C:\Users\Mohamed\Desktop\IMG_4970.MOV => moved successfully
C:\ProgramData\eMule => moved successfully
C:\ProgramData\Avg => moved successfully
C:\Users\Mohamed\AppData\Local\Avg => moved successfully
C:\Program Files (x86)\AVG Web TuneUp => moved successfully
C:\Program Files (x86)\AVG => moved successfully
C:\Users\Mohamed\AppData\Roaming\AVG => moved successfully
C:\Program Files\Common Files\AV => moved successfully
C:\Users\Mohamed\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl => moved successfully
C:\ProgramData\AVG Web TuneUp => moved successfully
C:\Program Files\AVG Web TuneUp => moved successfully
C:\ProgramData\mntemp => moved successfully
"C:\ProgramData\rxsmznjf.zcp" => not found.
C:\Users\Mohamed\AppData\Local\Temp\avguirn_08448574923.exe => moved successfully
Delta toolbar   (HKLM-x32\…\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD7575CC-5005-4B22-8E72-0637F6C01C58}\\SystemComponent => value removed successfully
Movavi Video Editor 11 (HKLM-x32\…\Movavi Video Editor 11) (Version: 11.2.0 - Movavi) => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0B4DC8FC-BDAD-4064-8529-DC71348B0DA2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0B4DC8FC-BDAD-4064-8529-DC71348B0DA2}" => key removed successfully
C:\WINDOWS\System32\Tasks\AVG_SYS_TASK_0215pit_RUN => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG_SYS_TASK_0215pit_RUN" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{25903C7C-5BDD-4B55-B241-794BAED09AA0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25903C7C-5BDD-4B55-B241-794BAED09AA0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2BFCBD49-912A-4A29-8E8F-A3DE01FCF636}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2BFCBD49-912A-4A29-8E8F-A3DE01FCF636}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4796AA0F-637C-4BD9-A388-3D8DF02C3975}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4796AA0F-637C-4BD9-A388-3D8DF02C3975}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{69993CC2-A246-4F22-93C4-147E66D44A01}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{69993CC2-A246-4F22-93C4-147E66D44A01}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{774F71DB-0FC3-4846-B083-F389DF638D80}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{774F71DB-0FC3-4846-B083-F389DF638D80}" => key removed successfully
C:\WINDOWS\System32\Tasks\StPrsSW => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\StPrsSW" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7820700A-9B7F-45FF-82E4-C34135218302}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7820700A-9B7F-45FF-82E4-C34135218302}" => key removed successfully
C:\WINDOWS\System32\Tasks\0116tbUpdateInfo => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0116tbUpdateInfo" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B320197-E3E5-4E55-B31B-0D8B272215EE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B320197-E3E5-4E55-B31B-0D8B272215EE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7CF6E46E-9035-495E-8E20-6FEAE62283E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7CF6E46E-9035-495E-8E20-6FEAE62283E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7ED2A75D-30C8-406E-9F28-E1E95E23EB61}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7ED2A75D-30C8-406E-9F28-E1E95E23EB61}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7ED76DB6-41DF-444D-BBEF-F68114064CD9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7ED76DB6-41DF-444D-BBEF-F68114064CD9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{817B72B9-1153-4C01-830E-FE168B2B4D95}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{817B72B9-1153-4C01-830E-FE168B2B4D95}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{877B2768-1F74-4A00-A173-57FA87DAF844}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{877B2768-1F74-4A00-A173-57FA87DAF844}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B7DEB27-1F51-41B5-B71F-762C86BFB579}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B7DEB27-1F51-41B5-B71F-762C86BFB579}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\xtgt\refreshxtgtconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A08B941B-5850-4495-8B64-22478DA6A511}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A08B941B-5850-4495-8B64-22478DA6A511}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ECF65DB4-DB74-41E5-BC91-39B4613BF219} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9D17CFB5-F059-44F6-B4C2-E84F715D94AF} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{306E741B-0BF4-48B6-8E82-29C1C2305554} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7246312F-41FD-492B-9169-A4FE9CE7AD4A} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D6D027DA-8710-4AA8-BD0A-226F29859DA0} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8BBCFE44-A535-40E9-A361-A9515802C70A} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A44FC839-B42D-4D54-ABD7-991622D25887}C:\program files (x86)\emule\emule.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9F6D9876-3F1A-41A3-A9D4-CDF020EB6753} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0C61DA2E-1D6C-4B65-B115-89306A8505DA} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{65F8552F-6714-4852-9340-54EE2342AB1E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E730E30E-580E-475A-9266-C29527C28FD4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3296E763-B5E2-464D-A16C-C85793837FAC} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{23A36BF3-185D-4490-8A11-29893A53736D} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{18701A33-5F97-416D-859B-A76BE195ED88} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{00FE0603-F42A-4C79-9F2E-DE8F997C4C31} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{17F07D65-1176-4321-88BA-6466B9C89351} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3A97DA7C-6BEE-4956-A763-01CF376F5855} => value removed successfully
"C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe" => not found.
C:\Users\Mohamed\AppData\Roaming\StPrsSW => moved successfully
"C:\ProgramData\Avg_Update_0116tb\0116tb_{15D7F18A-7969-4E9E-95ED-3112AA6B6B9D}.exe" => not found.
"C:\Users\Mohamed\AppData\Roaming\uTorrent" => not found.
"C:\Users\Mohamed\AppData\Roaming\uTorrent" => not found.
"C:\program files (x86)\emule" => not found.
EmptyTemp: => 2.4 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 08:50:50 ====
 
 
 
 
 
Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Mohamed on Sat 03/05/2016 at  9:31:02.99.
Microsoft Windows 10 Home 10.0.10586  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Mohamed\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
3/5/2016 9:34:28 AM Zoek.exe System Restore Point Created Successfully.
 
==== Empty Folders Check ======================
 
C:\PROGRA~2\GUMFD37.tmp deleted successfully
C:\PROGRA~2\McAfee deleted successfully
C:\PROGRA~3\Comms deleted successfully
C:\PROGRA~3\Lavasoft deleted successfully
C:\Users\Mohamed\AppData\Local\ActiveSync deleted successfully
C:\Users\Mohamed\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\Mohamed\AppData\Local\EmieSiteList deleted successfully
C:\Users\Mohamed\AppData\Local\EmieUserList deleted successfully
C:\Users\Mohamed\AppData\Local\NetworkTiles deleted successfully
C:\Users\Mohamed\AppData\Local\Opera Software deleted successfully
 
==== Deleting CLSID Registry Keys ======================
 
 
==== Deleting CLSID Registry Values ======================
 
 
==== Deleting Services ======================
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LavasoftTcpService deleted successfully
 
==== Deleting Files \ Folders ======================
 
C:\PROGRA~2\GUMFD37.tmp not found
C:\PROGRA~2\McAfee not found
C:\Users\Mohamed\AppData\Local\AVG Web TuneUp deleted
C:\PROGRA~2\Lavasoft\Web Companion deleted
C:\prefs.js deleted
C:\found.000 deleted
C:\Users\Mohamed\AppData\Local\Lavasoft\WebCompanion.exe_Url_siq0lwf3tzgxp2khfkllybk3idtbehng deleted
C:\Users\Mohamed\AppData\Local\avgchrome deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\LavasoftTcpService deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\lavasoft\WebCompanion deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Users\Mohamed\AppData\LocalLow\AVG Web TuneUp deleted
C:\WINDOWS\Syswow64\InstallUtil.InstallLog deleted
C:\WINDOWS\SysWow64\searchplugins deleted
C:\WINDOWS\SysWow64\Extensions deleted
"C:\Windows\Installer\19b3ebaa.msi" deleted
 
==== Chromium Look ======================
 
Google Chrome Version: 46.0.2490.86
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[01/08/2016 10:47 AM]
 
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
bbjllphbppobebmjpjcijfbakobcheof - No path found[]
odifdffdmeannfboglpliamjmoggdmci - C:\Users\Mohamed\AppData\Local\GAS Tecnologia\GBBD\bdv\sf.crx[09/26/2013 11:51 AM]
 
Skype - Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
GBBD Cl@veDefensa del Banco de Venezuela - Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\odifdffdmeannfboglpliamjmoggdmci
 
==== Set IE to Default ======================
 
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
 
==== All HKLM and HKCU SearchScopes ======================
 
HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
 
==== Reset Google Chrome ======================
 
C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data-journal was reset successfully
 
==== Reset IE Proxy ======================
 
Value(s) before fix:
"ProxyOverride"=";*.local"
"ProxyEnable"=dword:00000000
 
Value(s) after fix:
"ProxyEnable"=dword:00000000
 
==== Uninstall List x64 ======================
 
Adobe Reader XI (11.0.13)  MUI [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}]
Akamai NetSession Interface [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Akamai]
Apple Application Support (32-bit) [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}]
Apple Application Support (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0DE0A178-AC7B-4650-806C-CF226DE03766}]
Apple Mobile Device Support [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3540181E-340A-4E7A-B409-31663472B2F7}]
Apple Software Update [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}]
AVG Web TuneUp [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Web TuneUp]
Bonjour  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}]
Cl@veDefensa del Banco de Venezuela [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A0753E93-0933-4adc-B357-D60699B143B2}_is1]
Cl@veDefensa del Banco de Venezuela [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Cl@veDefensa del Banco de Venezuela_is1]
D3DX10  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E09C4DB7-630C-4F06-A631-8EA7239923AF}]
Dropbox  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Dropbox]
ExpressCache  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3EA6AB5D-D434-4ACA-9609-48F1319518EF}]
FDUx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3490653F-2789-46A1-B1BF-6BD4CF4131AB}]
Garmin MapSource [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}]
Garmin Training Center [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7D542452-84EB-47C0-97BA-735C523AB555}]
Garmin USB Drivers [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{510D2239-6C2E-457B-9590-485EC552D94D}]
Google Chrome [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome]
Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}]
Google Update Helper [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}]
HP Deskjet 3050 J610 series Basic Device Software [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6457BD83-98CF-4267-93D7-F173FF3E7C25}]
HP Deskjet 3050 J610 series Help [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}]
HP Deskjet 3050 J610 series Product Improvement Study [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5FB5B723-6B6E-45ED-BA73-F264D52AF916}]
HP Photo Creations [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\HP Photo Creations]
HP Update [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}]
Iminent  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD7575CC-5005-4B22-8E72-0637F6C01C58}]
Intel(R) Management Engine Components [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}]
Intel(R) Processor Graphics [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}]
Intel(R) Rapid Storage Technology [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}]
Intel(R) SDK for OpenCL - CPU Only Runtime Package [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}]
Intelr Trusted Connect Service Client [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{977D1ABF-4089-4CA7-BA33-CC75808B7ACE}]
iTunes  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E690A491-702F-4DEC-9977-C015D1DBB57C}]
Java 7 Update 9 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F86417009FF}]
Java 7 Update 9 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83217009FF}]
K-Lite Codec Pack 11.8.5 Full [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\KLiteCodecPack_is1]
KUx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{857087BB-A988-4462-A5C6-CF6739143B56}]
McAfee Security Scan Plus [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\McAfee Security Scan]
Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E9F0BCD8-6BD5-1ED7-EDA3-9FCF2A478AA1}]
Microsoft Office Professional Plus 2010 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Office14.PROPLUS]
Microsoft SQL Server 2005 Compact Edition [ENU] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}]
Microsoft Visio Professional 2013 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Office15.VISPROR]
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}]
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}]
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}]
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)]
Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{38F03569-A636-4CF3-BDDE-032C8C251304}]
Movie Maker [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD67BE4B-7E62-4215-AFA3-F123A800A389}]
MSVCRT  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}]
MSVCRT110  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}]
MSVCRT110_amd64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E9FA781F-3E80-4399-825A-AD3E11C28C77}]
Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CAA0F57A-BA8C-4AD8-AA03-F32B0E4F5623}]
Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{07AAB66E-4718-422D-9218-4AFB3C922A71}]
Photo Gallery [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C992FFE0-AC32-4FA9-BC9A-F1637B9E655D}]
PlayMemories Home [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{10DD6128-A810-4A90-9523-475D573FBB37}]
Qualcomm Atheros Bluetooth Suite (64) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A84A4FB1-D703-48DB-89E0-68B6499D2801}]
Rapport  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}]
Reader for PC [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{25340F94-F74E-4CCF-ABDF-ECBCF03911BE}]
Realtek High Definition Audio Driver [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}]
Realtek PCIE Card Reader [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C1594429-8296-4652-BF54-9DBE4932A44C}]
Restore  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ECCEB4D0-7080-4F8A-B498-E40A32A4FBED}]
Shared C Run-time for x64 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EF79C448-6946-4D71-8134-03407888C054}]
Skype Click to Call [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}]
SkypeT 7.10 [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6A0549A9-1B96-498C-ACBC-3943001FEB19}]
SSLx64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{312395BC-7CC2-434C-A660-30250276A926}]
SSLx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{63C43435-F428-42BA-8E7B-5848749D9262}]
Synaptics Pointing Device Driver [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\SynTPDeinstKey]
Trusteer Endpoint Protection [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Rapport_msi]
VAIO - Xperia Link [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D91558BF-D1F3-411F-AEFE-8774CB406512}]
VAIO Care [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{036400BD-B717-4D50-ACDC-96480C99EDD3}]
VAIO Care Recovery [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{15B9204E-BA09-485E-8F2C-094AC0077664}]
VAIO Control Center [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E797841-A110-41FD-B17A-3ABC0641187A}]
VAIO CPU Fan Diagnostic [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BCE6E3D7-B565-4E1B-AC77-F780666A35FB}]
VAIO Data Restore Tool [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}]
VAIO Easy Connect [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}]
VAIO Gate Default [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B7546697-2A80-4256-A24B-1C33163F535B}]
VAIO Gesture Control [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{692955F2-DE9F-4078-8FAA-858D6F3A1776}]
VAIO Gesture Control [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A31E4DB3-B774-45C8-BE70-DB8BE53D2A5B}]
VAIO Hardware Diagnostics Plugin for VAIO Care [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EC153498-00E1-4C9C-89BE-81527C6750BE}]
VAIO Health Report [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VAIO Health Report1.0]
VAIO Image Optimizer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5597C927-029A-46A7-A0C0-8DABD9891A50}]
VAIO Image Optimizer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{5597C927-029A-46A7-A0C0-8DABD9891A50}]
VAIO Improvement [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3A26D9BD-0F73-432D-B522-2BA18138F7EF}]
VAIO Manual [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}]
VAIO Media Server Settings [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{62A172B2-550E-499D-9A82-5190D18390AA}]
VAIO Movie Creator [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C2CC5822-32E6-4D21-88EA-DE8CED09EE2F}]
VAIO Movie Creator [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{C2CC5822-32E6-4D21-88EA-DE8CED09EE2F}]
VAIO Movie Creator Template Data [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{00A663F1-6C03-48CA-8E85-55806AAE2615}]
VAIO Movie Creator Template Data [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{00A663F1-6C03-48CA-8E85-55806AAE2615}]
VAIO Transfer Support [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}]
VAIO Update [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}]
VCCMMX64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{606DF716-F28D-4449-B0B1-3AB6081F51AF}]
VCCMMx64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B812401D-BAB2-4E33-9AC7-9862BC8CAF64}]
VCCMMX86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BC3FFCF0-3DB7-47D2-BF15-1979AB59D12B}]
VCCMMx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CC87BAAD-AA25-4727-9B7C-E0876722B784}]
VCCx64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{25ECAFCB-DCFB-4FCE-A5B2-772A57F59860}]
VCCx64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AB447E3B-7A95-4CA6-8ECD-B25C96314B67}]
VCCx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AFDC0CC0-39E8-42C0-9823-2C1C182676DC}]
VCCx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B31938C7-7E97-49EE-8F88-951E156268A3}]
VHD  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9D8112DB-3490-4BF1-AAFA-1D224FFB5D3C}]
Visual Studio 2012 x64 Redistributables [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}]
Visual Studio 2012 x86 Redistributables [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}]
VIx64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{D55EAC07-7207-44BD-B524-0F063F327743}]
VIx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D17C2A58-E0EA-4DD7-A2D6-C448FD25B6F6}]
VLC media player [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VLC media player]
VMLx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7E5A5CA6-B7D0-406E-A75E-157CAB47EB94}]
VPMx64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DBEAA361-F8A4-4298-B41C-9E9DCB9AAB84}]
VSSTx64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4F31AC31-0A28-4F5A-8416-513972DA1F79}]
VSSTx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B24BB74E-8359-43AA-985A-8E80C9219C70}]
VU5x64  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6B7DE186-374B-4873-AEC1-7464DA337DD6}]
VU5x86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9D12A8B5-9D41-4465-BF11-70719EB0CD02}]
VWSTx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B8991D99-88FD-41F2-8C32-DB70278D5C30}]
Web Companion [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{dfa2e17c-b3ae-4bd7-97c2-d25a373fe428}]
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (06/03/2009 2.3.0.0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\49CF605F02C7954F4E139D18828DE298CD59217C]
Windows Live Communications Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{41C61308-6CFD-4D54-AB6A-7136ED08A18E}]
Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{66B5819D-DE70-42BE-B40F-978FBA12452E}]
Windows Live Essentials [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite]
Windows Live Installer [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{659CB81C-B54E-4DF1-B618-F35777393A54}]
Windows Live Photo Common [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}]
Windows Live PIMT Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}]
Windows Live SOXE [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}]
Windows Live SOXE Definitions [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D1893000-EA77-493C-8DDD-E262436E959B}]
Windows Live UX Platform [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}]
Windows Live UX Platform Language Pack [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6522F5F9-411B-4513-A75B-CEA00395F032}]
WinRAR 4.20 (64-bit) [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver]
XperiaLinkx86  [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE402ACB-8269-4E44-9CA1-D81FDC4B4545}]
 
==== Deleting Registry Keys ======================
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CC5757DD500522B4E82760736F0CC185 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Web TuneUp deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD7575CC-5005-4B22-8E72-0637F6C01C58} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{dfa2e17c-b3ae-4bd7-97c2-d25a373fe428} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\CC5757DD500522B4E82760736F0CC185 deleted successfully
 
==== Empty IE Cache ======================
 
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Mohamed\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Mohamed\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Mohamed\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Mohamed\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
 
==== Empty FireFox Cache ======================
 
No FireFox Profiles found
 
==== Empty Chrome Cache ======================
 
C:\Users\Mohamed\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
 
==== Empty All Flash Cache ======================
 
No Flash Cache Found
 
==== Empty All Java Cache ======================
 
No Java Cache Found
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=343 folders=32 207762803 bytes)
 
==== Empty Temp Folders ======================
 
C:\WINDOWS\Temp will be emptied at reboot
 
==== After Reboot ======================
 
==== Empty Temp Folders ======================
 
C:\WINDOWS\Temp successfully emptied
C:\Users\Mohamed\AppData\Local\Temp successfully emptied
 
==== Empty Recycle Bin ======================
 
C:\$RECYCLE.BIN successfully emptied
 
==== EOF on Sat 03/05/2016 at 10:16:23.56 ======================
 

I deleted Delta bar, but when I tried to delete Iminent i couldn't, a massage will display saying already a session exists giving me just an 'ok' option….but when finished running all the programs you told me it doesn't appear anymore in the programs list…

That's why I asked you to run the fix before trying to uninstall it. Glad it has gone now though.


Run Zoek

 

  • run Zoek again by right-clicking Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    [-HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Web TuneUp] ;r
    [-HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD7575CC-5005-4B22-8E72-0637F6C01C58}];r
    ipconfig /flushdns;b
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

===================================================

Download Malwarebytes-Anti-Malware

Click here.

  • double-click mbam-setup.exe and follow the prompts to install the program – (Note: Vista & Windows 7 users, please right-click and select “Run as Administrator”)
  • select the “Scan” tab at the top
  • there are three scan types; choose Threat Scan, then click on Scan
  • when the scan is complete, if no malicious items are found you can close the program
  • if malicious items are found be sure that everything is checked and click Quarantine
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.

NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include with the next post:

New zoek-results.log
Mbam.txt


Can you tell me if there are any outstanding problems.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI