This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop Running Super Slow

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I'm working on my step-dad's laptop and it is running very slow and often becomes unresponsive.  He said he tried to upgrade to Windows 10 but when it still ran slow he reverted back to his previous version of Windows.  It's hard telling what we will find when we get into this thing.  I started with MBAM and Adware scans and aswMBR.  I could not copy and paste or attach the MBAM scan log because it was extremely long and would not allow me.  Thank you for your help.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-03-31 14:21:39
—————————–
14:21:39.689    OS Version: Windows x64 6.1.7601 Service Pack 1
14:21:39.689    Number of processors: 4 586 0x2A07
14:21:39.689    ComputerName: OWNER-PC  UserName: Owner
14:21:42.372    Initialize success
14:21:42.497    VM: initialized successfully
14:21:42.512    VM: Intel CPU supported
14:21:52.543    VM: supported disk I/O iaStor.sys
15:42:58.993    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:42:59.024    Disk 0 Vendor: TOSHIBA_ GB00 Size: 476940MB BusType: 3
15:42:59.133    VM: Disk 0 MBR read successfully
15:42:59.149    Disk 0 MBR scan
15:42:59.149    Disk 0 Windows VISTA default MBR code
15:42:59.180    Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS         1500 MB offset 2048
15:42:59.180    Disk 0 Boot: NTFS     code=1
15:42:59.211    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       462871 MB offset 3074048
15:42:59.243    Disk 0 Partition 3 00     17 Hidd HPFS/NTFS NTFS        12568 MB offset 951033856
15:42:59.430    Disk 0 scanning C:\windows\system32\drivers
15:43:14.765    Service scanning
15:43:46.729    Modules scanning
15:43:46.745    Disk 0 trace - called modules:
15:43:46.776    ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
15:43:46.776    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80069b2060]
15:43:46.776    3 CLASSPNP.SYS[fffff88001b5743f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005731050]
15:43:46.792    Disk 0 statistics 102632/0/22 @ 6.01 MB/s
15:43:46.792    Scan finished successfully
15:44:28.943    Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
15:44:28.943    The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"

 

 

# AdwCleaner v5.108 - Logfile created 31/03/2016 at 14:06:44
# Updated 30/03/2016 by Xplode
# Database : 2016-03-30.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Owner - OWNER-PC
# Running from : C:\Users\Owner\Desktop\AdwCleaner.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : netfilter64
[-] Service Deleted : YahooAUService

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Yahoo!\Companion
[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\ProgramData\Systweak
[-] Folder Deleted : C:\ProgramData\Yahoo! Companion
[-] Folder Deleted : C:\Users\Owner\AppData\Local\iac
[-] Folder Deleted : C:\Users\Owner\AppData\Local\Temp\apn
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\iac
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\Yahoo! Companion
[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\Yahoo!\Companion
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\Systweak
[-] Folder Deleted : C:\Users\Owner\AppData\Roaming\Yahoo!\Companion
[-] Folder Deleted : C:\windows\Installer\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
[-] Folder Deleted : C:\windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}

***** [ Files ] *****

[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\windows\SysNative\drivers\netfilter64.sys

***** [ DLLs ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MapsGalaxy_39bar Uninstall Internet Explorer
[-] Key Deleted : HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorBho.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{884189CF-7C10-41E8-A014-F7B2BE40AADB}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6818868a-1b3d-4e35-a561-fa964a96cd3b}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79e57afa-bc05-4636-9457-fbc0abb3576b}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9193e23b-4182-493f-a38e-682307a7c463}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{bf75b5a2-8403-4f70-88a6-488e3bea0d7b}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e1f80eb5-8af4-410d-87c1-4f3e2776822a}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\usyndication.com
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Uniblue
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PlurPush
[-] Key Deleted : HKU\.DEFAULT\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
[-] Key Deleted : HKLM\SOFTWARE\Classes\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1C19AC53289098045B06B0DD1D37CBAB
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\216F88E93A00F2B5494EDDCFD502D42E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23D9E9D21B4E77E41B9F50DD22F24E20
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23EEA1F105A7F45449974D9B95E7AC89
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\26982796A8AFD1246B95E00265A95BF9
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\32DA746012E6D4F488AAD113D6FA4A44
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D92D0D75AFEF74297E03876C8D9D33
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50FFE845C555A6E4BADB7CB7A145BFEB
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B417119DEEF2AE52B41C910B4B269FA
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\715A3348920B6534690067594BB69F60
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B7B13B037A7C2A42AC3E3EAF14D7107
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D05B2942E9CC80499F397F6114DFB35
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82306010F2A8A02519C2D6D1A4B48415
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8591B8948E1C4A04F90505B3CDEE8555
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8D841C5FEC311624CB88D49DB3884FA7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD04033484A18CA4CAB3EE59D39D756E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD746BF3B3B3FD8409B86604BA85982A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF767AE36C8829547ACD71A4249A42B9
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E9A2A2663AD8ED75E83332ACA3689A31
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F355F0DB7A2E3A14B8E7A568FBA25937
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDCBFFB76F9A2B15D9A475A10FA793A6
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8036C72171EF4ba46856BF57969F6A36
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89BB7852687BDC34B9A81E01C7FF9173
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89EA4F1B8FBCDEF47AE328E455E28AA0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CBC85D72B148084ABE8C2F072F781F4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC5A38A64D6098468BC8395BA0EFF03
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8DF9A1AC557F56c49B56F6B83E293C15
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97ECFF59EE08D4F47BB1464DEC37DA87
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8CB937199A57E748B6AC433DA453EE2
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A97C590397DCC454AA8923563BAB10E4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B08932C78B697C244BE7BA3E6FF09B62
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4E78E12704AFCE408C7FBE501F1AA0A
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6A54B56C58C82a4688AFB93F42EA17B
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFA51B44D54927c4E9B7BC1D3FD1E49F
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D14A7F65792054F418578C78367D13F7
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DFE9F0BD163D827438CB6AD6B100EC48
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F0390A76D28822743A68D7F1AB22E6D0
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F739A19A8327dc64C9A8B641A9E89646
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A5AC497E6BBC8D45BE8AD6619DA8217
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\158D6D9E3FE81fa428925F22ACB3A965
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15E6C514FEFC09f45BAFAAE1D7546ED4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DB42320A8525634AA089F0BEC86473B
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22468B0D6050b2e46B9C4B67A8F59577
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2251BF05A2F606d43BB064BD63CBD87E
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3255D95681398614190EDF0A4F3F77DB
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CDF313E9B28c944FBC7579CF4949414
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71E54748EDD3dc1468548785DC856EDA
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\754590DD06DE8d249B526503432F99D4
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\526AB318AF0B8D84B9579557C9882C91
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d2m2wsoho8qq12.cloudfront.net
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d3l3lkinz3f56t.cloudfront.net
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\findyourmaps.dl.tb.ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\getformsonline.dl.tb.ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\home.tb.ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mapsgalaxy.dl.tb.ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\search.tb.ask.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\televisionfanatic.dl.tb.ask.com

***** [ Web browsers ] *****

[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : fcfenmboojpjinhpgggodefccipikbpd

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [16304 bytes] - [31/03/2016 14:06:44]
C:\AdwCleaner\AdwCleaner[S1].txt - [16425 bytes] - [31/03/2016 14:05:09]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [16452 bytes] ##########

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 7 Home Premium x64
Ran by [removed] (Administrator) on Thu 03/31/2016 at 16:10:44.45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

File System: 35

Successfully deleted: C:\Users\Owner\AppData\Local\{180AB191-F37E-4EB9-AA2C-52214CA9104D} (Empty Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\{AED2A8CD-067F-479D-8E53-36FD6E7D4CC2} (Empty Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0Q6EAB65 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1C23UCSR (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1CAU94EC (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3DO2BUI6 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\96O2MPY0 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A615PHV1 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\APQHXMKZ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B5HNEU2K (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FLW226WT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IMZF0TLI (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF2LK20O (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZRK25V24 (Temporary Internet Files Folder)
Successfully deleted: C:\windows\prefetch\TOOLBAR.EXE-AEAAD474.pf (File)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0Q6EAB65 (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1C23UCSR (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1CAU94EC (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3DO2BUI6 (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\96O2MPY0 (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A615PHV1 (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\APQHXMKZ (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B5HNEU2K (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FLW226WT (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IMZF0TLI (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF2LK20O (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZRK25V24 (Temporary Internet Files Folder)

 

Registry: 2

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 03/31/2016 at 16:13:47.50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

So sorry for the wait.

[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Scan
  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

Here's the scan results you requested.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by [removed] (administrator) on OWNER-PC (03-04-2016 13:51:37)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe
(TOSHIBA Corporation) C:\windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\windows\System32\GWX\GWX.exe
(Intel Corporation) C:\windows\System32\igfxtray.exe
(Intel Corporation) C:\windows\System32\hkcmd.exe
(Intel Corporation) C:\windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\windows\System32\dllhost.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\windows\System32\Macromed\Flash\FlashUtil64_21_0_0_197_ActiveX.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtWatchDog.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\…\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [590256 2011-05-17] (TOSHIBA Corporation)
HKLM\…\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [972672 2011-04-27] (TOSHIBA Corporation)
HKLM\…\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\…\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2011-06-09] (TOSHIBA Corporation)
HKLM\…\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38824 2011-06-28] (TOSHIBA Corporation)
HKLM\…\Run: [PwmConsole.exe] => C:\Program Files\Trend Micro\TMIDS\PwmConsole.exe [2047216 2015-06-29] (Trend Micro Inc.)
HKLM\…\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [246264 2015-07-16] (Trend Micro Inc.)
HKLM\…\Run: [Platinum] => C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe [1258496 2015-07-16] (Trend Micro Inc.)
HKLM\…\Run: [YourLocalLotto Toolbar Home Page Guard 64 bit] => "C:\PROGRA~2\YOURLO~2\bar\1.bin\AppIntegrator64.exe"
HKLM\…\Run: [WeatherBlink Home Page Guard 64 bit] => "C:\PROGRA~2\WEATHE~2\bar\1.bin\AppIntegrator64.exe"
HKLM\…\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597936 2011-07-27] (TOSHIBA Corporation)
HKLM-x32\…\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKLM-x32\…\Run: [NortonOnlineBackupReminder] => C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe [3218864 2011-06-22] (Toshiba)
HKLM-x32\…\Run: [ToshibaAppPlace] => C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-2107236783-443684216-2808434022-1000\…\Run: [HP Photosmart 6520 series (NET)] => C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-2107236783-443684216-2808434022-1000\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-10-01] (Google Inc.)
HKU\S-1-5-21-2107236783-443684216-2808434022-1000\…\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [473496 2013-11-29] (TomTom)
HKU\S-1-5-21-2107236783-443684216-2808434022-1000\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [HP Photosmart 6520 series (NET)] => C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-10-01] (Google Inc.)
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [473496 2013-11-29] (TomTom)
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-2107236783-443684216-2808434022-1000] => http=127.0.0.1:49201;https=127.0.0.1:49201
ProxyServer: [S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] => http=127.0.0.1:49201;https=127.0.0.1:49201
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{09707604-6873-4ED2-BDAB-0C9EDC780A34}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{6D4D86C3-31B9-42AB-9E17-1A7105B0526F}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{A2930CBA-E39A-4B78-B2B5-9A1AE5D15402}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.wow.com/?hp_ps=msn.com&hp;_uid=16f4dfae-0ec3-4f26-a1d9-c703f94d9fc0&s;_chn=27&s;_chn2=994&s;_pt=start
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.wow.com/?hp_ps=msn.com&hp;_uid=16f4dfae-0ec3-4f26-a1d9-c703f94d9fc0&s;_chn=27&s;_chn2=994&s;_pt=start
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 - (No Name) - {08f9937e-0a4f-48cf-94e7-827223daec1d} - C:\Program Files (x86)\HeadlineAlley_29\bar\1.bin\29SrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 - (No Name) - {8a04fa5f-0a1a-4996-abe4-b607dad3840b} - C:\Program Files (x86)\GetFormsOnline_db\bar\1.bin\dbSrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {08f9937e-0a4f-48cf-94e7-827223daec1d} - C:\Program Files (x86)\HeadlineAlley_29\bar\1.bin\29SrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {8a04fa5f-0a1a-4996-abe4-b607dad3840b} - C:\Program Files (x86)\GetFormsOnline_db\bar\1.bin\dbSrcAs.dll No File
SearchScopes: HKLM -> DefaultScope {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNO
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNO
SearchScopes: HKLM-x32 -> DefaultScope {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNO
SearchScopes: HKLM-x32 -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNO
SearchScopes: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNO
SearchScopes: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNO
BHO: Trend Micro Password Manager BHO -> {3F019D1C-7EAA-4F25-A765-FBA635BD0AFF} -> C:\Program Files\Trend Micro\TMIDS\PwmIEBHO64.dll [2015-06-29] (Trend Micro Inc.)
BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg.dll [2015-07-16] (Trend Micro Inc.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-21] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1035\9.1.1035\TmBpIe64.dll [2015-08-16] (Trend Micro Inc.)
BHO: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2011-07-12] ()
BHO-x32: Trend Micro Password Manager BHO -> {3F019D1C-7EAA-4F25-A765-FBA635BD0AFF} -> C:\Program Files\Trend Micro\TMIDS\PwmIEBHO32.dll [2015-06-29] (Trend Micro Inc.)
BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-14] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll [2015-07-16] (Trend Micro Inc.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-21] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1035\9.1.1035\TmBpIe32.dll [2015-08-16] (Trend Micro Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-14] (Oracle Corporation)
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2011-07-12] ()
Toolbar: HKLM - Trend Micro Password Manager ToolBar - {9B4B91FC-EC4D-4018-9575-96FA5A3C03C5} - C:\Program Files\Trend Micro\TMIDS\PwmIEBHO64.dll [2015-06-29] (Trend Micro Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-21] (Google Inc.)
Toolbar: HKLM - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
Toolbar: HKLM-x32 - Trend Micro Password Manager ToolBar - {9B4B91FC-EC4D-4018-9575-96FA5A3C03C5} - C:\Program Files\Trend Micro\TMIDS\PwmIEBHO32.dll [2015-06-29] (Trend Micro Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-21] (Google Inc.)
Toolbar: HKLM-x32 - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
Toolbar: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-21] (Google Inc.)
Toolbar: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-21] (Google Inc.)
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1035\9.1.1035\TmBpIe64.dll [2015-08-16] (Trend Micro Inc.)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1035\9.1.1035\TmBpIe32.dll [2015-08-16] (Trend Micro Inc.)
Handler: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg.dll [2015-07-16] (Trend Micro Inc.)
Handler-x32: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll [2015-07-16] (Trend Micro Inc.)
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-14] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1035\9.1.1035\firefoxextension
FF Extension: Trend Micro BEP Firefox Extension - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1035\9.1.1035\firefoxextension [2016-01-15]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1035\9.1.1035\firefoxextension
FF HKLM-x32\…\Firefox\Extensions: [{22181a4d-af90-4ca3-a569-faed9118d6bc}] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension
FF Extension: Trend Micro Toolbar - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2016-03-08]
FF HKLM-x32\…\Firefox\Extensions: [{BBB77B49-9FF4-4d5c-8FE2-92B1D6CD696C}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension
FF Extension: Trend Micro Osprey Firefox Extension - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension [2016-01-15]

Chrome:
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Chrome Web Store Payments) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-03]
CHR HKLM\…\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] -
CHR HKLM-x32\…\Chrome\Extension: [idkknaphebegndgimgdpfnconcickdfn] -
CHR HKLM-x32\…\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
R2 Platinum Host Service; C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [1137664 2015-07-16] (Trend Micro Inc.)
R2 PwmSvc; C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe [333856 2015-06-29] (Trend Micro Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=qb -dt=60000 -ad -bt=0 [X]
S2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe /s [X]
S2 PCCUJobMgr; "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe" /s "PCCUJobMgr" /m "C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\diMaster.dll" /prefetch:1

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-03] (Malwarebytes)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation                           )
R1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [133424 2015-11-23] (Trend Micro Inc.)
R0 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [324912 2015-11-23] (Trend Micro Inc.)
R0 TMEBC; C:\Windows\System32\DRIVERS\TMEBC64.sys [59712 2015-06-11] (Trend Micro Inc.)
R3 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [116576 2015-06-08] (Trend Micro Inc.)
R1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [99632 2015-11-23] (Trend Micro Inc.)
R3 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [416608 2015-05-28] (Trend Micro Inc.)
S3 tmumh; C:\Windows\System32\DRIVERS\TMUMH.sys [91536 2015-06-28] (Trend Micro Inc.)
R2 tmusa; C:\Windows\System32\DRIVERS\tmusa.sys [116528 2015-06-26] (Trend Micro Inc.)
S3 kbfilter; system32\DRIVERS\kbfilter.sys [X]
U2 TMAgent; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-04-03 13:51 - 2016-04-03 13:52 - 00028989 _____ C:\Users\Owner\Desktop\FRST.txt
2016-04-03 13:51 - 2016-04-03 13:51 - 00000000 ____D C:\FRST
2016-04-03 13:50 - 2016-04-03 13:50 - 02374144 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2016-03-31 19:51 - 2016-04-03 13:40 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-31 19:51 - 2016-03-31 19:51 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-31 19:51 - 2016-03-31 19:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-31 19:51 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-03-31 19:51 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-03-31 19:51 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-03-31 19:50 - 2016-03-31 19:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-31 19:17 - 2016-03-31 19:17 - 00003608 ____N C:\bootsqm.dat
2016-03-31 16:13 - 2016-03-31 16:13 - 00006374 _____ C:\Users\Owner\Desktop\JRT.txt
2016-03-31 16:09 - 2016-03-31 16:09 - 01610352 _____ (Malwarebytes) C:\Users\Owner\Desktop\JRT.exe
2016-03-31 15:44 - 2016-03-31 15:44 - 00001854 _____ C:\Users\Owner\Desktop\aswMBR.txt
2016-03-31 15:44 - 2016-03-31 15:44 - 00000512 _____ C:\Users\Owner\Desktop\MBR.dat
2016-03-31 14:15 - 2016-03-31 14:15 - 00016760 _____ C:\Users\Owner\Desktop\AdwCleaner[C1].txt
2016-03-31 14:02 - 2016-03-31 14:06 - 00000000 ____D C:\AdwCleaner
2016-03-31 13:55 - 2016-03-31 14:00 - 03102720 _____ C:\Users\Owner\Desktop\AdwCleaner.exe
2016-03-31 13:27 - 2016-03-31 13:41 - 03069987 _____ C:\Users\Owner\Desktop\AdwCleaner.exe.ka4746m.partial
2016-03-31 09:57 - 2016-03-31 10:59 - 22851472 _____ (Malwarebytes ) C:\Users\Owner\Desktop\mbam-setup-2.2.1.1043.exe
2016-03-31 09:38 - 2016-03-31 09:49 - 05198336 _____ (AVAST Software) C:\Users\Owner\Desktop\aswMBR.exe
2016-03-30 22:48 - 2016-03-31 22:24 - 00262144 _____ C:\windows\system32\config\ELAM
2016-03-30 22:32 - 2016-03-30 22:32 - 00000000 ____D C:\$SysReset
2016-03-30 15:05 - 2016-03-30 15:05 - 00008192 _____ C:\windows\system32\config\userdiff
2016-03-30 14:49 - 2016-03-30 14:49 - 00001320 _____ C:\Users\Owner\Desktop\Trend Micro Maximum Security.lnk
2016-03-30 11:40 - 2016-03-30 12:52 - 00010447 _____ C:\windows\diagerr.xml
2016-03-30 11:40 - 2016-03-30 12:52 - 00009528 _____ C:\windows\diagwrn.xml
2016-03-09 09:07 - 2016-02-12 13:52 - 03169792 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2016-03-09 09:07 - 2016-02-12 13:52 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2016-03-09 09:07 - 2016-02-12 13:52 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2016-03-09 09:07 - 2016-02-12 13:44 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2016-03-09 09:07 - 2016-02-12 13:39 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2016-03-09 09:07 - 2016-02-12 13:22 - 02610688 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2016-03-09 09:07 - 2016-02-12 13:19 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2016-03-09 09:07 - 2016-02-12 13:18 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2016-03-09 09:07 - 2016-02-12 13:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2016-03-09 09:07 - 2016-02-12 13:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2016-03-09 09:07 - 2016-02-12 13:18 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2016-03-09 09:07 - 2016-02-12 13:18 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2016-03-09 09:07 - 2016-02-12 13:06 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2016-03-09 09:07 - 2016-02-12 13:05 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2016-03-09 09:07 - 2016-02-12 13:05 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2016-03-09 09:07 - 2016-02-12 13:05 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2016-03-09 09:07 - 2016-02-09 01:53 - 00387792 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-03-09 09:07 - 2016-02-09 01:10 - 00341200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-03-09 09:07 - 2016-02-08 16:05 - 20352512 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-03-09 09:07 - 2016-02-08 15:51 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-03-09 09:07 - 2016-02-08 15:39 - 00496640 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-03-09 09:07 - 2016-02-08 15:39 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-03-09 09:07 - 2016-02-08 15:38 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-03-09 09:07 - 2016-02-08 15:38 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-03-09 09:07 - 2016-02-08 15:37 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-03-09 09:07 - 2016-02-08 15:34 - 02280448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-03-09 09:07 - 2016-02-08 15:32 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-03-09 09:07 - 2016-02-08 15:31 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-03-09 09:07 - 2016-02-08 15:30 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-03-09 09:07 - 2016-02-08 15:28 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-03-09 09:07 - 2016-02-08 15:28 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-03-09 09:07 - 2016-02-08 15:28 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-03-09 09:07 - 2016-02-08 15:20 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-03-09 09:07 - 2016-02-08 15:16 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-03-09 09:07 - 2016-02-08 15:15 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2016-03-09 09:07 - 2016-02-08 15:13 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-03-09 09:07 - 2016-02-08 15:12 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-03-09 09:07 - 2016-02-08 15:11 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-03-09 09:07 - 2016-02-08 15:10 - 04611072 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-03-09 09:07 - 2016-02-08 15:10 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-03-09 09:07 - 2016-02-08 15:05 - 25816576 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-03-09 09:07 - 2016-02-08 15:03 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-03-09 09:07 - 2016-02-08 15:02 - 13012480 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-03-09 09:07 - 2016-02-08 15:02 - 00687104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-03-09 09:07 - 2016-02-08 15:01 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-03-09 09:07 - 2016-02-08 15:01 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-03-09 09:07 - 2016-02-08 14:43 - 02121216 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-03-09 09:07 - 2016-02-08 14:39 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-03-09 09:07 - 2016-02-08 14:38 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-03-09 09:07 - 2016-02-08 13:41 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-03-09 09:07 - 2016-02-08 13:41 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-03-09 09:07 - 2016-02-08 13:27 - 02887680 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-03-09 09:07 - 2016-02-08 13:27 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-03-09 09:07 - 2016-02-08 13:26 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-03-09 09:07 - 2016-02-08 13:26 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-03-09 09:07 - 2016-02-08 13:26 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-03-09 09:07 - 2016-02-08 13:26 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-03-09 09:07 - 2016-02-08 13:19 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-03-09 09:07 - 2016-02-08 13:18 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-03-09 09:07 - 2016-02-08 13:16 - 06052352 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-03-09 09:07 - 2016-02-08 13:15 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-03-09 09:07 - 2016-02-08 13:14 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-03-09 09:07 - 2016-02-08 13:14 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-03-09 09:07 - 2016-02-08 13:13 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-03-09 09:07 - 2016-02-08 13:13 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-03-09 09:07 - 2016-02-08 13:06 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-03-09 09:07 - 2016-02-08 13:03 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-03-09 09:07 - 2016-02-08 12:55 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-03-09 09:07 - 2016-02-08 12:54 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2016-03-09 09:07 - 2016-02-08 12:52 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-03-09 09:07 - 2016-02-08 12:51 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-03-09 09:07 - 2016-02-08 12:49 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-03-09 09:07 - 2016-02-08 12:47 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-03-09 09:07 - 2016-02-08 12:37 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-03-09 09:07 - 2016-02-08 12:35 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-03-09 09:07 - 2016-02-08 12:34 - 00798720 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-03-09 09:07 - 2016-02-08 12:33 - 14613504 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-03-09 09:07 - 2016-02-08 12:33 - 02123264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-03-09 09:07 - 2016-02-08 12:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-03-09 09:07 - 2016-02-08 12:19 - 02597376 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-03-09 09:07 - 2016-02-08 12:07 - 01546752 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-03-09 09:07 - 2016-02-08 11:55 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-03-09 09:07 - 2016-02-04 12:52 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-03-09 09:07 - 2016-02-03 13:58 - 00862208 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2016-03-09 09:07 - 2016-02-03 13:52 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2016-03-09 09:07 - 2016-02-03 13:49 - 00572416 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2016-03-09 09:07 - 2016-02-03 13:43 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2016-03-09 09:07 - 2016-02-03 13:07 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2016-03-09 09:07 - 2016-01-11 14:11 - 01684416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2016-03-09 09:07 - 2015-11-19 09:07 - 00994760 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2016-03-09 09:07 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2016-03-09 09:04 - 2016-02-11 13:56 - 05572032 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-03-09 09:04 - 2016-02-11 13:56 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-03-09 09:04 - 2016-02-11 13:56 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2016-03-09 09:04 - 2016-02-11 13:52 - 01733592 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2016-03-09 09:04 - 2016-02-11 13:49 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2016-03-09 09:04 - 2016-02-11 13:48 - 01214464 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2016-03-09 09:04 - 2016-02-11 13:48 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2016-03-09 09:04 - 2016-02-11 13:48 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2016-03-09 09:04 - 2016-02-11 13:48 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2016-03-09 09:04 - 2016-02-11 13:48 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2016-03-09 09:04 - 2016-02-11 13:47 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2016-03-09 09:04 - 2016-02-11 13:45 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-03-09 09:04 - 2016-02-11 13:45 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2016-03-09 09:04 - 2016-02-11 13:45 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2016-03-09 09:04 - 2016-02-11 13:45 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2016-03-09 09:04 - 2016-02-11 13:44 - 03994560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2016-03-09 09:04 - 2016-02-11 13:44 - 03938240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2016-03-09 09:04 - 2016-02-11 13:44 - 01461248 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2016-03-09 09:04 - 2016-02-11 13:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2016-03-09 09:04 - 2016-02-11 13:44 - 00730112 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2016-03-09 09:04 - 2016-02-11 13:44 - 00422400 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-03-09 09:04 - 2016-02-11 13:42 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2016-03-09 09:04 - 2016-02-11 13:42 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2016-03-09 09:04 - 2016-02-11 13:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 01314328 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00880128 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:38 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2016-03-09 09:04 - 2016-02-11 13:38 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2016-03-09 09:04 - 2016-02-11 13:38 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-03-09 09:04 - 2016-02-11 13:38 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2016-03-09 09:04 - 2016-02-11 13:38 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2016-03-09 09:04 - 2016-02-11 13:38 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2016-03-09 09:04 - 2016-02-11 13:38 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2016-03-09 09:04 - 2016-02-11 13:37 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2016-03-09 09:04 - 2016-02-11 13:37 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2016-03-09 09:04 - 2016-02-11 13:37 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2016-03-09 09:04 - 2016-02-11 13:35 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-03-09 09:04 - 2016-02-11 13:35 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2016-03-09 09:04 - 2016-02-11 13:35 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2016-03-09 09:04 - 2016-02-11 13:34 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2016-03-09 09:04 - 2016-02-11 13:33 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2016-03-09 09:04 - 2016-02-11 13:31 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00642560 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 12:48 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2016-03-09 09:04 - 2016-02-11 12:43 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2016-03-09 09:04 - 2016-02-11 12:41 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2016-03-09 09:04 - 2016-02-11 12:40 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2016-03-09 09:04 - 2016-02-11 12:34 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-03-09 09:04 - 2016-02-11 12:34 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-03-09 09:04 - 2016-02-11 12:33 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2016-03-09 09:04 - 2016-02-11 12:32 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2016-03-09 09:04 - 2016-02-11 12:32 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2016-03-09 09:04 - 2016-02-11 12:32 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2016-03-09 09:04 - 2016-02-11 12:32 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2016-03-09 09:04 - 2016-02-11 12:32 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2016-03-09 09:04 - 2016-02-11 12:32 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2016-03-09 09:04 - 2016-02-11 12:31 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2016-03-09 09:04 - 2016-02-11 12:30 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 12:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 12:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-03-09 09:04 - 2016-02-11 12:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-03-09 09:03 - 2016-02-19 14:02 - 00038336 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-03-09 09:03 - 2016-02-19 13:54 - 01168896 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-03-09 09:03 - 2016-02-19 09:07 - 01373184 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-03-09 09:03 - 2016-02-11 09:07 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-03-09 09:03 - 2016-02-09 04:57 - 14634496 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2016-03-09 09:03 - 2016-02-09 04:57 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2016-03-09 09:03 - 2016-02-09 04:56 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2016-03-09 09:03 - 2016-02-09 04:56 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2016-03-09 09:03 - 2016-02-09 04:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\seclogon.dll
2016-03-09 09:03 - 2016-02-09 04:54 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2016-03-09 09:03 - 2016-02-09 04:51 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2016-03-09 09:03 - 2016-02-09 04:51 - 11411456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2016-03-09 09:03 - 2016-02-09 04:13 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2016-03-09 09:03 - 2016-02-09 04:13 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2016-03-09 09:03 - 2016-02-09 04:13 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2016-03-09 09:03 - 2016-02-05 13:54 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2016-03-09 09:03 - 2016-02-05 13:54 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2016-03-09 09:03 - 2016-02-05 13:53 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-03-09 09:03 - 2016-02-05 13:53 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2016-03-09 09:03 - 2016-02-05 13:50 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2016-03-09 09:03 - 2016-02-05 13:44 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2016-03-09 09:03 - 2016-02-05 13:42 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2016-03-09 09:03 - 2016-02-05 12:48 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-03-09 09:03 - 2016-02-05 12:43 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-03-09 09:03 - 2016-02-05 12:43 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-03-09 09:03 - 2016-02-05 09:07 - 00696832 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-03-09 09:03 - 2016-02-05 09:07 - 00499200 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-03-09 09:03 - 2016-02-05 09:07 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-03-09 09:03 - 2016-02-04 20:19 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
2016-03-09 09:03 - 2016-02-04 13:41 - 00296448 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-04-03 13:47 - 2009-07-13 23:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-03 13:47 - 2009-07-13 23:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-03 13:43 - 2009-07-14 00:13 - 00797606 _____ C:\windows\system32\PerfStringBackup.INI
2016-04-03 13:43 - 2009-07-13 22:20 - 00000000 ____D C:\windows\inf
2016-04-03 13:40 - 2015-06-25 16:31 - 00000010 _____ C:\Users\Owner\AppData\Local\sponge.last.runtime.cache
2016-04-03 13:39 - 2013-10-01 11:02 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-03 13:39 - 2013-10-01 11:02 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-03 13:39 - 2013-10-01 09:53 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-04-01 09:14 - 2009-07-13 22:20 - 00000000 ____D C:\windows\system32\NDF
2016-03-31 22:22 - 2013-10-01 09:53 - 00797376 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-03-31 22:22 - 2013-10-01 09:53 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-31 22:19 - 2009-07-14 00:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-03-31 22:13 - 2015-10-30 04:42 - 00000000 ___HD C:\$WINDOWS.~BT
2016-03-31 22:00 - 2011-08-08 13:16 - 00000000 ____D C:\windows\Panther
2016-03-31 19:42 - 2015-04-06 09:10 - 00000000 ___SD C:\windows\SysWOW64\GWX
2016-03-31 19:42 - 2015-04-06 09:10 - 00000000 ___SD C:\windows\system32\GWX
2016-03-31 14:06 - 2014-03-25 13:39 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Yahoo!
2016-03-31 14:06 - 2014-03-25 13:39 - 00000000 ____D C:\Users\Owner\AppData\LocalLow\Yahoo!
2016-03-31 14:06 - 2014-03-25 13:39 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2016-03-31 13:44 - 2015-09-22 09:45 - 00000000 ____D C:\Program Files (x86)\GetFormsOnline_db
2016-03-31 13:23 - 2015-09-22 09:45 - 00000000 ____D C:\Users\Owner\AppData\LocalLow\GetFormsOnline_db
2016-03-31 12:12 - 2013-10-01 11:02 - 00002125 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-31 11:00 - 2014-03-27 17:48 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-31 01:37 - 2009-07-13 22:20 - 00000000 __RSD C:\windows\Media
2016-03-31 01:36 - 2016-01-15 10:42 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Maximum Security
2016-03-31 01:36 - 2016-01-15 10:41 - 00000000 ____D C:\windows\SysWOW64\tmumh
2016-03-31 01:36 - 2016-01-15 10:41 - 00000000 ____D C:\windows\system32\tmumh
2016-03-31 01:36 - 2015-06-11 12:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trend Micro Password Manager
2016-03-31 01:36 - 2014-03-25 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-31 01:36 - 2014-01-12 11:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2016-03-31 01:36 - 2013-10-30 13:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-03-31 01:36 - 2013-10-01 11:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-31 01:36 - 2013-10-01 10:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetZero
2016-03-31 01:36 - 2013-10-01 10:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel Label@Once
2016-03-31 01:36 - 2013-10-01 10:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-03-31 01:36 - 2013-10-01 10:44 - 00000000 ____D C:\windows\SysWOW64\sda
2016-03-31 01:36 - 2013-10-01 10:43 - 00000000 ____D C:\windows\SysWOW64\Atheros_L1e
2016-03-31 01:36 - 2013-10-01 10:36 - 00000000 ____D C:\Program Files\CONEXANT
2016-03-31 01:36 - 2013-10-01 10:25 - 00000000 ____D C:\Program Files (x86)\Intel
2016-03-31 01:36 - 2013-10-01 09:20 - 00000000 ____D C:\Users\Owner
2016-03-31 01:36 - 2011-08-07 21:11 - 00000000 ____D C:\windows\en
2016-03-31 01:36 - 2011-08-07 21:10 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
2016-03-31 01:36 - 2011-08-07 21:04 - 00000000 ____D C:\Program Files (x86)\TOSHIBA
2016-03-31 01:36 - 2011-08-07 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
2016-03-31 01:36 - 2010-11-21 02:16 - 00000000 ____D C:\windows\ShellNew
2016-03-31 01:36 - 2010-11-21 02:06 - 00000000 ____D C:\windows\SysWOW64\sysprep
2016-03-31 01:36 - 2009-07-14 00:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-03-31 01:36 - 2009-07-13 22:20 - 00000000 ___HD C:\windows\system32\GroupPolicy
2016-03-31 01:36 - 2009-07-13 22:20 - 00000000 ____D C:\windows\Resources
2016-03-31 01:36 - 2009-07-13 22:20 - 00000000 ____D C:\windows\PolicyDefinitions
2016-03-31 01:36 - 2009-07-13 22:20 - 00000000 ____D C:\windows\LiveKernelReports
2016-03-31 01:36 - 2009-07-13 22:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-03-30 22:54 - 2016-01-15 10:46 - 00000000 ___HD C:\TMRescueDisk
2016-03-30 15:42 - 2015-04-08 09:14 - 00000000 ____D C:\Users\Owner\AppData\Local\ElevatedDiagnostics
2016-03-30 15:38 - 2014-03-28 08:29 - 00000000 ____D C:\ProgramData\Trend Micro
2016-03-30 15:12 - 2014-03-28 08:31 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-03-30 15:10 - 2013-10-01 11:09 - 00000000 ____D C:\Program Files (x86)\Norton PC Checkup
2016-03-30 15:10 - 2013-10-01 11:08 - 00000000 ____D C:\ProgramData\Norton
2016-03-30 15:06 - 2013-10-08 20:17 - 00000000 ____D C:\Users\Owner\Desktop\vacation list
2016-03-30 12:51 - 2015-07-17 09:47 - 00003650 _____ C:\windows\System32\Tasks\Trend Micro Inspect of Platinum
2016-03-30 12:51 - 2014-01-12 11:29 - 00003730 _____ C:\windows\System32\Tasks\HPCustParticipation HP Photosmart 6520 series
2016-03-30 12:51 - 2013-10-01 11:02 - 00004004 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-03-30 12:51 - 2013-10-01 09:53 - 00003878 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2016-03-30 12:51 - 2009-07-13 22:20 - 00000000 ____D C:\windows\Registration
2016-03-30 12:50 - 2013-10-01 11:02 - 00003752 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-03-10 14:56 - 2009-07-13 23:45 - 00416136 _____ C:\windows\system32\FNTCACHE.DAT
2016-03-10 09:18 - 2013-10-01 10:18 - 00000000 ____D C:\windows\system32\MRT
2016-03-10 09:09 - 2014-12-15 08:12 - 00000000 ____D C:\windows\system32\appraiser
2016-03-10 09:09 - 2013-10-01 10:18 - 143659408 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-03-09 09:16 - 2013-12-05 13:42 - 00000000 ____D C:\Users\Owner\AppData\Local\CrashDumps

==================== Files in the root of some directories =======

2014-07-10 17:49 - 2014-07-10 17:49 - 0000036 _____ () C:\Users\Owner\AppData\Local\housecall.guid.cache
2015-06-25 16:31 - 2016-04-03 13:40 - 0000010 _____ () C:\Users\Owner\AppData\Local\sponge.last.runtime.cache
2014-01-12 11:24 - 2014-01-12 11:24 - 0000057 _____ () C:\ProgramData\Ament.ini

Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\libeay32.dll
C:\Users\Owner\AppData\Local\Temp\msvcr120.dll
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll
C:\Users\Owner\AppData\Local\Temp\{5F1E4766-6747-4AF4-8896-1CD502431CBF}-49.0.2623.110_48.0.2564.116_chrome_updater.exe
C:\Users\Owner\AppData\Local\Temp\{7B409EBF-2EBB-488C-89B3-48301C458A28}-49.0.2623.87_48.0.2564.116_chrome_updater.exe

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-03-23 12:48

==================== End of FRST.txt ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by [removed] (2016-04-03 13:53:32)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-10-01 14:19:58)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-2107236783-443684216-2808434022-500 - Administrator - Disabled)
Guest (S-1-5-21-2107236783-443684216-2808434022-501 - Limited - Disabled)
Owner (S-1-5-21-2107236783-443684216-2808434022-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Trend Micro Maximum Security (Enabled - Up to date) {8242D66F-41BD-4049-C2E6-E578E73B62A0}
AS: Trend Micro Maximum Security (Enabled - Up to date) {3923378B-6787-4FC7-F856-DE0A9CBC281D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 21 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Reader X (10.1.14) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-2107236783-443684216-2808434022-1000\…\Amazon Kindle) (Version:  - Amazon)
Amazon Kindle (HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Amazon Kindle) (Version:  - Amazon)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\…\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.1.42 - Atheros Communications Inc.)
Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.54.4.53 - Conexant)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
FATE - The Traitor Soul (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fishdom (TM) 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.110 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7210.1528 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\…\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Photosmart 6520 series Basic Device Software (HKLM\…\{1151BCF8-3246-4E34-9C17-22E66318C41C}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 6520 series Help (HKLM-x32\…\{D3293275-1002-41F5-BC37-099B4251FF5B}) (Version: 28.0.0 - Hewlett Packard)
HP Photosmart 6520 series Product Improvement Study (HKLM\…\{F144E07C-4019-4092-BE25-B57819C97D2F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Update (HKLM-x32\…\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2353 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Java 8 Update 31 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Label@Once 1.0 (HKLM-x32\…\{0D795777-9D60-4692-8386-F2B3F2B5E5BF}) (Version: 1.0 - Corel)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MyDriveConnect 3.3.0.1342 (HKLM-x32\…\MyDriveConnect) (Version: 3.3.0.1342 - TomTom)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
PictureMover (HKLM-x32\…\{6B074646-5977-4a00-A942-8E51B675EEB6}) (Version: 3.6.0.6 - Hewlett-Packard Company)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\…\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
PlayReady PC Runtime x86 (HKLM-x32\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30124 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\…\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
SavingsBull (HKLM\…\Level Quality Watcher) (Version: SavingsBull - SavingsBull) <==== ATTENTION
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Launcher (HKLM-x32\…\{DA84ECBF-4B79-47F2-B34C-95C38484C058}) (Version: 2.01 - TOSHIBA Corporation)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 15.0.8.1 - Synaptics Incorporated)
Tom Clancy's Splinter Cell (x32 Version: 2.2.0.97 - WildTangent) Hidden
Toshiba App Place (HKLM-x32\…\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}) (Version: 1.0.6.3 - Toshiba)
TOSHIBA Application Installer (HKLM-x32\…\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.2 - TOSHIBA)
TOSHIBA Assist (HKLM-x32\…\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.0 - TOSHIBA CORPORATION)
Toshiba Book Place (HKLM-x32\…\{A14962A7-2B7D-456E-BFCD-F54E3A88D41F}) (Version: 2.2.7530 - K-NFB Reading Technology, Inc.)
TOSHIBA Bulletin Board (HKLM-x32\…\InstallShield_{1C8C049A-145F-4A6E-8290-B5C245EBE39D}) (Version: 1.6.11.64 - TOSHIBA Corporation)
TOSHIBA Disc Creator (HKLM\…\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.11 for x64 - TOSHIBA Corporation)
TOSHIBA Face Recognition (HKLM-x32\…\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.17.64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\…\{97965331-BC5D-4D9F-B6DF-5C0A123E4AE0}) (Version: 2.1.0.3 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (HKLM\…\{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.9 - TOSHIBA Corporation)
Toshiba Laptop Checkup (HKLM-x32\…\NortonPCCheckup) (Version: 2.0.13.11 - Symantec Corporation)
TOSHIBA Media Controller (HKLM-x32\…\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}) (Version: 1.0.87.4 - TOSHIBA CORPORATION)
TOSHIBA Media Controller Plug-in (HKLM-x32\…\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: 1.0.7.5 - TOSHIBA CORPORATION)
Toshiba Online Backup (HKLM-x32\…\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 2.0.0.31 - Toshiba)
TOSHIBA Quality Application (HKLM-x32\…\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.3 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\…\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.5.5109a - TOSHIBA CORPORATION)
TOSHIBA ReelTime (HKLM-x32\…\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: 1.7.21.64 - TOSHIBA Corporation)
TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\…\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.1.2001 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM-x32\…\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.12 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\…\{0AF17224-CF88-40B8-BB1A-D179369847B4}) (Version: 2.1.0.2 - TOSHIBA Corporation)
TOSHIBA Value Added Package (HKLM-x32\…\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.1.64 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM-x32\…\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 2.0.3.3 - TOSHIBA Corporation)
TOSHIBA Wireless LAN Indicator (HKLM-x32\…\{5B01BCB7-A5D3-476F-AF11-E515BA206591}) (Version: 1.0.5 - TOSHIBA CORPORATION)
TOSHIBARegistration (HKLM-x32\…\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.0.6 - TOSHIBA)
Trend Micro DirectPass (Version: 1.9.0.1094 - Trend Micro Inc.) Hidden
Trend Micro Maximum Security (HKLM\…\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 10.0 - Trend Micro Inc.)
Trend Micro Password Manager (HKLM\…\{3075404F-5657-4f31-A064-FEF98661BDD4}) (Version: 1.9.1189 - Trend Micro Inc.)
Trend Micro Titanium (Version: 10.0 - Trend Micro Inc.) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
VCRT for DirectPass x64 (Version: 1.0.0.1000 - Trend Micro, Inc.) Hidden
VCRT for DirectPass x86 (x32 Version: 1.0.0.1000 - Trend Micro, Inc.) Hidden
Virtual Villagers 5 - New Believers (x32 Version: 2.2.0.97 - WildTangent) Hidden
Visual Studio C++ 10.0 Runtime (HKLM-x32\…\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
WildTangent Games (HKLM-x32\…\WildTangent toshiba Master Uninstall) (Version: 1.0.2.5 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.5.14 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {095057E5-EB16-4B28-A13D-1D4AAB00390A} - \RegClean Pro -> No File <==== ATTENTION
Task: {253ED8FE-D396-4D70-BAEB-729B2F5A9C7C} - System32\Tasks\Trend Micro Inspect of Platinum => C:\Program Files\Trend Micro\Titanium\plugin\Pt\win32\Inspect\Inspect.exe [2015-08-19] (Trend Micro Inc.)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {44E41D37-0D22-4312-8281-DB4E11F570FB} - System32\Tasks\HPCustParticipation HP Photosmart 6520 series => C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {7A23164B-B8F4-485F-807E-0C0CD28160CF} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {7C86BEF6-4EF9-460D-B90E-2864C8081EFE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {936D106E-9BB9-42DD-81F4-E22EE7F93C99} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe
Task: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\Windows\System32\LocationNotificationWindows.exe
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {D78A2F8E-EC67-4602-B5A1-802CB53567FC} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {E07C2B97-1987-4CB6-938C-5AFCCE684082} - \BrowserSafeguard Update Task -> No File <==== ATTENTION
Task: {E3B794D6-4932-4FEC-ABCE-F43C24056464} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-31] (Adobe Systems Incorporated)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2016-01-15 10:37 - 2015-03-31 06:08 - 00026408 _____ () C:\Program Files\Trend Micro\AMSP\boost_system-vc110-mt-1_57.dll
2016-01-15 10:37 - 2015-03-31 06:08 - 00058320 _____ () C:\Program Files\Trend Micro\AMSP\boost_date_time-vc110-mt-1_57.dll
2016-01-15 10:37 - 2015-03-31 06:09 - 00686608 _____ () C:\Program Files\Trend Micro\AMSP\sqlite3.dll
2016-01-15 10:37 - 2015-03-31 06:08 - 00110320 _____ () C:\Program Files\Trend Micro\AMSP\boost_thread-vc110-mt-1_57.dll
2016-01-15 10:37 - 2015-03-31 06:08 - 00036160 _____ () C:\Program Files\Trend Micro\AMSP\boost_chrono-vc110-mt-1_57.dll
2016-01-15 10:37 - 2015-03-31 06:09 - 01314920 _____ () C:\Program Files\Trend Micro\AMSP\libprotobuf.dll
2016-01-15 10:03 - 2015-07-16 13:31 - 00168544 _____ () C:\Program Files\Trend Micro\UniClient\plugins\LUADLL.dll
2011-04-04 21:18 - 2011-04-04 21:18 - 00094208 _____ () C:\windows\System32\IccLibDll_x64.dll
2010-11-18 19:18 - 2010-11-18 19:18 - 11190784 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
2016-01-15 10:41 - 2015-07-16 13:31 - 00018944 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_system-vc110-mt-1_52.dll
2016-01-15 10:41 - 2015-07-16 13:31 - 00049664 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_date_time-vc110-mt-1_52.dll
2016-01-15 10:41 - 2015-07-16 13:31 - 00761856 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_regex-vc110-mt-1_52.dll
2011-06-09 23:09 - 2011-06-09 23:09 - 00079784 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
2016-01-15 10:41 - 2015-07-16 13:31 - 00089088 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_thread-vc110-mt-1_52.dll
2016-01-15 10:03 - 2015-07-16 13:31 - 00024312 _____ () C:\Program Files\Trend Micro\Titanium\UIFramework\boost_system-vc110-mt-1_57.dll
2016-01-15 10:03 - 2015-07-16 13:31 - 00049544 _____ () C:\Program Files\Trend Micro\Titanium\UIFramework\boost_date_time-vc110-mt-1_57.dll
2016-01-15 10:03 - 2015-07-16 13:31 - 00092792 _____ () C:\Program Files\Trend Micro\Titanium\UIFramework\boost_thread-vc110-mt-1_57.dll
2016-01-15 10:03 - 2015-07-16 13:31 - 00032552 _____ () C:\Program Files\Trend Micro\Titanium\UIFramework\boost_chrono-vc110-mt-1_57.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2014-03-27 18:04 - 00000141 ____A C:\windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2107236783-443684216-2808434022-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{5532C67C-3CB7-4C77-81E8-F9475FF30155}C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [UDP Query User{C35DD703-F247-4522-93E0-05228EB7FECD}C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe] => (Allow) C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [TCP Query User{BB48339E-192E-4A40-B7F1-EB5F65B27A98}C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{B479A4BB-40A3-4309-AF23-C1A7537D0452}C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [TCP Query User{43DE1FA2-5A2E-4058-A253-7C140160654A}C:\program files (x86)\mapsgalaxy_39\bar\2.bin\crextp39.exe] => (Block) C:\program files (x86)\mapsgalaxy_39\bar\2.bin\crextp39.exe
FirewallRules: [UDP Query User{7797512D-0734-409C-8BA1-4FD4595A62E0}C:\program files (x86)\mapsgalaxy_39\bar\2.bin\crextp39.exe] => (Block) C:\program files (x86)\mapsgalaxy_39\bar\2.bin\crextp39.exe
FirewallRules: [TCP Query User{57F1D92E-B605-4B78-B909-F73C35A668C8}C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe] => (Block) C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [UDP Query User{8A447AD4-92F3-43BD-85D8-B6C4473217F6}C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe] => (Block) C:\program files\hp\hp photosmart 6520 series\bin\hpnetworkcommunicator.exe
FirewallRules: [TCP Query User{750443B8-22BE-418E-9710-0C561FBE9830}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{DA0C2AA1-4C38-4FE7-B124-9037B7143FC7}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{1ACDC5FA-552D-4294-9F7E-9DF53AD8A7F4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

31-03-2016 16:10:45 JRT Pre-Junkware Removal
31-03-2016 19:41:44 Windows Update

==================== Faulty Device Manager Devices =============

Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

==================== Event log errors: =========================

Application errors:
==================
Error: (03/31/2016 10:21:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/31/2016 10:20:41 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.ArgumentOutOfRangeException: Number must be either non-negative and less than or equal to Int32.MaxValue or -1.
Parameter name: dueTime
Stack Trace:
   at System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period)
   at System.Timers.Timer.set_Enabled(Boolean value)
   at SnappCloud.ActivationReminder.AraClient.PostInit()
   at SnappCloud.ActivationReminder.Program.Main(String[] args)

Error: (03/31/2016 09:12:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/31/2016 09:11:26 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.ArgumentOutOfRangeException: Number must be either non-negative and less than or equal to Int32.MaxValue or -1.
Parameter name: dueTime
Stack Trace:
   at System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period)
   at System.Timers.Timer.set_Enabled(Boolean value)
   at SnappCloud.ActivationReminder.AraClient.PostInit()
   at SnappCloud.ActivationReminder.Program.Main(String[] args)

Error: (03/31/2016 08:45:13 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.ArgumentOutOfRangeException: Number must be either non-negative and less than or equal to Int32.MaxValue or -1.
Parameter name: dueTime
Stack Trace:
   at System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period)
   at System.Timers.Timer.set_Enabled(Boolean value)
   at SnappCloud.ActivationReminder.AraClient.PostInit()
   at SnappCloud.ActivationReminder.Program.Main(String[] args)

Error: (03/31/2016 08:34:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: coreServiceShell.exe, version: 3.8.0.1193, time stamp: 0x55a35dab
Faulting module name: PtSdk.dll_unloaded, version: 0.0.0.0, time stamp: 0x55c30a81
Exception code: 0xc0000005
Fault offset: 0x000007fee52fe800
Faulting process id: 0x5f0
Faulting application start time: 0xcoreServiceShell.exe0
Faulting application path: coreServiceShell.exe1
Faulting module path: coreServiceShell.exe2
Report Id: coreServiceShell.exe3

Error: (03/31/2016 07:47:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/31/2016 07:46:56 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.ArgumentOutOfRangeException: Number must be either non-negative and less than or equal to Int32.MaxValue or -1.
Parameter name: dueTime
Stack Trace:
   at System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period)
   at System.Timers.Timer.set_Enabled(Boolean value)
   at SnappCloud.ActivationReminder.AraClient.PostInit()
   at SnappCloud.ActivationReminder.Program.Main(String[] args)

Error: (03/31/2016 07:38:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/31/2016 07:37:27 PM) (Source: Toshiba App Place) (EventID: 0) (User: )
Description: System.ArgumentOutOfRangeException: Number must be either non-negative and less than or equal to Int32.MaxValue or -1.
Parameter name: dueTime
Stack Trace:
   at System.Threading.Timer..ctor(TimerCallback callback, Object state, Int32 dueTime, Int32 period)
   at System.Timers.Timer.set_Enabled(Boolean value)
   at SnappCloud.ActivationReminder.AraClient.PostInit()
   at SnappCloud.ActivationReminder.Program.Main(String[] args)

System errors:
=============
Error: (04/03/2016 01:48:42 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Platinum Host Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (04/01/2016 08:56:02 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (04/01/2016 08:56:02 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (04/01/2016 04:43:53 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (03/31/2016 10:22:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Toshiba Laptop Checkup Application Launcher service failed to start due to the following error:
%%2

Error: (03/31/2016 10:20:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Common Client Job Manager Service service failed to start due to the following error:
%%2

Error: (03/31/2016 10:19:53 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\windows\system32\Rtlihvs.dll
Error Code: 126

Error: (03/31/2016 09:12:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Toshiba Laptop Checkup Application Launcher service failed to start due to the following error:
%%2

Error: (03/31/2016 09:10:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Common Client Job Manager Service service failed to start due to the following error:
%%2

Error: (03/31/2016 09:10:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\windows\system32\Rtlihvs.dll
Error Code: 126

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz
Percentage of memory in use: 68%
Total physical RAM: 4043.86 MB
Available physical RAM: 1253.92 MB
Total Virtual: 8085.93 MB
Available Virtual: 4579.98 MB

==================== Drives ================================

Drive c: (TI106238W0C) (Fixed) (Total:452.02 GB) (Free:386.64 GB) NTFS ==>[system with boot components (obtained from drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 2DD3541A)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=452 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=12.3 GB) - (Type=17)

==================== End of Addition.txt ============================

Please go to your add/remove programs list, look for and if found remove/uninstall
SavingsBull (HKLM\…\Level Quality Watcher) (Version: SavingsBull - SavingsBull) <==== ATTENTION


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
HKLM\…\Run: [YourLocalLotto Toolbar Home Page Guard 64 bit] => "C:\PROGRA~2\YOURLO~2\bar\1.bin\AppIntegrator64.exe"
HKLM\…\Run: [WeatherBlink Home Page Guard 64 bit] => "C:\PROGRA~2\WEATHE~2\bar\1.bin\AppIntegrator64.exe"
C:\PROGRA~2\YOURLO~2\bar\1.bin\AppIntegrator64.exe
C:\PROGRA~2\WEATHE~2\bar\1.bin\AppIntegrator64.exe
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 - (No Name) - {08f9937e-0a4f-48cf-94e7-827223daec1d} - C:\Program Files (x86)\HeadlineAlley_29\bar\1.bin\29SrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 - (No Name) - {8a04fa5f-0a1a-4996-abe4-b607dad3840b} - C:\Program Files (x86)\GetFormsOnline_db\bar\1.bin\dbSrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {08f9937e-0a4f-48cf-94e7-827223daec1d} - C:\Program Files (x86)\HeadlineAlley_29\bar\1.bin\29SrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {8a04fa5f-0a1a-4996-abe4-b607dad3840b} - C:\Program Files (x86)\GetFormsOnline_db\bar\1.bin\dbSrcAs.dll No File
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-14] (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-14] (Oracle Corporation)
CHR HKLM-x32\…\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] -
CHR HKLM-x32\…\Chrome\Extension: [idkknaphebegndgimgdpfnconcickdfn] -
C:\Users\Owner\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\libeay32.dll
C:\Users\Owner\AppData\Local\Temp\msvcr120.dll
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll
C:\Users\Owner\AppData\Local\Temp\{5F1E4766-6747-4AF4-8896-1CD502431CBF}-49.0.2623.110_48.0.2564.116_chrome_updater.exe
C:\Users\Owner\AppData\Local\Temp\{7B409EBF-2EBB-488C-89B3-48301C458A28}-49.0.2623.87_48.0.2564.116_chrome_updater.exe
Task: {095057E5-EB16-4B28-A13D-1D4AAB00390A} - \RegClean Pro -> No File <==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {7A23164B-B8F4-485F-807E-0C0CD28160CF} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {D78A2F8E-EC67-4602-B5A1-802CB53567FC} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {E07C2B97-1987-4CB6-938C-5AFCCE684082} - \BrowserSafeguard Update Task -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: bitsadmin /reset /allusers
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f

Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /fRemoveProxy:
EmptyTemp:
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~~~~~``

Please remove any usb or external drives from the computer before you run this scan!


Please download RogueKiller and save it to your desktop.

You can check here if you're not sure if your computer is 32-bit or 64-bit
  • Download RogueKiller to your desktop.
  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes Close the program > Don't Fix anything!
  • Don't run any other options, they're not all bad!!
  • Post back the report which should be located on your desktop.
Please post these 2 logs when finished.

Here are the logs you requested.

 

Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by [removed] (2016-04-04 10:20:37) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM\…\Run: [YourLocalLotto Toolbar Home Page Guard 64 bit] => "C:\PROGRA~2\YOURLO~2\bar\1.bin\AppIntegrator64.exe"
HKLM\…\Run: [WeatherBlink Home Page Guard 64 bit] => "C:\PROGRA~2\WEATHE~2\bar\1.bin\AppIntegrator64.exe"
C:\PROGRA~2\YOURLO~2\bar\1.bin\AppIntegrator64.exe
C:\PROGRA~2\WEATHE~2\bar\1.bin\AppIntegrator64.exe
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 - (No Name) - {08f9937e-0a4f-48cf-94e7-827223daec1d} - C:\Program Files (x86)\HeadlineAlley_29\bar\1.bin\29SrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000 - (No Name) - {8a04fa5f-0a1a-4996-abe4-b607dad3840b} - C:\Program Files (x86)\GetFormsOnline_db\bar\1.bin\dbSrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {08f9937e-0a4f-48cf-94e7-827223daec1d} - C:\Program Files (x86)\HeadlineAlley_29\bar\1.bin\29SrcAs.dll No File
URLSearchHook: HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {8a04fa5f-0a1a-4996-abe4-b607dad3840b} - C:\Program Files (x86)\GetFormsOnline_db\bar\1.bin\dbSrcAs.dll No File
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-14] (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-14] (Oracle Corporation)
CHR HKLM-x32\…\Chrome\Extension: [dflinnddekagfkncpgojoppgnppfkbkj] -
CHR HKLM-x32\…\Chrome\Extension: [idkknaphebegndgimgdpfnconcickdfn] -
C:\Users\Owner\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\Owner\AppData\Local\Temp\libeay32.dll
C:\Users\Owner\AppData\Local\Temp\msvcr120.dll
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll
C:\Users\Owner\AppData\Local\Temp\{5F1E4766-6747-4AF4-8896-1CD502431CBF}-49.0.2623.110_48.0.2564.116_chrome_updater.exe
C:\Users\Owner\AppData\Local\Temp\{7B409EBF-2EBB-488C-89B3-48301C458A28}-49.0.2623.87_48.0.2564.116_chrome_updater.exe
Task: {095057E5-EB16-4B28-A13D-1D4AAB00390A} - \RegClean Pro -> No File <==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {7A23164B-B8F4-485F-807E-0C0CD28160CF} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {D78A2F8E-EC67-4602-B5A1-802CB53567FC} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {E07C2B97-1987-4CB6-938C-5AFCCE684082} - \BrowserSafeguard Update Task -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\…\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\…\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\…\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\…\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\…\Policies\Explorer: [NoStartMenuSubFolders] 0
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
CMD: bitsadmin /reset /allusers
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f

Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /fRemoveProxy:
EmptyTemp:
End

*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\YourLocalLotto Toolbar Home Page Guard 64 bit => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\WeatherBlink Home Page Guard 64 bit => value removed successfully
"C:\PROGRA~2\YOURLO~2\bar\1.bin\AppIntegrator64.exe" => not found.
"C:\PROGRA~2\WEATHE~2\bar\1.bin\AppIntegrator64.exe" => not found.
HKU\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{08f9937e-0a4f-48cf-94e7-827223daec1d} => value removed successfully
"HKCR\Wow6432Node\CLSID\{08f9937e-0a4f-48cf-94e7-827223daec1d}" => key removed successfully
HKU\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{8a04fa5f-0a1a-4996-abe4-b607dad3840b} => value removed successfully
"HKCR\Wow6432Node\CLSID\{8a04fa5f-0a1a-4996-abe4-b607dad3840b}" => key removed successfully
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {08f9937e-0a4f-48cf-94e7-827223daec1d} => value not found.
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {8a04fa5f-0a1a-4996-abe4-b607dad3840b} => value not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2" => key removed successfully
C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll => moved successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2" => key removed successfully
C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll => moved successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dflinnddekagfkncpgojoppgnppfkbkj" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\idkknaphebegndgimgdpfnconcickdfn" => key removed successfully
C:\Users\Owner\AppData\Local\Temp\jre-8u31-windows-au.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\libeay32.dll => moved successfully
C:\Users\Owner\AppData\Local\Temp\msvcr120.dll => moved successfully
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll => moved successfully
C:\Users\Owner\AppData\Local\Temp\{5F1E4766-6747-4AF4-8896-1CD502431CBF}-49.0.2623.110_48.0.2564.116_chrome_updater.exe => moved successfully
C:\Users\Owner\AppData\Local\Temp\{7B409EBF-2EBB-488C-89B3-48301C458A28}-49.0.2623.87_48.0.2564.116_chrome_updater.exe => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{095057E5-EB16-4B28-A13D-1D4AAB00390A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{095057E5-EB16-4B28-A13D-1D4AAB00390A}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A23164B-B8F4-485F-807E-0C0CD28160CF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A23164B-B8F4-485F-807E-0C0CD28160CF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D78A2F8E-EC67-4602-B5A1-802CB53567FC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D78A2F8E-EC67-4602-B5A1-802CB53567FC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E07C2B97-1987-4CB6-938C-5AFCCE684082}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E07C2B97-1987-4CB6-938C-5AFCCE684082}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BrowserSafeguard Update Task => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector" => key removed successfully
"HKU\.DEFAULT\Software\Classes\exefile" => key removed successfully
"HKU\.DEFAULT\Software\Classes\.exe" => key removed successfully
HKU\.DEFAULT\Software\Classes\exefile => key not found.
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully
HKU\S-1-5-21-2107236783-443684216-2808434022-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableCMD => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispAppearancePage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispBackgroundPage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\system\\NoDispSettingsPage => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewOnDrive => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRun => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableLocalMachineRunOnce => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRun => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\DisableCurrentUserRunOnce => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoViewContextMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoShellSearchButton => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFind => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFile => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideClock => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayContextMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoTrayItemsDisplay => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetFolders => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDevMgrUpdate => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetTaskbar => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDeletePrinter => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDFSTab => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoChangeStartMenu => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLogoff => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoWindowsUpdate => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoEncryptOnMove => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoRunasInstallPrompt => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoResolveSearch => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoHardwareTab => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoStartMenuSubFolders => value removed successfully

=========  ipconfig /flushdns =========

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

=========  netsh winsock reset all =========

Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.

========= End of CMD: =========

=========  netsh int ipv4 reset =========

Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.

========= End of CMD: =========

=========  netsh int ipv6 reset =========

Reseting Interface, OK!
Restart the computer to complete this action.

========= End of CMD: =========

=========  bitsadmin /reset /allusers =========

BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

{DBE59260-D929-481D-A3FA-06EE9FC5E4C2} canceled.
1 out of 1 jobs canceled.

========= End of CMD: =========

========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

 

========= End of Reg: =========

========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

 

========= End of Reg: =========

========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

 

========= End of Reg: =========

========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /fRemoveProxy: =========

ERROR: Invalid syntax.
Type "REG ADD /?" for usage.

========= End of Reg: =========

EmptyTemp: => 2.1 GB temporary data Removed.

The system needed a reboot.

==== End of Fixlog 10:26:05 ====

 

 

RogueKiller V12.1.1.0 [Apr  4 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Owner [Administrator]
Started from : C:\Users\Owner\Desktop\RogueKiller.exe
Mode : Scan – Date : 04/04/2016 11:05:27

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 9 ¤¤¤
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:49201;https=127.0.0.1:49201  -> Found
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:49201;https=127.0.0.1:49201  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://us.wow.com/?hp_ps=msn.com&hp_uid=16f4dfae-0ec3-4f26-a1d9-c703f94d9fc0&s_chn=27&s_chn2=994&s_pt=start  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://us.wow.com/?hp_ps=msn.com&hp_uid=16f4dfae-0ec3-4f26-a1d9-c703f94d9fc0&s_chn=27&s_chn2=994&s_pt=start  -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2107236783-443684216-2808434022-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6D4D86C3-31B9-42AB-9E17-1A7105B0526F} | DhcpNameServer : [removed] [removed] ([X][X])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{6D4D86C3-31B9-42AB-9E17-1A7105B0526F} | DhcpNameServer : [removed] [removed] ([X][X])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{6D4D86C3-31B9-42AB-9E17-1A7105B0526F} | DhcpNameServer : [removed] [removed] ([X][X])  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK5076GSXN +++++
— User —
[MBR] 12739e231833ca60b31559d97d5dce66
[BSP] 3cb979e5c840e71c8a626ef0d7c93b25 : HP|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 462871 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 951033856 | Size: 12568 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK

What we can do now is run an online scan with Eset, it is a trusted scanner, reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.



[external image: GzlsbnV.png]ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme.
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click LIST OF FOUND THREATS. If no threats were found, skip the next two bullet points.
  • Click EXPORT TXT FILE and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to uninstall application on close and click Finish.
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.
~~~~~~~~~~~~~~~~~~~~~~``
After you run the scan please tell me how the computer is at the moment.

Here is the ESET scan you requested.

 

C:\AdwCleaner\FileQuarantine\C\windows\SysNative\drivers\netfilter64.sys.vir a variant of Win32/AdWare.Adpeak.G application
C:\Users\Owner\Downloads\pctuneupmaestro_installer_42_.exe a variant of Win32/PCTuneUpMaestro.A potentially unwanted application
C:\windows\Installer\2dc6f28c.msi multiple threats
C:\windows\Installer\2dc7259f.msi multiple threats
C:\windows\Installer\83c551.msi a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application
C:\windows\Installer\MSIABEA.tmp a variant of Win32/Bundled.Toolbar.Ask.M potentially unsafe application
 

Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
C:\Users\Owner\Downloads\pctuneupmaestro_installer_42_.exe
C:\windows\Installer\2dc6f28c.msi
C:\windows\Installer\2dc7259f.msi
C:\windows\Installer\83c551.msi
C:\windows\Installer\MSIABEA.tmp
EmptyTemp:
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Please post the log and give me an update on how your computer is.

Computer is running much better than when we started.  I can open windows explorer and download much faster and it hasn't become unresponsive since beginning.

 

Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by [removed] (2016-04-04 17:38:20) Run:2
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
C:\Users\Owner\Downloads\pctuneupmaestro_installer_42_.exe
C:\windows\Installer\2dc6f28c.msi
C:\windows\Installer\2dc7259f.msi
C:\windows\Installer\83c551.msi
C:\windows\Installer\MSIABEA.tmp
EmptyTemp:
End

*****************

Restore point was successfully created.
Processes closed successfully.
C:\Users\Owner\Downloads\pctuneupmaestro_installer_42_.exe => moved successfully
C:\windows\Installer\2dc6f28c.msi => moved successfully
C:\windows\Installer\2dc7259f.msi => moved successfully
C:\windows\Installer\83c551.msi => moved successfully
C:\windows\Installer\MSIABEA.tmp => moved successfully
EmptyTemp: => 63.7 MB temporary data Removed.

The system needed a reboot.

==== End of Fixlog 17:38:52 ====

I think your good to go!


[external image: AFZxnZc.jpg] DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).
~~~~~~~~~~~~~~~~~~~~~~~
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: jv4nhMJ.png]NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: j1OLIec.png]SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
  • [external image: JEP5iWI.png]Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.

Need a second opinion on a file or website? Scan the file/URL before clicking by using one of the following free online scanner services.
  • [external image: nWhGEI3.png]VirusTotal (File & URL)
  • [external image: MJUfyKX.png]Jotti's Malware Scan (File)
  • [external image: XeTvs74.png]Dr.Web Online Check (URL)
  • [external image: 5v676cC.png]Trend Micro Site Safety Center (URL)
  • [external image: 2tXp7dz.png] Norton Safe Web (URL)
Want to help others? Join the ClassRoom and learn how.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI