This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Failures on startup and reboot and flickering screen [Solved]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone. I am having troubles with restarts and an occasionally flickering screen. Also, my Memorex thumb drive seems to have been nuked but I have not yet tried it on another computer yet so I am not completely sure. I will try it on a friends computer as soon as I can to see if it works on their computer.  Intermittently, on either a restart or a fresh boot I only get through the logon screen and then it turns black except for the cursor which still moves. I let it sit but the screen stays black. It usually takes a couple of restarts to get it going and yesterday I actually had to unplug it and remove the battery for 30 seconds to get it going. Today I have had no problems yet. Also, I have seen the screen start flickering intermittently. I am suspicious of an infection. I ran a system scan from the administrator command prompt and all of my system files are intact. All of the updates are installed with no issues. Here is my system information:

 

Antivirus / Antimalware:      Microsoft Windows Defender (up to date)

Firewall:                              Windows Firewall

Operating System:              Windows 10 Home

Manufacturer:                     Dell

Model:                                 Inspiron 15 Series 1500

Processor:                          Intel Core i3 5005U @ 2 GHz

Installed Memory:               4.00 GB

 

I have completed the scans requested and the logs are pasted below.

 

Thanks kindly for any assistance you can offer.

 

The Cat Man

 

 

____________________________________________________________________________________________________________________________________________

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2016-05-20 15:58:35

—————————–

15:58:35.592    OS Version: Windows x64 6.2.9200

15:58:35.592    Number of processors: 4 586 0x3D04

15:58:35.608    ComputerName: DESKTOP-BAU9EJM  UserName: Jack Spratt

15:58:36.590    Initialize success

15:58:36.621    VM: initialized successfully

15:58:36.621    VM: Intel CPU supported

15:58:46.995    VM: disk I/O iaStorA.sys

16:00:07.151    AVAST engine defs: 16052004

16:00:23.610    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002d

16:00:23.610    Disk 0 Vendor: TOSHIBA_MQ01ABF050 AM0P1D Size: 476940MB BusType: 11

16:00:23.798    Disk 0 MBR read successfully

16:00:23.813    Disk 0 MBR scan

16:00:23.829    Disk 0 unknown MBR code

16:00:23.829    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1

16:00:24.110    Disk 0 scanning C:\WINDOWS\system32\drivers

16:00:45.655    Service scanning

16:02:05.584    Modules scanning

16:02:05.584    Disk 0 trace - called modules:

16:02:06.131    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys iaStorA.sys hal.dll

16:02:06.131    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000e3422060]

16:02:06.131    3 CLASSPNP.SYS[fffff801cc7d7d95] -> nt!IofCallDriver -> [0xffffe000e09a3190]

16:02:06.146    5 ACPI.sys[fffff801cc301361] -> nt!IofCallDriver -> [0xffffe000e09ecbd0]

16:02:06.146    7 ACPI.sys[fffff801cc301361] -> nt!IofCallDriver -> \Device\0000002d[0xffffe000df2b6400]

16:02:06.959    AVAST engine scan C:\WINDOWS

16:02:10.236    AVAST engine scan C:\WINDOWS\system32

16:08:16.618    AVAST engine scan C:\WINDOWS\system32\drivers

16:08:49.993    AVAST engine scan C:\Users\Jack Spratt

16:52:40.525    AVAST engine scan C:\ProgramData

16:55:53.554    Disk 0 statistics 5226292/0/0 @ 289.66 MB/s

16:55:53.585    Scan finished successfully

16:56:22.882    Disk 0 MBR has been saved successfully to "C:\Users\Jack Spratt\Desktop\MBR.dat"

16:56:22.898    The log file has been saved successfully to "C:\Users\Jack Spratt\Desktop\aswMBR log 1.txt"

 

 

 

 

____________________________________________________________________________________________________________________________________________

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:25-04-2016

Ran by [removed] (administrator) on DESKTOP-BAU9EJM (20-05-2016 16:58:34)

Running from C:\Users\[removed]\Desktop

[removed]

Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe

(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe

(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe

(Nalpeiron Ltd.) C:\Windows\SysWOW64\NlsSrv32.exe

(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe

(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe

() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe

(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe

(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe

(Microsoft Corporation) C:\Windows\System32\wlanext.exe

(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe

() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\igfxEM.exe

(Intel Corporation) C:\Windows\System32\igfxHK.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe

(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

(Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe

(CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe

() C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe

(Dell) C:\Program Files\Dell\Product Registration\PRSvc.exe

(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe

(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe

(Dell) C:\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe

(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe

(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe

(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe

() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x64__8wekyb3d8bbwe\Calculator.exe

 

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8712960 2015-10-07] (Realtek Semiconductor)

HKLM\…\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-10-07] (Realtek Semiconductor)

HKLM\…\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [714160 2015-09-21] (Waves Audio Ltd.)

HKLM-x32\…\Run: [MediaFace Integration] => C:\Program Files (x86)\Fellowes\MediaFACE 4.0\SetHook.exe [53248 2003-08-18] (Fellowes, Inc.)

HKLM-x32\…\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [2687488 2015-09-29] (Sony Corporation)

HKLM-x32\…\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058400 2012-01-26] (SEIKO EPSON CORPORATION)

HKLM-x32\…\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [502912 2012-02-29] (SEIKO EPSON CORPORATION)

HKLM-x32\…\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [863360 2012-02-29] (SEIKO EPSON CORPORATION)

HKLM-x32\…\Run: [LTCM Client] => C:\Program Files (x86)\LTCM Client\ltcmClient.exe [1596096 2009-08-05] (Leader Technologies Inc.)

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1399208 2016-04-08] (Garmin Ltd. or its subsidiaries)

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\RunOnce: [Uninstall C:\Users\Jack Spratt\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Jack Spratt\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64"

HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1399208 2016-04-08] (Garmin Ltd. or its subsidiaries)

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] [removed] [removed]

Tcpip\..\Interfaces\{5f6f5f30-ca08-4998-8400-f00ffc2d817a}: [DhcpNameServer] [removed] [removed]

 

Internet Explorer:

==================

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE

SearchScopes: HKU\S-1-5-21-2322127342-2752091441-2421920365-1001 -> DefaultScope {D1C9A910-F54D-4EB5-ABA2-F1B75BFDD091} URL =

SearchScopes: HKU\S-1-5-21-2322127342-2752091441-2421920365-1001 -> {D1C9A910-F54D-4EB5-ABA2-F1B75BFDD091} URL =

DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab

 

FireFox:

========

FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1220162.dll [2015-08-31] (Adobe Systems, Inc.)

FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)

FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)

FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)

 

==================== Services (Whitelisted) ========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)

R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [119656 2016-01-15] (Dell)

R2 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [87888 2016-05-03] ()

R2 Dell Product Registration; C:\Program Files\Dell\Product Registration\PRSvc.exe [32104 2016-01-25] (Dell)

R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.)

R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)

S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [792592 2016-04-08] (Garmin Ltd. or its subsidiaries)

R2 ibtsiva; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [150256 2015-06-09] (Intel Corporation)

R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [353896 2015-11-16] (Intel Corporation)

S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)

R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]

S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]

R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation)

S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-06-12] ()

R2 nlsX86cc; C:\Windows\SysWOW64\NlsSrv32.exe [66560 2012-08-24] (Nalpeiron Ltd.) [File not signed]

R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [496128 2015-09-29] (Sony Corporation)

R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2014-04-14] ()

R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [307456 2015-10-07] (Realtek Semiconductor)

R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [566192 2015-08-19] (Waves Audio Ltd.)

R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)

R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831200 2015-06-12] (Intel® Corporation)

 

===================== Drivers (Whitelisted) ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)

R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [19440 2015-05-08] (OSR Open Systems Resources, Inc.)

S3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [46856 2015-06-15] (Intel Corporation)

S3 iaLPSS_SPI; C:\Windows\System32\drivers\iaLPSS_SPI.sys [113416 2015-06-15] (Intel Corporation)

S3 iaLPSS_UART2; C:\Windows\System32\drivers\iaLPSS_UART2.sys [155400 2015-06-15] (Intel Corporation)

R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [263952 2016-01-09] (Intel Corporation)

R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [183584 2015-06-12] (Intel Corporation)

R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3776792 2015-06-22] (Intel Corporation)

R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek                                            )

R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402960 2016-01-09] (Realsil Semiconductor Corporation)

S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)

R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)

R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

R3 WirelessKeyboardFilter; C:\Windows\System32\drivers\WirelessKeyboardFilter.sys [49384 2016-03-29] (Microsoft Corporation)

U3 aswMBR; C:\Users\Jack Spratt\AppData\Local\Temp\aswMBR.sys [62728 2016-04-26] () [File not signed]

U3 aswVmm; C:\Users\Jack Spratt\AppData\Local\Temp\aswVmm.sys [224896 2016-04-26] ()

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-05-20 16:58 - 2016-05-20 16:59 - 00013730 _____ C:\Users\Jack Spratt\Desktop\FRST.txt

2016-05-20 16:57 - 2016-05-20 16:58 - 00000000 ____D C:\FRST

2016-05-20 16:56 - 2016-05-20 16:56 - 00002101 _____ C:\Users\Jack Spratt\Desktop\aswMBR log 1.txt

2016-05-20 16:56 - 2016-05-20 16:56 - 00000512 _____ C:\Users\Jack Spratt\Desktop\MBR 1.dat

2016-05-19 20:59 - 2016-05-19 20:59 - 00000000 ____D C:\Users\Jack Spratt\Desktop\Lisas Files

2016-05-15 20:37 - 2016-05-15 20:37 - 00000000 ____D C:\Users\Public\Documents\CyberLink

2016-05-15 20:37 - 2016-05-15 20:37 - 00000000 ____D C:\Users\Jack Spratt\AppData\Roaming\CyberLink

2016-05-12 00:13 - 2016-04-23 00:31 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll

2016-05-12 00:13 - 2016-04-23 00:30 - 22379008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll

2016-05-12 00:13 - 2016-04-23 00:28 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll

2016-05-12 00:13 - 2016-04-23 00:26 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll

2016-05-12 00:13 - 2016-04-23 00:25 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll

2016-05-12 00:13 - 2016-04-23 00:22 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll

2016-05-12 00:13 - 2016-04-23 00:20 - 19344384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll

2016-05-12 00:13 - 2016-04-23 00:19 - 07977472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll

2016-05-12 00:13 - 2016-04-23 00:19 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll

2016-05-12 00:13 - 2016-04-23 00:19 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll

2016-05-12 00:13 - 2016-04-23 00:19 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll

2016-05-12 00:13 - 2016-04-23 00:18 - 24604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll

2016-05-12 00:13 - 2016-04-23 00:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll

2016-05-12 00:13 - 2016-04-23 00:18 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll

2016-05-12 00:13 - 2016-04-23 00:18 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll

2016-05-12 00:13 - 2016-04-23 00:16 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll

2016-05-12 00:13 - 2016-04-23 00:15 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll

2016-05-12 00:13 - 2016-04-23 00:15 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll

2016-05-12 00:13 - 2016-04-23 00:14 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll

2016-05-12 00:13 - 2016-04-23 00:13 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll

2016-05-12 00:13 - 2016-04-23 00:13 - 06295552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll

2016-05-12 00:13 - 2016-04-23 00:09 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll

2016-05-12 00:13 - 2016-04-23 00:08 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll

2016-05-12 00:13 - 2016-04-23 00:07 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll

2016-05-12 00:12 - 2016-04-30 02:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys

2016-05-12 00:12 - 2016-04-30 02:31 - 03591168 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys

2016-05-12 00:12 - 2016-04-23 02:12 - 01401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll

2016-05-12 00:12 - 2016-04-23 02:12 - 01184960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll

2016-05-12 00:12 - 2016-04-23 02:12 - 00713920 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll

2016-05-12 00:12 - 2016-04-23 02:12 - 00514752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll

2016-05-12 00:12 - 2016-04-23 02:12 - 00294592 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll

2016-05-12 00:12 - 2016-04-23 02:12 - 00190144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe

2016-05-12 00:12 - 2016-04-23 02:12 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe

2016-05-12 00:12 - 2016-04-23 01:28 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll

2016-05-12 00:12 - 2016-04-23 01:28 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll

2016-05-12 00:12 - 2016-04-23 01:24 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe

2016-05-12 00:12 - 2016-04-23 01:24 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll

2016-05-12 00:12 - 2016-04-23 01:24 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll

2016-05-12 00:12 - 2016-04-23 01:24 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll

2016-05-12 00:12 - 2016-04-23 01:12 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll

2016-05-12 00:12 - 2016-04-23 01:12 - 00451928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll

2016-05-12 00:12 - 2016-04-23 01:12 - 00413536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe

2016-05-12 00:12 - 2016-04-23 01:11 - 01092464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll

2016-05-12 00:12 - 2016-04-23 01:11 - 00498960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll

2016-05-12 00:12 - 2016-04-23 01:10 - 03673424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll

2016-05-12 00:12 - 2016-04-23 01:10 - 02919832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll

2016-05-12 00:12 - 2016-04-23 01:09 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll

2016-05-12 00:12 - 2016-04-23 01:09 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll

2016-05-12 00:12 - 2016-04-23 01:09 - 05240960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll

2016-05-12 00:12 - 2016-04-23 01:09 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe

2016-05-12 00:12 - 2016-04-23 01:09 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe

2016-05-12 00:12 - 2016-04-23 01:09 - 00255168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe

2016-05-12 00:12 - 2016-04-23 01:08 - 06605504 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll

2016-05-12 00:12 - 2016-04-23 01:08 - 04515256 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe

2016-05-12 00:12 - 2016-04-23 01:08 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll

2016-05-12 00:12 - 2016-04-23 01:07 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll

2016-05-12 00:12 - 2016-04-23 01:07 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll

2016-05-12 00:12 - 2016-04-23 01:02 - 00188256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll

2016-05-12 00:12 - 2016-04-23 01:01 - 01996640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys

2016-05-12 00:12 - 2016-04-23 01:01 - 00650304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll

2016-05-12 00:12 - 2016-04-23 01:01 - 00577368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys

2016-05-12 00:12 - 2016-04-23 01:01 - 00522176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll

2016-05-12 00:12 - 2016-04-23 01:01 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys

2016-05-12 00:12 - 2016-04-23 01:00 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll

2016-05-12 00:12 - 2016-04-23 01:00 - 01594920 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll

2016-05-12 00:12 - 2016-04-23 01:00 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll

2016-05-12 00:12 - 2016-04-23 01:00 - 01372304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll

2016-05-12 00:12 - 2016-04-23 00:56 - 00534872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS

2016-05-12 00:12 - 2016-04-23 00:39 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll

2016-05-12 00:12 - 2016-04-23 00:32 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll

2016-05-12 00:12 - 2016-04-23 00:31 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll

2016-05-12 00:12 - 2016-04-23 00:30 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll

2016-05-12 00:12 - 2016-04-23 00:29 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll

2016-05-12 00:12 - 2016-04-23 00:26 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll

2016-05-12 00:12 - 2016-04-23 00:25 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll

2016-05-12 00:12 - 2016-04-23 00:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll

2016-05-12 00:12 - 2016-04-23 00:24 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll

2016-05-12 00:12 - 2016-04-23 00:24 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll

2016-05-12 00:12 - 2016-04-23 00:23 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll

2016-05-12 00:12 - 2016-04-23 00:22 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll

2016-05-12 00:12 - 2016-04-23 00:21 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll

2016-05-12 00:12 - 2016-04-23 00:21 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll

2016-05-12 00:12 - 2016-04-23 00:20 - 18676224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll

2016-05-12 00:12 - 2016-04-23 00:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll

2016-05-12 00:12 - 2016-04-23 00:20 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll

2016-05-12 00:12 - 2016-04-23 00:20 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll

2016-05-12 00:12 - 2016-04-23 00:19 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll

2016-05-12 00:12 - 2016-04-23 00:18 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys

2016-05-12 00:12 - 2016-04-23 00:18 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll

2016-05-12 00:12 - 2016-04-23 00:18 - 00804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll

2016-05-12 00:12 - 2016-04-23 00:18 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll

2016-05-12 00:12 - 2016-04-23 00:18 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe

2016-05-12 00:12 - 2016-04-23 00:18 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll

2016-05-12 00:12 - 2016-04-23 00:17 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll

2016-05-12 00:12 - 2016-04-23 00:17 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll

2016-05-12 00:12 - 2016-04-23 00:17 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll

2016-05-12 00:12 - 2016-04-23 00:16 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll

2016-05-12 00:12 - 2016-04-23 00:16 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll

2016-05-12 00:12 - 2016-04-23 00:15 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll

2016-05-12 00:12 - 2016-04-23 00:15 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll

2016-05-12 00:12 - 2016-04-23 00:15 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll

2016-05-12 00:12 - 2016-04-23 00:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll

2016-05-12 00:12 - 2016-04-23 00:14 - 13383168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll

2016-05-12 00:12 - 2016-04-23 00:14 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll

2016-05-12 00:12 - 2016-04-23 00:14 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll

2016-05-12 00:12 - 2016-04-23 00:14 - 00647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll

2016-05-12 00:12 - 2016-04-23 00:14 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll

2016-05-12 00:12 - 2016-04-23 00:14 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll

2016-05-12 00:12 - 2016-04-23 00:13 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll

2016-05-12 00:12 - 2016-04-23 00:13 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll

2016-05-12 00:12 - 2016-04-23 00:13 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll

2016-05-12 00:12 - 2016-04-23 00:10 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll

2016-05-12 00:12 - 2016-04-23 00:10 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll

2016-05-12 00:12 - 2016-04-23 00:09 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll

2016-05-12 00:12 - 2016-04-23 00:08 - 05324288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll

2016-05-12 00:12 - 2016-04-23 00:07 - 02598912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll

2016-05-12 00:12 - 2016-04-23 00:07 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll

2016-05-12 00:12 - 2016-04-23 00:06 - 06974464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll

2016-05-12 00:12 - 2016-04-23 00:05 - 05502976 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll

2016-05-12 00:12 - 2016-04-23 00:05 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll

2016-05-12 00:12 - 2016-04-23 00:05 - 02066432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll

2016-05-12 00:12 - 2016-04-23 00:05 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll

2016-05-12 00:12 - 2016-04-23 00:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll

2016-05-12 00:12 - 2016-04-23 00:05 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll

2016-05-12 00:12 - 2016-04-23 00:04 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll

2016-05-12 00:12 - 2016-04-23 00:04 - 01731072 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll

2016-05-12 00:12 - 2016-04-23 00:03 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll

2016-05-12 00:12 - 2016-04-23 00:03 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll

2016-05-12 00:12 - 2016-04-23 00:03 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll

2016-05-12 00:12 - 2016-04-23 00:03 - 02000896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll

2016-05-12 00:12 - 2016-04-23 00:03 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll

2016-05-12 00:12 - 2016-04-23 00:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll

2016-05-12 00:12 - 2016-04-23 00:02 - 07832576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll

2016-05-12 00:12 - 2016-04-23 00:02 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll

2016-05-12 00:12 - 2016-04-23 00:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll

2016-05-12 00:12 - 2016-04-23 00:00 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll

2016-05-12 00:12 - 2016-04-22 22:10 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll

2016-05-12 00:11 - 2016-05-06 00:53 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdport.sys

2016-05-12 00:11 - 2016-05-06 00:05 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll

2016-05-12 00:11 - 2016-05-06 00:03 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll

2016-05-12 00:11 - 2016-05-05 23:53 - 00351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll

2016-05-12 00:11 - 2016-05-05 23:49 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll

2016-05-12 00:11 - 2016-05-05 23:44 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll

2016-05-12 00:11 - 2016-05-05 23:43 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll

2016-05-12 00:11 - 2016-05-05 23:23 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll

2016-05-12 00:11 - 2016-04-23 02:12 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll

2016-05-12 00:11 - 2016-04-23 01:26 - 00707608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll

2016-05-12 00:11 - 2016-04-23 01:24 - 00638816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys

2016-05-12 00:11 - 2016-04-23 01:24 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys

2016-05-12 00:11 - 2016-04-23 01:24 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys

2016-05-12 00:11 - 2016-04-23 01:22 - 01161120 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll

2016-05-12 00:11 - 2016-04-23 01:18 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe

2016-05-12 00:11 - 2016-04-23 01:13 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll

2016-05-12 00:11 - 2016-04-23 01:13 - 00306832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll

2016-05-12 00:11 - 2016-04-23 01:13 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll

2016-05-12 00:11 - 2016-04-23 01:11 - 00696672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll

2016-05-12 00:11 - 2016-04-23 01:11 - 00390496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll

2016-05-12 00:11 - 2016-04-23 01:11 - 00131424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufxsynopsys.sys

2016-05-12 00:11 - 2016-04-23 01:11 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll

2016-05-12 00:11 - 2016-04-23 01:10 - 00330072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys

2016-05-12 00:11 - 2016-04-23 01:09 - 00569744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll

2016-05-12 00:11 - 2016-04-23 01:09 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe

2016-05-12 00:11 - 2016-04-23 01:09 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe

2016-05-12 00:11 - 2016-04-23 01:07 - 00204048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll

2016-05-12 00:11 - 2016-04-23 01:07 - 00183904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll

2016-05-12 00:11 - 2016-04-23 01:06 - 00291360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe

2016-05-12 00:11 - 2016-04-23 01:01 - 00619296 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll

2016-05-12 00:11 - 2016-04-23 01:01 - 00513368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll

2016-05-12 00:11 - 2016-04-23 01:01 - 00217440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll

2016-05-12 00:11 - 2016-04-23 01:00 - 01522152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll

2016-05-12 00:11 - 2016-04-23 01:00 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll

2016-05-12 00:11 - 2016-04-23 01:00 - 00550656 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll

2016-05-12 00:11 - 2016-04-23 01:00 - 00453472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll

2016-05-12 00:11 - 2016-04-23 01:00 - 00058208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwminit.dll

2016-05-12 00:11 - 2016-04-23 00:35 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll

2016-05-12 00:11 - 2016-04-23 00:34 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys

2016-05-12 00:11 - 2016-04-23 00:34 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll

2016-05-12 00:11 - 2016-04-23 00:34 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll

2016-05-12 00:11 - 2016-04-23 00:33 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll

2016-05-12 00:11 - 2016-04-23 00:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll

2016-05-12 00:11 - 2016-04-23 00:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys

2016-05-12 00:11 - 2016-04-23 00:33 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe

2016-05-12 00:11 - 2016-04-23 00:32 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll

2016-05-12 00:11 - 2016-04-23 00:32 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll

2016-05-12 00:11 - 2016-04-23 00:30 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll

2016-05-12 00:11 - 2016-04-23 00:29 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll

2016-05-12 00:11 - 2016-04-23 00:29 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll

2016-05-12 00:11 - 2016-04-23 00:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\filecrypt.sys

2016-05-12 00:11 - 2016-04-23 00:29 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe

2016-05-12 00:11 - 2016-04-23 00:29 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll

2016-05-12 00:11 - 2016-04-23 00:29 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe

2016-05-12 00:11 - 2016-04-23 00:29 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll

2016-05-12 00:11 - 2016-04-23 00:28 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll

2016-05-12 00:11 - 2016-04-23 00:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll

2016-05-12 00:11 - 2016-04-23 00:28 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll

2016-05-12 00:11 - 2016-04-23 00:28 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll

2016-05-12 00:11 - 2016-04-23 00:28 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll

2016-05-12 00:11 - 2016-04-23 00:27 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys

2016-05-12 00:11 - 2016-04-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll

2016-05-12 00:11 - 2016-04-23 00:26 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll

2016-05-12 00:11 - 2016-04-23 00:25 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll

2016-05-12 00:11 - 2016-04-23 00:25 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll

2016-05-12 00:11 - 2016-04-23 00:25 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll

2016-05-12 00:11 - 2016-04-23 00:24 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll

2016-05-12 00:11 - 2016-04-23 00:24 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll

2016-05-12 00:11 - 2016-04-23 00:24 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll

2016-05-12 00:11 - 2016-04-23 00:24 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll

2016-05-12 00:11 - 2016-04-23 00:23 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe

2016-05-12 00:11 - 2016-04-23 00:23 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll

2016-05-12 00:11 - 2016-04-23 00:23 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll

2016-05-12 00:11 - 2016-04-23 00:23 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll

2016-05-12 00:11 - 2016-04-23 00:22 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll

2016-05-12 00:11 - 2016-04-23 00:20 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll

2016-05-12 00:11 - 2016-04-23 00:20 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll

2016-05-12 00:11 - 2016-04-23 00:20 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll

2016-05-12 00:11 - 2016-04-23 00:19 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll

2016-05-12 00:11 - 2016-04-23 00:19 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll

2016-05-12 00:11 - 2016-04-23 00:18 - 00988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll

2016-05-12 00:11 - 2016-04-23 00:18 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll

2016-05-12 00:11 - 2016-04-23 00:18 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll

2016-05-12 00:11 - 2016-04-23 00:18 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll

2016-05-12 00:11 - 2016-04-23 00:18 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS

2016-05-12 00:11 - 2016-04-23 00:17 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll

2016-05-12 00:11 - 2016-04-23 00:15 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll

2016-05-12 00:11 - 2016-04-23 00:14 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll

2016-05-12 00:11 - 2016-04-23 00:12 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll

2016-05-12 00:11 - 2016-04-23 00:07 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll

2016-05-12 00:11 - 2016-04-23 00:05 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll

2016-05-12 00:11 - 2016-04-23 00:05 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll

2016-05-12 00:11 - 2016-04-23 00:03 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll

2016-05-12 00:11 - 2016-04-23 00:01 - 04775424 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll

2016-05-12 00:11 - 2016-04-22 23:45 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll

2016-05-12 00:11 - 2016-04-22 22:10 - 00002186 _____ C:\WINDOWS\system32\AppxProvisioning.xml

2016-05-12 00:11 - 2016-04-18 18:30 - 00002186 _____ C:\WINDOWS\SysWOW64\AppxProvisioning.xml

2016-05-05 22:27 - 2016-05-05 22:25 - 00238891 _____ C:\Users\Jack Spratt\Desktop\Animal Lovers Only.pdf

2016-05-05 22:25 - 2016-05-05 22:25 - 00238891 _____ C:\Users\Jack Spratt\Documents\Animal Lovers Only.pdf

2016-04-26 22:57 - 2016-05-20 16:57 - 02376192 _____ (Farbar) C:\Users\Jack Spratt\Desktop\FRST64.exe

2016-04-26 22:55 - 2016-04-26 22:55 - 05198336 _____ (AVAST Software) C:\Users\Jack Spratt\Desktop\aswMBR.exe

2016-04-26 15:04 - 2016-04-26 15:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin

2016-04-21 13:30 - 2016-04-21 13:31 - 00000000 ____D C:\Users\Jack Spratt\Desktop\Boston CD

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-05-20 16:33 - 2015-10-05 19:05 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

2016-05-20 14:30 - 2015-10-30 03:21 - 00000000 ____D C:\WINDOWS\INF

2016-05-20 14:30 - 2015-08-10 23:55 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI

2016-05-20 14:27 - 2016-01-31 13:17 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat

2016-05-20 14:27 - 2015-10-05 19:05 - 00000934 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

2016-05-20 14:27 - 2015-10-05 14:58 - 00000000 __SHD C:\Users\Jack Spratt\IntelGraphicsProfiles

2016-05-20 14:25 - 2016-01-31 13:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT

2016-05-20 14:24 - 2015-10-30 02:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI

2016-05-20 10:38 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\AppReadiness

2016-05-20 10:33 - 2015-10-30 03:24 - 00000000 ___HD C:\Program Files\WindowsApps

2016-05-19 20:55 - 2016-02-24 19:07 - 00000168 _____ C:\WINDOWS\SysWOW64\DLC_Debug_log.txt

2016-05-19 20:55 - 2015-08-11 00:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell

2016-05-19 20:55 - 2015-08-11 00:09 - 00000000 ____D C:\Program Files\Dell

2016-05-19 20:55 - 2015-08-10 23:59 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2016-05-19 17:34 - 2015-10-05 16:51 - 00000000 ____D C:\Users\Jack Spratt\AppData\Local\ElevatedDiagnostics

2016-05-19 12:27 - 2016-02-13 15:39 - 00000000 ____D C:\Users\Jack Spratt\Desktop\The Book I'm Writing

2016-05-17 16:54 - 2015-08-10 23:59 - 00000000 ____D C:\ProgramData\CyberLink

2016-05-15 20:41 - 2016-01-31 13:21 - 00000000 ____D C:\Users\Jack Spratt

2016-05-15 19:36 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp

2016-05-15 15:12 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\rescache

2016-05-13 19:18 - 2015-10-30 03:11 - 00000000 ____D C:\WINDOWS\CbsTemp

2016-05-13 19:12 - 2015-08-11 00:34 - 00000000 __RHD C:\Users\Public\AccountPictures

2016-05-13 19:01 - 2015-10-30 05:07 - 00000000 ____D C:\Program Files\Windows Journal

2016-05-13 19:01 - 2015-10-30 03:24 - 00015703 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml

2016-05-13 19:01 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\oobe

2016-05-13 19:01 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\appraiser

2016-05-13 19:01 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\Provisioning

2016-05-13 19:01 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\bcastdvr

2016-05-12 21:07 - 2015-10-05 15:38 - 00000000 ____D C:\WINDOWS\system32\MRT

2016-05-12 21:02 - 2015-10-05 15:38 - 139319312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

2016-05-11 15:57 - 2015-10-30 03:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe

2016-05-11 15:57 - 2015-10-30 03:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

2016-05-11 10:35 - 2015-10-05 16:15 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task

2016-05-11 10:35 - 2015-10-05 16:15 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk

2016-05-10 18:28 - 2015-10-05 19:05 - 00003996 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA

2016-05-10 18:28 - 2015-10-05 19:05 - 00003764 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore

2016-05-09 15:30 - 2015-10-05 20:23 - 00000000 ____D C:\Users\Jack Spratt\Desktop\Rich's Emergency Information

2016-05-03 17:45 - 2015-12-19 19:27 - 00000000 ____D C:\Users\Jack Spratt\Desktop\Health information

2016-05-02 17:17 - 2015-10-05 14:58 - 00000000 ____D C:\Users\Jack Spratt\AppData\Local\Packages

2016-04-26 21:07 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files

2016-04-26 17:06 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\NDF

2016-04-26 15:05 - 2015-08-11 00:03 - 00000000 ____D C:\ProgramData\Package Cache

2016-04-26 15:04 - 2016-03-20 20:53 - 00003624 _____ C:\WINDOWS\System32\Tasks\GarminUpdaterTask

2016-04-26 15:04 - 2015-10-05 19:04 - 00000000 ____D C:\Program Files (x86)\Garmin

2016-04-25 13:28 - 2015-10-05 15:33 - 00000000 ___HD C:\$SysReset

2016-04-22 03:57 - 2015-10-05 15:27 - 00453288 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

 

==================== Files in the root of some directories =======

 

2008-03-24 09:47 - 2008-06-13 10:26 - 0000012 _____ () C:\Users\Jack Spratt\AppData\Roaming\userdic.tlx

2016-01-31 13:18 - 2016-01-31 13:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

2015-10-05 16:52 - 2016-02-01 23:38 - 0000629 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2015-08-11 00:04 - 2015-08-11 00:04 - 0000121 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log

2015-08-10 23:59 - 2015-08-11 00:00 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log

2015-08-11 00:02 - 2015-08-11 00:04 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log

2015-08-11 00:00 - 2015-08-11 00:02 - 0000113 _____ () C:\ProgramData\{E1646825-D391-42A0-93AA-27FA810DA093}.log

 

==================== Bamital & volsnap =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\WINDOWS\system32\winlogon.exe => File is digitally signed

C:\WINDOWS\system32\wininit.exe => File is digitally signed

C:\WINDOWS\explorer.exe => File is digitally signed

C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed

C:\WINDOWS\system32\svchost.exe => File is digitally signed

C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed

C:\WINDOWS\system32\services.exe => File is digitally signed

C:\WINDOWS\system32\User32.dll => File is digitally signed

C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed

C:\WINDOWS\system32\userinit.exe => File is digitally signed

C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed

C:\WINDOWS\system32\rpcss.dll => File is digitally signed

C:\WINDOWS\system32\dnsapi.dll => File is digitally signed

C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed

C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

 

LastRegBack: 2016-05-13 13:43

 

==================== End of FRST.txt ============================

 

 

 

____________________________________________________________________________________________________________________________________________

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:25-04-2016

Ran by [removed] (2016-05-20 16:59:45)

Running from C:\Users\[removed]\Desktop

Windows 10 Home Version 1511 (X64) (2016-01-31 17:41:09)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-2322127342-2752091441-2421920365-500 - Administrator - Disabled)

DefaultAccount (S-1-5-21-2322127342-2752091441-2421920365-503 - Limited - Disabled)

Guest (S-1-5-21-2322127342-2752091441-2421920365-501 - Limited - Disabled)

Jack Spratt (S-1-5-21-2322127342-2752091441-2421920365-1001 - Administrator - Enabled) => C:\Users\Jack Spratt

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)

ABBYY FineReader 9.0 Sprint (HKLM-x32\…\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)

ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212 - ABBYY) Hidden

Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.016.20039 - Adobe Systems Incorporated)

Adobe Shockwave Player 12.2 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.2.0.162 - Adobe Systems, Inc.)

AnswerWorks 5.0 English Runtime (HKLM-x32\…\{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}) (Version: 5.0.7 - Vantage Software Technologies)

ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden

CyberLink Media Suite Essentials (HKLM-x32\…\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.)

D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

Dell Customer Connect (HKLM-x32\…\{99E581C6-471C-46CA-989E-3B17EB7E3F27}) (Version: 1.3.2.0 - Dell Inc.)

Dell Digital Delivery (HKLM-x32\…\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP)

Dell Foundation Services (HKLM\…\{AE5E3C86-2633-4DAF-A7F4-C43D1E738BAE}) (Version: 3.1.3300.0 - Dell Inc.)

Dell Help & Support (HKLM-x32\…\InstallShield_{32483B20-13B2-4747-9D34-15E588CE8034}) (Version: 2.1.78.0 - Dell Inc.)

Dell Help & Support (Version: 2.1.78.0 - Dell Inc.) Hidden

Dell Power Manager Lite (HKLM-x32\…\InstallShield_{BF1F9D57-57A1-4E87-A8E8-41F2B2AD6F53}) (Version: 1.0.0.3 - Compal Inc.)

Dell Power Manager Lite (x32 Version: 1.0.0.3 - Compal Inc.) Hidden

Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.10 - Dell)

Dell Update (HKLM-x32\…\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.)

DSC/AA Factory Installer (Version: 1.1.6664.10 - PC-Doctor, Inc.) Hidden

Elevated Installer (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden

EPSON Connect version 1.0 (HKLM-x32\…\EPSON Connect_is1) (Version: 1.0 - Epson America Inc.)

Epson Customer Participation (HKLM\…\{814FA673-A085-403C-9545-747FC1495069}) (Version: 1.4.0.0 - SEIKO EPSON CORPORATION)

Epson Event Manager (HKLM-x32\…\{44F72193-F59C-4303-BAE8-E3E4BC1C122C}) (Version: 3.01.0003 - Seiko Epson Corporation)

Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.30.00 - SEIKO EPSON CORPORATION)

Epson PC-FAX Driver (HKLM-x32\…\EPSON PC-FAX Driver 2) (Version:  - )

EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)

EPSON WF-2530 Series Printer Uninstall (HKLM\…\EPSON WF-2530 Series) (Version:  - SEIKO EPSON Corporation)

EpsonNet Print (HKLM-x32\…\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)

Garmin Express (HKLM-x32\…\{2639b4f0-83b4-4f3d-942f-e4ba22a40b9b}) (Version: 4.1.19.0 - Garmin Ltd or its subsidiaries)

Garmin Express (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden

Garmin Express Tray (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden

Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)

Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden

Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden

Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden

Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation)

Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4300 - Intel Corporation)

Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.253.0 - Intel Corporation)

Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{DC5673D2-228D-45BC-B9BB-9610CE67DFC0}) (Version: 17.1.1524.1353 - Intel Corporation)

Intel® PROSet/Wireless Software (HKLM-x32\…\{4544164b-edf0-455c-b150-bed7109d751e}) (Version: 18.11.0 - Intel Corporation)

Intel® Security Assist (HKLM-x32\…\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)

iSEEK AnswerWorks English Runtime (HKLM-x32\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)

Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden

LTCM Client (HKLM-x32\…\LTCM Client) (Version:  - Leader Technologies Inc.)

Maxx Audio Installer (x64) (Version: 2.6.6568.0 - Waves Audio Ltd.) Hidden

MediaFACE 4.01 (HKLM-x32\…\InstallShield_{41979C2F-34B8-4F92-8111-B13C5864682D}) (Version: 4.01 - Fellowes)

MediaFACE 4.01 (x32 Version: 4.01 - Fellowes) Hidden

MediaFACE 4.01 Image Library (HKLM-x32\…\InstallShield_{82AF77BC-423D-42DA-BE5B-FFCA04752181}) (Version: 4.01 - Fellowes)

MediaFACE 4.01 Image Library (x32 Version: 4.01 - Fellowes) Hidden

MergeModule_x86 (x32 Version: 9.3.00 - Sony Corporation) Hidden

Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)

Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)

Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden

PlayMemories Home (HKLM-x32\…\{94F4815B-755A-4FFA-AFDC-EE8FE776981E}) (Version: 5.0.02.09290 - Sony Corporation)

PMB_ModeEditor (x32 Version: 9.3.00 - Sony Corporation) Hidden

PMB_ServiceUploader (x32 Version: 10.0.02 - Sony Corporation) Hidden

Prism Video File Converter (HKLM-x32\…\Prism) (Version:  - NCH Software)

Product Registration (HKLM-x32\…\InstallShield_{C1600AC7-74E3-4BB5-8B42-B13653792252}) (Version: 2.2.38.0 - Dell Inc.)

Product Registration (Version: 2.2.38.0 - Dell Inc.) Hidden

Quicken 2009 (HKLM-x32\…\{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}) (Version: 18.1.6.25 - Intuit)

Quicken WillMaker Plus 2009 (HKLM-x32\…\Quicken WillMaker Plus 2009) (Version:  - )

Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.31213 - Realtek Semiconductor Corp.)

Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7628 - Realtek Semiconductor Corp.)

Software Updater (HKLM-x32\…\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION)

swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden

trakAxPC (HKLM-x32\…\{406550D6-0FAA-4B40-91D3-87E0BCB37482}) (Version: 4.02.4 - HighAndes)

TurboCAD Deluxe v12 (HKLM-x32\…\{2902BA57-1BB3-4EC6-91FB-8480F47FDA81}) (Version: 12.2 - IMSI)

TurboCAD Symbols (HKLM-x32\…\{40B62162-ADF5-485F-B81F-6344CB0E321B}) (Version: 12.0 - IMSI)

TurboTax 2013 (HKLM-x32\…\TurboTax 2013) (Version: 2013.0 - Intuit, Inc)

TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)

TurboTax 2015 (HKLM-x32\…\TurboTax 2015) (Version: 2015.0 - Intuit, Inc)

Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)

Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)

Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)

Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-2322127342-2752091441-2421920365-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Jack Spratt\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {1021F775-C7C7-43D4-A251-7323DF499EAD} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe

Task: {18D51B05-1A18-49F6-AD5A-517AA2BDB51E} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2016-04-08] ()

Task: {3F8C2179-79D4-4601-B10D-FB76A86D21D7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-05-12] (Microsoft Corporation)

Task: {43425CBE-F542-4E10-BC16-01782087944C} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-05-19] (PC-Doctor, Inc.)

Task: {472F3491-840B-4073-9906-CCFD5A73A6E0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-05] (Google Inc.)

Task: {531051E7-7D69-4BAB-ADD6-C9D3392919AC} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [2015-01-28] (CyberLink Corp.)

Task: {5E710194-54A1-424E-8737-DD047064E2EC} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-05-19] (PC-Doctor, Inc.)

Task: {62CE8E67-FB3A-4191-A846-A31AE5AA56C1} - System32\Tasks\UninstallDDS-C960901F-CE14-4DE1-9729-1305F719A337 => C:\Windows\TEMP\DeleteFolderTask.exe

Task: {9380F6D0-F094-4CB0-8C3F-8605D7AFDB0C} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-10-07] (Realtek Semiconductor)

Task: {A43268FB-CA5A-4084-BFFF-05D7AAD10B7F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated)

Task: {A73C458B-0702-4E26-A13C-6412D024F2D7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-05] (Google Inc.)

Task: {DE661BC8-2B4C-42CF-928C-60DE0D9C7C0F} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [2015-05-07] (CyberLink)

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\WINDOWS\Tasks\RunDLC.job => lMF cmd c sc start Dell Help Support WORKGROUP DESKTOP BAU9EJM

 

==================== Shortcuts =============================

 

(The entries could be listed to be restored or removed.)

 

==================== Loaded Modules (Whitelisted) ==============

 

2015-10-30 03:18 - 2015-10-30 03:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll

2015-08-11 00:02 - 2014-04-14 21:59 - 00253776 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

2016-04-12 21:41 - 2016-03-29 06:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll

2016-04-12 21:41 - 2016-03-29 06:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll

2016-04-18 21:34 - 2016-04-18 21:34 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe

2016-01-31 16:07 - 2016-01-31 16:07 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll

2016-05-12 00:11 - 2016-04-23 00:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll

2016-05-12 00:13 - 2016-04-23 00:02 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll

2016-05-12 00:12 - 2016-04-22 23:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll

2016-05-12 00:13 - 2016-04-22 23:58 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll

2016-05-12 00:12 - 2016-04-23 00:01 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll

2016-05-03 19:20 - 2016-05-03 19:20 - 00087888 _____ () C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe

2016-02-01 19:55 - 2016-02-01 19:55 - 03746816 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x64__8wekyb3d8bbwe\Calculator.exe

2016-01-05 18:36 - 2016-01-05 18:36 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll

2016-04-18 21:34 - 2016-04-18 21:34 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll

2016-04-18 21:34 - 2016-04-18 21:34 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll

2015-08-11 00:00 - 2014-12-08 03:28 - 00627672 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMediaLibrary.dll

2014-12-08 18:28 - 2014-12-08 18:28 - 00016856 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvcPS.dll

2015-06-23 19:26 - 2015-06-23 19:26 - 00155888 _____ () c:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll

2015-06-24 04:07 - 2015-06-24 04:07 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

AlternateDataStreams: C:\Windows:nlsPreferences [0]

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

 

==================== EXE Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2015-07-10 07:04 - 2015-07-10 07:02 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

 

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jack Spratt\Desktop\Inspiration\1525388_645731865483962_630974115_n.jpg

DNS Servers: [removed] - [removed]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

(Currently there is no automatic fix for this section.)

 

HKLM\…\StartupApproved\Run32: => "FUFAXRCV"

HKLM\…\StartupApproved\Run32: => "FUFAXSTM"

HKLM\…\StartupApproved\Run32: => "PMBVolumeWatcher"

HKLM\…\StartupApproved\Run32: => "MediaFace Integration"

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\StartupApproved\Run: => "EPLTarget\P0000000000000001"

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\StartupApproved\Run: => "EPLTarget\P0000000000000000"

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\StartupApproved\Run: => "GarminExpressTrayApp"

HKU\S-1-5-21-2322127342-2752091441-2421920365-1001\…\StartupApproved\Run: => "OneDrive"

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139

FirewallRules: [{84BB8E0B-2144-43E8-AD26-0D2B5F3ED2FE}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe

FirewallRules: [{33479D62-37B2-4408-89B3-492AA7AA95AB}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe

FirewallRules: [{41E438BF-637D-426A-8C59-B5B4185CBF5E}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe

FirewallRules: [{CBD941BA-5EC5-4ED3-8D27-45FCF1286B1E}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe

FirewallRules: [{55E1AD8D-9AA2-4F8A-8213-8546B97C2531}] => (Allow) LPort=1900

FirewallRules: [{FFE1E927-0E93-46C7-8D39-C1D03F760177}] => (Allow) LPort=2869

FirewallRules: [{616D711F-5B19-44D4-8DE0-3FFEE0A5C1AA}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

FirewallRules: [{FA352B76-230E-4566-8927-4B8737480989}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

FirewallRules: [{30E34036-A40C-4A60-8156-0B8F14F5FC2C}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe

FirewallRules: [{13B5E923-E5BE-4D6D-8E69-3D025348881F}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDirector12\PDR10.EXE

FirewallRules: [{42396CDC-BB42-4609-AA43-FDEE0D9DBD7B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe

FirewallRules: [{B16E72AB-A65C-4C85-9683-C406B1C8BC6B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{781678F2-3E9B-4FA8-A887-DC15F4212B14}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{B97AD4B0-6BAC-4C3C-BE66-8DFFCAE79A13}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{23BA8E2D-958C-4697-ADD6-FE2CEC5B0A19}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

FirewallRules: [{B7CDDE2B-1AF5-4ACD-8158-83D166EA3D13}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

 

==================== Restore Points =========================

 

26-04-2016 15:03:38 Garmin Express

05-05-2016 22:00:36 Scheduled Checkpoint

12-05-2016 21:00:37 Windows Update

12-05-2016 21:02:00 Windows Update

19-05-2016 20:50:59 Dell Update: eDellRoot Removal

19-05-2016 20:51:59 Dell Update: DSD Cert Removal

 

==================== Faulty Device Manager Devices =============

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (05/20/2016 01:52:54 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0x13a8

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 10:55:39 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0x1488

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 10:07:52 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0xd24

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 10:07:18 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0x1644

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 10:05:16 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0x1458

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 10:03:26 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0x1964

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 10:02:43 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0x61c

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 10:01:50 PM) (Source: Application Error) (EventID: 1000) (User: )

Description: Faulting application name: SystemSettings.exe, version: 10.0.10586.11, time stamp: 0x56457cb1

Faulting module name: OneBackupHandler.dll, version: 10.0.10586.0, time stamp: 0x5632d634

Exception code: 0xc0000005

Fault offset: 0x00000000000211df

Faulting process id: 0x1f94

Faulting application start time: 0xSystemSettings.exe0

Faulting application path: SystemSettings.exe1

Faulting module path: SystemSettings.exe2

Report Id: SystemSettings.exe3

Faulting package full name: SystemSettings.exe4

Faulting package-relative application ID: SystemSettings.exe5

 

Error: (05/19/2016 08:52:04 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )

Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

 

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

 

System Error:

Access is denied.

.

 

Error: (05/19/2016 08:51:31 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )

Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

 

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

 

System Error:

Access is denied.

.

 

 

System errors:

=============

Error: (05/20/2016 02:24:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The Sync Host_113f1f5 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

Error: (05/20/2016 02:24:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)

Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

 

Error: (05/20/2016 01:43:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)

Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

 

Error: (05/19/2016 10:56:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The Sync Host_f46167 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

Error: (05/19/2016 10:56:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)

Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

 

Error: (05/19/2016 10:48:03 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-BAU9EJM)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-BAU9EJMJack SprattS-1-5-21-2322127342-2752091441-2421920365-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (05/19/2016 10:48:03 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-BAU9EJM)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-BAU9EJMJack SprattS-1-5-21-2322127342-2752091441-2421920365-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (05/19/2016 10:48:01 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-BAU9EJM)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-BAU9EJMJack SprattS-1-5-21-2322127342-2752091441-2421920365-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (05/19/2016 10:47:59 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-BAU9EJM)

Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-BAU9EJMJack SprattS-1-5-21-2322127342-2752091441-2421920365-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

 

Error: (05/19/2016 10:46:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: )

Description: The Sync Host_2d5bd service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

 

 

CodeIntegrity:

===================================

  Date: 2016-05-20 16:04:59.601

  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-05-20 13:52:23.803

  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-05-15 00:23:50.836

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-05-14 22:17:35.693

  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-05-14 10:38:10.648

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-05-13 19:06:31.915

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-04-23 20:37:11.138

  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-04-16 01:12:38.759

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

 

  Date: 2016-04-13 19:48:03.172

  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

 

  Date: 2016-04-13 00:36:28.429

  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

 

 

==================== Memory info ===========================

 

Processor: Intel(R) Core(TM) i3-5005U CPU @ 2.00GHz

Percentage of memory in use: 47%

Total physical RAM: 4006.61 MB

Available physical RAM: 2087.44 MB

Total Virtual: 4710.61 MB

Available Virtual: 2590.55 MB

 

==================== Drives ================================

 

Drive c: (OS) (Fixed) (Total:452.23 GB) (Free:267.64 GB) NTFS

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (Size: 465.8 GB) (Disk ID: EB960AB4)

 

Partition: GPT.

 

==================== End of Addition.txt ============================

 

 

 

 

 

 

:welcome:

 

Your logs dont look to bad, so at this point not sure if this is a windows , hardware or malware issue.  What I would like to do is have you run some programs and see what they find, if we can determine its not malware than I can link you to our windows thread for help

 

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
 
 
[external image: MBAM220_zpsox89gdej.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 

Ken545,

 

Thank you for checking things out for me. I have completed the next set of scans as requested. They are pasted below.

 

TheCatMan

 

 

ADW CLEANER LOG

 

# AdwCleaner v5.117 - Logfile created 21/05/2016 at 12:57:30

# Updated 15/05/2016 by Xplode

# Database : 2016-05-15.2 [Server]

# Operating system : Windows 10 Home  (X64)

# Username : Jack Spratt - DESKTOP-BAU9EJM

# Running from : C:\Users\Jack Spratt\Desktop\AdwCleaner.exe

# Option : Clean

# Support : http://toolslib.net/forum

 

***** [ Services ] *****

 

 

***** [ Folders ] *****

 

 

***** [ Files ] *****

 

 

***** [ DLLs ] *****

 

 

***** [ WMI ] *****

 

 

***** [ Shortcuts ] *****

 

 

***** [ Scheduled tasks ] *****

 

 

***** [ Registry ] *****

 

[-] Key Deleted : HKCU\Software\Conduit

[-] Key Deleted : HKLM\SOFTWARE\Conduit

[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}

 

***** [ Web browsers ] *****

 

 

*************************

 

:: "Tracing" keys deleted

:: Winsock settings cleared

 

*************************

 

C:\AdwCleaner\AdwCleaner[C1].txt - [922 bytes] - [21/05/2016 12:57:30]

C:\AdwCleaner\AdwCleaner[S1].txt - [1046 bytes] - [21/05/2016 12:55:38]

 

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1067 bytes] ##########

 

 

JRT LOG

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Malwarebytes

Version: 8.0.6 (04.25.2016)

Operating System: Windows 10 Home x64

Ran by [removed] (Administrator) on Sat 05/21/2016 at 13:01:10.69

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

File System: 2

 

Successfully deleted: C:\WINDOWS\system32\Tasks\PCDEventLauncherTask (Task)

Successfully deleted: C:\WINDOWS\system32\Tasks\PCDoctorBackgroundMonitorTask (Task)

 

 

 

Registry: 1

 

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D1C9A910-F54D-4EB5-ABA2-F1B75BFDD091} (Registry Key)

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Sat 05/21/2016 at 13:04:04.36

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

MALWAREBYTES LOG

 

 

Malwarebytes Anti-Malware

www.malwarebytes.org

 

Scan Date: 5/21/2016

Scan Time: 1:11 PM

Logfile: MBAM Log 1.txt

Administrator: Yes

 

Version: 2.2.1.1043

Malware Database: v2016.05.21.03

Rootkit Database: v2016.05.20.01

License: Trial

Malware Protection: Enabled

Malicious Website Protection: Enabled

Self-protection: Disabled

 

OS: Windows 10

CPU: x64

File System: NTFS

User: Jack Spratt

 

Scan Type: Threat Scan

Result: Completed

Objects Scanned: 308805

Time Elapsed: 21 min, 36 sec

 

Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled

 

Processes: 0

(No malicious items detected)

 

Modules: 0

(No malicious items detected)

 

Registry Keys: 0

(No malicious items detected)

 

Registry Values: 0

(No malicious items detected)

 

Registry Data: 0

(No malicious items detected)

 

Folders: 0

(No malicious items detected)

 

Files: 0

(No malicious items detected)

 

Physical Sectors: 0

(No malicious items detected)

 

 

(end)

Nothing real earth shattering was found. Lets do this

 

Double click on AdwCleaner.exe to run the tool again.
  •  
  • Click on the Uninstall button.
  • Click Yes when asked are you sure you want to uninstall.
  • Both AdwCleaner.exe, its folder and all logs will be removed.
 
 
 
 
 

[external image: 3330203e-7304-4336-aa0a-eb3d8b6e3b35_zps]
 
Please run this Free Online Virus Scanner from ESET
  •  
  • Please be patient, depending on your system the scan can complete in 30 minutes and on others much longer.
  • You want the Online One-Time Scan
  • Note: It will run using Internet Explorer, Firefox or Chome.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is NOT TICKED, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
 
 
 

Ken545,

 

I ran the ESET Online scanner. It found 4 suspect files. When I looked at the log that was saved this information was not in there but fortunately I exported the list of found suspect files to a text file as well just to be safe. The scan took a long time so I didn’t want to have to repeat it unless I absolutely had to. Pasted below is a copy of the log and a copy of the text file version of the list of found suspect files.

 

Thanks ,

 

TheCatMan

 

LOG FILE

 

ESETSmartInstaller@High as CAB hook log:

OnlineScanner64.ocx - registred OK

OnlineScanner.ocx - registred OK

Update Init

Update Download

Update Finalize

Updated modules version: 29547

 

LIST OF SUSPECT FILES

 

C:\Program Files (x86)\NCH Software\Prism\prism.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application

 

C:\Program Files (x86)\NCH Software\Prism\prismsetup_v1.89.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application

 

C:\Users\Jack Spratt\Desktop\Back Up\Lisas Files\Lisa Whites Backup 01222013\LISA WHITES FILES\Lisas Dead Dell Dimension 4600 Backup\Lisas Dead Dell Dimension 4600 Desktop Take 2\PayPal-SecurityMeasure.html HTML/Fraud.AO trojan

 

C:\Users\Jack Spratt\Desktop\Back Up\Software Done\prismpsetup.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application

Those entries look fine, prism appears to be a valid program so they most likely are false positives. The entry from Paypal appears to be a bogus email from Paypal

 

https://www.paypal-community.com/t5/Buying-with-PayPal/quot-Security-Measures-quot-email-is-this-spam/td-p/399156?profile.language=en-gb

 

ESET is a great scanner, I have had some people post back and say it ran in under a half hour and some others said it took much longer, depends on your system.

 

 

Hows your system running now, still having startup problems ?

Ken545,

 

So far I have had no further problems so I am not sure what was happening. Perhaps it was just an anomaly that won't occur again. If it starts again I will post for help on the windows section of the web site and see what they say. For now I'll just throw some salt over my shoulder and hang a horseshoe on the wall next to my desk and call it good.

 

Thank you for your help.

 

Sincerely,

 

The Cat Man

Thats great, I dont see anything the programs removed that would have fixed it. Sounds simple but sometimes with a problem like yours just a few reboots is all that is needed .  If it happens again, be sure to post in our windows forum, they can run you through some tests to try and determine if it may be just a bad driver or a hardware component like a memory module or the hard drive itself that is causing it.  If you do post back, link them to this thread so that they can see what we have done and we have determined that its not a malware problem.

 

 

https://forums.whatthetech.com/index.php?showforum=119      <— Our windows forum

 

 

Please download DelFix and save the file to your Desktop.
 
[external image: DelFix_zps139e2ea1.jpg]
 
  •  
  • Windows XP Double Click DelFix.exe to run the program. 
  • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
  • Checkmark " Remove Disinfection Tools"
  • Click the Run button
 
 
This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
 
 
 
 
So How did I get infected in the first place <– Some reading for you to keep yourself safe online
 
 
Safe Surfn
Ken

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI