This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

This PC is blocking aswMBR and is very slow [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Following the excellent help from Ken545 on two PCs, my neighbour has asked if the ACER notebook she wants to leave in her holiday shack could be cleaned as well.

 

PC is an ACER V15 running Windows 8.1 64-bit with 8Gb DDR3 L memory and 1Tb HDD (~890Gb free).
 
Security is WIndows Firewall and Windows Defender.
 
Initial start was slow but bearable (about 1min to stable desktop).
 
I downlaoded aswMBR and Farbar tools to desktop. Shut down running tasks and ran aswMBR (as admin). All was normal unitl part way through definition update when PC restarted.
 
This time it took more than 3 minutes to get to a stable desktop.
 
Ran aswMBR (as admin) again; it took about 1 minute to open (I then started timing); it took some 30 seconds to show any content in window and started picking up where it had left off - restarting to downlaod definitions.
 
After some 5 minutes 10 seconds it gave a blue screen error (they don't have BSOD in WIn8!) saying Clock_Watchdog_Timeout error and restarted. This time it took more than 6 minutes to get to a stable desktop.
 
Tried to run aswMBR (as admin a third time. GOt to about 80Mb of definitions download when blue scree error kicked in again, with Clock_Watchdog_Timeout error.
 
This time splash screen stayed until 0:50, then a black screen until 1:20, got to login at 1:35, had Welcome until 2:10, and finally got to stable desktop at 5:31.
 
Ran FRST64 (as admin); Windows Smart Screen intercepted it and prevented it from running.
 
I disconnected from the Internet and ran FRST64 (as admin) again. This time WSS had an option to run anyway which I did.
 
I did not see an option for "All Users". Scan completed with logs: FRST.txt and Addition.txt inserted below.
 
I then tried to run aswMBR again without an Internet connection. Said "No" to download definitions and saw message runing without Avast engine. Scan completed successfully and saved aswMBR.txt log see below. I trust without the Avast engine this is still useful.
 
There was also an MBR.dat file on the desktop which wanted to run as a video. I did not open it.
 
I hope you can give some guidance on how to clean this PC, including how to stop the Windows Smart Screen intercepting utilities.
 
Here is the aswMBR log:
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-04-19 15:44:23
—————————–
15:44:23.158    OS Version: Windows x64 6.2.9200 
15:44:23.158    Number of processors: 4 586 0x4501
15:44:23.159    ComputerName: VALDA  UserName: Valda
15:44:24.346    Initialize success
15:44:24.376    VM: initialized successfully
15:44:24.377    VM: Intel CPU supported 
15:44:28.293    VM: supported disk I/O storport.sys
15:44:42.742    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002f
15:44:42.751    Disk 0 Vendor: ST1000LM024_HN-M101MBB 2BA30001 Size: 953869MB BusType: 11
15:44:42.896    VM: Disk 0 MBR read successfully
15:44:42.902    Disk 0 MBR scan
15:44:42.908    Disk 0 unknown MBR code
15:44:42.914    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
15:44:42.959    Disk 0 scanning C:\WINDOWS\system32\drivers
15:44:50.028    Service scanning
15:45:06.108    Modules scanning
15:45:06.122    Disk 0 trace - called modules:
15:45:06.156    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll storahci.sys 
15:45:06.163    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe00151d03450]
15:45:06.177    3 CLASSPNP.SYS[fffff80050cfff40] -> nt!IofCallDriver -> [0xffffe001513c7550]
15:45:06.187    5 ACPI.sys[fffff80050370c21] -> nt!IofCallDriver -> \Device\0000002f[0xffffe001513c8700]
15:45:06.196    Disk 0 statistics 135932/0/5 @ 10.24 MB/s
15:45:06.203    Scan finished successfully
15:45:29.372    Disk 0 MBR has been saved successfully to "C:\Users\Valda\Desktop\MBR.dat"
15:45:29.380    The log file has been saved successfully to "C:\Users\Valda\Desktop\aswMBR.txt"
 
 
And here is the FRST64 log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
Ran by [removed] (administrator) on VALDA (19-04-2016 15:41:11)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Dolby Laboratories Inc.) C:\Program Files\Dolby Digital Plus\ddp.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Spotify Ltd) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceStartMenuIndexer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-18] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1380056 2014-03-18] (Realtek Semiconductor)
HKLM-x32\…\Run: [abDocsDllLoader] => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [91488 2015-11-23] ()
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1298456 2015-04-20] (CANON INC.)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23248560 2016-04-09] (Dropbox, Inc.)
HKLM\…\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] (Qualcomm®Atheros®)
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\RunOnce: [RegDXVA1] => C:\Windows\system32\cmd.exe /c reg import "C:\Program Files (x86)\Acer\abPhoto\SwitchUserVideoKey.reg"
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\RunOnce: [SetAsDefault] => C:\Program Files (x86)\Acer\Acer Video Player\SwitchUserVideoKey.bat
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [ISUSPM] =>  -scheduler
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-09-20] (Spotify Ltd)
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\RunOnce: [Application Restart #1] => C:\Users\Valda\AppData\Local\Pokki\Engine\HostAppService.exe  –disable-internal-flash –noerrdialogs –no-message-box –disable-extensions –disable-web-security –disable-web-resources –disable-cli (the data entry has 549 more characters).
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\MountPoints2: {237434b1-df4d-11e5-826c-1008b127f26c} - "E:\AutoRun.exe" 
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{0A159044-1CA1-473A-A365-82A7E1CC161E}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{2EB4B5A8-928A-4E8F-8376-1261E9885494}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{2F364102-6AA1-4723-B2D6-A0A54DE7F775}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{B11A154C-321E-493A-93DF-87DD6FDEA81F}: [DhcpNameServer] 192.168.8.1 192.168.8.1
 
Internet Explorer:
==================
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/?pc=cosp&ptag;=A9C7EDF55B3&form;=CONMHP&conlogo;=CT3210127
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxps://www.bing.com/?pc=cosp&ptag;=A9C7EDF55B3&form;=CONMHP&conlogo;=CT3210127
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://accounts.google.com/Login#identifier
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://au.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://au.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> DefaultScope {953E7D0F-2D0D-11E5-825E-F0761C2C2D04} URL = hxxp://search.homepage-web.com/?src=omnibox&partner;=acer&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> {953E7D0F-2D0D-11E5-825E-F0761C2C2D04} URL = hxxp://search.homepage-web.com/?src=omnibox&partner;=acer&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://au.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> {D4DB4AE4-13D9-443A-81CC-41DA15D0B5AC} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-04-10] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-01-10] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default
FF DefaultSearchEngine: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: hxxps://homepage-web.com/?s=acer&m;=start
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2016-01-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-01] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF SearchPlugin: C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\searchplugins\Web Search.xml [2016-04-10]
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.com.au/"
CHR DefaultSearchURL: Default -> hxxps://secure.homepage-web.com/?partner=acer&src;=omnibox&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> homepage-web.com
CHR DefaultSuggestURL: Default -> hxxps://secure-suggest.homepage-web.com/suggest?format=json&locale;={language}&q;={searchTerms}
CHR Profile: C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-01]
CHR Extension: (Google Docs) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-01]
CHR Extension: (Google Drive) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-01]
CHR Extension: (YouTube) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-01]
CHR Extension: (Google Search) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-03-01]
CHR Extension: (Google Sheets) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-01]
CHR Extension: (Google Docs Offline) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-10]
CHR Extension: (Google Keep - notes and lists) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2016-04-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-10]
CHR Extension: (Gmail) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-01]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Windows (R) Win 7 DDK provider) [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2860760 2016-01-14] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-10] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-10] (Dropbox, Inc.)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-06-12] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-25] (WildTangent)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-19] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [466664 2014-06-10] (Acer Incorporate)
R2 Optus 4G Modem HL; C:\ProgramData\MobileBrServ\mbbservice.exe [242264 2014-11-20] ()
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-06-26] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-06-26] (Acer Incorporate)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240 2014-07-15] (acer)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-25] (Qualcomm Atheros)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [99320 2013-10-03] (Intel Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466136 2014-01-14] (Realsil Semiconductor Corporation)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-19 15:41 - 2016-04-19 15:41 - 00022755 _____ C:\Users\Valda\Desktop\FRST.txt
2016-04-19 15:40 - 2016-04-19 15:41 - 00000000 ____D C:\FRST
2016-04-19 15:10 - 2016-04-19 15:10 - 00293152 _____ C:\WINDOWS\Minidump\041916-32015-01.dmp
2016-04-19 15:04 - 2016-04-19 15:40 - 00001400 _____ C:\Users\Valda\Desktop\WTT topic content.txt
2016-04-19 14:56 - 2016-04-19 14:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-19 14:46 - 2016-04-19 14:46 - 00288504 _____ C:\WINDOWS\Minidump\041916-28109-01.dmp
2016-04-19 14:39 - 2016-04-19 15:10 - 597918099 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 14:39 - 2016-04-19 15:10 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 14:39 - 2016-04-19 14:40 - 00297552 _____ C:\WINDOWS\Minidump\041916-114406-01.dmp
2016-04-19 14:33 - 2016-04-19 14:34 - 02375680 _____ (Farbar) C:\Users\Valda\Desktop\FRST64.exe
2016-04-19 14:32 - 2016-04-19 14:32 - 05198336 _____ (AVAST Software) C:\Users\Valda\Desktop\aswMBR.exe
2016-04-12 09:35 - 2016-04-12 09:35 - 00243344 _____ C:\Users\Valda\Documents\WO 9646366.pdf
2016-04-12 07:53 - 2016-04-12 07:53 - 00533492 _____ C:\Users\Valda\Documents\WO 9749726.pdf
2016-04-12 07:16 - 2016-04-12 07:16 - 00147700 _____ C:\Users\Valda\Documents\WO 9809763.pdf
2016-04-11 18:16 - 2016-04-11 18:16 - 00002001 _____ C:\Users\Public\Desktop\abMusic.lnk
2016-04-11 08:32 - 2016-04-11 08:32 - 00787736 _____ C:\Users\Valda\Documents\WO9868772.pdf
2016-04-11 08:28 - 2016-04-11 08:28 - 00788025 _____ C:\Users\Valda\Documents\IMG_20160411_0001.pdf
2016-04-10 22:11 - 2016-04-10 22:11 - 00692088 _____ C:\Users\Valda\Documents\Get Started with Dropbox.pdf
2016-04-10 22:02 - 2016-04-19 15:14 - 00000000 ___RD C:\Users\Valda\Dropbox
2016-04-10 22:02 - 2016-04-10 22:02 - 00001246 _____ C:\Users\Valda\Desktop\Dropbox.lnk
2016-04-10 22:00 - 2016-04-10 22:00 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-04-10 21:38 - 2016-04-10 21:38 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller (2).exe
2016-04-10 21:33 - 2016-04-10 21:33 - 00000000 ____D C:\Users\Valda\AppData\Roaming\Dropbox
2016-04-10 21:32 - 2016-04-19 15:37 - 00000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-04-10 21:32 - 2016-04-19 15:11 - 00000914 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-04-10 21:32 - 2016-04-19 14:56 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-04-10 21:32 - 2016-04-19 14:52 - 00000000 ____D C:\Users\Valda\AppData\Local\Dropbox
2016-04-10 21:32 - 2016-04-10 21:32 - 00003890 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2016-04-10 21:32 - 2016-04-10 21:32 - 00003654 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2016-04-10 21:32 - 2016-04-10 21:32 - 00000000 ____D C:\ProgramData\Dropbox
2016-04-10 21:31 - 2016-04-10 21:32 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller (1).exe
2016-04-10 21:30 - 2016-04-10 21:30 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller.exe
2016-04-10 16:27 - 2016-04-10 16:27 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-19 15:26 - 2015-05-30 16:47 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-974442171-2668444937-4057906661-1002
2016-04-19 15:20 - 2015-05-30 17:10 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-04-19 15:20 - 2013-08-23 01:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-04-19 15:18 - 2015-05-30 16:31 - 00000000 ____D C:\Users\Valda\AppData\Local\SweetLabs App Platform
2016-04-19 15:17 - 2014-03-18 20:03 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-19 15:17 - 2013-08-22 23:36 - 00000000 ____D C:\WINDOWS\Inf
2016-04-19 15:15 - 2014-11-07 13:15 - 00000000 ___DO C:\Users\Valda\OneDrive
2016-04-19 15:11 - 2016-03-01 11:42 - 00000904 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-19 15:10 - 2013-08-23 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-19 15:02 - 2015-05-30 16:44 - 00002400 _____ C:\Users\Valda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2016-04-19 15:00 - 2015-11-02 13:06 - 00003292 _____ C:\WINDOWS\System32\Tasks\SweetLabs App Platform
2016-04-19 14:45 - 2014-09-20 12:48 - 00000000 ____D C:\Users\UpdatusUser
2016-04-19 14:42 - 2015-05-30 16:31 - 00000000 ____D C:\Users\Valda
2016-04-14 09:45 - 2016-03-01 11:26 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-12 09:47 - 2016-03-01 11:42 - 00000908 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-12 07:17 - 2016-03-11 19:25 - 00000000 ___HD C:\ProgramData\CanonIJMIG
2016-04-12 06:48 - 2016-03-01 11:43 - 00002219 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-12 06:48 - 2016-03-01 11:43 - 00002207 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-12 06:07 - 2016-02-18 18:07 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-04-11 18:16 - 2014-07-26 04:28 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2016-04-11 18:16 - 2014-07-26 04:28 - 00000000 ____D C:\Program Files (x86)\Acer
2016-04-11 18:15 - 2015-05-30 16:43 - 00000000 ____D C:\Users\Valda\AppData\Local\clear.fi
2016-04-10 22:01 - 2015-05-30 16:37 - 00000000 ____D C:\Users\Valda\AppData\Local\VirtualStore
2016-04-10 20:49 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-10 16:39 - 2013-08-23 01:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-10 16:38 - 2016-01-30 07:54 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2016-04-10 16:38 - 2016-01-30 07:54 - 00000000 ___SD C:\WINDOWS\system32\GWX
2016-04-10 16:28 - 2016-03-11 19:15 - 00000000 ____D C:\Users\Valda\AppData\LocalLow\Canon Easy-WebPrint EX
2016-04-10 15:58 - 2013-08-22 23:25 - 01310720 ___SH C:\WINDOWS\system32\config\BBI
 
==================== Files in the root of some directories =======
 
2014-09-20 13:01 - 2014-09-20 13:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\Valda\AppData\Local\Temp\FoxitUpdater.exe
C:\Users\Valda\AppData\Local\Temp\McCSPInstall.dll
C:\Users\Valda\AppData\Local\Temp\mccspuninstall.exe
C:\Users\Valda\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Valda\AppData\Local\Temp\oct12C.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct3DB0.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct4823.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct827D.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct8940.tmp.exe
C:\Users\Valda\AppData\Local\Temp\octD5D8.tmp.exe
C:\Users\Valda\AppData\Local\Temp\octDBE1.tmp.exe
C:\Users\Valda\AppData\Local\Temp\octECEA.tmp.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-04-19 15:26
 
==================== End of FRST.txt ============================
 
 
And finally, the Addition log from FRST64:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
Ran by [removed] (2016-04-19 15:41:51)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (X64) (2015-05-30 06:34:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-974442171-2668444937-4057906661-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-974442171-2668444937-4057906661-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-974442171-2668444937-4057906661-1004 - Limited - Enabled)
UpdatusUser (S-1-5-21-974442171-2668444937-4057906661-1001 - Limited - Enabled) => C:\Users\UpdatusUser
Valda (S-1-5-21-974442171-2668444937-4057906661-1002 - Administrator - Enabled) => C:\Users\Valda
Valda_2 (S-1-5-21-974442171-2668444937-4057906661-1005 - Limited - Enabled) => C:\Users\Valda_2
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
abDocs (HKLM-x32\…\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.09.2001 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\…\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.02.2001 - Acer Incorporated)
abFiles (HKLM-x32\…\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.00.3002 - Acer Incorporated)
abMusic (HKLM-x32\…\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 3.00.2003.6 - Acer Incorporated)
abPhoto (HKLM-x32\…\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.06.2000.22 - Acer Incorporated)
Acer Care Center (HKLM\…\{A424844F-CDB3-45E2-BB77-1DDE4A091E76}) (Version: 1.00.3013 - Acer Incorporated)
Acer Explorer Agent (HKLM\…\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\…\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8107 - Acer Incorporated)
Acer Portal (HKLM-x32\…\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.09.2002 - Acer Incorporated)
Acer Power Management (HKLM\…\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8105 - Acer Incorporated)
Acer Quick Access (HKLM\…\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3016.0 - Acer Incorporated)
Acer Recovery Management (HKLM\…\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\…\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3005 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\…\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3005 - Acer Incorporated)
Acer Video Player (HKLM-x32\…\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2005.0 - Acer Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Amazon 1Button App (HKLM-x32\…\{FF0A904E-8827-4F6E-9A59-900D4C997AD1}) (Version: 1.0.8 - Amazon) <==== ATTENTION
AOP Framework (HKLM-x32\…\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.15.2000.1 - Acer Incorporated)
Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\…\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: 4.1.0 - Canon Inc.)
Canon MG2500 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.02 - Canon Inc.)
Canon MG2500 series On-screen Manual (HKLM-x32\…\Canon MG2500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon My Image Garden (HKLM-x32\…\Canon My Image Garden) (Version: 3.3.0 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\…\Canon My Image Garden Design Files) (Version: 3.2.0 - Canon Inc.)
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.6.1 - Canon Inc.)
CyberLink PhotoDirector 3 (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.4218 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
Dolby Digital Plus Home Theater (HKLM\…\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Dropbox (HKLM-x32\…\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.35.1 - Dropbox, Inc.) Hidden
eBay Worldwide (HKLM-x32\…\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
Farm to Fork Collector's Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Game Explorer Categories - genres (HKLM-x32\…\WildTangentGameProvider-acer-genres) (Version: 11.0.0.7 - WildTangent, Inc.)
Game Explorer Categories - main (HKLM-x32\…\WildTangentGameProvider-acer-main) (Version: 11.0.0.7 - WildTangent, Inc.)
Goal United (HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Pokki_20bc77071450f86fee7470f383e7601729828efa) (Version: 1.0.3.41437 - SweetLabs)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Hidden Mysteries - Graceland (HKLM-x32\…\Hidden Mysteries - Graceland) (Version: 1.0 - GameMill Entertainment)
Host App Service (HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\SweetLabs_AP) (Version: 0.269.7.927 - Pokki)
Inspector Magnusson - Murder on the Titanic (x32 Version: 2.2.0.110 - WildTangent) Hidden
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.165.1 - Intel Corporation)
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
Lost in Night (x32 Version: 3.0.2.38 - WildTangent) Hidden
LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Microsoft Outlook 2013 - en-us (HKLM\…\OutlookRetail - en-us) (Version: 15.0.4815.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 44.0.2 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 44.0.2 (x86 en-US)) (Version: 44.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 44.0.2 - Mozilla)
MYOB AccountRight Plus v19.10 (x32 Version: 19.10.0 - MYOB Technology Pty Ltd) Hidden
NVIDIA Graphics Driver 332.35 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.35 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0927 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation)
NVIDIA Update 1.15.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Optus 4G Modem HL (HKLM-x32\…\Optus 4G Modem HL) (Version: 22.001.26.00.74 - Huawei Technologies Co.,Ltd)
Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Pokki) (Version: 0.269.2.471 - Pokki)
Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\SweetLabs_Start_Menu) (Version: 0.269.7.927 - Pokki)
Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.318 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.29 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.25.108.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7203 - Realtek Semiconductor Corp.)
Spotify (HKLM-x32\…\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.51 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.13 - WildTangent) Hidden
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-974442171-2668444937-4057906661-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02F765CE-0EC3-4DEE-ACB0-73FEDFFC82B9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-11] (Microsoft Corporation)
Task: {03555308-1C70-4DDE-8263-467280F623A3} - System32\Tasks\SweetLabs App Platform => C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe [2016-04-14] (Pokki)
Task: {065896BE-FAF6-4AEC-B86B-811D36A81FE9} - System32\Tasks\abDocsDllLoader => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe [2015-11-23] ()
Task: {15B8CED1-1430-4487-861D-74DDE81C6F62} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [2016-01-14] (Acer Incorporated)
Task: {185669F3-1C5B-46DE-A0A5-8E55A572676A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-01-10] (Microsoft Corporation)
Task: {3D222F32-B59A-4620-A1D1-670AC5F9E641} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-06-12] (Acer Incorporated)
Task: {3FCBB702-5090-4D41-B310-35AEB536818E} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2014-08-29] ()
Task: {48A31DC3-8986-473B-8968-244E049814DB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-01] (Google Inc.)
Task: {4B0864C2-AB5D-424A-A616-295DEF51C449} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2014-06-09] (Acer Incorporated)
Task: {609647A4-3D37-4E92-9B30-2ACAFF85A647} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-01] (Google Inc.)
Task: {6A1EA7FF-879B-4620-A9C2-C525C0993E78} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe [2013-09-09] (Dolby Laboratories Inc.)
Task: {81698CFC-4E31-44DF-8972-55A9E7F46582} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2014-08-29] ()
Task: {8F3D2505-F0D3-4937-8569-A2F38486955D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-10] (Dropbox, Inc.)
Task: {A15CE7A3-142F-4986-97F2-385E16FF95FE} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {B6EAA0B7-AF1A-4852-BE63-E8ECDBAADFD9} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-06-10] (Acer Incorporate)
Task: {C12C5A69-EA8A-4F1D-BBEC-81DB714052BB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-01-10] (Microsoft Corporation)
Task: {D35BDF10-850E-4701-9799-066F9AA5333C} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-18] (Acer Incorporated)
Task: {D7F524F5-77EE-485C-BA66-EA1FDD41D23E} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2016-01-19] (Acer)
Task: {DB317CD5-AA28-4374-BF64-BB03E5B01BF9} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {DD5B8A6B-8761-400F-83C8-43C3D1BA9F7A} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: )
Task: {E7638087-2ACF-42D4-A096-C9D652417475} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-10] (Dropbox, Inc.)
Task: {E7A59D9F-4E73-4799-A961-A18E64CE0BB1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {E9D1DF34-EFC9-435C-B43C-50EAEC279F11} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Public\Desktop\Agoda.lnk -> C:\ProgramData\OEM_Agoda\StartURL.exe () -> hxxp://www.agoda.com?cid=1630081
ShortcutWithArgument: C:\Users\Public\Desktop\Dropbox.lnk -> C:\Program Files\Dropbox\StartURL.exe () -> hxxps://www.dropbox.com/partners/acer2014/download
ShortcutWithArgument: C:\Users\Public\Desktop\PRIVATE WiFi.lnk -> C:\Program Files\PRIVATE WiFi\StartURL.exe () -> hxxp://www.privatewifi.com/partner/clicks.php?pid=928649&bid;=76&campaign;=default
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-09-20 12:48 - 2014-01-08 10:48 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-03-11 19:23 - 2013-05-14 17:50 - 00140936 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2016-03-11 12:17 - 2014-11-20 18:48 - 00242264 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2014-07-26 04:31 - 2012-04-24 20:43 - 00254512 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2013-09-09 13:13 - 2013-09-09 13:13 - 00050904 _____ () C:\Program Files\Dolby Digital Plus\Dolby.DDP.Controls_Desktop.dll
2014-03-19 11:35 - 2014-03-08 02:21 - 00080312 _____ () C:\Windows\system32\igfxexps.dll
2014-02-25 22:14 - 2014-02-25 22:14 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2014-02-25 22:11 - 2014-02-25 22:11 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2014-02-25 22:17 - 2014-02-25 22:17 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
2015-11-23 17:44 - 2015-11-23 17:44 - 01769312 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
2015-05-30 17:10 - 2015-10-13 05:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-04-10 21:37 - 2016-03-22 07:50 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2016-04-19 14:56 - 2016-03-22 07:51 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2016-04-19 14:56 - 2016-03-22 07:50 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-04-10 21:37 - 2016-03-22 07:50 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2016-04-10 21:37 - 2016-03-22 07:50 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-04-19 14:56 - 2016-03-22 07:50 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2016-04-10 21:37 - 2016-04-09 04:20 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-04-10 21:37 - 2016-03-22 07:50 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2016-04-10 21:37 - 2016-03-22 07:51 - 00112592 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-04-19 14:56 - 2016-03-22 07:52 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2016-04-10 21:37 - 2016-03-22 07:50 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
2016-04-19 14:56 - 2016-03-22 07:50 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2016-04-19 14:56 - 2016-03-22 07:51 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2016-04-19 14:56 - 2016-03-22 07:52 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2016-04-19 14:56 - 2016-04-09 04:19 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00021824 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-04-19 14:56 - 2016-04-09 04:20 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-04-10 21:37 - 2016-03-22 07:51 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00158008 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2016-04-19 14:56 - 2016-03-22 07:54 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2016-04-19 14:56 - 2016-03-22 07:54 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2016-04-10 21:37 - 2016-04-09 04:20 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-04-10 21:37 - 2016-03-22 07:56 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-11-16 18:55 - 2015-11-16 18:55 - 00202456 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2015-11-16 18:56 - 2015-11-16 18:56 - 00654000 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2015-11-16 18:56 - 2015-11-16 18:56 - 00641240 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2015-11-16 18:56 - 2015-11-16 18:56 - 00119000 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2016-02-18 18:21 - 2016-02-18 18:21 - 00015064 _____ () C:\WINDOWS\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2016-01-14 16:12 - 2016-01-14 16:12 - 00013016 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2016-01-14 16:11 - 2016-01-14 16:11 - 00277856 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
2016-01-19 14:06 - 2016-01-19 14:06 - 00194048 _____ () C:\Program Files (x86)\Acer\Acer Portal\curllib.dll
2016-01-19 14:06 - 2016-01-19 14:06 - 00110592 _____ () C:\Program Files (x86)\Acer\Acer Portal\OpenLDAP.dll
2014-09-20 12:50 - 2013-12-10 09:27 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 00569856 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ppGoogleNaClPluginChrome.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 01400846 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\avcodec-54.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 00151054 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\avutil-51.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 00222734 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\avformat-54.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 23:25 - 2013-08-22 23:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Valda\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\windows photo viewer wallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AFF950B5-E50F-490C-A356-61966989B856}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{D45F2DEB-5DC4-420F-B207-F9C8D794384C}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{368AA98A-9058-43BB-A710-FCAC404DB2B2}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{D7C97A6A-D6FB-4F06-929A-65D02CB2FB04}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{8DA6FF61-9BD7-4A38-9214-EBFF37DABA30}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{882C979D-4084-4E83-BE90-4DD269D16461}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{AB92FFF7-BD7F-44CB-A466-CB138D1F4976}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{F34EF84C-672F-4FA3-8F5D-4101A50451E5}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{40D8BE5C-FEF4-4461-9AE6-42AC315B734E}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{DB4357B3-A584-4542-8A1A-9072F7AB6376}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{81351C50-F528-4406-92C0-AEAEFE5517A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{8422D21D-4388-44B9-B159-CE040BACEEAA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{84AFACB1-02D8-40B7-8521-3B49310D4AA5}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{F9DD3586-975D-4006-A6F8-A3D79BCDA2CC}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{E08D6C5B-3A13-416B-9C86-3A1656E8A1DD}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{07E6C917-528E-4A12-A000-DA0B5272ADAB}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{D9D7D184-5CA8-4742-9017-6D373DB97E82}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Play.exe
FirewallRules: [{661AD751-0BD3-46C2-A576-2EF801EA31D2}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{CDF7EF82-B2BD-428A-A3EC-D0D7C59E7003}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{27879486-9ACA-4DE0-9C01-B04F0E60F631}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{59A0E661-DA1B-4E8D-A7AD-694E051B480F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{6DFE83AB-2734-4DAB-AC63-E9B92AB83D96}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{CADEC948-96E7-4F7D-A210-6A0482059E7A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{41446356-E125-4F1F-80D5-EF41489BA9FD}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{8DEF424D-E082-4AEF-ACD0-55FFD9733C01}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{C8B20BF5-4D3E-4A08-B9AC-8EF31116C6A3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{7338970A-57D6-4A38-B04C-0A0B923F87C3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{5345F876-5C7C-4CED-A297-9EF0EBAC6845}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{49628988-084F-4966-8916-4FEE0754E899}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{CE6E1F52-B3BE-4A72-AF60-2BCA5C9B1814}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{0877F64A-1DBC-4BBE-A531-C5400EED44AF}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{6FB69EA0-E7FD-48CD-BDFC-A87D145B2A93}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{32C1492B-5136-4FBF-8C15-EE84845E4BBA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{881C2E6D-A4C2-4B3D-A62D-B93A93F3BCC9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{C6CABB36-119D-47A4-ACBD-1DE32D773915}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{626F108E-2B9B-4A4B-AAF2-DF9BCE46BDF3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{1E075124-1D73-4931-900A-379A5F81992E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{EF373059-4F61-4844-B9C3-D0852B2865E1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{14A3214B-AD15-40AA-B145-718DC19C2C51}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{4EAFD24F-5150-455D-B2D5-420C0185270E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{C50DB59B-547D-478D-9E30-6789B0A01109}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{580AD0BB-E949-4A03-B0C5-4F3B7D523A2E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{942CFCDB-6200-4967-A85D-3AD927A6253D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{4C949DC1-9A11-440F-9876-36C8BA62F46D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{0AA96318-B905-4B51-AB9A-4569D52656E1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{A378F9A1-8708-4651-A547-EB5EB6516C96}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{39178852-F613-4809-85DF-097D83691827}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{19BE7717-FB95-4A7B-BEF2-FB28ABF0708C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{48A6D524-1FCF-4AD2-9A25-188AD945C3EF}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{B098A471-E99A-4692-8041-70A95D058F99}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0065F20B-B795-411C-984D-22C7586E0711}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{318E9D5C-8B01-4C6A-8874-EA44EF18E1C5}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{7D3E059A-294C-4787-9A3D-6A070C982125}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{E25FDA55-B2F4-445D-90C2-48B0F98E39EB}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{3E1E204A-6775-49EE-A4FD-B3987BA5C1DD}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{50F268CD-0DE1-49CF-B94C-3BF37137E07B}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{77A94F49-18C8-4428-8851-FEE9AF23C4FD}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{16B955D5-2F15-4F9A-8EED-D42DF822B5EC}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{5D02D7A8-0B9D-41CB-BA90-1EEE971E20FE}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{16DF9D5F-77FA-4C08-82FA-63165C9569DC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{95E2DA70-1198-4825-A7ED-6D9266312010}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
 
==================== Restore Points =========================
 
13-03-2016 16:24:44 Installed DirectX
10-04-2016 16:37:25 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Bluetooth Device (Personal Area Network)
Description: Bluetooth Device (Personal Area Network)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BthPan
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/19/2016 03:38:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1984
 
Start Time: 01d199fb734b7e56
 
Termination Time: 4294967295
 
Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe
 
Report Id: 66e8dbde-05ef-11e6-8273-0c5b8f279a64
 
Faulting package full name: Amazon.com.Amazon_3.1.2.8_neutral__343d40qqvtj1t
 
Faulting package-relative application ID: App
 
Error: (04/19/2016 03:20:16 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: VALDA)
Description: Application or service 'Microsoft Office Document Cache Sync Client Interface' could not be shut down.
 
Error: (04/10/2016 04:29:56 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database
 
Error: (04/10/2016 04:20:45 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: VALDA)
Description: Application or service 'Microsoft Office Document Cache Sync Client Interface' could not be shut down.
 
Error: (04/10/2016 04:12:52 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={E64FEA12-CE1F-42F5-BEA1-6C55FBF4E3F0}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (04/10/2016 03:56:05 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={1A795855-D091-4627-AA81-2FB9AADC868B}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (04/10/2016 03:53:16 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={8120AE4D-4298-479C-9FB4-06E99A6CF532}: The user SYSTEM dialed a connection named Broadband Connection 2 which has failed. The error code returned on failure is 651.
 
Error: (04/10/2016 03:38:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.20911 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1770
 
Start Time: 01d18b6c652c3ed9
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 5cf72444-fede-11e5-826f-1008b127f26c
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (03/31/2016 02:12:47 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={B0680815-F8BA-4BF1-ACB0-0FEE35F050B7}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (03/11/2016 07:06:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MRT.exe, version: 5.34.12400.0, time stamp: 0x56cebba9
Faulting module name: webio.dll, version: 6.3.9600.17415, time stamp: 0x545040e0
Exception code: 0xc0000409
Fault offset: 0x0000000000031035
Faulting process id: 0xbb4
Faulting application start time: 0xMRT.exe0
Faulting application path: MRT.exe1
Faulting module path: MRT.exe2
Report Id: MRT.exe3
Faulting package full name: MRT.exe4
Faulting package-relative application ID: MRT.exe5
 
 
System errors:
=============
Error: (04/19/2016 03:10:31 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000101 (0x0000000000000030, 0x0000000000000000, 0xffffd000b09d5180, 0x0000000000000001)C:\WINDOWS\MEMORY.DMP041916-32015-01
 
Error: (04/19/2016 03:10:30 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:46:49 PM on ‎19/‎04/‎2016 was unexpected.
 
Error: (04/19/2016 02:49:19 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}
 
Error: (04/19/2016 02:46:51 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000101 (0x0000000000000030, 0x0000000000000000, 0xffffd001d47d5180, 0x0000000000000001)C:\WINDOWS\MEMORY.DMP041916-28109-01
 
Error: (04/19/2016 02:46:49 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:39:52 PM on ‎19/‎04/‎2016 was unexpected.
 
Error: (04/19/2016 02:40:11 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000101 (0x0000000000000030, 0x0000000000000000, 0xffffd000bfdd5180, 0x0000000000000001)C:\WINDOWS\MEMORY.DMP041916-114406-01
 
Error: (04/19/2016 02:39:52 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:11:45 PM on ‎19/‎04/‎2016 was unexpected.
 
Error: (04/12/2016 10:09:18 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (04/12/2016 10:09:18 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (04/10/2016 10:01:26 PM) (Source: DCOM) (EventID: 10010) (User: VALDA)
Description: {005A3A96-BAC4-4B0A-94EA-C0CE100EA736}
 
 
CodeIntegrity:
===================================
  Date: 2016-04-19 15:31:32.150
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-04-11 08:42:43.036
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-14 09:02:43.703
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-12 11:40:19.746
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-11 14:01:51.579
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-01 13:08:30.215
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 21%
Total physical RAM: 8115.27 MB
Available physical RAM: 6387.83 MB
Total Virtual: 16307.27 MB
Available Virtual: 14100.91 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:915.07 GB) (Free:851.85 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 204DDE3E)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
 
I hope you can help again on this one.

Following the excellent help from Ken545 on two PCs, my neighbour has asked if the ACER notebook she wants to leave in her holiday shack could be cleaned as well.

 

PC is an ACER V15 running Windows 8.1 64-bit with 8Gb DDR3 L memory and 1Tb HDD (~890Gb free).
 
Security is WIndows Firewall and Windows Defender.
 
One complaint she had was the addition of Google's GadgetBox to Chrome. This, I believe, was just an update "service" to Chrome. I removed the two default home pages and set the home page to google.com.au
 
Initial start was slow but bearable (about 1min to stable desktop).
 
I downlaoded aswMBR and Farbar tools to desktop. Shut down running tasks and ran aswMBR (as admin). All was normal unitl part way through definition update when PC restarted.
 
This time it took more than 3 minutes to get to a stable desktop.
 
Ran aswMBR (as admin) again; it took about 1 minute to open (I then started timing); it took some 30 seconds to show any content in window and started picking up where it had left off - restarting to downlaod definitions.
 
After some 5 minutes 10 seconds it gave a blue screen error (they don't have BSOD in WIn8!) saying Clock_Watchdog_Timeout error and restarted. This time it took more than 6 minutes to get to a stable desktop.
 
Tried to run aswMBR (as admin a third time. GOt to about 80Mb of definitions download when blue scree error kicked in again, with Clock_Watchdog_Timeout error.
 
This time splash screen stayed until 0:50, then a black screen until 1:20, got to login at 1:35, had Welcome until 2:10, and finally got to stable desktop at 5:31.
 
Ran FRST64 (as admin); Windows Smart Screen intercepted it and prevented it from running.
 
I disconnected from the Internet and ran FRST64 (as admin) again. This time WSS had an option to run anyway which I did.
 
I did not see an option for "All Users". Scan completed with logs: FRST.txt and Addition.txt inserted below.
 
I then tried to run aswMBR again without an Internet connection. Said "No" to download definitions and saw message runing without Avast engine. Scan completed successfully and saved aswMBR.txt log see below. I trust without the Avast engine this is still useful.
 
There was also an MBR.dat file on the desktop which wanted to run as a video. I did not open it.
 
I hope you can give some guidance on how to clean this PC, including how to stop the Windows Smart Screen intercepting utilities.
 
Here is the aswMBR log:
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-04-19 15:44:23
—————————–
15:44:23.158    OS Version: Windows x64 6.2.9200 
15:44:23.158    Number of processors: 4 586 0x4501
15:44:23.159    ComputerName: VALDA  UserName: Valda
15:44:24.346    Initialize success
15:44:24.376    VM: initialized successfully
15:44:24.377    VM: Intel CPU supported 
15:44:28.293    VM: supported disk I/O storport.sys
15:44:42.742    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002f
15:44:42.751    Disk 0 Vendor: ST1000LM024_HN-M101MBB 2BA30001 Size: 953869MB BusType: 11
15:44:42.896    VM: Disk 0 MBR read successfully
15:44:42.902    Disk 0 MBR scan
15:44:42.908    Disk 0 unknown MBR code
15:44:42.914    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
15:44:42.959    Disk 0 scanning C:\WINDOWS\system32\drivers
15:44:50.028    Service scanning
15:45:06.108    Modules scanning
15:45:06.122    Disk 0 trace - called modules:
15:45:06.156    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll storahci.sys 
15:45:06.163    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe00151d03450]
15:45:06.177    3 CLASSPNP.SYS[fffff80050cfff40] -> nt!IofCallDriver -> [0xffffe001513c7550]
15:45:06.187    5 ACPI.sys[fffff80050370c21] -> nt!IofCallDriver -> \Device\0000002f[0xffffe001513c8700]
15:45:06.196    Disk 0 statistics 135932/0/5 @ 10.24 MB/s
15:45:06.203    Scan finished successfully
15:45:29.372    Disk 0 MBR has been saved successfully to "C:\Users\Valda\Desktop\MBR.dat"
15:45:29.380    The log file has been saved successfully to "C:\Users\Valda\Desktop\aswMBR.txt"
 
 
And here is the FRST64 log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
Ran by [removed] (administrator) on VALDA (19-04-2016 15:41:11)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Dolby Laboratories Inc.) C:\Program Files\Dolby Digital Plus\ddp.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Spotify Ltd) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Pokki) C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceStartMenuIndexer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-18] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1380056 2014-03-18] (Realtek Semiconductor)
HKLM-x32\…\Run: [abDocsDllLoader] => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [91488 2015-11-23] ()
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1298456 2015-04-20] (CANON INC.)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23248560 2016-04-09] (Dropbox, Inc.)
HKLM\…\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] (Qualcomm®Atheros®)
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\RunOnce: [RegDXVA1] => C:\Windows\system32\cmd.exe /c reg import "C:\Program Files (x86)\Acer\abPhoto\SwitchUserVideoKey.reg"
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\RunOnce: [SetAsDefault] => C:\Program Files (x86)\Acer\Acer Video Player\SwitchUserVideoKey.bat
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [ISUSPM] =>  -scheduler
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-09-20] (Spotify Ltd)
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\RunOnce: [Application Restart #1] => C:\Users\Valda\AppData\Local\Pokki\Engine\HostAppService.exe  –disable-internal-flash –noerrdialogs –no-message-box –disable-extensions –disable-web-security –disable-web-resources –disable-cli (the data entry has 549 more characters).
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\MountPoints2: {237434b1-df4d-11e5-826c-1008b127f26c} - "E:\AutoRun.exe" 
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{0A159044-1CA1-473A-A365-82A7E1CC161E}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{2EB4B5A8-928A-4E8F-8376-1261E9885494}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{2F364102-6AA1-4723-B2D6-A0A54DE7F775}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{B11A154C-321E-493A-93DF-87DD6FDEA81F}: [DhcpNameServer] 192.168.8.1 192.168.8.1
 
Internet Explorer:
==================
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.bing.com/?pc=cosp&ptag;=A9C7EDF55B3&form;=CONMHP&conlogo;=CT3210127
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxps://www.bing.com/?pc=cosp&ptag;=A9C7EDF55B3&form;=CONMHP&conlogo;=CT3210127
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://accounts.google.com/Login#identifier
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://au.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://au.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> DefaultScope {953E7D0F-2D0D-11E5-825E-F0761C2C2D04} URL = hxxp://search.homepage-web.com/?src=omnibox&partner;=acer&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> {953E7D0F-2D0D-11E5-825E-F0761C2C2D04} URL = hxxp://search.homepage-web.com/?src=omnibox&partner;=acer&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://au.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> {D4DB4AE4-13D9-443A-81CC-41DA15D0B5AC} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-04-10] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-01-10] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default
FF DefaultSearchEngine: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: hxxps://homepage-web.com/?s=acer&m;=start
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2016-01-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-01] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-01] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF SearchPlugin: C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\searchplugins\Web Search.xml [2016-04-10]
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.com.au/"
CHR DefaultSearchURL: Default -> hxxps://secure.homepage-web.com/?partner=acer&src;=omnibox&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> homepage-web.com
CHR DefaultSuggestURL: Default -> hxxps://secure-suggest.homepage-web.com/suggest?format=json&locale;={language}&q;={searchTerms}
CHR Profile: C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-01]
CHR Extension: (Google Docs) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-01]
CHR Extension: (Google Drive) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-01]
CHR Extension: (YouTube) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-01]
CHR Extension: (Google Search) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-03-01]
CHR Extension: (Google Sheets) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-01]
CHR Extension: (Google Docs Offline) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-10]
CHR Extension: (Google Keep - notes and lists) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2016-04-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-10]
CHR Extension: (Gmail) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-01]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Windows (R) Win 7 DDK provider) [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2860760 2016-01-14] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-10] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-10] (Dropbox, Inc.)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-06-12] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-25] (WildTangent)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-19] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [466664 2014-06-10] (Acer Incorporate)
R2 Optus 4G Modem HL; C:\ProgramData\MobileBrServ\mbbservice.exe [242264 2014-11-20] ()
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-06-26] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-06-26] (Acer Incorporate)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240 2014-07-15] (acer)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-25] (Qualcomm Atheros)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [99320 2013-10-03] (Intel Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466136 2014-01-14] (Realsil Semiconductor Corporation)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-19 15:41 - 2016-04-19 15:41 - 00022755 _____ C:\Users\Valda\Desktop\FRST.txt
2016-04-19 15:40 - 2016-04-19 15:41 - 00000000 ____D C:\FRST
2016-04-19 15:10 - 2016-04-19 15:10 - 00293152 _____ C:\WINDOWS\Minidump\041916-32015-01.dmp
2016-04-19 15:04 - 2016-04-19 15:40 - 00001400 _____ C:\Users\Valda\Desktop\WTT topic content.txt
2016-04-19 14:56 - 2016-04-19 14:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-19 14:46 - 2016-04-19 14:46 - 00288504 _____ C:\WINDOWS\Minidump\041916-28109-01.dmp
2016-04-19 14:39 - 2016-04-19 15:10 - 597918099 _____ C:\WINDOWS\MEMORY.DMP
2016-04-19 14:39 - 2016-04-19 15:10 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-19 14:39 - 2016-04-19 14:40 - 00297552 _____ C:\WINDOWS\Minidump\041916-114406-01.dmp
2016-04-19 14:33 - 2016-04-19 14:34 - 02375680 _____ (Farbar) C:\Users\Valda\Desktop\FRST64.exe
2016-04-19 14:32 - 2016-04-19 14:32 - 05198336 _____ (AVAST Software) C:\Users\Valda\Desktop\aswMBR.exe
2016-04-12 09:35 - 2016-04-12 09:35 - 00243344 _____ C:\Users\Valda\Documents\WO 9646366.pdf
2016-04-12 07:53 - 2016-04-12 07:53 - 00533492 _____ C:\Users\Valda\Documents\WO 9749726.pdf
2016-04-12 07:16 - 2016-04-12 07:16 - 00147700 _____ C:\Users\Valda\Documents\WO 9809763.pdf
2016-04-11 18:16 - 2016-04-11 18:16 - 00002001 _____ C:\Users\Public\Desktop\abMusic.lnk
2016-04-11 08:32 - 2016-04-11 08:32 - 00787736 _____ C:\Users\Valda\Documents\WO9868772.pdf
2016-04-11 08:28 - 2016-04-11 08:28 - 00788025 _____ C:\Users\Valda\Documents\IMG_20160411_0001.pdf
2016-04-10 22:11 - 2016-04-10 22:11 - 00692088 _____ C:\Users\Valda\Documents\Get Started with Dropbox.pdf
2016-04-10 22:02 - 2016-04-19 15:14 - 00000000 ___RD C:\Users\Valda\Dropbox
2016-04-10 22:02 - 2016-04-10 22:02 - 00001246 _____ C:\Users\Valda\Desktop\Dropbox.lnk
2016-04-10 22:00 - 2016-04-10 22:00 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-04-10 21:38 - 2016-04-10 21:38 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller (2).exe
2016-04-10 21:33 - 2016-04-10 21:33 - 00000000 ____D C:\Users\Valda\AppData\Roaming\Dropbox
2016-04-10 21:32 - 2016-04-19 15:37 - 00000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-04-10 21:32 - 2016-04-19 15:11 - 00000914 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-04-10 21:32 - 2016-04-19 14:56 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-04-10 21:32 - 2016-04-19 14:52 - 00000000 ____D C:\Users\Valda\AppData\Local\Dropbox
2016-04-10 21:32 - 2016-04-10 21:32 - 00003890 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2016-04-10 21:32 - 2016-04-10 21:32 - 00003654 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2016-04-10 21:32 - 2016-04-10 21:32 - 00000000 ____D C:\ProgramData\Dropbox
2016-04-10 21:31 - 2016-04-10 21:32 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller (1).exe
2016-04-10 21:30 - 2016-04-10 21:30 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller.exe
2016-04-10 16:27 - 2016-04-10 16:27 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-04-19 15:26 - 2015-05-30 16:47 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-974442171-2668444937-4057906661-1002
2016-04-19 15:20 - 2015-05-30 17:10 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-04-19 15:20 - 2013-08-23 01:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-04-19 15:18 - 2015-05-30 16:31 - 00000000 ____D C:\Users\Valda\AppData\Local\SweetLabs App Platform
2016-04-19 15:17 - 2014-03-18 20:03 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-19 15:17 - 2013-08-22 23:36 - 00000000 ____D C:\WINDOWS\Inf
2016-04-19 15:15 - 2014-11-07 13:15 - 00000000 ___DO C:\Users\Valda\OneDrive
2016-04-19 15:11 - 2016-03-01 11:42 - 00000904 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-19 15:10 - 2013-08-23 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-19 15:02 - 2015-05-30 16:44 - 00002400 _____ C:\Users\Valda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2016-04-19 15:00 - 2015-11-02 13:06 - 00003292 _____ C:\WINDOWS\System32\Tasks\SweetLabs App Platform
2016-04-19 14:45 - 2014-09-20 12:48 - 00000000 ____D C:\Users\UpdatusUser
2016-04-19 14:42 - 2015-05-30 16:31 - 00000000 ____D C:\Users\Valda
2016-04-14 09:45 - 2016-03-01 11:26 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-12 09:47 - 2016-03-01 11:42 - 00000908 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-12 07:17 - 2016-03-11 19:25 - 00000000 ___HD C:\ProgramData\CanonIJMIG
2016-04-12 06:48 - 2016-03-01 11:43 - 00002219 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-12 06:48 - 2016-03-01 11:43 - 00002207 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-12 06:07 - 2016-02-18 18:07 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-04-11 18:16 - 2014-07-26 04:28 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2016-04-11 18:16 - 2014-07-26 04:28 - 00000000 ____D C:\Program Files (x86)\Acer
2016-04-11 18:15 - 2015-05-30 16:43 - 00000000 ____D C:\Users\Valda\AppData\Local\clear.fi
2016-04-10 22:01 - 2015-05-30 16:37 - 00000000 ____D C:\Users\Valda\AppData\Local\VirtualStore
2016-04-10 20:49 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-10 16:39 - 2013-08-23 01:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-04-10 16:38 - 2016-01-30 07:54 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2016-04-10 16:38 - 2016-01-30 07:54 - 00000000 ___SD C:\WINDOWS\system32\GWX
2016-04-10 16:28 - 2016-03-11 19:15 - 00000000 ____D C:\Users\Valda\AppData\LocalLow\Canon Easy-WebPrint EX
2016-04-10 15:58 - 2013-08-22 23:25 - 01310720 ___SH C:\WINDOWS\system32\config\BBI
 
==================== Files in the root of some directories =======
 
2014-09-20 13:01 - 2014-09-20 13:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\Valda\AppData\Local\Temp\FoxitUpdater.exe
C:\Users\Valda\AppData\Local\Temp\McCSPInstall.dll
C:\Users\Valda\AppData\Local\Temp\mccspuninstall.exe
C:\Users\Valda\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Valda\AppData\Local\Temp\oct12C.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct3DB0.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct4823.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct827D.tmp.exe
C:\Users\Valda\AppData\Local\Temp\oct8940.tmp.exe
C:\Users\Valda\AppData\Local\Temp\octD5D8.tmp.exe
C:\Users\Valda\AppData\Local\Temp\octDBE1.tmp.exe
C:\Users\Valda\AppData\Local\Temp\octECEA.tmp.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-04-19 15:26
 
==================== End of FRST.txt ============================
 
 
And finally, the Addition log from FRST64:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
Ran by [removed] (2016-04-19 15:41:51)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (X64) (2015-05-30 06:34:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-974442171-2668444937-4057906661-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-974442171-2668444937-4057906661-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-974442171-2668444937-4057906661-1004 - Limited - Enabled)
UpdatusUser (S-1-5-21-974442171-2668444937-4057906661-1001 - Limited - Enabled) => C:\Users\UpdatusUser
Valda (S-1-5-21-974442171-2668444937-4057906661-1002 - Administrator - Enabled) => C:\Users\Valda
Valda_2 (S-1-5-21-974442171-2668444937-4057906661-1005 - Limited - Enabled) => C:\Users\Valda_2
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
abDocs (HKLM-x32\…\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.09.2001 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\…\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.02.2001 - Acer Incorporated)
abFiles (HKLM-x32\…\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.00.3002 - Acer Incorporated)
abMusic (HKLM-x32\…\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 3.00.2003.6 - Acer Incorporated)
abPhoto (HKLM-x32\…\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.06.2000.22 - Acer Incorporated)
Acer Care Center (HKLM\…\{A424844F-CDB3-45E2-BB77-1DDE4A091E76}) (Version: 1.00.3013 - Acer Incorporated)
Acer Explorer Agent (HKLM\…\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\…\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8107 - Acer Incorporated)
Acer Portal (HKLM-x32\…\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.09.2002 - Acer Incorporated)
Acer Power Management (HKLM\…\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8105 - Acer Incorporated)
Acer Quick Access (HKLM\…\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3016.0 - Acer Incorporated)
Acer Recovery Management (HKLM\…\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\…\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3005 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\…\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3005 - Acer Incorporated)
Acer Video Player (HKLM-x32\…\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2005.0 - Acer Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Amazon 1Button App (HKLM-x32\…\{FF0A904E-8827-4F6E-9A59-900D4C997AD1}) (Version: 1.0.8 - Amazon) <==== ATTENTION
AOP Framework (HKLM-x32\…\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.15.2000.1 - Acer Incorporated)
Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\…\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: 4.1.0 - Canon Inc.)
Canon MG2500 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.02 - Canon Inc.)
Canon MG2500 series On-screen Manual (HKLM-x32\…\Canon MG2500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon My Image Garden (HKLM-x32\…\Canon My Image Garden) (Version: 3.3.0 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\…\Canon My Image Garden Design Files) (Version: 3.2.0 - Canon Inc.)
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.6.1 - Canon Inc.)
CyberLink PhotoDirector 3 (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.4218 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
Dolby Digital Plus Home Theater (HKLM\…\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Dropbox (HKLM-x32\…\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.35.1 - Dropbox, Inc.) Hidden
eBay Worldwide (HKLM-x32\…\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
Farm to Fork Collector's Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Game Explorer Categories - genres (HKLM-x32\…\WildTangentGameProvider-acer-genres) (Version: 11.0.0.7 - WildTangent, Inc.)
Game Explorer Categories - main (HKLM-x32\…\WildTangentGameProvider-acer-main) (Version: 11.0.0.7 - WildTangent, Inc.)
Goal United (HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Pokki_20bc77071450f86fee7470f383e7601729828efa) (Version: 1.0.3.41437 - SweetLabs)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Hidden Mysteries - Graceland (HKLM-x32\…\Hidden Mysteries - Graceland) (Version: 1.0 - GameMill Entertainment)
Host App Service (HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\SweetLabs_AP) (Version: 0.269.7.927 - Pokki)
Inspector Magnusson - Murder on the Titanic (x32 Version: 2.2.0.110 - WildTangent) Hidden
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.165.1 - Intel Corporation)
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
Lost in Night (x32 Version: 3.0.2.38 - WildTangent) Hidden
LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Microsoft Outlook 2013 - en-us (HKLM\…\OutlookRetail - en-us) (Version: 15.0.4815.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 44.0.2 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 44.0.2 (x86 en-US)) (Version: 44.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 44.0.2 - Mozilla)
MYOB AccountRight Plus v19.10 (x32 Version: 19.10.0 - MYOB Technology Pty Ltd) Hidden
NVIDIA Graphics Driver 332.35 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.35 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0927 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation)
NVIDIA Update 1.15.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
Optus 4G Modem HL (HKLM-x32\…\Optus 4G Modem HL) (Version: 22.001.26.00.74 - Huawei Technologies Co.,Ltd)
Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Pokki) (Version: 0.269.2.471 - Pokki)
Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\SweetLabs_Start_Menu) (Version: 0.269.7.927 - Pokki)
Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.318 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.29 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.25.108.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7203 - Realtek Semiconductor Corp.)
Spotify (HKLM-x32\…\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.51 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.13 - WildTangent) Hidden
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-974442171-2668444937-4057906661-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02F765CE-0EC3-4DEE-ACB0-73FEDFFC82B9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-11] (Microsoft Corporation)
Task: {03555308-1C70-4DDE-8263-467280F623A3} - System32\Tasks\SweetLabs App Platform => C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ServiceHostAppUpdater.exe [2016-04-14] (Pokki)
Task: {065896BE-FAF6-4AEC-B86B-811D36A81FE9} - System32\Tasks\abDocsDllLoader => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe [2015-11-23] ()
Task: {15B8CED1-1430-4487-861D-74DDE81C6F62} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [2016-01-14] (Acer Incorporated)
Task: {185669F3-1C5B-46DE-A0A5-8E55A572676A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-01-10] (Microsoft Corporation)
Task: {3D222F32-B59A-4620-A1D1-670AC5F9E641} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-06-12] (Acer Incorporated)
Task: {3FCBB702-5090-4D41-B310-35AEB536818E} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2014-08-29] ()
Task: {48A31DC3-8986-473B-8968-244E049814DB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-01] (Google Inc.)
Task: {4B0864C2-AB5D-424A-A616-295DEF51C449} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2014-06-09] (Acer Incorporated)
Task: {609647A4-3D37-4E92-9B30-2ACAFF85A647} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-01] (Google Inc.)
Task: {6A1EA7FF-879B-4620-A9C2-C525C0993E78} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe [2013-09-09] (Dolby Laboratories Inc.)
Task: {81698CFC-4E31-44DF-8972-55A9E7F46582} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2014-08-29] ()
Task: {8F3D2505-F0D3-4937-8569-A2F38486955D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-10] (Dropbox, Inc.)
Task: {A15CE7A3-142F-4986-97F2-385E16FF95FE} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {B6EAA0B7-AF1A-4852-BE63-E8ECDBAADFD9} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-06-10] (Acer Incorporate)
Task: {C12C5A69-EA8A-4F1D-BBEC-81DB714052BB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-01-10] (Microsoft Corporation)
Task: {D35BDF10-850E-4701-9799-066F9AA5333C} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-18] (Acer Incorporated)
Task: {D7F524F5-77EE-485C-BA66-EA1FDD41D23E} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2016-01-19] (Acer)
Task: {DB317CD5-AA28-4374-BF64-BB03E5B01BF9} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {DD5B8A6B-8761-400F-83C8-43C3D1BA9F7A} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: )
Task: {E7638087-2ACF-42D4-A096-C9D652417475} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-10] (Dropbox, Inc.)
Task: {E7A59D9F-4E73-4799-A961-A18E64CE0BB1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {E9D1DF34-EFC9-435C-B43C-50EAEC279F11} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Public\Desktop\Agoda.lnk -> C:\ProgramData\OEM_Agoda\StartURL.exe () -> hxxp://www.agoda.com?cid=1630081
ShortcutWithArgument: C:\Users\Public\Desktop\Dropbox.lnk -> C:\Program Files\Dropbox\StartURL.exe () -> hxxps://www.dropbox.com/partners/acer2014/download
ShortcutWithArgument: C:\Users\Public\Desktop\PRIVATE WiFi.lnk -> C:\Program Files\PRIVATE WiFi\StartURL.exe () -> hxxp://www.privatewifi.com/partner/clicks.php?pid=928649&bid;=76&campaign;=default
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-09-20 12:48 - 2014-01-08 10:48 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-03-11 19:23 - 2013-05-14 17:50 - 00140936 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2016-03-11 12:17 - 2014-11-20 18:48 - 00242264 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
2014-07-26 04:31 - 2012-04-24 20:43 - 00254512 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2013-09-09 13:13 - 2013-09-09 13:13 - 00050904 _____ () C:\Program Files\Dolby Digital Plus\Dolby.DDP.Controls_Desktop.dll
2014-03-19 11:35 - 2014-03-08 02:21 - 00080312 _____ () C:\Windows\system32\igfxexps.dll
2014-02-25 22:14 - 2014-02-25 22:14 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2014-02-25 22:11 - 2014-02-25 22:11 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2014-02-25 22:17 - 2014-02-25 22:17 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
2015-11-23 17:44 - 2015-11-23 17:44 - 01769312 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
2015-05-30 17:10 - 2015-10-13 05:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-04-10 21:37 - 2016-03-22 07:50 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2016-04-19 14:56 - 2016-03-22 07:51 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2016-04-19 14:56 - 2016-03-22 07:50 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2016-04-10 21:37 - 2016-03-22 07:50 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2016-04-10 21:37 - 2016-03-22 07:50 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-04-19 14:56 - 2016-03-22 07:50 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2016-04-10 21:37 - 2016-04-09 04:20 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2016-04-10 21:37 - 2016-03-22 07:50 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2016-04-10 21:37 - 2016-03-22 07:51 - 00112592 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2016-04-19 14:56 - 2016-03-22 07:52 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2016-04-10 21:37 - 2016-03-22 07:50 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
2016-04-19 14:56 - 2016-03-22 07:50 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2016-04-19 14:56 - 2016-03-22 07:51 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2016-04-19 14:56 - 2016-03-22 07:52 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2016-04-19 14:56 - 2016-04-09 04:19 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00021824 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
2016-04-19 14:55 - 2016-04-09 04:19 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2016-04-10 21:37 - 2016-03-22 07:52 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2016-04-10 21:37 - 2016-04-09 04:20 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2016-04-19 14:56 - 2016-04-09 04:19 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-04-19 14:56 - 2016-04-09 04:20 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2016-04-10 21:37 - 2016-03-22 07:51 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00158008 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2016-04-19 14:56 - 2016-03-22 07:54 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2016-04-19 14:56 - 2016-03-22 07:54 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2016-04-10 21:37 - 2016-04-09 04:20 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2016-04-19 14:56 - 2016-04-09 04:20 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2016-04-10 21:37 - 2016-03-22 07:56 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-11-16 18:55 - 2015-11-16 18:55 - 00202456 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2015-11-16 18:56 - 2015-11-16 18:56 - 00654000 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2015-11-16 18:56 - 2015-11-16 18:56 - 00641240 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2015-11-16 18:56 - 2015-11-16 18:56 - 00119000 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2016-02-18 18:21 - 2016-02-18 18:21 - 00015064 _____ () C:\WINDOWS\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2016-01-14 16:12 - 2016-01-14 16:12 - 00013016 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2016-01-14 16:11 - 2016-01-14 16:11 - 00277856 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
2016-01-19 14:06 - 2016-01-19 14:06 - 00194048 _____ () C:\Program Files (x86)\Acer\Acer Portal\curllib.dll
2016-01-19 14:06 - 2016-01-19 14:06 - 00110592 _____ () C:\Program Files (x86)\Acer\Acer Portal\OpenLDAP.dll
2014-09-20 12:50 - 2013-12-10 09:27 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 00569856 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\ppGoogleNaClPluginChrome.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 01400846 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\avcodec-54.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 00151054 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\avutil-51.dll
2016-04-14 09:00 - 2016-04-14 09:00 - 00222734 _____ () C:\Users\Valda\AppData\Local\SweetLabs App Platform\Engine\avformat-54.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 23:25 - 2013-08-22 23:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Valda\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\windows photo viewer wallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{AFF950B5-E50F-490C-A356-61966989B856}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{D45F2DEB-5DC4-420F-B207-F9C8D794384C}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{368AA98A-9058-43BB-A710-FCAC404DB2B2}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{D7C97A6A-D6FB-4F06-929A-65D02CB2FB04}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{8DA6FF61-9BD7-4A38-9214-EBFF37DABA30}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{882C979D-4084-4E83-BE90-4DD269D16461}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{AB92FFF7-BD7F-44CB-A466-CB138D1F4976}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{F34EF84C-672F-4FA3-8F5D-4101A50451E5}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{40D8BE5C-FEF4-4461-9AE6-42AC315B734E}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{DB4357B3-A584-4542-8A1A-9072F7AB6376}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{81351C50-F528-4406-92C0-AEAEFE5517A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{8422D21D-4388-44B9-B159-CE040BACEEAA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{84AFACB1-02D8-40B7-8521-3B49310D4AA5}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{F9DD3586-975D-4006-A6F8-A3D79BCDA2CC}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{E08D6C5B-3A13-416B-9C86-3A1656E8A1DD}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{07E6C917-528E-4A12-A000-DA0B5272ADAB}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{D9D7D184-5CA8-4742-9017-6D373DB97E82}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Play.exe
FirewallRules: [{661AD751-0BD3-46C2-A576-2EF801EA31D2}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{CDF7EF82-B2BD-428A-A3EC-D0D7C59E7003}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{27879486-9ACA-4DE0-9C01-B04F0E60F631}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{59A0E661-DA1B-4E8D-A7AD-694E051B480F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{6DFE83AB-2734-4DAB-AC63-E9B92AB83D96}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{CADEC948-96E7-4F7D-A210-6A0482059E7A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{41446356-E125-4F1F-80D5-EF41489BA9FD}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{8DEF424D-E082-4AEF-ACD0-55FFD9733C01}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{C8B20BF5-4D3E-4A08-B9AC-8EF31116C6A3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{7338970A-57D6-4A38-B04C-0A0B923F87C3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{5345F876-5C7C-4CED-A297-9EF0EBAC6845}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{49628988-084F-4966-8916-4FEE0754E899}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{CE6E1F52-B3BE-4A72-AF60-2BCA5C9B1814}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{0877F64A-1DBC-4BBE-A531-C5400EED44AF}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{6FB69EA0-E7FD-48CD-BDFC-A87D145B2A93}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{32C1492B-5136-4FBF-8C15-EE84845E4BBA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{881C2E6D-A4C2-4B3D-A62D-B93A93F3BCC9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{C6CABB36-119D-47A4-ACBD-1DE32D773915}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{626F108E-2B9B-4A4B-AAF2-DF9BCE46BDF3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{1E075124-1D73-4931-900A-379A5F81992E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{EF373059-4F61-4844-B9C3-D0852B2865E1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{14A3214B-AD15-40AA-B145-718DC19C2C51}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{4EAFD24F-5150-455D-B2D5-420C0185270E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{C50DB59B-547D-478D-9E30-6789B0A01109}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{580AD0BB-E949-4A03-B0C5-4F3B7D523A2E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{942CFCDB-6200-4967-A85D-3AD927A6253D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{4C949DC1-9A11-440F-9876-36C8BA62F46D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{0AA96318-B905-4B51-AB9A-4569D52656E1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{A378F9A1-8708-4651-A547-EB5EB6516C96}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{39178852-F613-4809-85DF-097D83691827}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{19BE7717-FB95-4A7B-BEF2-FB28ABF0708C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{48A6D524-1FCF-4AD2-9A25-188AD945C3EF}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{B098A471-E99A-4692-8041-70A95D058F99}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0065F20B-B795-411C-984D-22C7586E0711}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{318E9D5C-8B01-4C6A-8874-EA44EF18E1C5}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{7D3E059A-294C-4787-9A3D-6A070C982125}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{E25FDA55-B2F4-445D-90C2-48B0F98E39EB}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{3E1E204A-6775-49EE-A4FD-B3987BA5C1DD}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{50F268CD-0DE1-49CF-B94C-3BF37137E07B}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{77A94F49-18C8-4428-8851-FEE9AF23C4FD}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
FirewallRules: [{16B955D5-2F15-4F9A-8EED-D42DF822B5EC}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{5D02D7A8-0B9D-41CB-BA90-1EEE971E20FE}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
FirewallRules: [{16DF9D5F-77FA-4C08-82FA-63165C9569DC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{95E2DA70-1198-4825-A7ED-6D9266312010}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
 
==================== Restore Points =========================
 
13-03-2016 16:24:44 Installed DirectX
10-04-2016 16:37:25 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Bluetooth Device (Personal Area Network)
Description: Bluetooth Device (Personal Area Network)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BthPan
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/19/2016 03:38:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program backgroundTaskHost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1984
 
Start Time: 01d199fb734b7e56
 
Termination Time: 4294967295
 
Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe
 
Report Id: 66e8dbde-05ef-11e6-8273-0c5b8f279a64
 
Faulting package full name: Amazon.com.Amazon_3.1.2.8_neutral__343d40qqvtj1t
 
Faulting package-relative application ID: App
 
Error: (04/19/2016 03:20:16 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: VALDA)
Description: Application or service 'Microsoft Office Document Cache Sync Client Interface' could not be shut down.
 
Error: (04/10/2016 04:29:56 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database
 
Error: (04/10/2016 04:20:45 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: VALDA)
Description: Application or service 'Microsoft Office Document Cache Sync Client Interface' could not be shut down.
 
Error: (04/10/2016 04:12:52 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={E64FEA12-CE1F-42F5-BEA1-6C55FBF4E3F0}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (04/10/2016 03:56:05 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={1A795855-D091-4627-AA81-2FB9AADC868B}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (04/10/2016 03:53:16 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={8120AE4D-4298-479C-9FB4-06E99A6CF532}: The user SYSTEM dialed a connection named Broadband Connection 2 which has failed. The error code returned on failure is 651.
 
Error: (04/10/2016 03:38:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program LiveComm.exe version 17.5.9600.20911 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1770
 
Start Time: 01d18b6c652c3ed9
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe
 
Report Id: 5cf72444-fede-11e5-826f-1008b127f26c
 
Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
 
Error: (03/31/2016 02:12:47 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={B0680815-F8BA-4BF1-ACB0-0FEE35F050B7}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
 
Error: (03/11/2016 07:06:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: MRT.exe, version: 5.34.12400.0, time stamp: 0x56cebba9
Faulting module name: webio.dll, version: 6.3.9600.17415, time stamp: 0x545040e0
Exception code: 0xc0000409
Fault offset: 0x0000000000031035
Faulting process id: 0xbb4
Faulting application start time: 0xMRT.exe0
Faulting application path: MRT.exe1
Faulting module path: MRT.exe2
Report Id: MRT.exe3
Faulting package full name: MRT.exe4
Faulting package-relative application ID: MRT.exe5
 
 
System errors:
=============
Error: (04/19/2016 03:10:31 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000101 (0x0000000000000030, 0x0000000000000000, 0xffffd000b09d5180, 0x0000000000000001)C:\WINDOWS\MEMORY.DMP041916-32015-01
 
Error: (04/19/2016 03:10:30 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:46:49 PM on ‎19/‎04/‎2016 was unexpected.
 
Error: (04/19/2016 02:49:19 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}
 
Error: (04/19/2016 02:46:51 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000101 (0x0000000000000030, 0x0000000000000000, 0xffffd001d47d5180, 0x0000000000000001)C:\WINDOWS\MEMORY.DMP041916-28109-01
 
Error: (04/19/2016 02:46:49 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:39:52 PM on ‎19/‎04/‎2016 was unexpected.
 
Error: (04/19/2016 02:40:11 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x00000101 (0x0000000000000030, 0x0000000000000000, 0xffffd000bfdd5180, 0x0000000000000001)C:\WINDOWS\MEMORY.DMP041916-114406-01
 
Error: (04/19/2016 02:39:52 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:11:45 PM on ‎19/‎04/‎2016 was unexpected.
 
Error: (04/12/2016 10:09:18 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (04/12/2016 10:09:18 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (04/10/2016 10:01:26 PM) (Source: DCOM) (EventID: 10010) (User: VALDA)
Description: {005A3A96-BAC4-4B0A-94EA-C0CE100EA736}
 
 
CodeIntegrity:
===================================
  Date: 2016-04-19 15:31:32.150
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-04-11 08:42:43.036
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-14 09:02:43.703
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-12 11:40:19.746
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-11 14:01:51.579
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-01 13:08:30.215
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 21%
Total physical RAM: 8115.27 MB
Available physical RAM: 6387.83 MB
Total Virtual: 16307.27 MB
Available Virtual: 14100.91 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:915.07 GB) (Free:851.85 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 204DDE3E)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
 
I hope you can help again on this one.

Good Morning

 

Been tied up for a bit or would have gotten to you sooner, I merged both your threads into one 

 

You may want to go to Programs and Features in the Control Panel and uninstall Pokki, it appears to be bundled with other software that she may have downloaded

 

 

http://www.shouldiremoveit.com/Pokki-5024-program.aspx
 
http://www.shouldiremoveit.com/Pokki-Start-Menu-93761-program.aspx
 
 
 
 
 
Her logs dont really look that bad but lets do some cleaning and see what they find and remove
 
 
 
All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
    [external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: MB%202.2.1.1043_zps9tg44ubl.jpg]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Hi again, Ken454; I understand completely "tied up for a bit".

           

          I uninstalled Pokki.

           

          Ran AdwCleaner and cleaned. Here is the log:

           

          AdwCleaner[C1].txt

           

          # AdwCleaner v5.112 - Logfile created 22/04/2016 at 08:24:38
          # Updated 17/04/2016 by Xplode
          # Database : 2016-04-19.5 [Server]
          # Operating system : Windows 8.1  (X64)
          # Username : Valda - VALDA
          # Running from : C:\Users\Valda\Desktop\AdwCleaner.exe
          # Option : Clean
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
           
          ***** [ Folders ] *****
           
          [-] Folder Deleted : C:\ProgramData\pokki
          [-] Folder Deleted : C:\Users\UpdatusUser\AppData\Local\pokki
          [-] Folder Deleted : C:\Users\Valda\AppData\Local\SweetLabs App Platform
          [-] Folder Deleted : C:\Users\Valda\AppData\LocalLow\iac
          [-] Folder Deleted : C:\Users\Valda_2\AppData\Local\pokki
           
          ***** [ Files ] *****
           
          [-] File Deleted : C:\Users\Public\Desktop\eBay.lnk
          [-] File Deleted : C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage
          [-] File Deleted : C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage-journal
          [-] File Deleted : C:\Users\Valda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
          [-] File Deleted : C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\searchplugins\Web Search.xml
           
          ***** [ DLLs ] *****
           
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Scheduled tasks ] *****
           
          [-] Task Deleted : SweetLabs App Platform
          [-] Task Deleted : ACC
           
          ***** [ Registry ] *****
           
          [-] Key Deleted : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
          [-] Key Deleted : HKCU\Software\Classes\Directory\shell\pokki
          [-] Key Deleted : HKCU\Software\Classes\Drive\shell\pokki
          [-] Key Deleted : HKCU\Software\Classes\lnkfile\shell\pokki
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_20bc77071450f86fee7470f383e7601729828efa
          [-] Key Deleted : HKCU\Software\Classes\pokki
          [-] Key Deleted : HKCU\Software\SweetLabs App Platform
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
          [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
          [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page Redirect Cache]
          [-] Data Restored : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main [Start Page]
          [-] Data Restored : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main [Start Page Redirect Cache]
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{953E7D0F-2D0D-11E5-825E-F0761C2C2D04}
          [-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
          [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
          [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
          [-] Data Restored : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
          [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com/blogs/gadgetbox-search-removal/
          [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\homepage-web.com
           
          ***** [ Web browsers ] *****
           
          [-] [C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\prefs.js] Deleted : user_pref("browser.search.defaultenginename", "Web Search");
          [-] [C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\prefs.js] Deleted : user_pref("browser.search.selectedEngine", "Web Search");
          [-] [C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\prefs.js] Deleted : user_pref("browser.startup.homepage", "hxxps://homepage-web.com/?s=acer&m=start");
           
          *************************
           
          :: "Tracing" keys deleted
          :: Winsock settings cleared
           
          *************************
           
          C:\AdwCleaner\AdwCleaner[C1].txt - [4011 bytes] - [22/04/2016 08:24:38]
          C:\AdwCleaner\AdwCleaner[S1].txt - [5191 bytes] - [22/04/2016 08:04:42]
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4157 bytes] ##########
           
           
          and AdwCleaner[S1].txt
           
          # AdwCleaner v5.112 - Logfile created 22/04/2016 at 08:04:42
          # Updated 17/04/2016 by Xplode
          # Database : 2016-04-19.5 [Server]
          # Operating system : Windows 8.1  (X64)
          # Username : Valda - VALDA
          # Running from : C:\Users\Valda\Desktop\AdwCleaner.exe
          # Option : Scan
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
           
          ***** [ Folders ] *****
           
          Folder Found : C:\ProgramData\pokki
          Folder Found : C:\Users\UpdatusUser\AppData\Local\pokki
          Folder Found : C:\Users\Valda\AppData\Local\SweetLabs App Platform
          Folder Found : C:\Users\Valda\AppData\LocalLow\iac
          Folder Found : C:\Users\Valda_2\AppData\Local\pokki
           
          ***** [ Files ] *****
           
          File Found : C:\Users\Public\Desktop\eBay.lnk
          File Found : C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage
          File Found : C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_homepage-web.com_0.localstorage-journal
          File Found : C:\Users\Valda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
          File Found : C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\searchplugins\Web Search.xml
           
          ***** [ DLL ] *****
           
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Scheduled tasks ] *****
           
          Task Found : SweetLabs App Platform
          Task Found : ACC
           
          ***** [ Registry ] *****
           
          Key Found : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
          Key Found : HKCU\Software\Classes\Directory\shell\pokki
          Key Found : HKCU\Software\Classes\Drive\shell\pokki
          Key Found : HKCU\Software\Classes\lnkfile\shell\pokki
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_20bc77071450f86fee7470f383e7601729828efa
          Key Found : HKCU\Software\Classes\pokki
          Key Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Classes\pokki
          Key Found : HKCU\Software\SweetLabs App Platform
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
          Key Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Pokki
          Key Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
          Key Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\SweetLabs App Platform
          Key Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
          Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxps://www.bing.com/?pc=cosp&ptag=A9C7EDF55B3&form=CONMHP&conlogo=CT3210127
          Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page Redirect Cache] - hxxps://www.bing.com/?pc=cosp&ptag=A9C7EDF55B3&form=CONMHP&conlogo=CT3210127
          Data Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxps://www.bing.com/?pc=cosp&ptag=A9C7EDF55B3&form=CONMHP&conlogo=CT3210127
          Data Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main [Start Page Redirect Cache] - hxxps://www.bing.com/?pc=cosp&ptag=A9C7EDF55B3&form=CONMHP&conlogo=CT3210127
          Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{953E7D0F-2D0D-11E5-825E-F0761C2C2D04}
          Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {953E7D0F-2D0D-11E5-825E-F0761C2C2D04}
          Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
          Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
          Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
          Key Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\SearchScopes\{953E7D0F-2D0D-11E5-825E-F0761C2C2D04}
          Data Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {953E7D0F-2D0D-11E5-825E-F0761C2C2D04}
          Key Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
          Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.com/blogs/gadgetbox-search-removal/
          Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\homepage-web.com
          Value Found : HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
           
          ***** [ Web browsers ] *****
           
          [C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\prefs.js] Found : user_pref("browser.search.defaultenginename", "Web Search");
          [C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\prefs.js] Found : user_pref("browser.search.selectedEngine", "Web Search");
          [C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default\prefs.js] Found : user_pref("browser.startup.homepage", "hxxps://homepage-web.com/?s=acer&m=start");
           
          *************************
           
          C:\AdwCleaner\AdwCleaner[S1].txt - [5035 bytes] - [22/04/2016 08:04:42]
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5108 bytes] ##########
           

           

          After turning off Windows Defender, ran Junkware Removal Tool and here is the log:

           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 8.0.4 (03.14.2016)
          Operating System: Windows 8.1 x64 
          Ran by [removed] (Administrator) on Fri 22/04/2016 at  8:46:26.16
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
           
           
          File System: 4 
           
          Successfully deleted: C:\Users\Valda\Appdata\LocalLow\mapsgalaxy_39 (Folder) 
          Successfully deleted: C:\Users\Valda\Appdata\LocalLow\mapsgalaxy_39ei (Folder) 
          Successfully deleted: C:\Users\Valda\Appdata\LocalLow\myfuncards_5m (Folder) 
          Successfully deleted: C:\Users\Valda\Appdata\LocalLow\myfuncards_5mei (Folder) 
           
           
           
          Registry: 3 
           
          Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D4DB4AE4-13D9-443A-81CC-41DA15D0B5AC} (Registry Key)
          Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
          Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
           
           
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Fri 22/04/2016 at  8:47:56.02
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
          Finally, I ran MalwareBytes, and here is the log:

           

          Malwarebytes Anti-Malware
          www.malwarebytes.org
           
          Scan Date: 22/04/2016
          Scan Time: 10:01 AM
          Logfile: 
          Administrator: Yes
           
          Version: 2.2.1.1043
          Malware Database: v2016.04.21.06
          Rootkit Database: v2016.04.17.01
          License: Trial
          Malware Protection: Enabled
          Malicious Website Protection: Enabled
          Self-protection: Disabled
           
          OS: Windows 8.1
          CPU: x64
          File System: NTFS
          User: Valda
           
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 451145
          Time Elapsed: 11 min, 5 sec
           
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
           
          Processes: 0
          (No malicious items detected)
           
          Modules: 0
          (No malicious items detected)
           
          Registry Keys: 0
          (No malicious items detected)
           
          Registry Values: 0
          (No malicious items detected)
           
          Registry Data: 0
          (No malicious items detected)
           
          Folders: 2
          PUP.Optional.MindSpark, C:\Users\UpdatusUser\AppData\LocalLow\MapsGalaxy_39, , [6b0f5e53b0e96bcbb521051a857e7090], 
          PUP.Optional.MindSpark, C:\Users\UpdatusUser\AppData\LocalLow\MyFunCards_5m, , [c9b1951caced5dd9a53935ea9271f709], 
           
          Files: 1
          PUP.Optional.MindSpark, C:\Users\Valda\Downloads\MyFunCards.exe, , [2753aa07dbbe20167848c631b84c55ab], 
           
          Physical Sectors: 0
          (No malicious items detected)
           
           
          (end)
           
           
          Looking forward to your analysis of these.

          As you can see AdwCleaner removed Pokki leftovers .  Things like Mindspark come bundled with other software that the user downloaded and wasnt watching what she downloaded and just kept clicking on NEXT during the installation. You have to really pay attention when you download and install programs. 

           

          Open up FRST64 by right clicking on it and select RUN AS ADMINISTRATOR . Make sure Additions is checked, leave everything else as is, click on Scan and post both new logs please

          Hi Ken545 (sorry for the misnomer last time),

           

          Have run FRST64 and here are the logs:

           

          First FRST.txt:

          Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-04-2016
          Ran by [removed] (administrator) on VALDA (22-04-2016 11:58:03)
          Running from C:\Users\[removed]\Desktop
          [removed]
          Platform: Windows 8.1 (X64) Language: English (United States)
          Internet Explorer Version 11 (Default browser: Chrome)
          Boot Mode: Normal
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
           
          ==================== Processes (Whitelisted) =================
           
          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
           
          (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
          (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
          (Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
          (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
          () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
          (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
          () C:\ProgramData\MobileBrServ\mbbService.exe
          () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
          (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
          (Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
          (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
          (WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
          (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
          (acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
          (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
          (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
          (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
          (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
          (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
          (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
          (Intel Corporation) C:\Windows\System32\igfxHK.exe
          (Intel Corporation) C:\Windows\System32\igfxTray.exe
          (Intel Corporation) C:\Windows\System32\igfxEM.exe
          (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
          (Dolby Laboratories Inc.) C:\Program Files\Dolby Digital Plus\ddp.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
          (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
          (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
          (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
          (Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
          () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
          (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
          (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
          (Spotify Ltd) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
          (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
          (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
          () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
          (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
          (Intel Corporation) C:\Windows\System32\igfxext.exe
          (Microsoft Corporation) C:\Windows\splwow64.exe
          (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
          (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
          (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
          (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
          (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
          (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE
          (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
          (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
          (Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
          (Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
           
           
          ==================== Registry (Whitelisted) ===========================
           
          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
           
          HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-18] (Realtek Semiconductor)
          HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1380056 2014-03-18] (Realtek Semiconductor)
          HKLM-x32\…\Run: [abDocsDllLoader] => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [91488 2015-11-23] ()
          HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1298456 2015-04-20] (CANON INC.)
          HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23248560 2016-04-09] (Dropbox, Inc.)
          HKLM\…\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] (Qualcomm®Atheros®)
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\RunOnce: [RegDXVA1] => C:\Windows\system32\cmd.exe /c reg import "C:\Program Files (x86)\Acer\abPhoto\SwitchUserVideoKey.reg"
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\RunOnce: [SetAsDefault] => C:\Program Files (x86)\Acer\Acer Video Player\SwitchUserVideoKey.bat
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [ISUSPM] =>  -scheduler
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-09-20] (Spotify Ltd)
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\RunOnce: [Application Restart #1] => C:\Users\Valda\AppData\Local\Pokki\Engine\HostAppService.exe  –disable-internal-flash –noerrdialogs –no-message-box –disable-extensions –disable-web-security –disable-web-resources –disable-cli (the data entry has 549 more characters).
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\MountPoints2: {237434b1-df4d-11e5-826c-1008b127f26c} - "E:\AutoRun.exe" 
          ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
          ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
          ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
          ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
          ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-09] (Dropbox, Inc.)
           
          ==================== Internet (Whitelisted) ====================
           
          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
           
          Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.1
          Tcpip\..\Interfaces\{0A159044-1CA1-473A-A365-82A7E1CC161E}: [DhcpNameServer] 192.168.8.1 192.168.8.1
          Tcpip\..\Interfaces\{2EB4B5A8-928A-4E8F-8376-1261E9885494}: [DhcpNameServer] 192.168.8.1 192.168.8.1
          Tcpip\..\Interfaces\{2F364102-6AA1-4723-B2D6-A0A54DE7F775}: [DhcpNameServer] 192.168.8.1 192.168.8.1
          Tcpip\..\Interfaces\{B11A154C-321E-493A-93DF-87DD6FDEA81F}: [DhcpNameServer] 192.168.0.1 192.168.0.1
           
          Internet Explorer:
          ==================
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer13.msn.com/?pc=ACJB
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://accounts.google.com/Login#identifier
          SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
          SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
          BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-04-10] (Microsoft Corporation)
          BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
          BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-04-19] (Microsoft Corporation)
          BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
          Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
          Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
          Toolbar: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
          Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-01-10] (Microsoft Corporation)
           
          FireFox:
          ========
          FF ProfilePath: C:\Users\Valda\AppData\Roaming\Mozilla\Firefox\Profiles\i45o3vvz.default
          FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
          FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
          FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
          FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2016-01-10] (Microsoft Corporation)
          FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-01] (Google Inc.)
          FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-01] (Google Inc.)
          FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
           
          Chrome: 
          =======
          CHR StartupUrls: Default -> "hxxp://www.google.com.au/"
          CHR DefaultSearchURL: Default -> hxxps://secure.homepage-web.com/?partner=acer&src;=omnibox&q;={searchTerms}
          CHR DefaultSearchKeyword: Default -> homepage-web.com
          CHR DefaultSuggestURL: Default -> hxxps://secure-suggest.homepage-web.com/suggest?format=json&locale;={language}&q;={searchTerms}
          CHR Profile: C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default
          CHR Extension: (Google Slides) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-01]
          CHR Extension: (Google Docs) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-01]
          CHR Extension: (Google Drive) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-01]
          CHR Extension: (YouTube) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-01]
          CHR Extension: (Google Search) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-03-01]
          CHR Extension: (Google Sheets) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-01]
          CHR Extension: (Google Docs Offline) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-10]
          CHR Extension: (Google Keep - notes and lists) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2016-04-22]
          CHR Extension: (Chrome Web Store Payments) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-10]
          CHR Extension: (Gmail) - C:\Users\Valda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-01]
           
          ==================== Services (Whitelisted) ========================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Windows (R) Win 7 DDK provider) [File not signed]
          R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2860760 2016-01-14] (Acer Incorporated)
          R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2829552 2016-03-08] (Microsoft Corporation)
          S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-10] (Dropbox, Inc.)
          S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-04-10] (Dropbox, Inc.)
          R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-06-12] (Acer Incorporated)
          R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-25] (WildTangent)
          R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-19] (Intel Corporation)
          R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
          R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
          S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
          R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
          R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [466664 2014-06-10] (Acer Incorporate)
          R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
          R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
          R2 Optus 4G Modem HL; C:\ProgramData\MobileBrServ\mbbservice.exe [242264 2014-11-20] ()
          R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-06-26] (Acer Incorporate)
          R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
          R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-06-26] (Acer Incorporate)
          R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240 2014-07-15] (acer)
          S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
          S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
           
          ===================== Drivers (Whitelisted) ==========================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
          R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-25] (Qualcomm Atheros)
          S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
          R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [99320 2013-10-03] (Intel Corporation)
          R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
          R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
          R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-04-22] (Malwarebytes)
          R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
          R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
          R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
          R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466136 2014-01-14] (Realsil Semiconductor Corporation)
          R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
          S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
          S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
          S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
           
          ==================== NetSvcs (Whitelisted) ===================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
           
          ==================== One Month Created files and folders ========
           
          (If an entry is included in the fixlist, the file/folder will be moved.)
           
          2016-04-22 11:58 - 2016-04-22 11:58 - 00021642 _____ C:\Users\Valda\Desktop\FRST.txt
          2016-04-22 11:56 - 2016-04-19 15:42 - 00046210 _____ C:\Users\Valda\Desktop\Addition.txt
          2016-04-22 10:36 - 2016-04-22 10:39 - 00000000 ____D C:\Users\Valda\Desktop\WTT logs
          2016-04-22 10:12 - 2016-04-22 10:12 - 00000000 ____D C:\Users\Valda\AppData\Local\TempTaskUpdateDetectionA86117F4-46B1-4946-9936-EB2BF337E45C
          2016-04-22 09:46 - 2016-04-22 11:55 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
          2016-04-22 09:46 - 2016-04-22 09:46 - 00001118 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
          2016-04-22 09:46 - 2016-04-22 09:46 - 00000000 ____D C:\ProgramData\Malwarebytes
          2016-04-22 09:46 - 2016-04-22 09:46 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
          2016-04-22 09:46 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
          2016-04-22 09:46 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
          2016-04-22 09:46 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
          2016-04-22 08:40 - 2016-04-22 08:40 - 01610352 _____ (Malwarebytes) C:\Users\Valda\Desktop\JRT.exe
          2016-04-22 08:08 - 2016-04-04 16:35 - 00046768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
          2016-04-22 08:08 - 2016-04-02 23:26 - 01386496 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
          2016-04-22 08:08 - 2016-04-02 23:26 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
          2016-04-22 08:08 - 2016-03-28 23:21 - 00698368 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
          2016-04-22 08:08 - 2016-03-28 23:21 - 00499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
          2016-04-22 08:08 - 2016-03-28 23:21 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
          2016-04-22 08:08 - 2016-03-28 23:21 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
          2016-04-22 08:08 - 2016-03-28 23:21 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
          2016-04-22 08:08 - 2016-03-16 09:00 - 00561952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
          2016-04-22 08:08 - 2016-03-16 00:14 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
          2016-04-22 08:08 - 2016-03-12 00:48 - 00833024 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
          2016-04-22 08:08 - 2016-03-11 05:19 - 07452512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
          2016-04-22 08:08 - 2016-03-11 05:17 - 01663192 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
          2016-04-22 08:08 - 2016-03-11 05:17 - 01523216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
          2016-04-22 08:08 - 2016-03-11 05:17 - 01490128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
          2016-04-22 08:08 - 2016-03-11 05:17 - 01358960 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
          2016-04-22 08:08 - 2016-03-11 05:17 - 01133752 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
          2016-04-22 08:08 - 2016-03-11 04:22 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
          2016-04-22 08:08 - 2016-03-11 04:21 - 00401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
          2016-04-22 08:08 - 2016-03-11 04:20 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
          2016-04-22 08:08 - 2016-03-11 03:48 - 00862720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
          2016-04-22 08:08 - 2016-03-11 03:44 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
          2016-04-22 08:08 - 2016-03-11 03:43 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
          2016-04-22 08:08 - 2016-03-11 03:16 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
          2016-04-22 08:08 - 2016-03-11 03:03 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
          2016-04-22 08:08 - 2016-03-11 02:55 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
          2016-04-22 08:08 - 2016-03-11 02:48 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
          2016-04-22 08:08 - 2016-03-11 02:42 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
          2016-04-22 08:08 - 2016-03-04 02:47 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
          2016-04-22 08:08 - 2016-03-04 02:33 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
          2016-04-22 08:08 - 2016-03-03 11:39 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
          2016-04-22 08:08 - 2016-03-03 11:39 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
          2016-04-22 08:08 - 2016-02-09 11:31 - 22365472 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
          2016-04-22 08:08 - 2016-02-09 11:31 - 19794896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
          2016-04-22 08:08 - 2016-02-09 11:31 - 02757616 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
          2016-04-22 08:08 - 2016-02-09 11:31 - 02412576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
          2016-04-22 08:08 - 2016-02-09 11:31 - 00273264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
          2016-04-22 08:08 - 2016-02-09 06:55 - 02712576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
          2016-04-22 08:08 - 2016-02-09 06:15 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
          2016-04-22 08:08 - 2016-02-09 06:02 - 01197056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
          2016-04-22 08:08 - 2016-02-09 05:48 - 12879360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
          2016-04-22 08:08 - 2016-02-09 05:43 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
          2016-04-22 08:08 - 2016-02-09 05:40 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
          2016-04-22 08:08 - 2016-02-09 05:39 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
          2016-04-22 08:08 - 2016-02-09 05:37 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingMonitor.dll
          2016-04-22 08:08 - 2016-02-09 05:35 - 00954880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
          2016-04-22 08:08 - 2016-02-09 05:34 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
          2016-04-22 08:08 - 2016-02-09 05:33 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
          2016-04-22 08:08 - 2016-02-09 04:50 - 03120640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
          2016-04-22 08:08 - 2016-02-09 03:55 - 02592256 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
          2016-04-22 08:08 - 2016-02-09 03:33 - 01278464 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
          2016-04-22 08:08 - 2016-02-09 03:12 - 14466560 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
          2016-04-22 08:08 - 2016-02-09 03:02 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
          2016-04-22 08:08 - 2016-02-09 03:00 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
          2016-04-22 08:08 - 2016-02-09 02:58 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
          2016-04-22 08:08 - 2016-02-09 02:55 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll
          2016-04-22 08:08 - 2016-02-09 02:53 - 02171904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
          2016-04-22 08:08 - 2016-02-09 02:53 - 01348096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
          2016-04-22 08:08 - 2016-02-09 02:50 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
          2016-04-22 08:08 - 2016-02-09 02:50 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
          2016-04-22 08:08 - 2016-02-09 02:48 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
          2016-04-22 08:08 - 2016-02-09 02:47 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
          2016-04-22 08:08 - 2016-02-09 02:44 - 00955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
          2016-04-22 08:08 - 2016-02-06 01:11 - 00845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
          2016-04-22 08:08 - 2016-02-06 01:11 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
          2016-04-22 08:08 - 2016-02-06 01:07 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
          2016-04-22 08:08 - 2016-02-06 01:02 - 01083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
          2016-04-22 08:08 - 2016-02-06 00:46 - 01455104 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
          2016-04-22 08:08 - 2016-02-05 02:23 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
          2016-04-22 08:08 - 2016-02-04 01:14 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
          2016-04-22 08:08 - 2016-02-04 01:11 - 01673728 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
          2016-04-22 08:08 - 2016-02-03 03:51 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
          2016-04-22 08:08 - 2016-02-03 03:19 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
          2016-04-22 08:08 - 2016-02-03 03:15 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
          2016-04-22 08:08 - 2016-02-03 03:01 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
          2016-04-22 08:08 - 2016-02-03 02:51 - 02609152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
          2016-04-22 08:08 - 2016-02-03 02:48 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
          2016-04-22 08:08 - 2016-02-03 02:46 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
          2016-04-22 08:08 - 2016-02-03 02:41 - 02170880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
          2016-04-22 08:08 - 2016-02-03 02:39 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
          2016-04-22 08:08 - 2016-01-28 01:18 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
          2016-04-22 08:08 - 2016-01-27 05:15 - 00072024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
          2016-04-22 08:08 - 2016-01-22 05:35 - 00952928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
          2016-04-22 08:08 - 2016-01-22 04:42 - 00786152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
          2016-04-22 08:08 - 2016-01-21 08:40 - 00099672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\disk.sys
          2016-04-22 08:08 - 2014-11-08 12:38 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
          2016-04-22 08:08 - 2014-11-08 12:17 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
          2016-04-22 08:07 - 2016-02-06 05:07 - 00378712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
          2016-04-22 08:07 - 2016-02-05 04:07 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpsapi.dll
          2016-04-22 08:07 - 2016-02-05 03:35 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpsapi.dll
          2016-04-22 08:07 - 2016-02-05 02:22 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
          2016-04-22 08:07 - 2016-02-03 03:18 - 01574912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
          2016-04-22 08:07 - 2016-01-22 15:22 - 02487296 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
          2016-04-22 08:07 - 2016-01-22 15:11 - 01482240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
          2016-04-22 08:06 - 2016-03-04 02:13 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
          2016-04-22 08:06 - 2016-02-07 09:05 - 00551256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
          2016-04-22 08:06 - 2016-02-07 08:41 - 00316760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
          2016-04-22 08:06 - 2016-02-01 03:17 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsAnytimeUpgradeui.exe
          2016-04-22 08:05 - 2016-03-30 00:05 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
          2016-04-22 08:04 - 2016-04-22 08:24 - 00000000 ____D C:\AdwCleaner
          2016-04-22 08:03 - 2016-04-22 08:03 - 03683904 _____ C:\Users\Valda\Desktop\AdwCleaner.exe
          2016-04-19 15:40 - 2016-04-22 11:58 - 00000000 ____D C:\FRST
          2016-04-19 15:10 - 2016-04-19 15:10 - 00293152 _____ C:\WINDOWS\Minidump\041916-32015-01.dmp
          2016-04-19 15:04 - 2016-04-19 15:56 - 00002061 _____ C:\Users\Valda\Desktop\WTT topic content.txt
          2016-04-19 14:56 - 2016-04-19 14:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
          2016-04-19 14:46 - 2016-04-19 14:46 - 00288504 _____ C:\WINDOWS\Minidump\041916-28109-01.dmp
          2016-04-19 14:39 - 2016-04-19 15:10 - 597918099 _____ C:\WINDOWS\MEMORY.DMP
          2016-04-19 14:39 - 2016-04-19 15:10 - 00000000 ____D C:\WINDOWS\Minidump
          2016-04-19 14:39 - 2016-04-19 14:40 - 00297552 _____ C:\WINDOWS\Minidump\041916-114406-01.dmp
          2016-04-19 14:33 - 2016-04-19 14:34 - 02375680 _____ (Farbar) C:\Users\Valda\Desktop\FRST64.exe
          2016-04-19 14:32 - 2016-04-19 14:32 - 05198336 _____ (AVAST Software) C:\Users\Valda\Desktop\aswMBR.exe
          2016-04-12 09:35 - 2016-04-12 09:35 - 00243344 _____ C:\Users\Valda\Documents\WO 9646366.pdf
          2016-04-12 07:53 - 2016-04-12 07:53 - 00533492 _____ C:\Users\Valda\Documents\WO 9749726.pdf
          2016-04-12 07:16 - 2016-04-12 07:16 - 00147700 _____ C:\Users\Valda\Documents\WO 9809763.pdf
          2016-04-11 18:16 - 2016-04-11 18:16 - 00002001 _____ C:\Users\Public\Desktop\abMusic.lnk
          2016-04-11 08:32 - 2016-04-11 08:32 - 00787736 _____ C:\Users\Valda\Documents\WO9868772.pdf
          2016-04-11 08:28 - 2016-04-11 08:28 - 00788025 _____ C:\Users\Valda\Documents\IMG_20160411_0001.pdf
          2016-04-10 22:11 - 2016-04-10 22:11 - 00692088 _____ C:\Users\Valda\Documents\Get Started with Dropbox.pdf
          2016-04-10 22:02 - 2016-04-22 11:56 - 00000000 ___RD C:\Users\Valda\Dropbox
          2016-04-10 22:02 - 2016-04-10 22:02 - 00001246 _____ C:\Users\Valda\Desktop\Dropbox.lnk
          2016-04-10 22:00 - 2016-04-10 22:00 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
          2016-04-10 21:38 - 2016-04-10 21:38 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller (2).exe
          2016-04-10 21:33 - 2016-04-10 21:33 - 00000000 ____D C:\Users\Valda\AppData\Roaming\Dropbox
          2016-04-10 21:32 - 2016-04-22 11:55 - 00000914 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
          2016-04-10 21:32 - 2016-04-22 10:37 - 00000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
          2016-04-10 21:32 - 2016-04-19 14:56 - 00000000 ____D C:\Program Files (x86)\Dropbox
          2016-04-10 21:32 - 2016-04-19 14:52 - 00000000 ____D C:\Users\Valda\AppData\Local\Dropbox
          2016-04-10 21:32 - 2016-04-10 21:32 - 00003890 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
          2016-04-10 21:32 - 2016-04-10 21:32 - 00003654 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
          2016-04-10 21:32 - 2016-04-10 21:32 - 00000000 ____D C:\ProgramData\Dropbox
          2016-04-10 21:31 - 2016-04-10 21:32 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller (1).exe
          2016-04-10 21:30 - 2016-04-10 21:30 - 00691096 _____ (Dropbox, Inc.) C:\Users\Valda\Downloads\DropboxInstaller.exe
          2016-04-10 16:27 - 2016-04-10 16:27 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
           
          ==================== One Month Modified files and folders ========
           
          (If an entry is included in the fixlist, the file/folder will be moved.)
           
          2016-04-22 11:55 - 2016-03-01 11:42 - 00000904 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
          2016-04-22 11:55 - 2014-11-07 13:15 - 00000000 __RDO C:\Users\Valda\OneDrive
          2016-04-22 09:47 - 2016-03-01 11:42 - 00000908 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
          2016-04-22 09:06 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\rescache
          2016-04-22 08:51 - 2015-05-30 16:47 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-974442171-2668444937-4057906661-1002
          2016-04-22 08:41 - 2014-03-18 20:03 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
          2016-04-22 08:41 - 2013-08-22 23:36 - 00000000 ____D C:\WINDOWS\Inf
          2016-04-22 08:34 - 2013-08-23 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
          2016-04-22 08:34 - 2013-08-23 00:44 - 00369608 _____ C:\WINDOWS\system32\FNTCACHE.DAT
          2016-04-22 08:32 - 2013-08-22 23:25 - 01310720 ___SH C:\WINDOWS\system32\config\BBI
          2016-04-22 08:31 - 2016-01-30 07:41 - 00000000 ____D C:\WINDOWS\system32\appraiser
          2016-04-22 08:31 - 2013-08-23 01:36 - 00000000 ___RD C:\WINDOWS\ToastData
          2016-04-22 08:24 - 2016-01-22 02:38 - 00000000 ____D C:\WINDOWS\system32\MRT
          2016-04-22 08:24 - 2014-09-20 12:48 - 00000000 ____D C:\Users\UpdatusUser
          2016-04-22 08:24 - 2013-08-23 01:20 - 00000000 ____D C:\WINDOWS\CbsTemp
          2016-04-22 08:18 - 2016-01-22 02:38 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
          2016-04-22 08:06 - 2016-01-22 01:51 - 00177488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
          2016-04-22 08:04 - 2016-03-11 18:10 - 01737080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
          2016-04-22 08:04 - 2016-03-11 18:10 - 01501488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
          2016-04-22 08:04 - 2016-03-11 18:10 - 00246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
          2016-04-19 16:06 - 2015-05-30 16:31 - 00000000 ____D C:\Users\Valda
          2016-04-19 15:20 - 2015-05-30 17:10 - 00000000 ____D C:\Program Files\Microsoft Office 15
          2016-04-19 15:20 - 2013-08-23 01:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
          2016-04-14 09:45 - 2016-03-01 11:26 - 00453280 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
          2016-04-12 07:17 - 2016-03-11 19:25 - 00000000 ___HD C:\ProgramData\CanonIJMIG
          2016-04-12 06:48 - 2016-03-01 11:43 - 00002219 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
          2016-04-12 06:48 - 2016-03-01 11:43 - 00002207 _____ C:\Users\Public\Desktop\Google Chrome.lnk
          2016-04-12 06:07 - 2016-02-18 18:07 - 00000000 ____D C:\ProgramData\CanonIJPLM
          2016-04-11 18:16 - 2014-07-26 04:28 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
          2016-04-11 18:16 - 2014-07-26 04:28 - 00000000 ____D C:\Program Files (x86)\Acer
          2016-04-11 18:15 - 2015-05-30 16:43 - 00000000 ____D C:\Users\Valda\AppData\Local\clear.fi
          2016-04-10 22:01 - 2015-05-30 16:37 - 00000000 ____D C:\Users\Valda\AppData\Local\VirtualStore
          2016-04-10 20:49 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\AppReadiness
          2016-04-10 16:38 - 2016-01-30 07:54 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
          2016-04-10 16:38 - 2016-01-30 07:54 - 00000000 ___SD C:\WINDOWS\system32\GWX
          2016-04-10 16:28 - 2016-03-11 19:15 - 00000000 ____D C:\Users\Valda\AppData\LocalLow\Canon Easy-WebPrint EX
          2016-04-06 07:53 - 2016-01-30 08:05 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
          2016-04-06 07:53 - 2016-01-30 08:05 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
           
          ==================== Files in the root of some directories =======
           
          2014-09-20 13:01 - 2014-09-20 13:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
           
          Some files in TEMP:
          ====================
          C:\Users\Valda\AppData\Local\Temp\FoxitUpdater.exe
          C:\Users\Valda\AppData\Local\Temp\McCSPInstall.dll
          C:\Users\Valda\AppData\Local\Temp\mccspuninstall.exe
          C:\Users\Valda\AppData\Local\Temp\MSETUP4.EXE
          C:\Users\Valda\AppData\Local\Temp\oct12C.tmp.exe
          C:\Users\Valda\AppData\Local\Temp\oct3DB0.tmp.exe
          C:\Users\Valda\AppData\Local\Temp\oct4823.tmp.exe
          C:\Users\Valda\AppData\Local\Temp\oct827D.tmp.exe
          C:\Users\Valda\AppData\Local\Temp\oct8940.tmp.exe
          C:\Users\Valda\AppData\Local\Temp\octD5D8.tmp.exe
          C:\Users\Valda\AppData\Local\Temp\octDBE1.tmp.exe
          C:\Users\Valda\AppData\Local\Temp\octECEA.tmp.exe
           
           
          ==================== Bamital & volsnap =================
           
          (There is no automatic fix for files that do not pass verification.)
           
          C:\WINDOWS\system32\winlogon.exe => File is digitally signed
          C:\WINDOWS\system32\wininit.exe => File is digitally signed
          C:\WINDOWS\explorer.exe => File is digitally signed
          C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
          C:\WINDOWS\system32\svchost.exe => File is digitally signed
          C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
          C:\WINDOWS\system32\services.exe => File is digitally signed
          C:\WINDOWS\system32\User32.dll => File is digitally signed
          C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
          C:\WINDOWS\system32\userinit.exe => File is digitally signed
          C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
          C:\WINDOWS\system32\rpcss.dll => File is digitally signed
          C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
          C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
          C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
           
           
          LastRegBack: 2016-04-22 07:51
           
          ==================== End of FRST.txt ============================
           
          and here Addition.txt
           
          Additional scan result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
          Ran by [removed] (2016-04-22 11:58:53)
          Running from C:\Users\[removed]\Desktop
          Windows 8.1 (X64) (2015-05-30 06:34:43)
          Boot Mode: Normal
          ==========================================================
           
           
          ==================== Accounts: =============================
           
          Administrator (S-1-5-21-974442171-2668444937-4057906661-500 - Administrator - Disabled) => C:\Users\Administrator
          Guest (S-1-5-21-974442171-2668444937-4057906661-501 - Limited - Disabled)
          HomeGroupUser$ (S-1-5-21-974442171-2668444937-4057906661-1004 - Limited - Enabled)
          UpdatusUser (S-1-5-21-974442171-2668444937-4057906661-1001 - Limited - Enabled) => C:\Users\UpdatusUser
          Valda (S-1-5-21-974442171-2668444937-4057906661-1002 - Administrator - Enabled) => C:\Users\Valda
          Valda_2 (S-1-5-21-974442171-2668444937-4057906661-1005 - Limited - Enabled) => C:\Users\Valda_2
           
          ==================== Security Center ========================
           
          (If an entry is included in the fixlist, it will be removed.)
           
          AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
           
          ==================== Installed Programs ======================
           
          (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
           
          abDocs (HKLM-x32\…\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.09.2001 - Acer Incorporated)
          abDocs Office AddIn (HKLM-x32\…\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.02.2001 - Acer Incorporated)
          abFiles (HKLM-x32\…\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.00.3002 - Acer Incorporated)
          abMusic (HKLM-x32\…\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 3.00.2003.6 - Acer Incorporated)
          abPhoto (HKLM-x32\…\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.06.2000.22 - Acer Incorporated)
          Acer Care Center (HKLM\…\{A424844F-CDB3-45E2-BB77-1DDE4A091E76}) (Version: 1.00.3013 - Acer Incorporated)
          Acer Explorer Agent (HKLM\…\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
          Acer Launch Manager (HKLM\…\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8107 - Acer Incorporated)
          Acer Portal (HKLM-x32\…\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.09.2002 - Acer Incorporated)
          Acer Power Management (HKLM\…\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8105 - Acer Incorporated)
          Acer Quick Access (HKLM\…\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3016.0 - Acer Incorporated)
          Acer Recovery Management (HKLM\…\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
          Acer User Experience Improvement Program App Monitor Plugin (HKLM\…\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3005 - Acer Incorporated)
          Acer User Experience Improvement Program Framework (HKLM\…\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3005 - Acer Incorporated)
          Acer Video Player (HKLM-x32\…\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2005.0 - Acer Incorporated)
          Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
          Amazon 1Button App (HKLM-x32\…\{FF0A904E-8827-4F6E-9A59-900D4C997AD1}) (Version: 1.0.8 - Amazon) <==== ATTENTION
          AOP Framework (HKLM-x32\…\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.15.2000.1 - Acer Incorporated)
          Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
          Canon IJ Scan Utility (HKLM-x32\…\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
          Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: 4.1.0 - Canon Inc.)
          Canon MG2500 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.02 - Canon Inc.)
          Canon MG2500 series On-screen Manual (HKLM-x32\…\Canon MG2500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
          Canon My Image Garden (HKLM-x32\…\Canon My Image Garden) (Version: 3.3.0 - Canon Inc.)
          Canon My Image Garden Design Files (HKLM-x32\…\Canon My Image Garden Design Files) (Version: 3.2.0 - Canon Inc.)
          Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
          Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.6.1 - Canon Inc.)
          CyberLink PhotoDirector 3 (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
          CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.4218 - CyberLink Corp.)
          CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
          Dolby Digital Plus Home Theater (HKLM\…\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
          Dropbox (HKLM-x32\…\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
          Dropbox Update Helper (x32 Version: 1.3.35.1 - Dropbox, Inc.) Hidden
          eBay Worldwide (HKLM-x32\…\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
          Farm to Fork Collector's Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
          Game Explorer Categories - genres (HKLM-x32\…\WildTangentGameProvider-acer-genres) (Version: 11.0.0.7 - WildTangent, Inc.)
          Game Explorer Categories - main (HKLM-x32\…\WildTangentGameProvider-acer-main) (Version: 11.0.0.7 - WildTangent, Inc.)
          Google Chrome (HKLM-x32\…\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
          Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
          Governor of Poker 2 Premium Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
          Hidden Mysteries - Graceland (HKLM-x32\…\Hidden Mysteries - Graceland) (Version: 1.0 - GameMill Entertainment)
          Inspector Magnusson - Murder on the Titanic (x32 Version: 2.2.0.110 - WildTangent) Hidden
          Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
          Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
          Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.165.1 - Intel Corporation)
          King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
          Lost in Night (x32 Version: 3.0.2.38 - WildTangent) Hidden
          LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
          Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
          Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
          Microsoft Outlook 2013 - en-us (HKLM\…\OutlookRetail - en-us) (Version: 15.0.4815.1001 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
          Mozilla Firefox 44.0.2 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 44.0.2 (x86 en-US)) (Version: 44.0.2 - Mozilla)
          Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 44.0.2 - Mozilla)
          MYOB AccountRight Plus v19.10 (x32 Version: 19.10.0 - MYOB Technology Pty Ltd) Hidden
          NVIDIA Graphics Driver 332.35 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.35 - NVIDIA Corporation)
          NVIDIA PhysX System Software 9.13.0927 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation)
          NVIDIA Update 1.15.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
          Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
          Office 15 Click-to-Run Licensing Component (Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
          Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4815.1001 - Microsoft Corporation) Hidden
          Optus 4G Modem HL (HKLM-x32\…\Optus 4G Modem HL) (Version: 22.001.26.00.74 - Huawei Technologies Co.,Ltd)
          Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Pokki) (Version: 0.269.2.471 - Pokki)
          Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
          Qualcomm Atheros Bluetooth Suite (64) (HKLM\…\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.318 - Qualcomm Atheros Communications)
          Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\…\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.29 - Qualcomm Atheros)
          Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
          Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.25.108.2014 - Realtek)
          Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7203 - Realtek Semiconductor Corp.)
          Spotify (HKLM-x32\…\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
          The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.51 - WildTangent) Hidden
          Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
          Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
          WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
          WildTangent Games App (x32 Version: 4.0.11.13 - WildTangent) Hidden
          Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden
           
          ==================== Custom CLSID (Whitelisted): ==========================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          CustomCLSID: HKU\S-1-5-21-974442171-2668444937-4057906661-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
           
          ==================== Scheduled Tasks (Whitelisted) =============
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          Task: {02F765CE-0EC3-4DEE-ACB0-73FEDFFC82B9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-22] (Microsoft Corporation)
          Task: {065896BE-FAF6-4AEC-B86B-811D36A81FE9} - System32\Tasks\abDocsDllLoader => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe [2015-11-23] ()
          Task: {15B8CED1-1430-4487-861D-74DDE81C6F62} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [2016-01-14] (Acer Incorporated)
          Task: {185669F3-1C5B-46DE-A0A5-8E55A572676A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-01-10] (Microsoft Corporation)
          Task: {3D222F32-B59A-4620-A1D1-670AC5F9E641} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-06-12] (Acer Incorporated)
          Task: {3FCBB702-5090-4D41-B310-35AEB536818E} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2014-08-29] ()
          Task: {48A31DC3-8986-473B-8968-244E049814DB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-01] (Google Inc.)
          Task: {4B0864C2-AB5D-424A-A616-295DEF51C449} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2014-06-09] (Acer Incorporated)
          Task: {609647A4-3D37-4E92-9B30-2ACAFF85A647} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-01] (Google Inc.)
          Task: {6A1EA7FF-879B-4620-A9C2-C525C0993E78} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe [2013-09-09] (Dolby Laboratories Inc.)
          Task: {8F3D2505-F0D3-4937-8569-A2F38486955D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-10] (Dropbox, Inc.)
          Task: {A15CE7A3-142F-4986-97F2-385E16FF95FE} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
          Task: {B6EAA0B7-AF1A-4852-BE63-E8ECDBAADFD9} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-06-10] (Acer Incorporate)
          Task: {C12C5A69-EA8A-4F1D-BBEC-81DB714052BB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2016-01-10] (Microsoft Corporation)
          Task: {D35BDF10-850E-4701-9799-066F9AA5333C} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-18] (Acer Incorporated)
          Task: {D7F524F5-77EE-485C-BA66-EA1FDD41D23E} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2016-01-19] (Acer)
          Task: {DB317CD5-AA28-4374-BF64-BB03E5B01BF9} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
          Task: {DD5B8A6B-8761-400F-83C8-43C3D1BA9F7A} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: )
          Task: {E7638087-2ACF-42D4-A096-C9D652417475} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-04-10] (Dropbox, Inc.)
          Task: {E7A59D9F-4E73-4799-A961-A18E64CE0BB1} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
          Task: {E9D1DF34-EFC9-435C-B43C-50EAEC279F11} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
           
          (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
           
          Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
          Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
          Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
           
          ==================== Shortcuts =============================
           
          (The entries could be listed to be restored or removed.)
           
          ShortcutWithArgument: C:\Users\Public\Desktop\Agoda.lnk -> C:\ProgramData\OEM_Agoda\StartURL.exe () -> hxxp://www.agoda.com?cid=1630081
          ShortcutWithArgument: C:\Users\Public\Desktop\Dropbox.lnk -> C:\Program Files\Dropbox\StartURL.exe () -> hxxps://www.dropbox.com/partners/acer2014/download
          ShortcutWithArgument: C:\Users\Public\Desktop\PRIVATE WiFi.lnk -> C:\Program Files\PRIVATE WiFi\StartURL.exe () -> hxxp://www.privatewifi.com/partner/clicks.php?pid=928649&bid;=76&campaign;=default
           
          ==================== Loaded Modules (Whitelisted) ==============
           
          2015-05-30 17:10 - 2015-10-13 05:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
          2016-03-11 19:23 - 2013-05-14 17:50 - 00140936 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
          2016-03-11 12:17 - 2014-11-20 18:48 - 00242264 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe
          2014-07-26 04:31 - 2012-04-24 20:43 - 00254512 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
          2014-09-20 12:48 - 2014-01-08 10:48 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
          2014-07-26 04:35 - 2014-07-02 07:13 - 00111872 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll
          2013-09-09 13:13 - 2013-09-09 13:13 - 00050904 _____ () C:\Program Files\Dolby Digital Plus\Dolby.DDP.Controls_Desktop.dll
          2014-02-25 22:14 - 2014-02-25 22:14 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
          2014-02-25 22:11 - 2014-02-25 22:11 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
          2014-02-25 22:17 - 2014-02-25 22:17 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
          2015-11-23 17:44 - 2015-11-23 17:44 - 01769312 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
          2014-03-19 11:35 - 2014-03-08 02:21 - 00080312 _____ () C:\Windows\system32\igfxexps.dll
          2014-09-20 12:50 - 2013-12-10 09:27 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
          2016-04-10 21:37 - 2016-03-22 07:50 - 00034768 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
          2016-04-19 14:56 - 2016-03-22 07:51 - 00019408 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
          2016-04-19 14:56 - 2016-03-22 07:50 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
          2016-04-10 21:37 - 2016-03-22 07:50 - 00093640 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
          2016-04-10 21:37 - 2016-03-22 07:50 - 00018376 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00019760 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
          2016-04-19 14:56 - 2016-03-22 07:50 - 00392144 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
          2016-04-10 21:37 - 2016-04-09 04:20 - 00381752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
          2016-04-10 21:37 - 2016-03-22 07:50 - 00692688 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
          2016-04-19 14:55 - 2016-04-09 04:19 - 00020816 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
          2016-04-10 21:37 - 2016-03-22 07:51 - 00112592 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
          2016-04-19 14:55 - 2016-04-09 04:19 - 01682760 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
          2016-04-19 14:55 - 2016-04-09 04:19 - 00020808 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00021840 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
          2016-04-19 14:56 - 2016-04-09 04:19 - 00038696 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
          2016-04-19 14:56 - 2016-03-22 07:52 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00114640 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00021832 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
          2016-04-19 14:56 - 2016-04-09 04:19 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
          2016-04-19 14:55 - 2016-04-09 04:19 - 00117056 _____ () C:\Program Files (x86)\Dropbox\Client\breakpad.client.windows.handler.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00023376 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
          2016-04-10 21:37 - 2016-03-22 07:50 - 00134608 _____ () C:\Program Files (x86)\Dropbox\Client\_elementtree.pyd
          2016-04-19 14:56 - 2016-03-22 07:50 - 00134088 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
          2016-04-19 14:56 - 2016-03-22 07:51 - 00240584 _____ () C:\Program Files (x86)\Dropbox\Client\jpegtran.pyd
          2016-04-19 14:56 - 2016-04-09 04:19 - 00024392 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
          2016-04-19 14:56 - 2016-03-22 07:52 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
          2016-04-19 14:56 - 2016-04-09 04:19 - 00052024 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi._winffi_iphlpapi.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00021824 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32._winffi_kernel32.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00019776 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror._winffi_winerror.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet._winffi_wininet.pyd
          2016-04-19 14:55 - 2016-04-09 04:19 - 00020280 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
          2016-04-10 21:37 - 2016-03-22 07:52 - 00350152 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
          2016-04-10 21:37 - 2016-04-09 04:20 - 00022352 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
          2016-04-19 14:56 - 2016-04-09 04:19 - 00084280 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
          2016-04-19 14:56 - 2016-04-09 04:20 - 01826096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
          2016-04-10 21:37 - 2016-03-22 07:51 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 03928880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 01971504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00531248 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00132912 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00223544 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00207672 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00158008 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00042808 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
          2016-04-19 14:56 - 2016-03-22 07:54 - 00017864 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
          2016-04-19 14:56 - 2016-03-22 07:54 - 01631184 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
          2016-04-10 21:37 - 2016-04-09 04:20 - 00024904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00546096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
          2016-04-19 14:56 - 2016-04-09 04:20 - 00357680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
          2016-04-10 21:37 - 2016-03-22 07:56 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
          2016-02-24 09:54 - 2016-02-24 09:54 - 00325824 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll
          2016-02-24 09:55 - 2016-02-24 09:55 - 00325824 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
          2015-11-16 18:55 - 2015-11-16 18:55 - 00202456 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
          2015-11-16 18:56 - 2015-11-16 18:56 - 00654000 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
          2015-11-16 18:56 - 2015-11-16 18:56 - 00641240 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
          2015-11-16 18:56 - 2015-11-16 18:56 - 00119000 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
          2016-02-18 18:21 - 2016-02-18 18:21 - 00015064 _____ () C:\WINDOWS\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
          2016-01-14 16:12 - 2016-01-14 16:12 - 00013016 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
          2016-01-14 16:11 - 2016-01-14 16:11 - 00277856 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
          2016-01-19 14:06 - 2016-01-19 14:06 - 00194048 _____ () C:\Program Files (x86)\Acer\Acer Portal\curllib.dll
          2016-01-19 14:06 - 2016-01-19 14:06 - 00110592 _____ () C:\Program Files (x86)\Acer\Acer Portal\OpenLDAP.dll
           
          ==================== Alternate Data Streams (Whitelisted) =========
           
          (If an entry is included in the fixlist, only the ADS will be removed.)
           
           
          ==================== Safe Mode (Whitelisted) ===================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
           
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
           
          ==================== EXE Association (Whitelisted) ===============
           
          (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
           
           
          ==================== Internet Explorer trusted/restricted ===============
           
          (If an entry is included in the fixlist, it will be removed from the registry.)
           
           
          ==================== Hosts content: ===============================
           
          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
           
          2013-08-22 23:25 - 2013-08-22 23:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
           
           
          ==================== Other Areas ============================
           
          (Currently there is no automatic fix for this section.)
           
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Valda\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\windows photo viewer wallpaper.jpg
          DNS Servers: 192.168.0.1
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
          Windows Firewall is enabled.
           
          ==================== MSCONFIG/TASK MANAGER disabled items ==
           
          (Currently there is no automatic fix for this section.)
           
           
          ==================== FirewallRules (Whitelisted) ===============
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
          FirewallRules: [{AFF950B5-E50F-490C-A356-61966989B856}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
          FirewallRules: [{D45F2DEB-5DC4-420F-B207-F9C8D794384C}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
          FirewallRules: [{368AA98A-9058-43BB-A710-FCAC404DB2B2}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
          FirewallRules: [{D7C97A6A-D6FB-4F06-929A-65D02CB2FB04}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
          FirewallRules: [{8DA6FF61-9BD7-4A38-9214-EBFF37DABA30}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
          FirewallRules: [{882C979D-4084-4E83-BE90-4DD269D16461}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
          FirewallRules: [{AB92FFF7-BD7F-44CB-A466-CB138D1F4976}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
          FirewallRules: [{F34EF84C-672F-4FA3-8F5D-4101A50451E5}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
          FirewallRules: [{40D8BE5C-FEF4-4461-9AE6-42AC315B734E}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
          FirewallRules: [{DB4357B3-A584-4542-8A1A-9072F7AB6376}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
          FirewallRules: [{81351C50-F528-4406-92C0-AEAEFE5517A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
          FirewallRules: [{8422D21D-4388-44B9-B159-CE040BACEEAA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
          FirewallRules: [{84AFACB1-02D8-40B7-8521-3B49310D4AA5}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
          FirewallRules: [{F9DD3586-975D-4006-A6F8-A3D79BCDA2CC}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
          FirewallRules: [{E08D6C5B-3A13-416B-9C86-3A1656E8A1DD}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
          FirewallRules: [{07E6C917-528E-4A12-A000-DA0B5272ADAB}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
          FirewallRules: [{D9D7D184-5CA8-4742-9017-6D373DB97E82}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Play.exe
          FirewallRules: [{661AD751-0BD3-46C2-A576-2EF801EA31D2}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
          FirewallRules: [{CDF7EF82-B2BD-428A-A3EC-D0D7C59E7003}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
          FirewallRules: [{27879486-9ACA-4DE0-9C01-B04F0E60F631}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
          FirewallRules: [{59A0E661-DA1B-4E8D-A7AD-694E051B480F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
          FirewallRules: [{6DFE83AB-2734-4DAB-AC63-E9B92AB83D96}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
          FirewallRules: [{CADEC948-96E7-4F7D-A210-6A0482059E7A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{41446356-E125-4F1F-80D5-EF41489BA9FD}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{8DEF424D-E082-4AEF-ACD0-55FFD9733C01}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{C8B20BF5-4D3E-4A08-B9AC-8EF31116C6A3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{7338970A-57D6-4A38-B04C-0A0B923F87C3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{5345F876-5C7C-4CED-A297-9EF0EBAC6845}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{49628988-084F-4966-8916-4FEE0754E899}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{CE6E1F52-B3BE-4A72-AF60-2BCA5C9B1814}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{0877F64A-1DBC-4BBE-A531-C5400EED44AF}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
          FirewallRules: [{6FB69EA0-E7FD-48CD-BDFC-A87D145B2A93}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
          FirewallRules: [{32C1492B-5136-4FBF-8C15-EE84845E4BBA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
          FirewallRules: [{881C2E6D-A4C2-4B3D-A62D-B93A93F3BCC9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{C6CABB36-119D-47A4-ACBD-1DE32D773915}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{626F108E-2B9B-4A4B-AAF2-DF9BCE46BDF3}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{1E075124-1D73-4931-900A-379A5F81992E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{EF373059-4F61-4844-B9C3-D0852B2865E1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{14A3214B-AD15-40AA-B145-718DC19C2C51}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{4EAFD24F-5150-455D-B2D5-420C0185270E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{C50DB59B-547D-478D-9E30-6789B0A01109}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{580AD0BB-E949-4A03-B0C5-4F3B7D523A2E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{942CFCDB-6200-4967-A85D-3AD927A6253D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{4C949DC1-9A11-440F-9876-36C8BA62F46D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{0AA96318-B905-4B51-AB9A-4569D52656E1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{A378F9A1-8708-4651-A547-EB5EB6516C96}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{39178852-F613-4809-85DF-097D83691827}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
          FirewallRules: [{19BE7717-FB95-4A7B-BEF2-FB28ABF0708C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{48A6D524-1FCF-4AD2-9A25-188AD945C3EF}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
          FirewallRules: [{B098A471-E99A-4692-8041-70A95D058F99}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{0065F20B-B795-411C-984D-22C7586E0711}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{318E9D5C-8B01-4C6A-8874-EA44EF18E1C5}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
          FirewallRules: [{7D3E059A-294C-4787-9A3D-6A070C982125}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
          FirewallRules: [{E25FDA55-B2F4-445D-90C2-48B0F98E39EB}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
          FirewallRules: [{3E1E204A-6775-49EE-A4FD-B3987BA5C1DD}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
          FirewallRules: [{50F268CD-0DE1-49CF-B94C-3BF37137E07B}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
          FirewallRules: [{77A94F49-18C8-4428-8851-FEE9AF23C4FD}] => (Allow) C:\Program Files (x86)\Acer\abMusic\DMCDaemon.exe
          FirewallRules: [{16B955D5-2F15-4F9A-8EED-D42DF822B5EC}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
          FirewallRules: [{5D02D7A8-0B9D-41CB-BA90-1EEE971E20FE}] => (Allow) C:\Program Files (x86)\Acer\abMusic\WindowsUpnpMV.exe
          FirewallRules: [{16DF9D5F-77FA-4C08-82FA-63165C9569DC}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          FirewallRules: [{95E2DA70-1198-4825-A7ED-6D9266312010}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
           
          ==================== Restore Points =========================
           
          13-03-2016 16:24:44 Installed DirectX
          10-04-2016 16:37:25 Windows Update
          22-04-2016 08:12:29 Windows Update
          22-04-2016 08:46:30 JRT Pre-Junkware Removal
           
          ==================== Faulty Device Manager Devices =============
           
          Name: Bluetooth Device (Personal Area Network)
          Description: Bluetooth Device (Personal Area Network)
          Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
          Manufacturer: Microsoft
          Service: BthPan
          Problem: : This device is disabled. (Code 22)
          Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
           
           
          ==================== Event log errors: =========================
           
          Application errors:
          ==================
          Error: (04/22/2016 08:31:38 AM) (Source: Application Error) (EventID: 1000) (User: )
          Description: Faulting application name: svchost.exe_ProfSvc, version: 6.3.9600.17415, time stamp: 0x54504177
          Faulting module name: combase.dll, version: 6.3.9600.18202, time stamp: 0x569e6ee3
          Exception code: 0xc0000005
          Fault offset: 0x000000000003a02f
          Faulting process id: 0x208
          Faulting application start time: 0xsvchost.exe_ProfSvc0
          Faulting application path: svchost.exe_ProfSvc1
          Faulting module path: svchost.exe_ProfSvc2
          Report Id: svchost.exe_ProfSvc3
          Faulting package full name: svchost.exe_ProfSvc4
          Faulting package-relative application ID: svchost.exe_ProfSvc5
           
          Error: (04/19/2016 03:38:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
          Description: The program backgroundTaskHost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
           
          Process ID: 1984
           
          Start Time: 01d199fb734b7e56
           
          Termination Time: 4294967295
           
          Application Path: C:\WINDOWS\system32\backgroundTaskHost.exe
           
          Report Id: 66e8dbde-05ef-11e6-8273-0c5b8f279a64
           
          Faulting package full name: Amazon.com.Amazon_3.1.2.8_neutral__343d40qqvtj1t
           
          Faulting package-relative application ID: App
           
          Error: (04/19/2016 03:20:16 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: VALDA)
          Description: Application or service 'Microsoft Office Document Cache Sync Client Interface' could not be shut down.
           
          Error: (04/10/2016 04:29:56 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
          Description: There was an error with the Windows Location Provider database
           
          Error: (04/10/2016 04:20:45 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: VALDA)
          Description: Application or service 'Microsoft Office Document Cache Sync Client Interface' could not be shut down.
           
          Error: (04/10/2016 04:12:52 PM) (Source: RasClient) (EventID: 20227) (User: )
          Description: CoId={E64FEA12-CE1F-42F5-BEA1-6C55FBF4E3F0}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
           
          Error: (04/10/2016 03:56:05 PM) (Source: RasClient) (EventID: 20227) (User: )
          Description: CoId={1A795855-D091-4627-AA81-2FB9AADC868B}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
           
          Error: (04/10/2016 03:53:16 PM) (Source: RasClient) (EventID: 20227) (User: )
          Description: CoId={8120AE4D-4298-479C-9FB4-06E99A6CF532}: The user SYSTEM dialed a connection named Broadband Connection 2 which has failed. The error code returned on failure is 651.
           
          Error: (04/10/2016 03:38:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
          Description: The program LiveComm.exe version 17.5.9600.20911 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
           
          Process ID: 1770
           
          Start Time: 01d18b6c652c3ed9
           
          Termination Time: 4294967295
           
          Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe
           
          Report Id: 5cf72444-fede-11e5-826f-1008b127f26c
           
          Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe
           
          Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1
           
          Error: (03/31/2016 02:12:47 PM) (Source: RasClient) (EventID: 20227) (User: )
          Description: CoId={B0680815-F8BA-4BF1-ACB0-0FEE35F050B7}: The user SYSTEM dialed a connection named Broadband Connection which has failed. The error code returned on failure is 651.
           
           
          System errors:
          =============
          Error: (04/22/2016 08:53:18 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
          Description: A corruption was discovered in the file system structure on volume Acer.
           
          The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
           
          Error: (04/22/2016 08:53:18 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
          Description: A corruption was discovered in the file system structure on volume Acer.
           
          The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
           
          Error: (04/22/2016 08:53:18 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
          Description: A corruption was discovered in the file system structure on volume Acer.
           
          The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
           
          Error: (04/22/2016 08:53:18 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
          Description: A corruption was discovered in the file system structure on volume Acer.
           
          The exact nature of the corruption is unknown.  The file system structures need to be scanned online.
           
          Error: (04/22/2016 08:53:18 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
          Description: A corruption was discovered in the file system structure on volume Acer.
           
          A corruption was found in a file system index structure.  The file reference number is 0x5000000000005.  The name of the file is "\".  The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".
           
          Error: (04/22/2016 08:46:48 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
          Description: The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 1 time(s).
           
          Error: (04/22/2016 08:26:37 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
          Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Modules Installer service, but this action failed with the following error: 
          %%1056
           
          Error: (04/22/2016 08:25:04 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
          Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
          %%1056
           
          Error: (04/22/2016 08:24:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
          Description: Installation Failure: Windows failed to install the following update with error 0x800706ba: Update for Windows 8.1 for x64-based Systems (KB3140234).
           
          Error: (04/22/2016 08:24:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
          Description: Installation Failure: Windows failed to install the following update with error 0x800706ba: Update for Windows 8.1 for x64-based Systems (KB3109976).
           
           
          CodeIntegrity:
          ===================================
            Date: 2016-04-19 15:31:32.150
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2016-04-11 08:42:43.036
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2016-03-14 09:02:43.703
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2016-03-12 11:40:19.746
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2016-03-11 14:01:51.579
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2016-03-01 13:08:30.215
            Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvinitx.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
           
          ==================== Memory info =========================== 
           
          Processor: Intel(R) Core(TM) i5-4210U CPU @ 1.70GHz
          Percentage of memory in use: 23%
          Total physical RAM: 8115.27 MB
          Available physical RAM: 6175.44 MB
          Total Virtual: 16307.27 MB
          Available Virtual: 14088.93 MB
           
          ==================== Drives ================================
           
          Drive c: (Acer) (Fixed) (Total:915.07 GB) (Free:848.89 GB) NTFS
           
          ==================== MBR & Partition Table ==================
           
          ========================================================
          Disk: 0 (Size: 931.5 GB) (Disk ID: 204DDE3E)
           
          Partition: GPT.
           
          ==================== End of Addition.txt ============================
           
          Did you see Mindspark in one of the logs or do you just know it is one of the many culprits. I always tell people to look out for "extras" like that (eg, Java updates always offer the Google Toolbar - not so bad but you should be wanting it rather than have it foisted on you).

           

          Look forward to your next post.

          Just a few leftovers to remove but before I post the fix look at these

           

          Might want to uninstall this

          Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Pokki) (Version: 0.269.2.471 - Pokki)

           

          Spotify, this is up to you if you want to keep it or not, this can be uninstalled also if you wish

           

          https://www.slimwareutilities.com/community/info.php?id=373678&type=startup

           

           

          Let me know about Spotify if you uninstalled it or not

          Hi Ken545,

           

          I've uninstalled Spotify through Control Panel.

           

          I don't know how to uninstall Pokki Start Menu now that it was uninstalled through Control Panel and n longer shows there.

           

          Regedit shows numerous occurrences of Pokki and quite a few of Spotify still.

           

          I could not see any processes in Task Manager that were obviously related to Pokki and Spotify.

           

          Have you any advice on how this can be cleaned now? (In retrospect, maybe I should have used Revo Uninstaller to uninstall them; it seems to make a better job of cleaning the registry after an uninstall.)

           

          I look forward to your advice.

          Revo is great, it removes more from a program than windows does

           

           

           

           
          Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
          Please copy the entire contents Inside of the code box below beginning with START and ending with END
          (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
          Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
           
          Start
          CloseProcesses:
          CreateRestorePoint: 
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\RunOnce: [Application Restart #1] => C:\Users\Valda\AppData\Local\Pokki\Engine\HostAppService.exe  –disable-internal-flash –noerrdialogs –no-message-box –disable-extensions –disable-web-security –disable-web-resources –disable-cli (the data entry has 549 more characters)
          SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
          SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Pokki) (Version: 0.269.2.471 - Pokki)
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-09-20] (Spotify Ltd)
          CHR DefaultSearchURL: Default -> hxxps://secure.homepage-web.com/?partner=acer&src=omnibox&q={searchTerms}
          CHR DefaultSearchKeyword: Default -> homepage-web.com
          CHR DefaultSuggestURL: Default -> hxxps://secure-suggest.homepage-web.com/suggest?format=json&locale={language}&q={searchTerms}
          FirewallRules: [{84AFACB1-02D8-40B7-8521-3B49310D4AA5}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
          FirewallRules: [{F9DD3586-975D-4006-A6F8-A3D79BCDA2CC}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
          FirewallRules: [{E08D6C5B-3A13-416B-9C86-3A1656E8A1DD}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
          FirewallRules: [{07E6C917-528E-4A12-A000-DA0B5272ADAB}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
          Hosts:
          CMD: ipconfig /flushdns
          EmptyTemp:
          End
          
           
          NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

          Done, Ken545. Here is the fixlog:

           

          Fix result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
          Ran by [removed] (2016-04-22 22:36:14) Run:1
          Running from C:\Users\[removed]\Desktop
          [removed]
          Boot Mode: Normal
          ==============================================
           
          fixlist content:
          *****************
          Start
          CloseProcesses:
          CreateRestorePoint: 
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\RunOnce: [Application Restart #1] => C:\Users\Valda\AppData\Local\Pokki\Engine\HostAppService.exe  –disable-internal-flash –noerrdialogs –no-message-box –disable-extensions –disable-web-security –disable-web-resources –disable-cli (the data entry has 549 more characters)
          SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
          SearchScopes: HKU\S-1-5-21-974442171-2668444937-4057906661-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
          Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Pokki) (Version: 0.269.2.471 - Pokki)
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\…\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-09-20] (Spotify Ltd)
          CHR DefaultSearchURL: Default -> hxxps://secure.homepage-web.com/?partner=acer&src=omnibox&q={searchTerms}
          CHR DefaultSearchKeyword: Default -> homepage-web.com
          CHR DefaultSuggestURL: Default -> hxxps://secure-suggest.homepage-web.com/suggest?format=json&locale={language}&q={searchTerms}
          FirewallRules: [{84AFACB1-02D8-40B7-8521-3B49310D4AA5}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
          FirewallRules: [{F9DD3586-975D-4006-A6F8-A3D79BCDA2CC}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
          FirewallRules: [{E08D6C5B-3A13-416B-9C86-3A1656E8A1DD}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
          FirewallRules: [{07E6C917-528E-4A12-A000-DA0B5272ADAB}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
          Hosts:
          CMD: ipconfig /flushdns
          EmptyTemp:
          End
          *****************
           
          Processes closed successfully.
          Restore point was successfully created.
          HKU\S-1-5-21-974442171-2668444937-4057906661-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Pokki => value not found.
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #1 => value removed successfully
          "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
          HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found. 
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
          Pokki Start Menu (HKU\S-1-5-21-974442171-2668444937-4057906661-1001\…\Pokki) (Version: 0.269.2.471 - Pokki) => Error: No automatic fix found for this entry.
          HKU\S-1-5-21-974442171-2668444937-4057906661-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Spotify Web Helper => value not found.
          Chrome DefaultSearchURL => removed successfully
          Chrome DefaultSearchKeyword => removed successfully
          Chrome DefaultSuggestURL => removed successfully
          HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{84AFACB1-02D8-40B7-8521-3B49310D4AA5} => value removed successfully
          HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F9DD3586-975D-4006-A6F8-A3D79BCDA2CC} => value removed successfully
          HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E08D6C5B-3A13-416B-9C86-3A1656E8A1DD} => value removed successfully
          HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{07E6C917-528E-4A12-A000-DA0B5272ADAB} => value removed successfully
          C:\Windows\System32\Drivers\etc\hosts => moved successfully
          Hosts restored successfully.
           
          =========  ipconfig /flushdns =========
           
           
          Windows IP Configuration
           
          Successfully flushed the DNS Resolver Cache.
           
          ========= End of CMD: =========
           
          EmptyTemp: => 1.9 GB temporary data Removed.
           
           
          The system needed a reboot.
           
          ==== End of Fixlog 22:37:11 ====
           
          What's next?

          Here ya go

           

          Double click on AdwCleaner.exe to run the tool again.
          • Click on the Uninstall button.
          • Click Yes when asked are you sure you want to uninstall.
          • Both AdwCleaner.exe, its folder and all logs will be removed.
          •  
             
            ==========================================================
             
             
            Please download DelFix and save the file to your Desktop.
             
            [external image: DelFix_zps139e2ea1.jpg]
             
            • Windows XP Double Click DelFix.exe to run the program. 
            • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
            • Checkmark " Remove Disinfection Tools"
            • Click the Run button
            •  
              This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
               
               
               
               
               
              Please run this free online virus scanner from ESET 
                   
              • Note: It will run using Internet Explorer, Firefox or Chome.
              •    
              • Tick the box next to YES, I accept the Terms of Use.
              •    
              • Click Start
              •    
              • When asked, allow the activex control to install
              •    
              • Click Start
              •    
              • Make sure that the option Remove found threats is NOT TICKED, and the option Scan unwanted applications is checked
              •    
              • Click Scan
              •    
              • Wait for the scan to finish
              •    
              • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
              •    
              • Copy and paste that log as a reply to this topic
              • Hi Ken545,

                 

                Done the utility clean-up.

                 

                Completed the ESET online scan; here is the log:

                 

                ESETSmartInstaller@High as downloader log:
                all ok
                # product=EOS
                # version=8
                # OnlineScannerApp.exe=1.0.0.1
                # EOSSerial=39c3f609c195d3468921950e9d4945e3
                # end=init
                # utc_time=2016-04-22 01:14:12
                # local_time=2016-04-22 11:14:12 (+1000, AUS Eastern Standard Time)
                # country="Australia"
                # osver=6.2.9200 NT 
                Update Init
                Update Download
                Update Finalize
                Updated modules version: 29191
                # product=EOS
                # version=8
                # OnlineScannerApp.exe=1.0.0.1
                # EOSSerial=39c3f609c195d3468921950e9d4945e3
                # end=updated
                # utc_time=2016-04-22 01:18:49
                # local_time=2016-04-22 11:18:49 (+1000, AUS Eastern Standard Time)
                # country="Australia"
                # osver=6.2.9200 NT 
                # product=EOS
                # version=8
                # OnlineScannerApp.exe=1.0.0.1
                # OnlineScanner.ocx=1.0.0.7777
                # api_version=3.1.1
                # EOSSerial=39c3f609c195d3468921950e9d4945e3
                # engine=29191
                # end=finished
                # remove_checked=false
                # archives_checked=false
                # unwanted_checked=true
                # unsafe_checked=false
                # antistealth_checked=true
                # utc_time=2016-04-22 02:29:15
                # local_time=2016-04-23 12:29:15 (+1000, AUS Eastern Standard Time)
                # country="Australia"
                # lang=1033
                # osver=6.2.9200 NT 
                # compatibility_mode_1=''
                # compatibility_mode=5893 16776574 100 94 62763 25128525 0 0
                # scanned=277154
                # found=4
                # cleaned=0
                # scan_time=4225
                sh=3ECA0775261CEE69E3CF81BEBB1B17D56815BBE6 ft=1 fh=35dff886860ce388 vn="a variant of Win32/AdInstaller potentially unwanted application" ac=I fn="C:\Users\Valda\Downloads\MyFunCards.exe"
                sh=E25F8F3B9C0138F041F1A56808285679F9ED4146 ft=1 fh=a222460cd2793cde vn="a variant of Win32/InstallCore.ACZ potentially unwanted application" ac=I fn="C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\G9GH6Q3R\Spotify Download Manager.exe"
                sh=75216B08B1C3480CB499B0DBEC9F13ECC9BE166E ft=1 fh=c5cdbb09ddabdf7c vn="a variant of Win32/AdInstaller potentially unwanted application" ac=I fn="C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\JHD5LY22\MapsGalaxy.exe"
                sh=5458AB9102A2E85F586C0836055AA2FB83E3A9F0 ft=1 fh=db220e66c5a446d4 vn="a variant of Win32/SoftonicDownloader.G potentially unwanted application" ac=I fn="C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\YJSWRNNQ\SoftonicDownloader_for_online-tv.exe"
                 
                 
                Where to now?

                If you have the time run it again and this time have it remove those items

                 

                 

                Or you can also remove those with this fix

                 

                 

                 
                 
                Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
                Please copy the entire contents Inside of the code box below beginning with START and ending with END
                (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
                Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
                 
                Start
                CloseProcesses:
                CreateRestorePoint: 
                C:\Users\Valda\Downloads\MyFunCards.exe
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\G9GH6Q3R\Spotify Download Manager.exe
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\JHD5LY22\MapsGalaxy.exe
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\YJSWRNNQ\SoftonicDownloader_for_online-tv.exe
                EmptyTemp:
                End
                

                Done thanks, Ken545. Here is the Fixlog:

                 

                Fix result of Farbar Recovery Scan Tool (x64) Version:18-04-2016
                Ran by [removed] (2016-04-23 06:16:09) Run:1
                Running from C:\Users\[removed]\Desktop
                [removed]
                Boot Mode: Normal
                ==============================================
                 
                fixlist content:
                *****************
                Start
                CloseProcesses:
                CreateRestorePoint: 
                C:\Users\Valda\Downloads\MyFunCards.exe
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\G9GH6Q3R\Spotify Download Manager.exe
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\JHD5LY22\MapsGalaxy.exe
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\YJSWRNNQ\SoftonicDownloader_for_online-tv.exe
                EmptyTemp:
                End
                *****************
                 
                Processes closed successfully.
                Restore point was successfully created.
                C:\Users\Valda\Downloads\MyFunCards.exe => moved successfully
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\G9GH6Q3R\Spotify Download Manager.exe => moved successfully
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\JHD5LY22\MapsGalaxy.exe => moved successfully
                C:\Windows.old\Users\Valda\AppData\Local\Microsoft\Windows\INetCache\IE\YJSWRNNQ\SoftonicDownloader_for_online-tv.exe => moved successfully
                EmptyTemp: => 22.7 MB temporary data Removed.
                 
                 
                The system needed a reboot.
                 
                ==== End of Fixlog 06:17:03 ====
                 
                 
                I await your instructions.

                Ask AI

                AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

                Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI