This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Is it time for a new computer, mine is running VERY slow [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-07-2016
Ran by [removed] (administrator) on MICH-PC (16-07-2016 08:54:24)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\iTunes\iTunes.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\ATH.exe
(Google Inc.) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Users\Mich\AppData\Local\Temp\~nsu.tmp\Au_.exe
(AVAST Software) C:\Users\Mich\Downloads\aswMBR.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\…\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM\…\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3666800 2011-01-21] (Dell Inc.)
HKLM\…\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\…\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-07-27] (Intel(R) Corporation)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\…\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-06-01] (Apple Inc.)
HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\…\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\…\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [520330 2011-08-12] (Creative Technology Ltd)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-04-22] (Apple Inc.)
HKLM-x32\…\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [Google Update] => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [Facebook Update] => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.)
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [MobileDocuments] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-04-22] (Apple Inc.)
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-04-22] (Apple Inc.)
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2016-07-03] (SUPERAntiSpyware)
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\MountPoints2: E - E:\LaunchU3.exe -a
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\PhotoScreensaver.scr [477696 2010-11-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
Tcpip\..\Interfaces\{33E5BA2A-21AA-4562-B886-E625191AA1AB}: [DhcpNameServer] 75.75.76.76 75.75.75.75
Tcpip\..\Interfaces\{49E7CA06-D35A-45A5-9469-04120A7E9A08}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{C311A143-18DE-454E-B30E-5A6CAF40F3AA}: [DhcpNameServer] 75.75.76.76 75.75.75.75
 
Internet Explorer:
==================
SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {C26464FC-6658-404B-B6A4-9D64D370854D} URL = 
SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=DLCDF8&pc;=MDDC&src;=IE-SearchBox
BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL => No File
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-05-17] (Microsoft Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120625173408.dll => No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-04-12] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-05] (Sun Microsystems, Inc.)
BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\progra~1\mcafee\msk\mskapbho.dll => No File
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-05-17] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-21] (Oracle Corporation)
BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120625173408.dll => No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-04-12] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-21] (Oracle Corporation)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-19] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] ()
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-10-05] (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-21] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-25] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3254994897-3864387644-3395939058-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mich\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-3254994897-3864387644-3395939058-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-3254994897-3864387644-3395939058-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF HKLM-x32\…\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://facebook.com/
CHR Profile: C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-05]
CHR Extension: (Google Docs) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-05]
CHR Extension: (Google Drive) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Google Sheets) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-05]
CHR Extension: (Google Docs Offline) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (AdBlock) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-07-06]
CHR Extension: (Viralands Age Verify) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfjjinndcdohhjckcokpfkihdogegfib [2016-02-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-27]
StartMenuInternet: Google Chrome - C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
StartMenuInternet: Google Chrome.VQDWRR5IBQ3J6QZM2SXDUIVFTM - C:\Users\Ed\AppData\Local\Google\Chrome\Application\chrome.exe
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [921664 2011-05-19] (Intel Corporation) [File not signed]
R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1335360 2011-05-19] (Intel Corporation) [File not signed]
R2 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [995392 2011-05-19] (Intel Corporation) [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe [76616 2016-06-20] (Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3009776 2016-05-27] (Microsoft Corporation)
S2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [210808 2015-02-10] (Dell Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-07-27] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
U3 aswMBR; \??\C:\Users\Mich\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Mich\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-07-16 08:54 - 2016-07-16 08:55 - 00023484 _____ C:\Users\Mich\Downloads\FRST.txt
2016-07-16 08:53 - 2016-07-16 08:54 - 00000000 ____D C:\FRST
2016-07-16 08:53 - 2016-07-16 08:53 - 02391040 _____ (Farbar) C:\Users\Mich\Downloads\FRST64.exe
2016-07-16 08:50 - 2016-07-16 08:50 - 00000613 _____ C:\Users\Mich\Desktop\aswMBR.txt
2016-07-16 08:38 - 2016-07-16 08:38 - 05198336 _____ (AVAST Software) C:\Users\Mich\Downloads\aswMBR.exe
2016-07-15 20:28 - 2016-07-15 20:28 - 00170151 _____ C:\Users\Mich\Downloads\e61638df-9b5d-46eb-b17f-6f448b9b112f_268674.pdf
2016-07-14 19:59 - 2016-07-14 19:59 - 00000000 ____D C:\Program Files (x86)\Dell Update
2016-07-12 20:24 - 2016-06-11 00:48 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-07-12 20:24 - 2016-06-10 17:19 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-07-12 20:24 - 2016-06-10 17:08 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-07-12 20:24 - 2016-06-10 17:03 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-07-12 20:24 - 2016-06-10 16:40 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-07-12 20:24 - 2016-06-10 16:38 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2016-07-12 20:24 - 2016-06-10 16:13 - 00724992 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-07-12 20:24 - 2016-06-10 14:53 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-07-12 20:24 - 2016-06-10 14:53 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-07-12 20:24 - 2016-06-10 14:52 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-07-12 20:24 - 2016-06-10 14:45 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-07-12 20:24 - 2016-06-10 14:42 - 20348928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-07-12 20:24 - 2016-06-10 14:27 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-07-12 20:24 - 2016-06-10 14:26 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2016-07-12 20:24 - 2016-06-10 14:23 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-07-12 20:24 - 2016-06-10 14:21 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-07-12 20:24 - 2016-06-10 14:19 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-07-12 20:24 - 2016-06-10 14:10 - 00692736 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-07-12 20:24 - 2016-06-10 13:41 - 01315840 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-07-12 20:23 - 2016-06-11 02:57 - 00394448 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-07-12 20:23 - 2016-06-10 17:38 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-07-12 20:23 - 2016-06-10 17:38 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-07-12 20:23 - 2016-06-10 17:20 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-07-12 20:23 - 2016-06-10 17:19 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-07-12 20:23 - 2016-06-10 17:18 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-07-12 20:23 - 2016-06-10 17:18 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-07-12 20:23 - 2016-06-10 17:17 - 02895360 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-07-12 20:23 - 2016-06-10 17:10 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-07-12 20:23 - 2016-06-10 17:05 - 25814016 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-07-12 20:23 - 2016-06-10 17:04 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-07-12 20:23 - 2016-06-10 17:03 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-07-12 20:23 - 2016-06-10 17:02 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-07-12 20:23 - 2016-06-10 17:02 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-07-12 20:23 - 2016-06-10 16:53 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-07-12 20:23 - 2016-06-10 16:50 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-07-12 20:23 - 2016-06-10 16:49 - 06047744 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-07-12 20:23 - 2016-06-10 16:35 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-07-12 20:23 - 2016-06-10 16:34 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-07-12 20:23 - 2016-06-10 16:31 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-07-12 20:23 - 2016-06-10 16:28 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-07-12 20:23 - 2016-06-10 16:15 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-07-12 20:23 - 2016-06-10 16:12 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-07-12 20:23 - 2016-06-10 16:11 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-07-12 20:23 - 2016-06-10 16:10 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-07-12 20:23 - 2016-06-10 15:45 - 15409664 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-07-12 20:23 - 2016-06-10 15:44 - 02869248 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-07-12 20:23 - 2016-06-10 15:30 - 01550848 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-07-12 20:23 - 2016-06-10 15:21 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-07-12 20:23 - 2016-06-10 15:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-07-12 20:23 - 2016-06-10 14:54 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-07-12 20:23 - 2016-06-10 14:53 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-07-12 20:23 - 2016-06-10 14:47 - 02287104 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-07-12 20:23 - 2016-06-10 14:46 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-07-12 20:23 - 2016-06-10 14:42 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-07-12 20:23 - 2016-06-10 14:41 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-07-12 20:23 - 2016-06-10 14:41 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-07-12 20:23 - 2016-06-10 14:41 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-07-12 20:23 - 2016-06-10 14:32 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-07-12 20:23 - 2016-06-10 14:24 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-07-12 20:23 - 2016-06-10 14:14 - 04608000 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-07-12 20:23 - 2016-06-10 14:12 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-07-12 20:23 - 2016-06-10 14:09 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-07-12 20:23 - 2016-06-10 14:09 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-07-12 20:23 - 2016-06-10 13:58 - 13806080 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-07-12 20:23 - 2016-06-10 13:45 - 02392576 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-07-12 20:23 - 2016-06-10 13:42 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-07-12 20:22 - 2016-06-25 20:35 - 00041704 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-07-12 20:22 - 2016-06-25 20:27 - 01208320 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-07-12 20:22 - 2016-06-25 20:27 - 00970240 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2016-07-12 20:22 - 2016-06-25 20:27 - 00756736 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2016-07-12 20:22 - 2016-06-25 20:27 - 00344576 _____ (Microsoft Corporation) C:\windows\system32\ntprint.dll
2016-07-12 20:22 - 2016-06-25 20:27 - 00166400 _____ (Microsoft Corporation) C:\windows\system32\inetpp.dll
2016-07-12 20:22 - 2016-06-25 20:27 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\inetppui.dll
2016-07-12 20:22 - 2016-06-25 15:54 - 00497152 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2016-07-12 20:22 - 2016-06-25 15:53 - 00297472 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.dll
2016-07-12 20:22 - 2016-06-25 15:53 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\ntprint.exe
2016-07-12 20:22 - 2016-06-25 15:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wpnpinst.exe
2016-07-12 20:22 - 2016-06-25 15:41 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.exe
2016-07-12 20:22 - 2016-06-22 09:06 - 00268800 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2016-07-12 20:22 - 2016-06-17 14:24 - 01490432 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-07-12 20:22 - 2016-06-17 14:24 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-07-12 20:22 - 2016-06-17 14:24 - 00544256 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-07-12 20:22 - 2016-06-17 14:24 - 00294912 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-07-12 20:22 - 2016-06-17 14:24 - 00219136 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2016-07-12 20:22 - 2016-06-17 14:24 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-07-12 20:22 - 2016-06-14 11:03 - 03217408 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-07-04 12:36 - 2016-07-04 12:36 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair (1).exe
2016-07-04 12:34 - 2016-07-16 08:24 - 00000000 ____D C:\Program Files\Reimage
2016-07-04 12:34 - 2016-07-04 16:30 - 00000121 _____ C:\windows\Reimage.ini
2016-07-04 12:34 - 2016-07-04 12:34 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-07-16 08:51 - 2011-10-10 12:20 - 00000904 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job
2016-07-16 08:40 - 2009-07-14 00:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-07-16 08:40 - 2009-07-14 00:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-07-16 08:37 - 2013-04-04 19:58 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-16 08:31 - 2014-06-23 04:54 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-07-16 08:29 - 2011-10-10 18:41 - 00000924 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job
2016-07-16 08:25 - 2012-10-27 09:57 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-07-15 21:37 - 2013-04-04 19:58 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-07-15 17:29 - 2011-10-10 18:41 - 00000902 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job
2016-07-15 16:51 - 2011-10-10 12:20 - 00000852 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job
2016-07-15 09:41 - 2016-03-26 15:23 - 00003484 _____ C:\windows\System32\Tasks\PCDEventLauncherTask
2016-07-14 20:00 - 2009-07-14 01:13 - 00783424 _____ C:\windows\system32\PerfStringBackup.INI
2016-07-14 20:00 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf
2016-07-14 19:59 - 2013-10-19 16:17 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-07-14 19:59 - 2011-10-05 12:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DELL
2016-07-14 19:56 - 2011-10-05 13:15 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2016-07-14 19:55 - 2011-10-05 13:26 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2016-07-14 19:55 - 2011-10-05 13:26 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2016-07-14 19:54 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-07-14 10:25 - 2012-10-27 09:57 - 00796352 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-07-14 10:25 - 2012-10-27 09:57 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-07-14 10:25 - 2012-10-27 09:57 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2016-07-13 04:28 - 2009-07-13 23:20 - 00000000 ____D C:\windows\rescache
2016-07-13 03:40 - 2009-07-14 00:45 - 00489376 _____ C:\windows\system32\FNTCACHE.DAT
2016-07-13 03:36 - 2013-07-12 19:44 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2016-07-13 03:34 - 2014-12-10 04:21 - 00000000 ____D C:\windows\system32\appraiser
2016-07-13 03:34 - 2011-10-05 15:07 - 00000000 ____D C:\Program Files\Windows Journal
2016-07-13 03:17 - 2013-08-15 03:01 - 00000000 ____D C:\windows\system32\MRT
2016-07-13 03:04 - 2011-10-10 11:47 - 144749672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-07-12 20:38 - 2013-04-04 19:58 - 00000000 ____D C:\Program Files (x86)\Google
2016-07-12 06:25 - 2012-10-27 09:57 - 00000000 ____D C:\windows\system32\Macromed
2016-07-12 06:25 - 2011-10-05 12:23 - 00000000 ____D C:\windows\SysWOW64\Macromed
2016-06-30 19:42 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-06-30 19:42 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-06-24 13:00 - 2015-01-29 19:05 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-06-24 12:59 - 2015-01-29 19:04 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-06-24 03:02 - 2013-03-14 03:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-06-21 12:13 - 2010-11-20 23:27 - 00485032 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2016-06-17 20:53 - 2011-10-10 12:21 - 00002374 _____ C:\Users\Mich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-17 20:53 - 2011-10-10 12:21 - 00002366 _____ C:\Users\Mich\Desktop\Google Chrome.lnk
 
==================== Files in the root of some directories =======
 
2011-10-11 17:33 - 2016-05-15 13:18 - 0006144 _____ () C:\Users\Mich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
Some files in TEMP:
====================
C:\Users\Mich\AppData\Local\Temp\aulauncher.exe
C:\Users\Mich\AppData\Local\Temp\BackupSetup.exe
C:\Users\Mich\AppData\Local\Temp\criminalminds-510006264-setup.s510006264.c110268333.len.u.dl.exe
C:\Users\Mich\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Mich\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Mich\AppData\Local\Temp\ghostwhisperer-510006920-setup.s510006920.c110268333.len.u.dl.exe
C:\Users\Mich\AppData\Local\Temp\GURAE96.exe
C:\Users\Mich\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Mich\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\Mich\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Mich\AppData\Local\Temp\ReimagePackage.exe
C:\Users\Mich\AppData\Local\Temp\SAS6_Update.exe
C:\Users\Mich\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Mich\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\Mich\AppData\Local\Temp\setup32.exe
C:\Users\Mich\AppData\Local\Temp\sqlite3.exe
C:\Users\Mich\AppData\Local\Temp\TUUUninstallHelper.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-07-07 00:58
 

==================== End of FRST.txt ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-07-2016
Ran by [removed] (2016-07-16 08:56:07)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2011-10-10 15:18:52)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3254994897-3864387644-3395939058-500 - Administrator - Disabled)
Ed (S-1-5-21-3254994897-3864387644-3395939058-1001 - Administrator - Enabled) => C:\Users\Ed
Guest (S-1-5-21-3254994897-3864387644-3395939058-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3254994897-3864387644-3395939058-1004 - Limited - Enabled)
Mich (S-1-5-21-3254994897-3864387644-3395939058-1000 - Administrator - Enabled) => C:\Users\Mich
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 22 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 22.0.0.210 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Adobe Reader X (10.1.16) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Apple Application Support (32-bit) (HKLM-x32\…\{26356515-5821-40FA-9C3D-9785052A1062}) (Version: 4.3.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{C2651553-6CA3-4822-B2E6-BC4ACA6E0EA2}) (Version: 4.3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Chrome Remote Desktop Host (HKLM-x32\…\{159AA592-31AA-4EAC-A6CB-B47AB2CB1476}) (Version: 52.0.2743.48 - Google Inc.)
Consumer In-Home Service Agreement (HKLM-x32\…\{F47C37A4-7189-430A-B81D-739FF8A7A554}) (Version: 2.0.0 - Dell Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell Inc.)
Dell DataSafe Local Backup (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell Inc.)
Dell DataSafe Online (HKLM-x32\…\{C53BCCBE-9268-4C09-82E9-611444A73B3F}) (Version: 2.10.1.3 - Dell)
Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell MusicStage (HKLM-x32\…\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
Dell Perks Webslice IE8 (HKLM-x32\…\{CF67ED0C-F85D-4791-AED3-3FE882EDB45D}) (Version: 8.0 - Nextjump Inc)
Dell PhotoStage (HKLM-x32\…\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
Dell Stage (HKLM-x32\…\{FE182796-F6BA-486A-8590-89B7E8D1D60F}) (Version: 1.7.209.0 - Fingertapps)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell)
Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.)
Dell Update (HKLM-x32\…\{3F862535-33F3-4F3F-864E-6D4F6FD3258D}) (Version: 1.5.2000.0 - Dell Inc.)
Dell VideoStage  (HKLM-x32\…\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
Dell VideoStage  (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden
Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 2.00.46 - Creative Technology Ltd)
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
Facebook Video Calling 1.2.0.287 (HKLM-x32\…\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Google Chrome (HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Google Chrome) (Version: 51.0.2704.103 - Google Inc.)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
GoToAssist 8.0.0.514 (HKLM-x32\…\GoToAssist) (Version:  - )
iCloud (HKLM\…\{ADFDB647-35C0-4254-9EE6-2D9C3B7104BD}) (Version: 5.2.1.69 - Apple Inc.)
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2361 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.2.0.0587 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\…\{25FBDA9A-E868-4B3B-B9FF-D923818511A1}) (Version: 14.2.0000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
Intel(R) WiDi (HKLM-x32\…\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Internet Explorer (x32 Version: 8 - Microsoft Corporation) Hidden
iTunes (HKLM\…\{9F4BF859-C3A4-4AB6-BDD1-9C5D58188598}) (Version: 12.4.1.6 - Apple Inc.)
Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.670 - Oracle)
Java 8 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Java(TM) 6 Update 27 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86416027FF}) (Version: 6.0.270 - Oracle)
Java(TM) 6 Update 27 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216027FF}) (Version: 6.0.270 - Oracle)
JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 15.0.4833.1001 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\…\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.09.20 - Dell Inc.)
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Roxio Creator Starter (HKLM-x32\…\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Safari (HKLM-x32\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1200 - SUPERAntiSpyware.com)
TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.41110 - TeamViewer)
TrustedID (HKLM-x32\…\{C16A92EF-017B-4839-9C75-FBADB5A1FA27}) (Version: 5.0 - TrustedID)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {097891E7-A1FA-45DB-8970-D66BEA02FE26} - System32\Tasks\{2D167E16-22C5-47C5-B428-2DD72CB1E184} => C:\Program Files (x86)\iTunes\iTunes.exe
Task: {117D1711-A022-4A6C-B4E8-25F0E70A79AB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {395C42C4-DB74-4B8E-9493-801F74C730BE} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2016-03-24] (PC-Doctor, Inc.)
Task: {3E51C7F5-752B-4C3B-9687-86278CFA42A0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-04-12] (Microsoft Corporation)
Task: {40A12098-818A-400A-9F40-F5E9FFE4E0D3} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
Task: {5C50D41F-9E7C-47AF-B4F5-CEDB97BF8194} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-14] (Adobe Systems Incorporated)
Task: {66397D50-9156-499A-896B-46BE59613F40} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {685A250F-1A02-4E24-9D1E-DFA18EE5FB3C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {6FE65E53-3E23-440D-9149-D7B66E903213} - System32\Tasks\{5805F2ED-FCF7-4132-A918-604FC3F9E978} => C:\Program Files (x86)\iTunes\iTunes.exe
Task: {7610959A-0C0A-4EC7-9C23-2A62418BDDA4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated)
Task: {8F515F50-F1AB-492D-B156-7284870B3DF0} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {9986ADE0-77F3-45DD-BD5E-530D77B27D5D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
Task: {9EEF7C7A-ECBC-47D8-9E0E-CF0F3DCDEE35} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-04-12] (Microsoft Corporation)
Task: {A08DF513-C0B6-48A9-9AC9-596ED754260F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {A67037A5-1A1D-40AD-BCA7-19F7A55AA16B} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
Task: {ABBE246E-B21C-4430-90CB-C179E73660A8} - System32\Tasks\{3BD868C2-52A2-4F77-BDB6-F769CA421241} => C:\Program Files (x86)\iTunes\iTunes.exe
Task: {C8633B7F-E5D4-451A-B1C5-72B27FCBF613} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {D60C9C31-436B-41C9-9CC8-57E773663A9F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
Task: {DFF5618D-9BF3-4CE0-BCDA-6D2E77CF00C0} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2016-03-24] (PC-Doctor, Inc.)
Task: {FE337633-7008-4FE4-9030-E6D12F8225ED} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1001Core1cf16c338b4de59.job => C:\Users\Ed\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1001Core1d163702fefa5a5.job => C:\Users\Ed\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2011-07-27 21:07 - 2011-07-27 21:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-04-22 01:07 - 2016-04-22 01:07 - 01337144 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-23 18:30 - 2016-04-19 19:26 - 00114888 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-10-27 18:14 - 2015-09-01 12:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2011-10-05 14:51 - 2011-04-10 14:40 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-07-27 21:07 - 2011-07-27 21:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2016-04-22 01:07 - 2016-04-22 01:07 - 00313656 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
2010-11-17 11:35 - 2010-11-17 11:35 - 00514544 _____ () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
2012-02-01 11:50 - 2012-02-01 11:50 - 00968048 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
2011-10-05 13:15 - 2011-08-18 11:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
2016-07-16 08:22 - 2016-06-15 09:05 - 00195384 _____ () C:\Users\Mich\AppData\Local\Temp\~nsu.tmp\Au_.exe
2016-04-22 01:08 - 2016-04-22 01:08 - 01047864 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2016-04-22 01:07 - 2016-04-22 01:07 - 00244024 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2015-10-27 18:14 - 2015-09-01 08:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2010-11-24 23:44 - 2010-11-24 23:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 08151040 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 02278400 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
2016-05-11 03:58 - 2016-05-11 03:58 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f1b815cf32572cea383bc47659c174fa\IsdiInterop.ni.dll
2011-10-05 12:23 - 2010-11-06 00:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2016-06-17 20:53 - 2016-06-15 05:15 - 01745560 _____ () C:\Users\Mich\AppData\Local\Google\Chrome\Application\51.0.2704.103\libglesv2.dll
2016-06-17 20:53 - 2016-06-15 05:15 - 00091288 _____ () C:\Users\Mich\AppData\Local\Google\Chrome\Application\51.0.2704.103\libegl.dll
2016-07-12 20:02 - 2016-07-06 18:01 - 17602240 _____ () C:\Users\Mich\AppData\Local\Google\Chrome\User Data\PepperFlash\22.0.0.209\pepflashplayer.dll
2016-07-16 08:32 - 2016-07-16 08:32 - 00011264 _____ () C:\Users\Mich\AppData\Local\Temp\nsy70F5.tmp\System.dll
2016-07-16 08:32 - 2016-07-16 08:32 - 00045056 _____ () C:\Users\Mich\AppData\Local\Temp\nsy70F5.tmp\LogEx.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Mich\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.76.76 - 75.75.75.75
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{BFAC85B0-8458-4635-94CC-83A71DC1E9A1}] => (Allow) C:\Program Files (x86)\Dell\VideoStage\VideoStage.exe
FirewallRules: [{63749035-E4F4-49C1-93D6-7B526AAE54E8}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{0AE6250A-9076-4119-8D1C-313658FAF41C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{E3700119-20EE-4A61-8379-AB2D04961576}] => (Allow) LPort=2869
FirewallRules: [{868AE0DC-FD64-4385-B800-A40EBD0CFABA}] => (Allow) LPort=1900
FirewallRules: [{78BCDD1A-F795-4CB1-B1F2-09E08D877F96}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{2E6ECBED-8325-4F01-88CC-AC3CCCC13D7B}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{A6987437-93DE-4931-9445-DCE8D0958236}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{30B7EBC9-6171-4221-885C-377CDDD95E7C}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{822A5918-FE4D-4B68-9601-EFFDD37B9C55}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe
FirewallRules: [{1B672475-D4A1-48D2-BDD3-D5B4CC23F8FA}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe
FirewallRules: [{FED9AF36-06B6-4830-B7DC-D000B53C432B}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe
FirewallRules: [TCP Query User{5FD1672C-3261-4E85-82F8-CD604EF6F4AA}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Block) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
FirewallRules: [UDP Query User{B3087126-2230-4409-829A-464E08D2E240}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Block) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
FirewallRules: [{6E5EC36A-F0A1-46B1-9E2E-3FE5623A4B60}] => (Allow) C:\Users\Mich\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{146E5909-93C0-4539-986D-858A2F3B5329}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
FirewallRules: [{D985C636-0CC9-4FE5-BE99-6B48AFD7D0D8}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
FirewallRules: [{F5733F38-9E8C-4646-9800-F5A8BCB11B4D}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
FirewallRules: [{46DE42C5-B5B3-4F9C-9DF9-CFF327F9F33D}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
FirewallRules: [{34ACAADB-3377-4A2E-AB01-29D27DCEFEAE}] => (Allow) C:\Users\Mich\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
FirewallRules: [{E9330290-048B-4256-B495-9CC09CC1D6C2}] => (Allow) C:\Users\Mich\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
FirewallRules: [TCP Query User{84AD8C05-C7DC-44A5-9FCC-89EB386296C3}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Allow) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
FirewallRules: [UDP Query User{94DF4912-4D2C-4FC2-BAF5-654E8FF9C59F}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Allow) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
FirewallRules: [{428720FC-EBFE-4828-94EE-8F68ADEC696C}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{9CB3C3A6-F2E9-4DCE-A8D3-E7810174BD76}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{ECCB822C-B4B6-40A0-8F08-643EDC2FCF82}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{4B64EF89-C1D8-497F-B832-E18E95414525}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{9C2DAFEB-8B04-4C33-A815-2A3ED289734B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{40AD4E30-A8D1-4B12-BD5C-25D533271C5A}] => (Allow) C:\Users\Mich\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{876DE33A-54E1-41CF-B24D-12F5F6D4FBF8}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{465C6FE1-B4DF-40C1-80DA-9AEE28683E31}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{C764FCAC-A31D-4782-A153-EDBD7DCB2B2C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{2BD5A315-B67F-4DA0-9367-884A4656DF2A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{28177821-4C83-4DD0-9D96-35E889D7A97B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{AEEEC527-1AF1-4CE4-9A6E-C759E5A6B125}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{1A5D74F3-99DF-4E38-AB70-21024131FD26}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{DB2565B0-5C5F-462C-B724-6D1B166FC15D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7A335D39-6869-4047-9417-D2D4187D0390}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{743159AE-6E05-4216-8D1F-2A4A2D11C9FC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3A71DA86-10CB-4496-AA6B-8268FEEF22DD}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BFD96DFD-C0F4-4248-BC24-54D01D4AD45D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{B0233BAC-818D-42D8-A7A3-718996A77CE3}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{972A8CF8-3C8F-4CEE-A11F-C9794559CBD6}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{0DE8E662-189D-4F65-BE0A-3D5A9D1EAD6B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{A8943CCB-B949-4AA6-B9FB-9A4DD4032650}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{B35F8DB5-9AC8-4FF7-8CAD-C4600216D9F5}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe
 
==================== Restore Points =========================
 
01-07-2016 05:01:55 Windows Update
05-07-2016 03:50:30 Windows Update
08-07-2016 04:20:16 Windows Update
11-07-2016 21:48:31 Windows Update
13-07-2016 03:00:12 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/16/2016 01:25:54 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (07/15/2016 06:28:24 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (07/15/2016 05:42:00 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (07/14/2016 07:59:21 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
Description: Product: Dell Update – The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738. The arguments are: , ,
 
Error: (07/14/2016 07:55:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (07/14/2016 11:21:58 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (07/13/2016 05:05:36 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
Description: Product: Dell Update – The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738. The arguments are: , ,
 
Error: (07/13/2016 04:16:59 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 90080108
 
Error: (07/13/2016 03:24:28 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80004005
 
Error: (07/13/2016 03:40:35 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
 
System errors:
=============
Error: (07/14/2016 07:59:21 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{33E5BA2A-21AA-4562-B886-E625191AA1AB}.
The backup browser is stopping.
 
Error: (07/14/2016 07:56:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (07/14/2016 07:54:55 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
 
Error: (07/13/2016 05:03:58 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TeamViewer9 service.
 
Error: (07/13/2016 05:03:27 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
 
Error: (07/13/2016 03:44:15 AM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{33E5BA2A-21AA-4562-B886-E625191AA1AB}.
The backup browser is stopping.
 
Error: (07/13/2016 03:41:59 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
 
Error: (07/06/2016 06:29:06 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{33E5BA2A-21AA-4562-B886-E625191AA1AB}.
The backup browser is stopping.
 
Error: (07/06/2016 06:02:19 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the chromoting service.
 
Error: (07/03/2016 07:46:59 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{33E5BA2A-21AA-4562-B886-E625191AA1AB}.
The backup browser is stopping.
 
 
CodeIntegrity:
===================================
  Date: 2015-08-16 15:41:58.239
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-16 15:41:57.789
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-16 15:41:57.242
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-16 15:41:56.837
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-10-26 05:01:31.909
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\McAfee\Temp\qxzEEDB\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-10-26 05:01:31.904
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\McAfee\Temp\qxzEEDB\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-10-26 05:01:31.902
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\McAfee\Temp\qxzEEDB\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz
Percentage of memory in use: 58%
Total physical RAM: 6051.17 MB
Available physical RAM: 2482.31 MB
Total Virtual: 12100.53 MB
Available Virtual: 7944.85 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:441.74 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: BA3A09FA)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=581.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

:welcome:

 

Looking at a few things that may be bad. This is installed but its not listed in Programs and Features so it can be removed

C:\Program Files\Reimage

 

Lets run a few programs and lets see what they remove and we can go from there

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
 
 
[external image: MBAM220_zpsox89gdej.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes

 

 

 

# AdwCleaner v5.201 - Logfile created 16/07/2016 at 20:46:25
# Updated 30/06/2016 by ToolsLib
# Database : 2016-07-16.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Mich - MICH-PC
# Running from : C:\Users\Mich\Downloads\AdwCleaner.exe
# Option : Clean
# Support : https://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\ProgramData\Avg_Update_1014avt
[#] Folder Deleted : C:\ProgramData\Application Data\Avg_Update_1014avt
[-] Folder Deleted : C:\Program Files (x86)\Coupons
[-] Folder Deleted : C:\Users\Mich\AppData\Roaming\Avg_Update_1014avt
 
***** [ Files ] *****
 
[-] File Deleted : C:\END
[-] File Deleted : C:\windows\Reimage.ini
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gjkpcnacdgdlpfejlgflolpaigoicibh_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gjkpcnacdgdlpfejlgflolpaigoicibh_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_zynga2-a.akamaihd.net_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_zynga2-a.akamaihd.net_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_land.pckeeper.software_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_land.pckeeper.software_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wtov9.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_wtov9.com_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.shopathome.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.shopathome.com_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wtov9.com_0.localstorage
[-] File Deleted : C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wtov9.com_0.localstorage-journal
 
***** [ DLLs ] *****
 
 
***** [ WMI ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\PIP
[-] Key Deleted : [x64] HKLM\SOFTWARE\Reimage
[-] Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WebCakeUpdaterService
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : search.conduit.com
[-] [C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : fmeemomfelpigklppifflheakfpkfjjg
[-] [C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : gjkpcnacdgdlpfejlgflolpaigoicibh
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : communitymapbuilder.org
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ares.en.softonic.com
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : isearch.avg.com
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : netflix.com_
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : r
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : stubhub.com_
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : netflix.com
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : stubhub.com
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : picasa.en.softonic.com
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : vso-image-resizer.en.softonic.com
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Ed\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [7858 bytes] - [16/07/2016 20:46:25]
C:\AdwCleaner\AdwCleaner[S1].txt - [7861 bytes] - [16/07/2016 20:45:12]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [8004 bytes] ##########

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on Sat 07/16/2016 at 21:07:46.41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 37 
 
Successfully deleted: C:\windows\system32\Tasks\PCDEventLauncherTask (Task)
Successfully deleted: C:\windows\system32\Tasks\PCDoctorBackgroundMonitorTask (Task)
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0HB2NB6Z (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NEQA85I (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6JRZBZ2T (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7O9S63Y9 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TKT0N27 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9VFMWS2T (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A9LHFYQK (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BAE7SI5J (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KDWYMPEL (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LFTUPOCG (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NOKA3ISX (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SDYMZNGA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Mich\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U6I9TSAC (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0HB2NB6Z (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NEQA85I (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6JRZBZ2T (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7O9S63Y9 (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7TKT0N27 (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9VFMWS2T (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A9LHFYQK (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BAE7SI5J (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KDWYMPEL (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LFTUPOCG (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NOKA3ISX (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SDYMZNGA (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U6I9TSAC (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\SysWOW64\sho6DBA.tmp (File) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 07/16/2016 at 21:11:01.63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 7/16/2016
Scan Time: 9:17 PM
Logfile: 
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.07.16.04
Rootkit Database: v2016.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mich
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 396342
Time Elapsed: 26 min, 3 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 2
PUP.Optional.CrossRider, C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, , [dbd943e18119c86e070cf0fa28db44bc], 
PUP.Optional.CrossRider, C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, , [03b13de72c6ea78f15fe7d6d5da6c23e], 
 
Physical Sectors: 0
(No malicious items detected)
 
 

(end)

Good Morning

 

Looks like we removed some bad stuff. When you ran Malwarebytes, did you have it remove both those entries ??   It should show them as QUARANTINED and it does not. 

 

Run the program again
 
  • You can highlight one of the detections by left clicking on it.
  • Then, right click on the highlighted detection, and select 'Check All Items'.
  • Next, click 'Remove Selected'. That should remove them all
  •  
     
     
    After your sure that those two Malwarebytes entries are gone, lets do this
     
    Your running FRST64  from C:\Users\Mich\Downloads, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST64, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST64 exactly where we want it to be.
     
     
    Then on your desktop, right click on FRST64 and select RUN AS ADMINISTRATOR. When it opens, make sure to checkmark ADDITIONS,  leave everything else as is.  Then click on SCAN and post both the new FRST64 and Additions logs please.
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-07-2016 02
    Ran by [removed] (administrator) on MICH-PC (17-07-2016 08:09:20)
    Running from C:\Users\[removed]\Desktop
    [removed]
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
     
    ==================== Processes (Whitelisted) =================
     
    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
     
    (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
    (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
    () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
    (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Microsoft Corporation) C:\Windows\System32\msiexec.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
     
     
    ==================== Registry (Whitelisted) ===========================
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
     
    HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
    HKLM\…\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
    HKLM\…\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3666800 2011-01-21] (Dell Inc.)
    HKLM\…\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
    HKLM\…\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-07-27] (Intel(R) Corporation)
    HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
    HKLM\…\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
    HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-06-01] (Apple Inc.)
    HKLM-x32\…\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
    HKLM-x32\…\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
    HKLM-x32\…\Run: [] => [X]
    HKLM-x32\…\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
    HKLM-x32\…\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
    HKLM-x32\…\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-09-24] (Adobe Systems Incorporated)
    HKLM-x32\…\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [520330 2011-08-12] (Creative Technology Ltd)
    HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-04-22] (Apple Inc.)
    HKLM-x32\…\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
    HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
    Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
    Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [Google Update] => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.)
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [Facebook Update] => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-11] (Facebook Inc.)
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [MobileDocuments] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-04-22] (Apple Inc.)
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-04-22] (Apple Inc.)
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2016-07-03] (SUPERAntiSpyware)
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\MountPoints2: E - E:\LaunchU3.exe -a
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\PhotoScreensaver.scr [477696 2010-11-20] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
     
    ==================== Internet (Whitelisted) ====================
     
    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
     
    Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
    Tcpip\..\Interfaces\{33E5BA2A-21AA-4562-B886-E625191AA1AB}: [DhcpNameServer] 75.75.76.76 75.75.75.75
    Tcpip\..\Interfaces\{49E7CA06-D35A-45A5-9469-04120A7E9A08}: [DhcpNameServer] 172.20.10.1
    Tcpip\..\Interfaces\{C311A143-18DE-454E-B30E-5A6CAF40F3AA}: [DhcpNameServer] 75.75.76.76 75.75.75.75
     
    Internet Explorer:
    ==================
    SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope {C26464FC-6658-404B-B6A4-9D64D370854D} URL = 
    SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    BHO: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL => No File
    BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-05-17] (Microsoft Corporation)
    BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120625173408.dll => No File
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-04-12] (Microsoft Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
    BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-05] (Sun Microsystems, Inc.)
    BHO-x32: McAfee Phishing Filter -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> c:\progra~1\mcafee\msk\mskapbho.dll => No File
    BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-05-17] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-21] (Oracle Corporation)
    BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120625173408.dll => No File
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-04-12] (Microsoft Corporation)
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-21] (Oracle Corporation)
    DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
    DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
    DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab
    Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-19] (Microsoft Corporation)
     
    FireFox:
    ========
    FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] ()
    FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-10-05] (Sun Microsystems, Inc.)
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
    FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-21] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-21] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-25] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-3254994897-3864387644-3395939058-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mich\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
    FF Plugin HKU\S-1-5-21-3254994897-3864387644-3395939058-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
    FF Plugin HKU\S-1-5-21-3254994897-3864387644-3395939058-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
    FF HKLM-x32\…\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found
    FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found
     
    Chrome: 
    =======
    CHR HomePage: Default -> hxxp://facebook.com/
    CHR Profile: C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Slides) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-05]
    CHR Extension: (Google Docs) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-05]
    CHR Extension: (Google Drive) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
    CHR Extension: (YouTube) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
    CHR Extension: (Google Search) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
    CHR Extension: (Google Sheets) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-05]
    CHR Extension: (Google Docs Offline) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
    CHR Extension: (AdBlock) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-07-06]
    CHR Extension: (Viralands Age Verify) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfjjinndcdohhjckcokpfkihdogegfib [2016-02-29]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
    CHR Extension: (Gmail) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-27]
    StartMenuInternet: Google Chrome - C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
    StartMenuInternet: Google Chrome.VQDWRR5IBQ3J6QZM2SXDUIVFTM - C:\Users\Ed\AppData\Local\Google\Chrome\Application\chrome.exe
     
    ==================== Services (Whitelisted) ========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
    R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [921664 2011-05-19] (Intel Corporation) [File not signed]
    R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1335360 2011-05-19] (Intel Corporation) [File not signed]
    R2 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [995392 2011-05-19] (Intel Corporation) [File not signed]
    R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe [76616 2016-06-20] (Google Inc.)
    R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3009776 2016-05-27] (Microsoft Corporation)
    S2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [210808 2015-02-10] (Dell Inc.)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-07-27] ()
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
     
    ===================== Drivers (Whitelisted) ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
     
    ==================== One Month Created files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-07-17 08:09 - 2016-07-17 08:10 - 00022410 _____ C:\Users\Mich\Desktop\FRST.txt
    2016-07-17 08:09 - 2016-07-17 08:09 - 00000000 ____D C:\Users\Mich\Desktop\FRST-OlderVersion
    2016-07-17 08:02 - 2016-07-17 08:02 - 00000000 ____D C:\Program Files (x86)\Dell Update
    2016-07-16 21:14 - 2016-07-16 21:15 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
    2016-07-16 21:14 - 2016-07-16 21:14 - 00001108 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2016-07-16 21:14 - 2016-07-16 21:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2016-07-16 21:14 - 2016-07-16 21:14 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-07-16 21:14 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
    2016-07-16 21:14 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
    2016-07-16 21:14 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
    2016-07-16 21:13 - 2016-07-16 21:14 - 22851472 _____ (Malwarebytes ) C:\Users\Mich\Downloads\mbam-setup-2.2.1.1043.exe
    2016-07-16 21:11 - 2016-07-16 21:11 - 00006347 _____ C:\Users\Mich\Desktop\JRT.txt
    2016-07-16 21:06 - 2016-07-16 21:06 - 01610560 _____ (Malwarebytes) C:\Users\Mich\Downloads\JRT.exe
    2016-07-16 20:44 - 2016-07-16 20:46 - 00000000 ____D C:\AdwCleaner
    2016-07-16 20:43 - 2016-07-16 20:43 - 03712064 _____ C:\Users\Mich\Downloads\AdwCleaner.exe
    2016-07-16 08:56 - 2016-07-16 08:56 - 00040393 _____ C:\Users\Mich\Downloads\Addition.txt
    2016-07-16 08:54 - 2016-07-16 08:56 - 00041028 _____ C:\Users\Mich\Downloads\FRST.txt
    2016-07-16 08:53 - 2016-07-17 08:09 - 02391040 _____ (Farbar) C:\Users\Mich\Desktop\FRST64.exe
    2016-07-16 08:53 - 2016-07-17 08:09 - 00000000 ____D C:\FRST
    2016-07-16 08:50 - 2016-07-16 08:50 - 00000613 _____ C:\Users\Mich\Desktop\aswMBR.txt
    2016-07-16 08:38 - 2016-07-16 08:38 - 05198336 _____ (AVAST Software) C:\Users\Mich\Downloads\aswMBR.exe
    2016-07-15 20:28 - 2016-07-15 20:28 - 00170151 _____ C:\Users\Mich\Downloads\e61638df-9b5d-46eb-b17f-6f448b9b112f_268674.pdf
    2016-07-12 20:24 - 2016-06-11 00:48 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
    2016-07-12 20:24 - 2016-06-10 17:19 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
    2016-07-12 20:24 - 2016-06-10 17:08 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
    2016-07-12 20:24 - 2016-06-10 17:03 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
    2016-07-12 20:24 - 2016-06-10 16:40 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
    2016-07-12 20:24 - 2016-06-10 16:38 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
    2016-07-12 20:24 - 2016-06-10 16:13 - 00724992 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
    2016-07-12 20:24 - 2016-06-10 14:53 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
    2016-07-12 20:24 - 2016-06-10 14:53 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
    2016-07-12 20:24 - 2016-06-10 14:52 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
    2016-07-12 20:24 - 2016-06-10 14:45 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
    2016-07-12 20:24 - 2016-06-10 14:42 - 20348928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
    2016-07-12 20:24 - 2016-06-10 14:27 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
    2016-07-12 20:24 - 2016-06-10 14:26 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
    2016-07-12 20:24 - 2016-06-10 14:23 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
    2016-07-12 20:24 - 2016-06-10 14:21 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
    2016-07-12 20:24 - 2016-06-10 14:19 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
    2016-07-12 20:24 - 2016-06-10 14:10 - 00692736 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
    2016-07-12 20:24 - 2016-06-10 13:41 - 01315840 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
    2016-07-12 20:23 - 2016-06-11 02:57 - 00394448 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
    2016-07-12 20:23 - 2016-06-10 17:38 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
    2016-07-12 20:23 - 2016-06-10 17:38 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
    2016-07-12 20:23 - 2016-06-10 17:20 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
    2016-07-12 20:23 - 2016-06-10 17:19 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
    2016-07-12 20:23 - 2016-06-10 17:18 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
    2016-07-12 20:23 - 2016-06-10 17:18 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
    2016-07-12 20:23 - 2016-06-10 17:17 - 02895360 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
    2016-07-12 20:23 - 2016-06-10 17:10 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
    2016-07-12 20:23 - 2016-06-10 17:05 - 25814016 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
    2016-07-12 20:23 - 2016-06-10 17:04 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
    2016-07-12 20:23 - 2016-06-10 17:03 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
    2016-07-12 20:23 - 2016-06-10 17:02 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
    2016-07-12 20:23 - 2016-06-10 17:02 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
    2016-07-12 20:23 - 2016-06-10 16:53 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
    2016-07-12 20:23 - 2016-06-10 16:50 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
    2016-07-12 20:23 - 2016-06-10 16:49 - 06047744 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
    2016-07-12 20:23 - 2016-06-10 16:35 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
    2016-07-12 20:23 - 2016-06-10 16:34 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
    2016-07-12 20:23 - 2016-06-10 16:31 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
    2016-07-12 20:23 - 2016-06-10 16:28 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
    2016-07-12 20:23 - 2016-06-10 16:15 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
    2016-07-12 20:23 - 2016-06-10 16:12 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
    2016-07-12 20:23 - 2016-06-10 16:11 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
    2016-07-12 20:23 - 2016-06-10 16:10 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
    2016-07-12 20:23 - 2016-06-10 15:45 - 15409664 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
    2016-07-12 20:23 - 2016-06-10 15:44 - 02869248 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
    2016-07-12 20:23 - 2016-06-10 15:30 - 01550848 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
    2016-07-12 20:23 - 2016-06-10 15:21 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
    2016-07-12 20:23 - 2016-06-10 15:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
    2016-07-12 20:23 - 2016-06-10 14:54 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
    2016-07-12 20:23 - 2016-06-10 14:53 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
    2016-07-12 20:23 - 2016-06-10 14:47 - 02287104 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
    2016-07-12 20:23 - 2016-06-10 14:46 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
    2016-07-12 20:23 - 2016-06-10 14:42 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
    2016-07-12 20:23 - 2016-06-10 14:41 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
    2016-07-12 20:23 - 2016-06-10 14:41 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
    2016-07-12 20:23 - 2016-06-10 14:41 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
    2016-07-12 20:23 - 2016-06-10 14:32 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
    2016-07-12 20:23 - 2016-06-10 14:24 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
    2016-07-12 20:23 - 2016-06-10 14:14 - 04608000 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
    2016-07-12 20:23 - 2016-06-10 14:12 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
    2016-07-12 20:23 - 2016-06-10 14:09 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
    2016-07-12 20:23 - 2016-06-10 14:09 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
    2016-07-12 20:23 - 2016-06-10 13:58 - 13806080 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
    2016-07-12 20:23 - 2016-06-10 13:45 - 02392576 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
    2016-07-12 20:23 - 2016-06-10 13:42 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
    2016-07-12 20:22 - 2016-06-25 20:35 - 00041704 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
    2016-07-12 20:22 - 2016-06-25 20:27 - 01208320 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
    2016-07-12 20:22 - 2016-06-25 20:27 - 00970240 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
    2016-07-12 20:22 - 2016-06-25 20:27 - 00756736 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
    2016-07-12 20:22 - 2016-06-25 20:27 - 00344576 _____ (Microsoft Corporation) C:\windows\system32\ntprint.dll
    2016-07-12 20:22 - 2016-06-25 20:27 - 00166400 _____ (Microsoft Corporation) C:\windows\system32\inetpp.dll
    2016-07-12 20:22 - 2016-06-25 20:27 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\inetppui.dll
    2016-07-12 20:22 - 2016-06-25 15:54 - 00497152 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
    2016-07-12 20:22 - 2016-06-25 15:53 - 00297472 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.dll
    2016-07-12 20:22 - 2016-06-25 15:53 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\ntprint.exe
    2016-07-12 20:22 - 2016-06-25 15:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wpnpinst.exe
    2016-07-12 20:22 - 2016-06-25 15:41 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.exe
    2016-07-12 20:22 - 2016-06-22 09:06 - 00268800 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
    2016-07-12 20:22 - 2016-06-17 14:24 - 01490432 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
    2016-07-12 20:22 - 2016-06-17 14:24 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
    2016-07-12 20:22 - 2016-06-17 14:24 - 00544256 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
    2016-07-12 20:22 - 2016-06-17 14:24 - 00294912 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
    2016-07-12 20:22 - 2016-06-17 14:24 - 00219136 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
    2016-07-12 20:22 - 2016-06-17 14:24 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
    2016-07-12 20:22 - 2016-06-14 11:03 - 03217408 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
    2016-07-04 12:36 - 2016-07-04 12:36 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair (1).exe
    2016-07-04 12:34 - 2016-07-04 12:34 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair.exe
     
    ==================== One Month Modified files and folders ========
     
    (If an entry is included in the fixlist, the file/folder will be moved.)
     
    2016-07-17 08:08 - 2009-07-14 00:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-07-17 08:08 - 2009-07-14 00:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-07-17 08:02 - 2011-10-05 12:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DELL
    2016-07-17 08:01 - 2013-04-04 19:58 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    2016-07-17 08:01 - 2011-10-05 13:26 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
    2016-07-17 08:01 - 2011-10-05 13:26 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
    2016-07-17 08:01 - 2011-10-05 13:15 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
    2016-07-17 07:57 - 2013-10-19 16:17 - 00000000 ____D C:\ProgramData\boost_interprocess
    2016-07-17 07:53 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
    2016-07-17 07:51 - 2011-10-10 12:20 - 00000904 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job
    2016-07-17 07:37 - 2013-04-04 19:58 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    2016-07-17 07:25 - 2012-10-27 09:57 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
    2016-07-17 05:29 - 2011-10-10 18:41 - 00000924 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job
    2016-07-16 20:29 - 2009-07-14 01:13 - 00783424 _____ C:\windows\system32\PerfStringBackup.INI
    2016-07-16 20:29 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf
    2016-07-16 20:22 - 2011-10-10 18:41 - 00000902 _____ C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job
    2016-07-16 20:22 - 2011-10-10 12:20 - 00000852 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job
    2016-07-14 10:25 - 2012-10-27 09:57 - 00796352 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
    2016-07-14 10:25 - 2012-10-27 09:57 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
    2016-07-14 10:25 - 2012-10-27 09:57 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
    2016-07-13 04:28 - 2009-07-13 23:20 - 00000000 ____D C:\windows\rescache
    2016-07-13 03:40 - 2009-07-14 00:45 - 00489376 _____ C:\windows\system32\FNTCACHE.DAT
    2016-07-13 03:36 - 2013-07-12 19:44 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
    2016-07-13 03:34 - 2014-12-10 04:21 - 00000000 ____D C:\windows\system32\appraiser
    2016-07-13 03:34 - 2011-10-05 15:07 - 00000000 ____D C:\Program Files\Windows Journal
    2016-07-13 03:17 - 2013-08-15 03:01 - 00000000 ____D C:\windows\system32\MRT
    2016-07-13 03:04 - 2011-10-10 11:47 - 144749672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
    2016-07-12 20:38 - 2013-04-04 19:58 - 00000000 ____D C:\Program Files (x86)\Google
    2016-07-12 06:25 - 2012-10-27 09:57 - 00000000 ____D C:\windows\system32\Macromed
    2016-07-12 06:25 - 2011-10-05 12:23 - 00000000 ____D C:\windows\SysWOW64\Macromed
    2016-06-30 19:42 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2016-06-30 19:42 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2016-06-24 13:00 - 2015-01-29 19:05 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2016-06-24 12:59 - 2015-01-29 19:04 - 00000000 ____D C:\Program Files\Microsoft Office 15
    2016-06-24 03:02 - 2013-03-14 03:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2016-06-21 12:13 - 2010-11-20 23:27 - 00485032 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
    2016-06-17 20:53 - 2011-10-10 12:21 - 00002374 _____ C:\Users\Mich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2016-06-17 20:53 - 2011-10-10 12:21 - 00002366 _____ C:\Users\Mich\Desktop\Google Chrome.lnk
     
    ==================== Files in the root of some directories =======
     
    2011-10-11 17:33 - 2016-05-15 13:18 - 0006144 _____ () C:\Users\Mich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
     
    Some files in TEMP:
    ====================
    C:\Users\Mich\AppData\Local\Temp\aulauncher.exe
    C:\Users\Mich\AppData\Local\Temp\BackupSetup.exe
    C:\Users\Mich\AppData\Local\Temp\criminalminds-510006264-setup.s510006264.c110268333.len.u.dl.exe
    C:\Users\Mich\AppData\Local\Temp\DseShExt-x64.dll
    C:\Users\Mich\AppData\Local\Temp\DseShExt-x86.dll
    C:\Users\Mich\AppData\Local\Temp\ghostwhisperer-510006920-setup.s510006920.c110268333.len.u.dl.exe
    C:\Users\Mich\AppData\Local\Temp\GURAE96.exe
    C:\Users\Mich\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
    C:\Users\Mich\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
    C:\Users\Mich\AppData\Local\Temp\libeay32.dll
    C:\Users\Mich\AppData\Local\Temp\msvcr120.dll
    C:\Users\Mich\AppData\Local\Temp\OfficeSetup.exe
    C:\Users\Mich\AppData\Local\Temp\ReimagePackage.exe
    C:\Users\Mich\AppData\Local\Temp\SAS6_Update.exe
    C:\Users\Mich\AppData\Local\Temp\SDShelEx-win32.dll
    C:\Users\Mich\AppData\Local\Temp\SDShelEx-x64.dll
    C:\Users\Mich\AppData\Local\Temp\setup32.exe
    C:\Users\Mich\AppData\Local\Temp\sqlite3.dll
    C:\Users\Mich\AppData\Local\Temp\sqlite3.exe
    C:\Users\Mich\AppData\Local\Temp\TUUUninstallHelper.exe
     
     
    ==================== Bamital & volsnap =================
     
    (There is no automatic fix for files that do not pass verification.)
     
    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\SysWOW64\wininit.exe => File is digitally signed
    C:\windows\explorer.exe => File is digitally signed
    C:\windows\SysWOW64\explorer.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\SysWOW64\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\SysWOW64\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\SysWOW64\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\dnsapi.dll => File is digitally signed
    C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
     
     
    LastRegBack: 2016-07-17 00:05
     

    ==================== End of FRST.txt ============================

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-07-2016 02
    Ran by [removed] (2016-07-17 08:10:44)
    Running from C:\Users\[removed]\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2011-10-10 15:18:52)
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Accounts: =============================
     
    Administrator (S-1-5-21-3254994897-3864387644-3395939058-500 - Administrator - Disabled)
    Ed (S-1-5-21-3254994897-3864387644-3395939058-1001 - Administrator - Enabled) => C:\Users\Ed
    Guest (S-1-5-21-3254994897-3864387644-3395939058-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3254994897-3864387644-3395939058-1004 - Limited - Enabled)
    Mich (S-1-5-21-3254994897-3864387644-3395939058-1000 - Administrator - Enabled) => C:\Users\Mich
     
    ==================== Security Center ========================
     
    (If an entry is included in the fixlist, it will be removed.)
     
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
     
    ==================== Installed Programs ======================
     
    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
     
    Adobe Flash Player 22 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 22.0.0.210 - Adobe Systems Incorporated)
    Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.16) MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
    Advanced Audio FX Engine (HKLM-x32\…\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
    Apple Application Support (32-bit) (HKLM-x32\…\{26356515-5821-40FA-9C3D-9785052A1062}) (Version: 4.3.1 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\…\{C2651553-6CA3-4822-B2E6-BC4ACA6E0EA2}) (Version: 4.3.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
    Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
    Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
    Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    Chrome Remote Desktop Host (HKLM-x32\…\{159AA592-31AA-4EAC-A6CB-B47AB2CB1476}) (Version: 52.0.2743.48 - Google Inc.)
    Consumer In-Home Service Agreement (HKLM-x32\…\{F47C37A4-7189-430A-B81D-739FF8A7A554}) (Version: 2.0.0 - Dell Inc.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dell DataSafe Local Backup - Support Software (HKLM-x32\…\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell Inc.)
    Dell DataSafe Local Backup (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell Inc.)
    Dell DataSafe Online (HKLM-x32\…\{C53BCCBE-9268-4C09-82E9-611444A73B3F}) (Version: 2.10.1.3 - Dell)
    Dell Edoc Viewer (HKLM\…\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
    Dell Getting Started Guide (HKLM-x32\…\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
    Dell MusicStage (HKLM-x32\…\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
    Dell Perks Webslice IE8 (HKLM-x32\…\{CF67ED0C-F85D-4791-AED3-3FE882EDB45D}) (Version: 8.0 - Nextjump Inc)
    Dell PhotoStage (HKLM-x32\…\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
    Dell Stage (HKLM-x32\…\{FE182796-F6BA-486A-8590-89B7E8D1D60F}) (Version: 1.7.209.0 - Fingertapps)
    Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell)
    Dell Touchpad (HKLM\…\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.)
    Dell Update (HKLM-x32\…\{3F862535-33F3-4F3F-864E-6D4F6FD3258D}) (Version: 1.5.2000.0 - Dell Inc.)
    Dell VideoStage  (HKLM-x32\…\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
    Dell VideoStage  (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden
    Dell Webcam Central (HKLM-x32\…\Dell Webcam Central) (Version: 2.00.46 - Creative Technology Ltd)
    DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
    Facebook Video Calling 1.2.0.287 (HKLM-x32\…\{B92C5909-1D37-4C51-8397-A28BB28E5DC3}) (Version: 1.2.287 - Skype Limited)
    Facebook Video Calling 3.1.0.521 (HKLM-x32\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
    Google Chrome (HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\Google Chrome) (Version: 51.0.2704.103 - Google Inc.)
    Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
    GoToAssist 8.0.0.514 (HKLM-x32\…\GoToAssist) (Version:  - )
    iCloud (HKLM\…\{ADFDB647-35C0-4254-9EE6-2D9C3B7104BD}) (Version: 5.2.1.69 - Apple Inc.)
    IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
    Intel PROSet Wireless (x32 Version:  - ) Hidden
    Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2361 - Intel Corporation)
    Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.2.0.0587 - Intel Corporation)
    Intel(R) PROSet/Wireless WiFi Software (HKLM\…\{25FBDA9A-E868-4B3B-B9FF-D923818511A1}) (Version: 14.2.0000 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
    Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\…\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
    Intel(R) WiDi (HKLM-x32\…\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation)
    Intel(R) Wireless Display (HKLM\…\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
    Internet Explorer (x32 Version: 8 - Microsoft Corporation) Hidden
    iTunes (HKLM\…\{9F4BF859-C3A4-4AB6-BDD1-9C5D58188598}) (Version: 12.4.1.6 - Apple Inc.)
    Java 7 Update 67 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.670 - Oracle)
    Java 8 Update 45 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
    Java(TM) 6 Update 27 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86416027FF}) (Version: 6.0.270 - Oracle)
    Java(TM) 6 Update 27 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83216027FF}) (Version: 6.0.270 - Oracle)
    JavaFX 2.1.1 (HKLM-x32\…\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
    Microsoft Office Click-to-Run 2010 (HKLM-x32\…\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Professional Plus 2013 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 15.0.4833.1001 - Microsoft Corporation)
    Microsoft Office Starter 2010 - English (HKLM-x32\…\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\…\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\…\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version: 8.0.51011 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Licensing Component (Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
    PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
    Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.09.20 - Dell Inc.)
    RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
    Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
    Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)
    Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\…\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
    Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
    Roxio Creator Starter (HKLM-x32\…\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
    Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
    Safari (HKLM-x32\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
    Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
    Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
    SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1200 - SUPERAntiSpyware.com)
    TeamViewer 9 (HKLM-x32\…\TeamViewer 9) (Version: 9.0.41110 - TeamViewer)
    TrustedID (HKLM-x32\…\{C16A92EF-017B-4839-9C75-FBADB5A1FA27}) (Version: 5.0 - TrustedID)
    Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
     
    ==================== Custom CLSID (Whitelisted): ==========================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-3254994897-3864387644-3395939058-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Mich\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
     
    ==================== Scheduled Tasks (Whitelisted) =============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    Task: {097891E7-A1FA-45DB-8970-D66BEA02FE26} - System32\Tasks\{2D167E16-22C5-47C5-B428-2DD72CB1E184} => C:\Program Files (x86)\iTunes\iTunes.exe
    Task: {117D1711-A022-4A6C-B4E8-25F0E70A79AB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {3E51C7F5-752B-4C3B-9687-86278CFA42A0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-04-12] (Microsoft Corporation)
    Task: {40A12098-818A-400A-9F40-F5E9FFE4E0D3} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
    Task: {5C50D41F-9E7C-47AF-B4F5-CEDB97BF8194} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-14] (Adobe Systems Incorporated)
    Task: {66397D50-9156-499A-896B-46BE59613F40} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
    Task: {685A250F-1A02-4E24-9D1E-DFA18EE5FB3C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
    Task: {6FE65E53-3E23-440D-9149-D7B66E903213} - System32\Tasks\{5805F2ED-FCF7-4132-A918-604FC3F9E978} => C:\Program Files (x86)\iTunes\iTunes.exe
    Task: {7610959A-0C0A-4EC7-9C23-2A62418BDDA4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated)
    Task: {8F515F50-F1AB-492D-B156-7284870B3DF0} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
    Task: {9986ADE0-77F3-45DD-BD5E-530D77B27D5D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
    Task: {9EEF7C7A-ECBC-47D8-9E0E-CF0F3DCDEE35} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-04-12] (Microsoft Corporation)
    Task: {A08DF513-C0B6-48A9-9AC9-596ED754260F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
    Task: {A67037A5-1A1D-40AD-BCA7-19F7A55AA16B} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
    Task: {ABBE246E-B21C-4430-90CB-C179E73660A8} - System32\Tasks\{3BD868C2-52A2-4F77-BDB6-F769CA421241} => C:\Program Files (x86)\iTunes\iTunes.exe
    Task: {C8633B7F-E5D4-451A-B1C5-72B27FCBF613} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
    Task: {D60C9C31-436B-41C9-9CC8-57E773663A9F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
    Task: {FE337633-7008-4FE4-9030-E6D12F8225ED} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-11] (Facebook Inc.)
     
    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
     
    Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job => C:\Users\Mich\AppData\Local\Facebook\Update\FacebookUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000Core.job => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1000UA.job => C:\Users\Mich\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1001Core1cf16c338b4de59.job => C:\Users\Ed\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3254994897-3864387644-3395939058-1001Core1d163702fefa5a5.job => C:\Users\Ed\AppData\Local\Google\Update\GoogleUpdate.exe
     
    ==================== Shortcuts =============================
     
    (The entries could be listed to be restored or removed.)
     
    ==================== Loaded Modules (Whitelisted) ==============
     
    2011-07-27 21:07 - 2011-07-27 21:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
    2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2016-04-22 01:07 - 2016-04-22 01:07 - 01337144 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2015-02-23 18:30 - 2016-04-19 19:26 - 00114888 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
    2015-10-27 18:14 - 2015-09-01 12:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    2011-10-05 13:15 - 2011-08-18 11:05 - 02751808 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
    2011-10-05 14:51 - 2011-04-10 14:40 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
    2011-07-27 21:07 - 2011-07-27 21:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
    2010-11-17 11:35 - 2010-11-17 11:35 - 00514544 _____ () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
    2012-02-01 11:50 - 2012-02-01 11:50 - 00968048 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
    2016-05-11 03:58 - 2016-05-11 03:58 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f1b815cf32572cea383bc47659c174fa\IsdiInterop.ni.dll
    2011-10-05 12:23 - 2010-11-06 00:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
    2016-04-22 01:08 - 2016-04-22 01:08 - 01047864 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2016-03-18 22:56 - 2016-03-18 22:56 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2016-04-22 01:07 - 2016-04-22 01:07 - 00244024 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
    2015-10-27 18:14 - 2015-09-01 08:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
    2010-11-24 23:44 - 2010-11-24 23:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
    2012-02-01 11:44 - 2012-02-01 11:44 - 08151040 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
    2012-02-01 11:44 - 2012-02-01 11:44 - 02278400 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
     
    ==================== Alternate Data Streams (Whitelisted) =========
     
    (If an entry is included in the fixlist, only the ADS will be removed.)
     
     
    ==================== Safe Mode (Whitelisted) ===================
     
    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
     
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
     
    ==================== Association (Whitelisted) ===============
     
    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
     
     
    ==================== Internet Explorer trusted/restricted ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry.)
     
     
    ==================== Hosts content: ===============================
     
    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
     
    2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
     
     
    ==================== Other Areas ============================
     
    (Currently there is no automatic fix for this section.)
     
    HKU\S-1-5-21-3254994897-3864387644-3395939058-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Mich\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 75.75.76.76 - 75.75.75.75
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.
     
    ==================== MSCONFIG/TASK MANAGER disabled items ==
     
    (Currently there is no automatic fix for this section.)
     
     
    ==================== FirewallRules (Whitelisted) ===============
     
    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
    FirewallRules: [{BFAC85B0-8458-4635-94CC-83A71DC1E9A1}] => (Allow) C:\Program Files (x86)\Dell\VideoStage\VideoStage.exe
    FirewallRules: [{63749035-E4F4-49C1-93D6-7B526AAE54E8}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
    FirewallRules: [{0AE6250A-9076-4119-8D1C-313658FAF41C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{E3700119-20EE-4A61-8379-AB2D04961576}] => (Allow) LPort=2869
    FirewallRules: [{868AE0DC-FD64-4385-B800-A40EBD0CFABA}] => (Allow) LPort=1900
    FirewallRules: [{78BCDD1A-F795-4CB1-B1F2-09E08D877F96}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{2E6ECBED-8325-4F01-88CC-AC3CCCC13D7B}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
    FirewallRules: [{A6987437-93DE-4931-9445-DCE8D0958236}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{30B7EBC9-6171-4221-885C-377CDDD95E7C}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{822A5918-FE4D-4B68-9601-EFFDD37B9C55}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe
    FirewallRules: [{1B672475-D4A1-48D2-BDD3-D5B4CC23F8FA}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe
    FirewallRules: [{FED9AF36-06B6-4830-B7DC-D000B53C432B}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe
    FirewallRules: [TCP Query User{5FD1672C-3261-4E85-82F8-CD604EF6F4AA}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Block) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
    FirewallRules: [UDP Query User{B3087126-2230-4409-829A-464E08D2E240}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Block) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
    FirewallRules: [{6E5EC36A-F0A1-46B1-9E2E-3FE5623A4B60}] => (Allow) C:\Users\Mich\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
    FirewallRules: [{146E5909-93C0-4539-986D-858A2F3B5329}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
    FirewallRules: [{D985C636-0CC9-4FE5-BE99-6B48AFD7D0D8}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
    FirewallRules: [{F5733F38-9E8C-4646-9800-F5A8BCB11B4D}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
    FirewallRules: [{46DE42C5-B5B3-4F9C-9DF9-CFF327F9F33D}] => (Allow) C:\Users\Mich\AppData\Local\Google\Chrome\Application\chrome.exe
    FirewallRules: [{34ACAADB-3377-4A2E-AB01-29D27DCEFEAE}] => (Allow) C:\Users\Mich\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
    FirewallRules: [{E9330290-048B-4256-B495-9CC09CC1D6C2}] => (Allow) C:\Users\Mich\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
    FirewallRules: [TCP Query User{84AD8C05-C7DC-44A5-9FCC-89EB386296C3}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Allow) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
    FirewallRules: [UDP Query User{94DF4912-4D2C-4FC2-BAF5-654E8FF9C59F}C:\program files (x86)\dell\dell datasafe online\nobuclient.exe] => (Allow) C:\program files (x86)\dell\dell datasafe online\nobuclient.exe
    FirewallRules: [{428720FC-EBFE-4828-94EE-8F68ADEC696C}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [{9CB3C3A6-F2E9-4DCE-A8D3-E7810174BD76}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{ECCB822C-B4B6-40A0-8F08-643EDC2FCF82}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{4B64EF89-C1D8-497F-B832-E18E95414525}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    FirewallRules: [{9C2DAFEB-8B04-4C33-A815-2A3ED289734B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    FirewallRules: [{40AD4E30-A8D1-4B12-BD5C-25D533271C5A}] => (Allow) C:\Users\Mich\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
    FirewallRules: [{876DE33A-54E1-41CF-B24D-12F5F6D4FBF8}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
    FirewallRules: [{465C6FE1-B4DF-40C1-80DA-9AEE28683E31}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
    FirewallRules: [{C764FCAC-A31D-4782-A153-EDBD7DCB2B2C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
    FirewallRules: [{2BD5A315-B67F-4DA0-9367-884A4656DF2A}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
    FirewallRules: [{28177821-4C83-4DD0-9D96-35E889D7A97B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
    FirewallRules: [{AEEEC527-1AF1-4CE4-9A6E-C759E5A6B125}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{1A5D74F3-99DF-4E38-AB70-21024131FD26}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{DB2565B0-5C5F-462C-B724-6D1B166FC15D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{7A335D39-6869-4047-9417-D2D4187D0390}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{743159AE-6E05-4216-8D1F-2A4A2D11C9FC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{3A71DA86-10CB-4496-AA6B-8268FEEF22DD}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{BFD96DFD-C0F4-4248-BC24-54D01D4AD45D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{B0233BAC-818D-42D8-A7A3-718996A77CE3}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{972A8CF8-3C8F-4CEE-A11F-C9794559CBD6}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{0DE8E662-189D-4F65-BE0A-3D5A9D1EAD6B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{A8943CCB-B949-4AA6-B9FB-9A4DD4032650}] => (Allow) C:\Program Files\iTunes\iTunes.exe
    FirewallRules: [{B35F8DB5-9AC8-4FF7-8CAD-C4600216D9F5}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe
     
    ==================== Restore Points =========================
     
    05-07-2016 03:50:30 Windows Update
    08-07-2016 04:20:16 Windows Update
    11-07-2016 21:48:31 Windows Update
    13-07-2016 03:00:12 Windows Update
    16-07-2016 21:07:52 JRT Pre-Junkware Removal
     
    ==================== Faulty Device Manager Devices =============
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
    Error: (07/17/2016 08:02:18 AM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
    Description: Product: Dell Update – The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738. The arguments are: , ,
     
    Error: (07/17/2016 07:53:48 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
     
    Error: (07/16/2016 08:53:00 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
    Description: Product: Dell Update – The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738. The arguments are: , ,
     
    Error: (07/16/2016 08:48:24 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
     
    Error: (07/16/2016 08:28:23 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
    Description: Product: Dell Update – The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738. The arguments are: , ,
     
    Error: (07/16/2016 08:24:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
     
    Error: (07/16/2016 01:25:54 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80004005
     
    Error: (07/15/2016 06:28:24 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80004005
     
    Error: (07/15/2016 05:42:00 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80004005
     
    Error: (07/14/2016 07:59:21 PM) (Source: MsiInstaller) (EventID: 10005) (User: NT AUTHORITY)
    Description: Product: Dell Update – The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2738. The arguments are: , ,
     
     
    System errors:
    =============
    Error: (07/17/2016 08:09:39 AM) (Source: BROWSER) (EventID: 8032) (User: )
    Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{33E5BA2A-21AA-4562-B886-E625191AA1AB}.
    The backup browser is stopping.
     
    Error: (07/17/2016 08:01:55 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
     
    Error: (07/17/2016 07:55:54 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
     
    Error: (07/16/2016 09:40:39 PM) (Source: BROWSER) (EventID: 8032) (User: )
    Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{33E5BA2A-21AA-4562-B886-E625191AA1AB}.
    The backup browser is stopping.
     
    Error: (07/16/2016 08:49:10 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)
     
    Error: (07/16/2016 08:46:58 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has stopped unexpectedly.
     
    Module Path: C:\windows\System32\IWMSSvc.dll
     
    Error: (07/16/2016 08:46:58 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has stopped unexpectedly.
     
    Module Path: C:\windows\System32\IWMSSvc.dll
     
    Error: (07/16/2016 08:46:58 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has stopped unexpectedly.
     
    Module Path: C:\windows\System32\IWMSSvc.dll
     
    Error: (07/16/2016 08:46:57 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has stopped unexpectedly.
     
    Module Path: C:\windows\System32\IWMSSvc.dll
     
    Error: (07/16/2016 08:46:55 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
    Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
    %%1056 = An instance of the service is already running.
     
     
     
    CodeIntegrity:
    ===================================
      Date: 2015-08-16 15:41:58.239
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
     
      Date: 2015-08-16 15:41:57.789
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpx.exe because the set of per-page image hashes could not be found on the system.
     
      Date: 2015-08-16 15:41:57.242
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
     
      Date: 2015-08-16 15:41:56.837
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\avgdumpa.exe because the set of per-page image hashes could not be found on the system.
     
      Date: 2012-10-26 05:01:31.909
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\McAfee\Temp\qxzEEDB\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
     
      Date: 2012-10-26 05:01:31.904
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\McAfee\Temp\qxzEEDB\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
     
      Date: 2012-10-26 05:01:31.902
      Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\McAfee\Temp\qxzEEDB\mfeelamk.sys because the set of per-page image hashes could not be found on the system.
     
     
    ==================== Memory info =========================== 
     
    Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz
    Percentage of memory in use: 33%
    Total physical RAM: 6051.17 MB
    Available physical RAM: 4020.68 MB
    Total Virtual: 12100.53 MB
    Available Virtual: 9814.95 MB
     
    ==================== Drives ================================
     
    Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:444.26 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: BA3A09FA)
    Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
    Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=581.4 GB) - (Type=07 NTFS)
     
    ==================== End of Addition.txt ============================

    TrustedID  <– If this is a program you installed and use thats ok but if you did not, then go to Programs and Features in the Control Panel and uninstall it

     

     

     


     
    Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
    Please copy the entire contents Inside of the code box below beginning with START and ending with END
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
    Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
     
    Start
    CloseProcesses:
    CreateRestorePoint: 
    HKLM-x32\…\Run: [] => [X]
    SearchScopes: HKLM-x32 -> DefaultScope {C26464FC-6658-404B-B6A4-9D64D370854D} URL = 
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    CHR Extension: (Viralands Age Verify) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfjjinndcdohhjckcokpfkihdogegfib [2016-02-29]
    2016-07-17 08:09 - 2016-07-17 08:09 - 00000000 ____D C:\Users\Mich\Desktop\FRST-OlderVersion
    2016-07-04 12:36 - 2016-07-04 12:36 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair (1).exe
    2016-07-04 12:34 - 2016-07-04 12:34 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair.exe
    C:\Users\Mich\AppData\Local\Temp\ReimagePackage.exe
    CMD: ipconfig /flushdns
    Hosts:
    EmptyTemp:
    End
    
     
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

     

    Fix result of Farbar Recovery Scan Tool (x64) Version: 17-07-2016 03
    Ran by [removed] (2016-07-17 14:43:43) Run:1
    Running from C:\Users\[removed]\Desktop
    [removed]
    Boot Mode: Normal
    ==============================================
     
    fixlist content:
    *****************
    Start
    CloseProcesses:
    CreateRestorePoint: 
    HKLM-x32\…\Run: [] => [X]
    SearchScopes: HKLM-x32 -> DefaultScope {C26464FC-6658-404B-B6A4-9D64D370854D} URL = 
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    CHR Extension: (Viralands Age Verify) - C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfjjinndcdohhjckcokpfkihdogegfib [2016-02-29]
    2016-07-17 08:09 - 2016-07-17 08:09 - 00000000 ____D C:\Users\Mich\Desktop\FRST-OlderVersion
    2016-07-04 12:36 - 2016-07-04 12:36 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair (1).exe
    2016-07-04 12:34 - 2016-07-04 12:34 - 00603920 _____ (Reimage) C:\Users\Mich\Downloads\ReimageRepair.exe
    C:\Users\Mich\AppData\Local\Temp\ReimagePackage.exe
    CMD: ipconfig /flushdns
    Hosts:
    EmptyTemp:
    End
    *****************
     
    Processes closed successfully.
    Restore point was successfully created.
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
    "HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
    "HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
    C:\Users\Mich\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfjjinndcdohhjckcokpfkihdogegfib => moved successfully
    C:\Users\Mich\Desktop\FRST-OlderVersion => moved successfully
    C:\Users\Mich\Downloads\ReimageRepair (1).exe => moved successfully
    C:\Users\Mich\Downloads\ReimageRepair.exe => moved successfully
    C:\Users\Mich\AppData\Local\Temp\ReimagePackage.exe => moved successfully
     
    ========= ipconfig /flushdns =========
     
     
    Windows IP Configuration
     
    Successfully flushed the DNS Resolver Cache.
     
    ========= End ofCMD: =========
     
    C:\Windows\System32\Drivers\etc\hosts => moved successfully
    Hosts restored successfully.
     
    =========== EmptyTemp: ==========
     
    BITS transfer queue => 8388608 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 29666414 B
    Java, Flash, Steam htmlcache => 125812 B
    Windows/system/drivers => 191794055 B
    Edge => 0 B
    Chrome => 235447825 B
    Firefox => 0 B
    Opera => 0 B
     
    Temp, IE cache, history, cookies, recent:
    Default => 66228 B
    Public => 0 B
    ProgramData => 0 B
    systemprofile => 42371347 B
    systemprofile32 => 112431 B
    LocalService => 3464644653 B
    NetworkService => 79438024 B
    Mich => 773045275 B
    Ed => 15921790 B
     
    RecycleBin => 24346387276 B
    EmptyTemp: => 27.2 GB temporary data Removed.
     
    ================================
     
     
    The system needed a reboot.
     
    ==== End of Fixlog 14:45:07 ====

    Thats good to hear, just as a precaution, lets run a free online virus scanner

     

     

    [external image: 3330203e-7304-4336-aa0a-eb3d8b6e3b35_zps]
     
    Please run this Free Online Virus Scanner from ESET 
    • Please be patient, depending on your system the scan can complete in 30 minutes and on others much longer.
    • You want the Online One-Time Scan
    • Note: It will run using Internet Explorer, Firefox or Chome.
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Click Start
    • Make sure that the option Remove found threats is NOT TICKED, and the option Scan unwanted applications is checked
    • Click Scan
    • Wait for the scan to finish
    • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    • Sometimes these online scanners will run great on one system and not on another, you can try this one from Trendmicro, you will need the 64 Bit version

      http://housecall.trendmicro.com/

       

       

      I dont see any anti virus programs installed, just McAfee plishing filter, you need to install one, here is the free version from Avast. 

      https://www.avast.com/en-us/index

       

       

      You have TeamViewer installed, do you use it, have you given anyone else access to your computer?

       

       

      We used Malwarebytes to clean your system and you also have SuperAntiSpyware installed, Malwarebytes is the better of the two so you may want to uninstall SuperAntiSpyware. 

      Ask AI

      AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

      Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI