This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"New" Used Computer Can Someone Give it a Look [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:welcome:

 

Please reply to this topic and do not start a new topic for each reply or else your posts will be all over the forum and I wont be able to keep track of you.  

 

When you ran FRST64,  the first time its run there should have been an Additions log also, it should be on your desktop, post it please. If you cant find it than run FRST64 again by right clicking on FRST64 and selecting RUN AS ADMINISTRATOR, make sure to put a checkmark in ADDITIONS , click on scan and post the Additions log.  Also, all the logs from the tools we run will open up in Notepad, I prefer if you would copy and paste the logs into this thread in lieu of attaching them.

 

I see a few issues with the log you posted, but lets wait until I see the Additions log before we take any action

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:29-05-2016 02
Ran by [removed] (administrator) on WINDOWS (29-05-2016 18:40:15)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Cypress Semiconductor Corporation) C:\Program Files\Cypress\TrackPad\CyTpService.exe
() C:\Windows\System32\DptfParticipantProcessorService.exe
() C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.9\ToolbarUpdater.exe
(Microsoft) C:\Program Files (x86)\Intel Corporation\Intel(R) Sensor Solution Service\wakeupSensor.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(Cypress Semiconductor, Inc.) C:\Program Files\Cypress\TrackPad\CyHidWin.exe
(Cypress Semiconductor Corporation) C:\Program Files\Cypress\TrackPad\CyCpIo.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Compal Electronics, INC.) C:\Program Files\Dell\QuickSet\ResetTouch.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Dropbox, Inc.) C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Dropbox, Inc.) C:\Users\Windows8\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
() C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent Inc.) C:\Users\Windows8\AppData\Roaming\uTorrent\uTorrent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6827664 2012-08-14] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-06] (Realtek Semiconductor)
HKLM\…\Run: [ResetTouch] => c:\Program Files\Dell\QuickSet\ResetTouch.exe [8500120 2012-10-17] (Compal Electronics, INC.)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5757328 2012-10-17] (Dell Inc.)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3820440 2016-04-21] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [1941064 2016-05-29] ()
HKLM-x32\…\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [73216 2016-01-19] ()
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Google Update] => C:\Users\Windows8\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-03-24] (Google Inc.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Dropbox Update] => C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-07] (Dropbox, Inc.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\MountPoints2: {72a0de9a-f1ef-11e3-bea8-c48508fe0b3b} - "D:\PhotoViewer.exe" 
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\MountPoints2: {7ebd172e-4acd-11e5-beda-c48508fe0b3b} - "D:\VZW_Software_upgrade_assistant.exe" 
HKU\S-1-5-18\…\RunOnce: [Application Restart #0] => C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe [372424 2016-02-08] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\FileSyncShell64.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\FileSyncShell64.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\FileSyncShell64.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileSyncShell.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileSyncShell.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileSyncShell.dll [2016-04-21] (Microsoft Corporation)
Startup: C:\Users\Windows8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-05-11]
ShortcutTarget: Dropbox.lnk -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{4105E6F7-9EEA-471D-9BDD-A85D657353AC}: [DhcpNameServer] 10.0.0.1
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={D6ACD94B-A806-468C-BF2F-7A79F28E2140}∣=b44dc21ea30447d2a1f515cc4e1ae2c8-e5330d70026651cc34e2857f33dfffeb5b36bc74⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0715av≺=fr&d;=2015-07-16 18:15:11&v;=4.1.4.948&pid;=wtu&sg;=&sap;=hp
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com
SearchScopes: HKLM -> DefaultScope {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKLM -> {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> DefaultScope {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> {589B893E-773C-4941-88C2-0DCC718E621C} URL = 
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D6ACD94B-A806-468C-BF2F-7A79F28E2140}∣=b44dc21ea30447d2a1f515cc4e1ae2c8-e5330d70026651cc34e2857f33dfffeb5b36bc74⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0715av≺=fr&d;=2015-07-16 18:15:11&v;=4.1.4.948&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.2.9.726\AVG Web TuneUp.dll [2016-04-21] (AVG)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.2.9.726\AVG Web TuneUp.dll [2016-04-21] (AVG)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.2.9\\npsitesafety.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-18] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-1111288859-4143947986-3219784061-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Windows8\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-1111288859-4143947986-3219784061-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Windows8\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-11-18] (Microsoft Corporation)
 
Chrome: 
=======
CHR HomePage: Default -> hxxps://www.google.com/webhp?sourceid=chrome-instant&ion;=1&espv;=2&ie;=UTF-8
CHR StartupUrls: Default -> "hxxp://Taplika.com/?f=7&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=","hxxp://www.msn.com/?pc=UP97&ocid;=UP97DHP"
CHR Profile: C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Google Drive) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-28]
CHR Extension: (YouTube) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Google Cast) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-05-11]
CHR Extension: (Google Search) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Google Docs Offline) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-11]
CHR Extension: (Gmail) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR HKLM\…\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3646888 2016-02-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [335656 2016-02-04] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 CyTpService; C:\Program Files\Cypress\TrackPad\CyTpService.exe [30208 2012-10-24] (Cypress Semiconductor Corporation)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [29056 2012-07-30] ()
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [30592 2012-07-30] ()
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2016-01-19] (Freemake) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [File not signed]
R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193576 2012-07-28] (Intel Corporation)
R2 ISCTAgent; c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [149032 2012-08-16] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [200808 2012-05-09] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1915408 2013-10-09] (SoftThinks SAS)
R2 vToolbarUpdater40.2.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.9\ToolbarUpdater.exe [1964616 2016-04-21] (AVG Secure Search)
R2 WakeupService; C:\Program Files (x86)\Intel Corporation\Intel(R) Sensor Solution Service\wakeupSensor.exe [8704 2012-08-30] (Microsoft) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1223752 2016-04-21] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [296368 2015-12-16] (AVG Technologies CZ, s.r.o.)
R3 cyhid; C:\Windows\System32\drivers\cyhid.sys [143360 2012-11-07] (Cypress Semiconductor, Inc.)
R3 cykbfltrService; C:\Windows\system32\DRIVERS\cykbfltr.sys [20992 2012-11-07] (Cypress Semiconductor, Inc.)
R3 cymfltrService; C:\Windows\system32\DRIVERS\cymfltr.sys [98816 2012-11-07] (Cypress Semiconductor, Inc.)
S3 CySmb; C:\Windows\System32\drivers\CySmb.sys [10752 2012-11-07] (Cypress Semiconductor, Inc.)
S3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2012-08-04] (OSR Open Systems Resources, Inc.)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107328 2012-07-13] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42816 2012-07-13] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64832 2012-07-13] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96064 2012-07-13] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [228672 2012-07-13] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [361792 2012-07-13] (Intel Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-08] (REALiXâ„¢)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [20968 2012-08-16] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [19944 2012-08-16] ()
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [43800 2012-07-28] (Intel Corporation)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46016 2012-08-18] ()
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SensorsAlsDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-28] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-28] (Microsoft Corporation)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2016-02-08] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2016-05-29] ()
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
U3 aswMBR; \??\C:\Users\Windows8\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Windows8\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-05-29 18:40 - 2016-05-29 18:40 - 00030786 _____ C:\Users\Windows8\Desktop\FRST.txt
2016-05-29 18:40 - 2016-05-29 18:40 - 00000000 ____D C:\FRST
2016-05-29 18:38 - 2016-05-29 18:39 - 02383872 _____ (Farbar) C:\Users\Windows8\Desktop\FRST64.exe
2016-05-29 18:37 - 2016-05-29 18:37 - 00001564 _____ C:\Users\Windows8\Desktop\aswMBR.txt
2016-05-29 18:37 - 2016-05-29 18:37 - 00000512 _____ C:\Users\Windows8\Desktop\MBR.dat
2016-05-29 18:35 - 2016-05-29 18:36 - 05198336 _____ (AVAST Software) C:\Users\Windows8\Downloads\aswMBR.exe
2016-05-29 18:33 - 2016-05-29 18:35 - 2746903220 _____ C:\Users\Windows8\Downloads\[ www.CpasBien.cm ] Zootopia.2016.MULTi.1080p.BluRay.x264-VENUE.mkv
2016-05-29 18:32 - 2016-05-29 18:32 - 00538073 _____ C:\Users\Windows8\Downloads\Zootopia+2016+MULTi+1080p+BluRay+x264-VENUE+mkv.torrent
2016-05-29 18:15 - 2016-05-29 18:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\Windows8\Downloads\HijackThis.exe
2016-05-29 18:13 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2016-05-29 17:59 - 2016-05-29 18:04 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA.job
2016-05-29 17:59 - 2016-05-29 18:04 - 00000884 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core.job
2016-05-29 17:57 - 2016-05-29 18:02 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-29 17:57 - 2016-05-29 17:57 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-29 17:54 - 2016-05-29 17:54 - 00094656 _____ (CACE Technologies) C:\WINDOWS\system32\WPRO_41_2001woem.tmp
2016-05-11 19:58 - 2016-05-11 19:58 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-05-11 19:50 - 2016-04-05 14:53 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-05-11 19:50 - 2016-04-05 14:53 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-11 19:48 - 2016-05-11 19:48 - 00000988 _____ C:\Users\Public\Desktop\AVG 2015.lnk
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-05-29 18:39 - 2015-01-03 21:02 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\uTorrent
2016-05-29 18:19 - 2012-07-26 00:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-05-29 18:13 - 2015-06-26 19:50 - 00000000 ____D C:\Program Files\Common Files\AV
2016-05-29 18:13 - 2013-12-25 18:50 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-05-29 18:09 - 2013-12-04 12:41 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1111288859-4143947986-3219784061-1001
2016-05-29 18:08 - 2013-08-22 08:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-05-29 18:08 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-05-29 18:04 - 2013-12-04 12:42 - 00002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-29 18:04 - 2013-12-04 12:42 - 00002210 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-05-29 18:02 - 2013-11-14 00:28 - 00865408 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-05-29 18:02 - 2013-08-22 06:36 - 00000000 ____D C:\WINDOWS\Inf
2016-05-29 18:01 - 2016-02-08 18:43 - 00003246 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2016-05-29 18:01 - 2016-02-08 18:43 - 00002878 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Windows8)
2016-05-29 17:59 - 2015-03-24 18:51 - 00003888 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA
2016-05-29 17:59 - 2015-03-24 18:51 - 00003508 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core
2016-05-29 17:59 - 2013-12-04 12:39 - 00000000 ____D C:\ProgramData\MFAData
2016-05-29 17:58 - 2015-07-16 18:15 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-05-29 17:58 - 2014-12-01 18:21 - 00000000 ___RD C:\Users\Windows8\Dropbox
2016-05-29 17:58 - 2014-09-02 20:00 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\Skype
2016-05-29 17:58 - 2014-02-15 16:30 - 00980480 ___SH C:\Users\Windows8\Desktop\Thumbs.db
2016-05-29 17:58 - 2013-12-24 17:42 - 00000000 ___DO C:\Users\Windows8\SkyDrive
2016-05-29 17:57 - 2015-06-07 19:47 - 00000946 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA.job
2016-05-29 17:57 - 2013-12-04 12:41 - 00003894 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-29 17:57 - 2013-12-04 12:41 - 00003658 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-29 17:57 - 2013-08-22 06:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2016-05-29 17:56 - 2013-01-23 03:01 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2016-05-29 17:54 - 2013-08-22 07:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-05-29 17:54 - 2013-08-22 07:44 - 00481744 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-05-29 17:54 - 2013-01-23 02:57 - 00034752 _____ C:\WINDOWS\system32\Drivers\WPRO_41_2001.sys
2016-05-29 17:52 - 2016-02-08 18:43 - 00000000 ____D C:\ProgramData\ProductData
2016-05-29 17:52 - 2015-07-16 18:15 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-05-29 17:52 - 2015-07-16 18:15 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-05-29 17:52 - 2013-08-22 06:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-05-29 17:51 - 2014-12-11 19:58 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-05-29 17:51 - 2013-08-22 08:36 - 00000000 ___RD C:\WINDOWS\ToastData
2016-05-11 20:00 - 2013-12-24 17:34 - 00000000 ____D C:\Users\Windows8
2016-05-11 20:00 - 2013-12-21 14:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-05-11 19:59 - 2014-10-21 19:28 - 00325120 ___SH C:\Users\Windows8\Downloads\Thumbs.db
2016-05-11 19:58 - 2014-12-01 18:17 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\Dropbox
2016-05-11 19:56 - 2013-12-24 17:13 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-05-11 19:56 - 2013-12-21 14:09 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-05-11 19:51 - 2015-04-11 20:18 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2016-05-11 19:51 - 2015-04-11 20:18 - 00000000 ___SD C:\WINDOWS\system32\GWX
2016-05-11 19:49 - 2014-04-20 13:41 - 00003934 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{64551A90-571D-4DB0-89BB-C3EF1BA1C0F0}
2016-05-11 19:48 - 2014-04-03 21:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-05-11 19:47 - 2016-02-08 18:42 - 00002283 _____ C:\Users\Public\Desktop\Advanced SystemCare 9.lnk
 
==================== Files in the root of some directories =======
 
2015-01-04 19:47 - 2015-01-14 20:47 - 0000128 _____ () C:\Users\Windows8\AppData\Roaming\WB.CFG
2015-01-06 11:47 - 2015-01-06 11:47 - 0000001 _____ () C:\Users\Windows8\AppData\Local\DSI.DAT
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-04-21 19:58
 
==================== End of FRST.txt ============================

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:29-05-2016 02
Ran by [removed] (administrator) on WINDOWS (29-05-2016 18:40:15)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Cypress Semiconductor Corporation) C:\Program Files\Cypress\TrackPad\CyTpService.exe
() C:\Windows\System32\DptfParticipantProcessorService.exe
() C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.9\ToolbarUpdater.exe
(Microsoft) C:\Program Files (x86)\Intel Corporation\Intel(R) Sensor Solution Service\wakeupSensor.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
(Cypress Semiconductor, Inc.) C:\Program Files\Cypress\TrackPad\CyHidWin.exe
(Cypress Semiconductor Corporation) C:\Program Files\Cypress\TrackPad\CyCpIo.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Compal Electronics, INC.) C:\Program Files\Dell\QuickSet\ResetTouch.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Dropbox, Inc.) C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Dropbox, Inc.) C:\Users\Windows8\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
() C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(BitTorrent Inc.) C:\Users\Windows8\AppData\Roaming\uTorrent\uTorrent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6827664 2012-08-14] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-06] (Realtek Semiconductor)
HKLM\…\Run: [ResetTouch] => c:\Program Files\Dell\QuickSet\ResetTouch.exe [8500120 2012-10-17] (Compal Electronics, INC.)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5757328 2012-10-17] (Dell Inc.)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3820440 2016-04-21] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [1941064 2016-05-29] ()
HKLM-x32\…\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [73216 2016-01-19] ()
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Google Update] => C:\Users\Windows8\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-03-24] (Google Inc.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Dropbox Update] => C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-07] (Dropbox, Inc.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2019616 2016-01-11] (IObit)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\MountPoints2: {72a0de9a-f1ef-11e3-bea8-c48508fe0b3b} - "D:\PhotoViewer.exe" 
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\MountPoints2: {7ebd172e-4acd-11e5-beda-c48508fe0b3b} - "D:\VZW_Software_upgrade_assistant.exe" 
HKU\S-1-5-18\…\RunOnce: [Application Restart #0] => C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe [372424 2016-02-08] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\FileSyncShell64.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\FileSyncShell64.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\FileSyncShell64.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileSyncShell.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileSyncShell.dll [2016-04-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileSyncShell.dll [2016-04-21] (Microsoft Corporation)
Startup: C:\Users\Windows8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-05-11]
ShortcutTarget: Dropbox.lnk -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{4105E6F7-9EEA-471D-9BDD-A85D657353AC}: [DhcpNameServer] 10.0.0.1
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={D6ACD94B-A806-468C-BF2F-7A79F28E2140}∣=b44dc21ea30447d2a1f515cc4e1ae2c8-e5330d70026651cc34e2857f33dfffeb5b36bc74⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0715av≺=fr&d;=2015-07-16 18:15:11&v;=4.1.4.948&pid;=wtu&sg;=&sap;=hp
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com
SearchScopes: HKLM -> DefaultScope {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKLM -> {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> DefaultScope {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} URL = hxxp://Taplika.com/results.php?f=4&q;={searchTerms}&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> {589B893E-773C-4941-88C2-0DCC718E621C} URL = 
SearchScopes: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={D6ACD94B-A806-468C-BF2F-7A79F28E2140}∣=b44dc21ea30447d2a1f515cc4e1ae2c8-e5330d70026651cc34e2857f33dfffeb5b36bc74⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0715av≺=fr&d;=2015-07-16 18:15:11&v;=4.1.4.948&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.2.9.726\AVG Web TuneUp.dll [2016-04-21] (AVG)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-03-15] (Microsoft Corporation)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.2.9.726\AVG Web TuneUp.dll [2016-04-21] (AVG)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-03-15] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.2.9\\npsitesafety.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-18] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-1111288859-4143947986-3219784061-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Windows8\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin HKU\S-1-5-21-1111288859-4143947986-3219784061-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Windows8\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-29] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-11-18] (Microsoft Corporation)
 
Chrome: 
=======
CHR HomePage: Default -> hxxps://www.google.com/webhp?sourceid=chrome-instant&ion;=1&espv;=2&ie;=UTF-8
CHR StartupUrls: Default -> "hxxp://Taplika.com/?f=7&a;=tpl_idaddy_15_01&cd;=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr;=519532889&ir;=","hxxp://www.msn.com/?pc=UP97&ocid;=UP97DHP"
CHR Profile: C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-06]
CHR Extension: (Google Drive) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-28]
CHR Extension: (YouTube) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Google Cast) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2016-05-11]
CHR Extension: (Google Search) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Google Docs Offline) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-11]
CHR Extension: (Gmail) - C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR HKLM\…\Chrome\Extension: [lfkjojacgdjkninepeghaamnapdjmlfn] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3646888 2016-02-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [335656 2016-02-04] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 CyTpService; C:\Program Files\Cypress\TrackPad\CyTpService.exe [30208 2012-10-24] (Cypress Semiconductor Corporation)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [29056 2012-07-30] ()
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [30592 2012-07-30] ()
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2016-01-19] (Freemake) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [File not signed]
R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193576 2012-07-28] (Intel Corporation)
R2 ISCTAgent; c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [149032 2012-08-16] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [200808 2012-05-09] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [1915408 2013-10-09] (SoftThinks SAS)
R2 vToolbarUpdater40.2.9; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.2.9\ToolbarUpdater.exe [1964616 2016-04-21] (AVG Secure Search)
R2 WakeupService; C:\Program Files (x86)\Intel Corporation\Intel(R) Sensor Solution Service\wakeupSensor.exe [8704 2012-08-30] (Microsoft) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1223752 2016-04-21] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [296368 2015-12-16] (AVG Technologies CZ, s.r.o.)
R3 cyhid; C:\Windows\System32\drivers\cyhid.sys [143360 2012-11-07] (Cypress Semiconductor, Inc.)
R3 cykbfltrService; C:\Windows\system32\DRIVERS\cykbfltr.sys [20992 2012-11-07] (Cypress Semiconductor, Inc.)
R3 cymfltrService; C:\Windows\system32\DRIVERS\cymfltr.sys [98816 2012-11-07] (Cypress Semiconductor, Inc.)
S3 CySmb; C:\Windows\System32\drivers\CySmb.sys [10752 2012-11-07] (Cypress Semiconductor, Inc.)
S3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2012-08-04] (OSR Open Systems Resources, Inc.)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107328 2012-07-13] (Intel Corporation)
R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42816 2012-07-13] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64832 2012-07-13] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96064 2012-07-13] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [228672 2012-07-13] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [361792 2012-07-13] (Intel Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-02-08] (REALiXâ„¢)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [20968 2012-08-16] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [19944 2012-08-16] ()
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [43800 2012-07-28] (Intel Corporation)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46016 2012-08-18] ()
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SensorsAlsDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-28] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-28] (Microsoft Corporation)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2016-02-08] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2016-05-29] ()
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
U3 aswMBR; \??\C:\Users\Windows8\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Windows8\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-05-29 18:40 - 2016-05-29 18:40 - 00030786 _____ C:\Users\Windows8\Desktop\FRST.txt
2016-05-29 18:40 - 2016-05-29 18:40 - 00000000 ____D C:\FRST
2016-05-29 18:38 - 2016-05-29 18:39 - 02383872 _____ (Farbar) C:\Users\Windows8\Desktop\FRST64.exe
2016-05-29 18:37 - 2016-05-29 18:37 - 00001564 _____ C:\Users\Windows8\Desktop\aswMBR.txt
2016-05-29 18:37 - 2016-05-29 18:37 - 00000512 _____ C:\Users\Windows8\Desktop\MBR.dat
2016-05-29 18:35 - 2016-05-29 18:36 - 05198336 _____ (AVAST Software) C:\Users\Windows8\Downloads\aswMBR.exe
2016-05-29 18:33 - 2016-05-29 18:35 - 2746903220 _____ C:\Users\Windows8\Downloads\[ www.CpasBien.cm ] Zootopia.2016.MULTi.1080p.BluRay.x264-VENUE.mkv
2016-05-29 18:32 - 2016-05-29 18:32 - 00538073 _____ C:\Users\Windows8\Downloads\Zootopia+2016+MULTi+1080p+BluRay+x264-VENUE+mkv.torrent
2016-05-29 18:15 - 2016-05-29 18:15 - 00388608 _____ (Trend Micro Inc.) C:\Users\Windows8\Downloads\HijackThis.exe
2016-05-29 18:13 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2016-05-29 17:59 - 2016-05-29 18:04 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA.job
2016-05-29 17:59 - 2016-05-29 18:04 - 00000884 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core.job
2016-05-29 17:57 - 2016-05-29 18:02 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-29 17:57 - 2016-05-29 17:57 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-29 17:54 - 2016-05-29 17:54 - 00094656 _____ (CACE Technologies) C:\WINDOWS\system32\WPRO_41_2001woem.tmp
2016-05-11 19:58 - 2016-05-11 19:58 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-05-11 19:50 - 2016-04-05 14:53 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-05-11 19:50 - 2016-04-05 14:53 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-11 19:48 - 2016-05-11 19:48 - 00000988 _____ C:\Users\Public\Desktop\AVG 2015.lnk
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-05-29 18:39 - 2015-01-03 21:02 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\uTorrent
2016-05-29 18:19 - 2012-07-26 00:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-05-29 18:13 - 2015-06-26 19:50 - 00000000 ____D C:\Program Files\Common Files\AV
2016-05-29 18:13 - 2013-12-25 18:50 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-05-29 18:09 - 2013-12-04 12:41 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1111288859-4143947986-3219784061-1001
2016-05-29 18:08 - 2013-08-22 08:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-05-29 18:08 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-05-29 18:04 - 2013-12-04 12:42 - 00002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-29 18:04 - 2013-12-04 12:42 - 00002210 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-05-29 18:02 - 2013-11-14 00:28 - 00865408 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-05-29 18:02 - 2013-08-22 06:36 - 00000000 ____D C:\WINDOWS\Inf
2016-05-29 18:01 - 2016-02-08 18:43 - 00003246 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2016-05-29 18:01 - 2016-02-08 18:43 - 00002878 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Windows8)
2016-05-29 17:59 - 2015-03-24 18:51 - 00003888 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA
2016-05-29 17:59 - 2015-03-24 18:51 - 00003508 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core
2016-05-29 17:59 - 2013-12-04 12:39 - 00000000 ____D C:\ProgramData\MFAData
2016-05-29 17:58 - 2015-07-16 18:15 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-05-29 17:58 - 2014-12-01 18:21 - 00000000 ___RD C:\Users\Windows8\Dropbox
2016-05-29 17:58 - 2014-09-02 20:00 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\Skype
2016-05-29 17:58 - 2014-02-15 16:30 - 00980480 ___SH C:\Users\Windows8\Desktop\Thumbs.db
2016-05-29 17:58 - 2013-12-24 17:42 - 00000000 ___DO C:\Users\Windows8\SkyDrive
2016-05-29 17:57 - 2015-06-07 19:47 - 00000946 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA.job
2016-05-29 17:57 - 2013-12-04 12:41 - 00003894 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-29 17:57 - 2013-12-04 12:41 - 00003658 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-29 17:57 - 2013-08-22 06:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2016-05-29 17:56 - 2013-01-23 03:01 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2016-05-29 17:54 - 2013-08-22 07:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-05-29 17:54 - 2013-08-22 07:44 - 00481744 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-05-29 17:54 - 2013-01-23 02:57 - 00034752 _____ C:\WINDOWS\system32\Drivers\WPRO_41_2001.sys
2016-05-29 17:52 - 2016-02-08 18:43 - 00000000 ____D C:\ProgramData\ProductData
2016-05-29 17:52 - 2015-07-16 18:15 - 00000000 ____D C:\Program Files\AVG Web TuneUp
2016-05-29 17:52 - 2015-07-16 18:15 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-05-29 17:52 - 2013-08-22 06:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-05-29 17:51 - 2014-12-11 19:58 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-05-29 17:51 - 2013-08-22 08:36 - 00000000 ___RD C:\WINDOWS\ToastData
2016-05-11 20:00 - 2013-12-24 17:34 - 00000000 ____D C:\Users\Windows8
2016-05-11 20:00 - 2013-12-21 14:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-05-11 19:59 - 2014-10-21 19:28 - 00325120 ___SH C:\Users\Windows8\Downloads\Thumbs.db
2016-05-11 19:58 - 2014-12-01 18:17 - 00000000 ____D C:\Users\Windows8\AppData\Roaming\Dropbox
2016-05-11 19:56 - 2013-12-24 17:13 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-05-11 19:56 - 2013-12-21 14:09 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-05-11 19:51 - 2015-04-11 20:18 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2016-05-11 19:51 - 2015-04-11 20:18 - 00000000 ___SD C:\WINDOWS\system32\GWX
2016-05-11 19:49 - 2014-04-20 13:41 - 00003934 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{64551A90-571D-4DB0-89BB-C3EF1BA1C0F0}
2016-05-11 19:48 - 2014-04-03 21:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2016-05-11 19:47 - 2016-02-08 18:42 - 00002283 _____ C:\Users\Public\Desktop\Advanced SystemCare 9.lnk
 
==================== Files in the root of some directories =======
 
2015-01-04 19:47 - 2015-01-14 20:47 - 0000128 _____ () C:\Users\Windows8\AppData\Roaming\WB.CFG
2015-01-06 11:47 - 2015-01-06 11:47 - 0000001 _____ () C:\Users\Windows8\AppData\Local\DSI.DAT
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-04-21 19:58
 
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:29-05-2016 02
Ran by [removed] (2016-05-29 18:40:42)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (Update) (X64) (2013-12-25 00:41:06)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1111288859-4143947986-3219784061-500 - Administrator - Disabled)
Guest (S-1-5-21-1111288859-4143947986-3219784061-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1111288859-4143947986-3219784061-1005 - Limited - Enabled)
Windows8 (S-1-5-21-1111288859-4143947986-3219784061-1001 - Administrator - Enabled) => C:\Users\Windows8
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Out of date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Out of date) {F620D48B-1497-73CC-F290-58052563BEAE}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
Advanced SystemCare 9 (HKLM-x32\…\Advanced SystemCare_is1) (Version: 9.1.0 - IObit)
Apple Application Support (HKLM-x32\…\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG 2015 (HKLM\…\AVG) (Version: 2015.0.6201 - AVG Technologies)
AVG 2015 (Version: 15.0.4568 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6201 - AVG Technologies) Hidden
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.2.9.726 - AVG Technologies)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
ChromecastApp (HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.1693.0 - Google Inc.)
Cypress TrackPad (HKLM\…\{7F2F6CC5-434B-4311-9DE2-60C7CAF50B73}_is1) (Version: 2.5.1.27 - Cypress Semiconductor, Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Backup and Recovery - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 1.6.1.1 - Dell Inc.)
Dell Backup and Recovery (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.6.1.1 - Dell Inc.)
Dell Support Center (HKLM\…\PC-Doctor for Windows) (Version: 3.2.6032.39 - PC-Doctor, Inc.)
Driver Booster 3.2 (HKLM-x32\…\Driver Booster_is1) (Version: 3.2 - IObit)
DriverUpdate (HKLM-x32\…\{E2A3A216-9DFE-4EC1-AA69-162588FEF014}) (Version: 2.2.36929 - SlimWare Utilities, Inc.)
Dropbox (HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\Dropbox) (Version: 3.20.1 - Dropbox, Inc.)
DSC/AA Factory Installer (Version: 3.2.6032.39 - PC-Doctor, Inc.) Hidden
Freemake Video Converter version 4.1.9 (HKLM-x32\…\Freemake Video Converter_is1) (Version: 4.1.9 - Ellora Assets Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 50.0.2661.102 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\…\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 6.0.5.1080 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3379 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\…\{E77289CF-12B9-4CAB-A49E-FEAE947F4D95}) (Version: 15.5.4.0423 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{7854AA22-A2F0-4F29-A2E9-D0C5A2B685E7}) (Version: 2.5.0.0248 - Motorola Solutions, Inc)
Intel(R) Rapid Start Technology (HKLM-x32\…\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 2.1.0.1002 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.0.1207 - Intel Corporation)
Intel(R) Smart Connect Technology 3.0 x64 (HKLM\…\{DE788AD4-F7CE-4995-ADF8-56174A7B613C}) (Version: 3.0.41.1571 - Intel)
Intel(R) WiDi (HKLM\…\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
IObit Uninstaller (HKLM-x32\…\IObitUninstall) (Version: 5.2.1.126 - IObit)
iTunes (HKLM\…\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\OneDriveSetup.exe) (Version: 17.3.6386.0412 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
NWZ-W270S WALKMAN Guide (HKLM-x32\…\{2DD336BD-D504-4AD7-AA03-201114C24495}) (Version: 2.2.0.07230 - Sony Corporation)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.15.011 - Dell Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6704 - Realtek Semiconductor Corp.)
Secure Download Manager (HKLM-x32\…\{E86B07AE-9F94-44D5-AD47-DC2716EA90D2}) (Version: 3.1.40 - Kivuto Solutions Inc.)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\…\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.0.0.9103 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.)
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.3 - IObit)
Update for Skype for Business 2015 (KB3039776) 64-Bit Edition (HKLM\…\{90150000-012B-0409-1000-0000000FF1CE}_Office15.PROPLUSR_{0FA8AE0C-69AE-4F60-A1AB-F79C6BA5A999}) (Version:  - Microsoft)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Windows8\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Windows8\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Windows8\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Windows8\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {08493D07-95F2-4819-A0EF-5A92CAC8A381} - System32\Tasks\Uninstaller_SkipUac_Windows8 => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-01-12] (IObit)
Task: {11CFFD5D-F18B-4DA6-8A01-6993C3E245A6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {17647455-016C-4246-A7CF-7434ED4EDDC7} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-07-28] (Intel)
Task: {1AFF13F5-7A07-476F-B48B-F9D14EB43ECF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {21794EA1-882E-4195-A525-89E9F30C65A0} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {23FF464C-A40C-44F1-9E45-39EA4A3C7B37} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {29F4DAF6-345D-425E-8466-6FBC511821CB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {2C11253F-49F2-4B34-98E7-388D3BDF02AB} - System32\Tasks\1015tbUpdateInfo => C:\ProgramData\Avg_Update_1015tb\1015tb_{AE64D40E-1BEE-4610-BFC9-1FB99089736A}.exe [2015-11-03] ()
Task: {321F5878-2878-4F45-B30B-BA4257C9663A} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2016-01-13] (IObit)
Task: {32BF4194-7813-4662-8037-8A4C15CF0146} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2013-09-20] (Safer-Networking Ltd.)
Task: {3B7406C4-611B-467B-98D5-3DA17D2BABF8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA => C:\Users\Windows8\AppData\Local\Google\Update\GoogleUpdate.exe [2015-03-24] (Google Inc.)
Task: {3F4F36C0-507B-4672-9B3B-F2BAAA94DF61} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {503D63E9-0F68-48D8-ABA3-FF3543A946BD} - System32\Tasks\Driver Booster SkipUAC (Windows8) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2016-01-18] (IObit)
Task: {5644832E-4948-4F73-A206-47C6C782462F} - System32\Tasks\ASC9_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-01-15] (IObit)
Task: {5B3202DA-EF61-4E2F-8ED1-280912E5A999} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core => C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-07] (Dropbox, Inc.)
Task: {7B56A085-69A9-4F50-88D3-9BB3124912DA} - System32\Tasks\DriverUpdate Startup => C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe [2014-03-19] (SlimWare Utilities, Inc.)
Task: {A9EF24F4-8A77-4B4F-82D2-213932E27E0C} - System32\Tasks\ASC9_SkipUac_Windows8 => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-01-26] (IObit)
Task: {AC3E2BE0-43E2-4DC1-AB8B-160E8E20A529} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA => C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-07] (Dropbox, Inc.)
Task: {B91D28F1-5E64-41E4-A0C8-BD4995C7CBEC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {BFA72960-AD91-4AFE-9CB8-854057611B24} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-1111288859-4143947986-3219784061-1001 => C:\Users\Windows8\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-04-21] (Microsoft Corporation)
Task: {BFC1047B-D2A8-4374-B22B-C9CCD6680387} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {CC3D3302-E55E-4FC8-9E87-B487CB13F30C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core => C:\Users\Windows8\AppData\Local\Google\Update\GoogleUpdate.exe [2015-03-24] (Google Inc.)
Task: {D7D420C5-FCBD-4610-A006-4E48FB3010B6} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell Support Center\uaclauncher.exe [2012-07-17] (PC-Doctor, Inc.)
Task: {D8AC1357-1002-438D-B0BF-1957EC7EC19B} - System32\Tasks\PCDEventLauncher => C:\Program Files\Dell Support Center\sessionchecker.exe [2012-07-17] (PC-Doctor, Inc.)
Task: {E3514D57-E5BB-42D7-A4D4-8769BD58ACFA} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\1015tbUpdateInfo.job => C:\ProgramData\Avg_Update_1015tb\1015tb_{AE64D40E-1BEE-4610-BFC9-1FB99089736A}.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_Windows8.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\DriverUpdate Startup.job => C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core.job => C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA.job => C:\Users\Windows8\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001Core.job => C:\Users\Windows8\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1111288859-4143947986-3219784061-1001UA.job => C:\Users\Windows8\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_Windows8.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-04-21 19:00 - 2016-04-21 19:00 - 01223752 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2013-01-23 02:21 - 2012-07-30 20:26 - 00029056 _____ () C:\WINDOWS\system32\DptfParticipantProcessorService.exe
2013-01-23 02:21 - 2012-07-30 20:27 - 00030592 _____ () C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe
2012-08-16 21:36 - 2012-08-16 21:36 - 00149032 _____ () c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2012-08-16 21:36 - 2012-08-16 21:36 - 00058920 _____ () c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2015-09-15 14:58 - 2015-09-15 14:58 - 08901184 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-07-16 18:15 - 2016-05-29 17:52 - 01941064 _____ () C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
2016-02-08 19:08 - 2016-01-19 17:51 - 00073216 _____ () C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-02-08 18:42 - 2015-12-28 14:49 - 00629536 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2013-12-25 18:50 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-12-25 18:50 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-12-25 18:50 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-12-25 18:50 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-12-25 18:50 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2016-05-11 19:52 - 2016-05-11 19:52 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\8e749780289ceb24f72730345e019061\PSIClient.ni.dll
2013-01-23 02:58 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2016-02-08 18:42 - 2015-12-23 19:32 - 00355616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madExcept_.bpl
2016-02-08 18:42 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madBasic_.bpl
2016-02-08 18:42 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\madDisAsm_.bpl
2016-05-11 19:58 - 2016-04-19 12:47 - 00034768 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
2016-05-11 19:58 - 2016-04-19 12:48 - 00019408 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\faulthandler.pyd
2016-05-11 19:58 - 2016-04-19 12:47 - 00116688 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\pywintypes27.dll
2016-05-11 19:58 - 2016-04-19 12:47 - 00093640 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\_ctypes.pyd
2016-05-11 19:58 - 2016-04-19 12:47 - 00018376 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\select.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00019760 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00105928 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32api.pyd
2016-05-11 19:58 - 2016-04-19 12:47 - 00392144 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\pythoncom27.dll
2016-05-11 19:58 - 2016-05-06 15:35 - 00381752 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
2016-05-11 19:58 - 2016-04-19 12:47 - 00692688 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\unicodedata.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00020816 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
2016-05-11 19:58 - 2016-04-19 12:48 - 00121296 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 01682760 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00020808 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00021840 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00038696 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\fastpath.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00020936 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\mmapfile.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00024528 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32event.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00114640 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32security.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00124880 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32file.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00021832 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00024016 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00175560 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32gui.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00030160 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32pipe.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00043472 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32process.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00028616 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32ts.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00048592 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32service.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00026456 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00057808 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00024016 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32profile.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00117056 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00052024 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
2016-05-11 19:58 - 2016-04-19 12:47 - 00134608 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\_elementtree.pyd
2016-05-11 19:58 - 2016-04-19 12:47 - 00134088 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\pyexpat.pyd
2016-05-11 19:58 - 2016-04-19 12:48 - 00240584 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\jpegtran.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00020800 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00021824 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00019776 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00020800 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00024392 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
2016-05-11 19:58 - 2016-04-19 12:50 - 00036296 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\librsync.dll
2016-05-11 19:58 - 2016-05-06 15:34 - 00020280 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00023376 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00350152 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\winxpgui.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00022352 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00084280 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL
2016-05-11 19:58 - 2016-05-06 15:34 - 01826096 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
2016-05-11 19:58 - 2016-04-19 12:48 - 00083912 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\sip.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 03928880 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 01971504 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00531248 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00132912 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00223544 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
2016-05-11 19:58 - 2016-05-06 15:34 - 00207672 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
2016-05-11 19:58 - 2016-04-19 12:49 - 00060880 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\win32print.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00024904 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00546096 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
2016-05-11 19:58 - 2016-05-06 15:35 - 00357680 _____ () C:\Users\Windows8\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
2016-02-08 18:42 - 2015-12-28 14:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll
2016-02-08 18:42 - 2015-12-28 14:49 - 00629536 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll
2016-02-08 18:42 - 2015-12-23 19:32 - 00355616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2016-02-08 18:42 - 2015-12-23 19:32 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2016-02-08 18:42 - 2015-12-23 19:32 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2016-05-29 18:04 - 2016-05-11 04:48 - 01738904 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\libglesv2.dll
2016-05-29 18:04 - 2016-05-11 04:48 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
 
There are 7864 more sites.
 
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\…\1-se.com -> 1-se.com
 
There are 11406 more sites.
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2014-06-11 21:00 - 00450639 ____R C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
 
There are 15459 more lines.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Windows8\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\dscf3029.jpg
DNS Servers: 10.0.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{B74841EF-D19C-4A59-AD12-0074742947B2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3DF3340E-8E1E-4831-8080-F9B7E082A0B6}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0C4D8989-8CBF-468E-A3EA-0151F5294C5F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{9CA38F24-E92F-492C-8EB3-3E6EBE0955AE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A650D865-A8DD-46C7-9567-9153629131E6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{8601C018-AFA7-4DB6-B096-FB610D5BAF40}] => (Allow) LPort=1900
FirewallRules: [{A7932E08-9DB1-40B2-A4A2-48EE22A8F558}] => (Allow) LPort=2869
FirewallRules: [{B163C1DC-4E4A-4FC3-B573-D49CD06873C9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{D73BBD5C-1A14-4296-B2DD-74A77A722B23}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{05649B14-3868-4DA7-8353-A2C24D82FABC}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{5CA61427-46A0-4806-AA20-320F8139A888}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{ECE3BE6A-0D1D-4004-98D9-8A4C7E5D285E}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{A4840003-265A-4CD9-A8F2-08732DCAADDE}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{A27E8AC7-47D5-4417-A525-0C0550094F38}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{485A7AB5-AD69-449B-903D-B0F26E8805FC}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{1744C66D-D9FC-4996-9EE6-66853A9F35F8}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{1680C258-C402-4A44-B2DE-D4EA0D8D087C}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{835233FF-78E5-46C9-9CE2-5324A25C4071}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [TCP Query User{256D2195-85D4-4E9F-953E-5E52A2693719}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{6BE91B13-7898-47EC-8841-68A933AE12A1}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{AED09B2E-AED9-401A-A29C-C602DFD157B5}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{519AFE76-9BA1-4C7A-9AA7-026124D32970}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{A84D8A40-19C5-4156-97EC-CEFE81E38E60}] => (Allow) C:\Users\Windows8\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{06B5367D-E5D0-4764-BA94-AB50D9F99511}] => (Allow) C:\Users\Windows8\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{41423131-5AF8-49A6-B557-599A966E52B3}C:\users\windows8\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\windows8\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{30E1A6E8-581F-4675-9142-82BE74B739A9}C:\users\windows8\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\windows8\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{71B0BD0D-6C45-46A7-B329-3110538AF487}] => (Allow) C:\Users\Windows8\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{661C4392-B9F8-41FC-915B-3BCC1A5677A1}] => (Allow) C:\Users\Windows8\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DEF45839-DDD5-452E-82D8-5B888F81BC44}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{3324330D-C9F4-4090-B0B5-F8EF0E84F8ED}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{74F9DFEE-E783-478D-AC56-A3D2B274AF3C}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{2789F43A-9EE3-4D10-B0D5-66F35E8E30C3}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{5B47A005-04E3-46C7-BBEA-DC7509D4BEF2}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{9F4235EC-742E-48D0-AA44-9E28A3961625}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{9DE4464B-6AF0-49B1-9FE7-A941A3455130}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{BB80D171-261F-40C0-94C1-2AC1DFF0CB5D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{F3BFEF8B-9C9E-4B2E-AC64-14FBF7517537}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot-S&D; 2 Tray Icon
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service
 
==================== Restore Points =========================
 
11-05-2016 19:48:44 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/29/2016 06:04:31 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418231
 
Error: (05/29/2016 05:51:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: The Cryptographic Services service failed to initialize the Catalog Database. The ESENT error was: -550.
 
Error: (05/11/2016 07:49:13 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418231
 
Error: (05/11/2016 07:47:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: pcdrsysinfocsmi.p5x, version: 6.0.6032.39, time stamp: 0x4ffe56d2
Faulting module name: MSVCR90.dll, version: 9.0.30729.8387, time stamp: 0x51ea1bbd
Exception code: 0x40000015
Fault offset: 0x000000000004267f
Faulting process id: 0x1a40
Faulting application start time: 0xpcdrsysinfocsmi.p5x0
Faulting application path: pcdrsysinfocsmi.p5x1
Faulting module path: pcdrsysinfocsmi.p5x2
Report Id: pcdrsysinfocsmi.p5x3
Faulting package full name: pcdrsysinfocsmi.p5x4
Faulting package-relative application ID: pcdrsysinfocsmi.p5x5
 
Error: (04/22/2016 08:30:25 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1062
 
Error: (04/22/2016 08:30:25 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1062
 
Error: (04/22/2016 08:30:25 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (04/22/2016 08:30:11 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1110
 
Error: (04/22/2016 08:30:11 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1110
 
Error: (04/22/2016 08:30:11 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (05/29/2016 06:08:22 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80246013: ACMEAtronOmaticLLC.MyRadar.
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The WinHTTP Web Proxy Auto-Discovery Service service failed to start due to the following error: 
%%1069
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The WinHttpAutoProxySvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: 
%%50
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Bluetooth Support Service service failed to start due to the following error: 
%%1069
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The bthserv service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: 
%%50
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Application Experience service failed to start due to the following error: 
%%1115
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SSDP Discovery service failed to start due to the following error: 
%%1069
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The SSDPSRV service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: 
%%50
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Driver Foundation - User-mode Driver Framework service failed to start due to the following error: 
%%1115
 
Error: (05/29/2016 05:52:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Portable Device Enumerator Service service failed to start due to the following error: 
%%1115
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-3317U CPU @ 1.70GHz
Percentage of memory in use: 64%
Total physical RAM: 3975.27 MB
Available physical RAM: 1414.83 MB
Total Virtual: 5767.27 MB
Available Virtual: 2733.27 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:102.34 GB) (Free:11.71 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: D8EA4C22)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

Ahh, thats better thanks

 

Lets go over a few things.

 

Since you just got this computer I wont fault you for some of the programs installed, you need to go to Programs and Features in the Control Panel and uninstall all these

 

Driver Booster
µTorrent 
Advanced SystemCare 9
DriverUpdate
IObit Uninstaller
Surfing Protection 
 
You can get in trouble using any of the torrents as almost 100% of programs downloaded via the torrents are infected, if you look at your Additions log under Firewall rules, uTorrent has permission both in and out of your computer, not nice and not to safe
 
As far as Driver update, the basic rule is if its not broke dont fix it, if you need an updated driver its always best to go right to the manufactures website and download and install it from there in lieu of downloading it through some third party program
 

IObit
 
I want to give you a heads up on IObit , its a program from China and not recommended. The Chinese company behind this product was found to be stealing Malwarebytes database. I would like you to uninstall it as there are better program out there,   why use one from from a questional company with unethical business practices.
 
 
 
Not now but after we determine that your system is clean it would be to your advantage to upgrade to windows 10, its more reliable and secure than previous operating systems and its a free upgrade until July 29th 2016, after that date if you wanted to upgrade you will have to purchase it
 
http://windows.microsoft.com/en-us/windows-10/upgrade-to-windows-10-faq
 
 
 
 
Lets do some generally cleaning and see what they remove and whats left that we may have to deal with
 
 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
 
 
[external image: MBAM220_zpsox89gdej.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 
 
Update, the computer has lost Internet connectivity, and the mouse icon is no longer present. It says that it can't find any wireless connections and my WiFi in the house is working fine. It's a touch screen so I can still operate it, but is there anything we can do to attempt to get the Internet back? I have reset my modem and router and it is still saying there are no networks available.

Well, lets run the programs that I posted earlier and lets see what they find and remove

# AdwCleaner v5.119 - Logfile created 30/05/2016 at 16:02:35
# Updated 30/05/2016 by Xplode
# Database : 2016-05-30.3 [Server]
# Operating system : Windows 8.1  (X64)
# Username : Windows8 - WINDOWS
# Running from : C:\Users\Windows8\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 
Service Found : swdumon
Service Found : WtuSystemSupport
Service Found : vToolbarUpdater40.2.9
 
***** [ Folders ] *****
 
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\AVG Security Toolbar
Folder Found : C:\ProgramData\avg web tuneup
Folder Found : C:\ProgramData\Avg_Update_1015tb
Folder Found : C:\ProgramData\Application Data\apn
Folder Found : C:\ProgramData\Application Data\AVG Secure Search
Folder Found : C:\ProgramData\Application Data\AVG Security Toolbar
Folder Found : C:\ProgramData\Application Data\avg web tuneup
Folder Found : C:\ProgramData\Application Data\Avg_Update_1015tb
Folder Found : C:\Users\Public\Documents\Downloaded Installers
Folder Found : C:\Program Files (x86)\avg web tuneup
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Users\Windows8\AppData\Local\slimware utilities inc
Folder Found : C:\Users\Windows8\AppData\Local\avg web tuneup
Folder Found : C:\Users\Windows8\AppData\Roaming\Systweak
Folder Found : C:\Users\Windows8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlvPlayer
Folder Found : C:\Program Files\avg web tuneup
Folder Found : C:\Program Files\Common Files\AVG Secure Search
 
***** [ Files ] *****
 
File Found : C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage
File Found : C:\WINDOWS\SysNative\roboot64.exe
File Found : C:\WINDOWS\SysNative\drivers\swdumon.sys
 
***** [ DLL ] *****
 
 
***** [ WMI ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
Task Found : 1015tbUpdateInfo
Task Found : 1015tbUpdateInfo
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\lfkjojacgdjkninepeghaamnapdjmlfn
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
Key Found : HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
Key Found : HKCU\Software\powerpack
Key Found : HKCU\Software\systweak
Key Found : HKLM\SOFTWARE\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\AVG Tuneup
Key Found : HKLM\SOFTWARE\systweak
Key Found : [x64] HKLM\SOFTWARE\AVG Secure Search
Key Found : HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\powerpack
Key Found : HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\systweak
Data Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxps://mysearch.avg.com/?cid={D6ACD94B-A806-468C-BF2F-7A79F28E2140}&mid=b44dc21ea30447d2a1f515cc4e1ae2c8-e5330d70026651cc34e2857f33dfffeb5b36bc74&lang=en&ds=AVG&coid=avgtbavg&cmpid=0715av&pr=fr&d=2015-07-16 18:15:11&v=4.1.4.948&pid=wtu&sg=&sap=hp
Data Found : HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxps://mysearch.avg.com/?cid={D6ACD94B-A806-468C-BF2F-7A79F28E2140}&mid=b44dc21ea30447d2a1f515cc4e1ae2c8-e5330d70026651cc34e2857f33dfffeb5b36bc74&lang=en&ds=AVG&coid=avgtbavg&cmpid=0715av&pr=fr&d=2015-07-16 18:15:11&v=4.1.4.948&pid=wtu&sg=&sap=hp
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0}
Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0}
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0}
Key Found : HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0}
Data Found : HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0}
Key Found : HKU\S-1-5-21-1111288859-4143947986-3219784061-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\taplika.com
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
 
***** [ Web browsers ] *****
 
[C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://Taplika.com/?f=7&a=tpl_idaddy_15_01&cd=2XzuyEtN2Y1L1Qzu0CyEzzyDtDzz0F0EtD0BtAzzyBzzyE0EtN0D0Tzu0StCtDzyzztN1L2XzutAtFyCtFyCtFtDtN1L1Czu2Z1E1I1V1L1Q1T1Q1Q2UtN1L1G1B1V1N2Y1L1Qzu2SyDtCtAtByEtA0BzytG0D0DyC0DtGtCzy0CyBtGyDtByD0DtGtDyEyCyC0AyDyCyB0D0DtCyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDyCyB0FyCzztByEtGyB0F0BtAtGyEtC0FzztG0AyB0DtAtGyDtC0EzyyBzyyB0EzzyBtDyD2Q&cr=519532889&ir=
[C:\Users\Windows8\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : lfkjojacgdjkninepeghaamnapdjmlfn
 
*************************
 
C:\AdwCleaner\AdwCleaner[S1].txt - [7281 bytes] - [30/05/2016 16:02:35]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7354 bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 8.1 x64 
Ran by [removed] (Administrator) on Mon 05/30/2016 at 16:07:18.86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 8 
 
Successfully deleted: C:\ProgramData\iobit\driver booster (Folder) 
Successfully deleted: C:\ProgramData\productdata (Folder) 
Successfully deleted: C:\Users\Windows8\AppData\Roaming\iobit\driver booster (Folder) 
Successfully deleted: C:\Users\Windows8\AppData\Roaming\productdata (Folder) 
Successfully deleted: C:\WINDOWS\system32\Tasks\PCDoctorBackgroundMonitorTask (Task)
Successfully deleted: C:\WINDOWS\prefetch\DRIVER BOOSTER.TMP-93B53C7B.pf (File) 
Successfully deleted: C:\WINDOWS\prefetch\DRIVERBOOSTER.EXE-96C4BAB3.pf (File) 
Successfully deleted: C:\WINDOWS\prefetch\DRIVERUPDATE.EXE-7973A8B6.pf (File) 
 
 
 
Registry: 4 
 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0F4D66F3-7CE2-49F0-BC37-4A0711EBE9C0} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{589B893E-773C-4941-88C2-0DCC718E621C} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page (Registry Value) 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 05/30/2016 at 16:08:13.04
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI